Privacy

your browsing stays a local matter.

No account to create, no sync server to trust and no telemetry we could hand over even if someone asked politely with a subpoena.

01

principles.

Three rules the product was designed around.
01

Block before the request

Trackers and fingerprinting scripts are dropped at the network layer, not hidden after they load.

02

Encrypt at rest, locally

History, cookies and cache are sealed with a key held in the Secure Enclave. Losing the Mac loses the data.

03

Collect nothing by default

Crash reports are opt-in and stripped of URLs. There is no analytics SDK in the binary.

02

what is stored.

And where it lives.
Data
Where
Sent to us
History and open tabs
Where: This Mac, encrypted
Sent to us: Never
Passwords and passkeys
Where: iCloud Keychain
Sent to us: Never
Extension permissions
Where: This Mac, per space
Sent to us: Never
Crash reports
Where: Opt-in, URL-stripped
Sent to us: Only if you say yes
Update checks
Where: Anonymous version ping
Sent to us: Version number only

The shield report

see exactly what was turned away.

Click the shield in the address field for a per-site log: what was requested, what was blocked and what the page tried to fingerprint. Nothing summarised, nothing hidden.

Blocked on this page
last 30s
Ad networks9
Analytics beacons5
Canvas fingerprinting3
Private by default
Every new window. There is no separate mode to remember, and no badge of shame when you use it.

browse like nobody is watching.

Because nobody is. Free, no account, macOS 15 or later.