Honest limits

A browser is not a VPN and does not hide your IP address. Tracking protection is list-based and not absolute: known ads, analytics, and social trackers from bundled lists are blocked on the device, but no blocker catches everything. Private Browser Incognito is rated 17+ for unrestricted web access and is intended for adults.

A block list is only as private as its delivery. If the list is fetched while you browse, the fetcher learns the app is open. If blocking happens on a remote filter, the filter sees destinations. If iOS is asked to send every lookup to a special resolver, that resolver sits in the path for more than one app. On-device lists are the design that keeps those extra parties out: the rules travel in the binary, and they run on the phone that already loaded the page.

Private Browser Incognito uses content-blocking rules powered by the open Disconnect lists. The lists ship inside the app. They are not downloaded at runtime. This is not a DNS filter and not a VPN. This article is the mechanics: where the file lives, what happens at request time, how updates actually arrive, and the gap no list closes. The product-level overview is in On-Device Ad and Tracker Blocking on iPhone.

Where the lists live

On-device means inside the installed app. When you download Private Browser Incognito from the App Store, the lists come with that copy. They are not a second download you opt into. They are not a profile. They are not a subscription feed we host. Opening a tab does not check a list server. The rules are already there, next to the rest of the binary.

That location is a privacy choice. Private Browser Incognito has no accounts, no sign-in, and no app server for browsing. The App Store privacy label is Data Not Collected. There is no analytics SDK, no ads in the app, and no third-party SDKs. A list updater would have been a quiet exception to that story. We did not add one. The network the app makes is the pages you visit, a search engine if you search, optional suggestions if you opt in, downloads you start, and StoreKit if you purchase. Block lists are not on that list because they never leave with you.

Disconnect is the source of the categories, not a tracker we are naming as a villain, and not a ranking of other products. We describe what the rules catch with generic labels: ads, analytics, social trackers. An ad request tries to load a creative or an auction. An analytics beacon reports that a page viewed. A social widget tries to attach a share button or a comment count from a network you did not open as the main page. Company names do not belong in the examples.

Shipping in the binary also means a freeze. The copy you have is the copy that matches. A host that appeared after this app version shipped can miss until you install an update. That is the cost of the design, and it is said in the same breath as the feature. The longer honesty note is Tracker Blocking Is Not Absolute.

What happens when a page loads

You type a URL or follow a link. The browser loads the document from that host. Subresources try to follow: scripts, images, frames, beacons. Content-blocking rules inspect those requests against the bundled lists. A match does not go out. A non-match does, using the usual HTTPS path when the site supports it. HTTPS-Only Mode is a separate default. It encrypts the hop. It does not decide whether a tracker is allowed.

Matching is mechanical. It is not a person reading the page. A first-party script served from the same site you opened may not look like a tracker. A renamed host may not be on the list yet. A pixel folded into the article’s own origin can pass. Those are limits of rule systems on iOS, not footnotes. Built-in ad blocking is still useful. It is still incomplete. For the “built into the browser” framing, see Ad Blocking Built Into a Private Browser.

When a page needs a blocked resource, a per-site exception is the local fix. It lives on that device. It does not report to us. It does not disable the lists on every other tab. Finish the task. Erase if you do not want that site’s cookies for the rest of the session. One-tap erase closes every tab and destroys cookies, cache, and site data. The lists themselves are not erased. They are part of the app, not part of the session.

You may see fewer banners and fewer third-party scripts. You may also see a hole where an ad slot was. Both are the feature working. We do not invent a blocked-item count as a scientific result. A counter can illustrate that rules fired. It is not a lab study, and it is not a promise about next week’s hosts.

Private Browser IncognitoDisconnect lists ship in the app. Nothing to fetch while you browse. Get the app

Not a DNS filter, not a VPN, not a list server

Three other machines get confused with on-device lists. A DNS filter answers name lookups and can refuse known ad domains. It often needs a configuration profile or a local VPN shell so iOS will send lookups to that resolver. It can work across apps. It also places a resolver in the path. Our rules do not. They apply to this browser. They do not claim to clean Mail, Safari, or a game’s web view.

A VPN encrypts traffic to a remote hop and, in typical consumer use, changes the IP address sites see. That is a network product. Private Browser Incognito is not one. We do not hide IP addresses. We do not route browsing through our servers. We do not market a proxy. Sites you visit and your network operator can still see your address. On-device blocking only means a matched extra request never started.

A remote list server is the third lookalike. Some blockers keep a fresh file in the cloud and pull it on a timer. Freshness is real. So is the telemetry of the pull. We took the freeze instead. Updates arrive as App Store updates to the app that contains the lists. If you never update, you keep the older freeze. That is visible, boring, and honest.

Design Where lists live What else is in the path
On-device content blocking Inside this app’s binary Nothing extra. This process only
DNS filter A resolver you install Lookups for many apps
VPN adblocker A remote hop Your traffic, often a new IP story
Runtime list download A server you contact while browsing A fetcher that knows the app is open

If a listing cannot say which row it occupies, it is not done explaining the feature. On-device is the row that matches no accounts and Data Not Collected. It is not the row that covers the whole phone. Choose it for the right reason.

What this does not replace

Lists do not replace a forgetful session. Every tab in this app is still a private session in memory. There is no history file to clear. Blocking extra beacons does not create or destroy that file. Lists do not replace erase. Cookies for the site you meant to visit still exist until you destroy the session. Lists do not replace App Lock. A person holding the phone is not a tracker host.

Lists do not replace HTTPS-Only Mode. Encryption hides contents from a local listener. A tracker over HTTPS is still a tracker until a rule matches. Lists do not hide you from the destination. They do not spoof fingerprints. They do not make you anonymous. Rated 17+ still applies: this is a real web browser with unrestricted access. You choose URLs. You are responsible for using the app lawfully.

Stealth Suite does not change how lists work. Decoy, panic, the break-in log, self-destruct, and the encrypted vault answer a borrowed phone and files you chose to keep. The blocker is free and already in the binary. There is no paid “stronger list.” There is no cloud dashboard of threats. If you needed a live feed of new names, you would be buying a different architecture, with a different privacy cost.

A local stance, including the freeze

The useful summary is short. Disconnect categories ship in the app. Rules run on the device at request time. No list download while you browse. Not a DNS filter. Not a VPN. Not 100 percent. New names, first-party code, and exceptions remain. App updates are how the file thaws. Combined with no history, one-tap erase, HTTPS-Only Mode, and no accounts, that is a coherent local stance: less extra traffic, nothing to trust us with, a gap we will not paper over.

Use the lists. When a page breaks, exception, finish, erase. When you are done with the session, destroy it. When someone else might open the app, lock it. When a host is only on HTTP, the app will ask. None of those switches hides your IP. Together they are the product we can stand behind without a list server in the story.

Private Browser IncognitoFree on the App Store. No history, on-device blocking, one-tap erase. Get the app

Frequently asked questions

Where do Private Browser Incognito block lists live?

Inside the app. Content-blocking rules powered by the open Disconnect lists ship in the binary and run on the device. They are not downloaded at runtime. There is no list server in the browsing path, and there is no app server for browsing.

Are on-device block lists a DNS filter?

No. A DNS filter intercepts name lookups, often with a profile or a local VPN shell, and can affect many apps. On-device lists in this browser are content-blocking rules for this app’s tabs. They do not claim to clean Safari, Mail, or other processes.

Do the Disconnect lists download while I browse?

No. Block lists are not downloaded at runtime. An app update is how a newer copy arrives. That freeze is the cost of keeping a list server off the phone. The network the app makes is the pages you visit, search you choose to send, optional suggestions, downloads you start, and StoreKit.

Is on-device blocking a VPN?

No. A browser is not a VPN and does not hide your IP address. Lists match known ads, analytics, and social trackers on the device. Page loads still go to the sites you open. We do not route browsing through our servers. Blocking is list-based and not absolute.

What do Disconnect lists block?

Known ads, analytics, and social trackers, described with generic labels rather than company names. Matching is rule-based. New hosts, first-party scripts, and per-site exceptions can still get through. No blocker catches everything. Treat the lists as a reduction of known noise.