A browser is not a VPN. Sites you visit and your network operator can still see your IP address. Tracking protection is list-based and not absolute: known ads, analytics, and social trackers from bundled lists are blocked on the device, but no blocker catches everything. Private Browser Incognito is rated 17+ for unrestricted web access and is intended for adults. We do not claim fingerprint spoofing, randomization, or anti-fingerprint magic as a product.
Fingerprinting is the word people reach for when they want a private tab to look like a stranger. The hope is that a site will see a blank machine: no fonts, no canvas, no stable shape. That is not how a real web browser works, and it is not a claim we make. Private Browser Incognito is a forgetful iPhone browser. It holds sessions in memory, blocks known trackers from lists that ship on the device, and lets you destroy the session in one tap. It does not disguise the browser that loaded the page.
This article is the limit, stated as a product sentence rather than a score. We will not invent a uniqueness number. We will not name tracker companies as villains in a demo. We will describe what a page can still observe, what list-based blocking actually cuts, and why omitting a history file is a different job from pretending the visit never had an address.
What a site can still observe
A page that wants to recognize a client does not need a cookie you left last week. It can look at the environment that arrived with the request: screen metrics, language, timezone, installed fonts, how canvas and similar APIs draw, and other stable traits of a real iPhone running a real browser engine. Those signals are not a diary on your phone. They are properties of the session as it talks to the server.
Private mode, incognito, and a no-history engine all still present a browser. They still execute site JavaScript unless you have blocked a specific resource. Fonts still exist. Canvas still draws. We do not spoof those surfaces. We do not randomize them as a feature. If a site runs that kind of script, it can still collect what the platform exposes. Treating erase as a new identity on that site is a category error.
That is uncomfortable copy. It is also the honest one. A product that advertised a rotating disguise would be selling a different machine: noise injected into rendering, fake fonts, a synthetic client. Private Browser Incognito is not that machine. It is iOS only. It loads pages. Privacy here is residue and extra requests, not theater in the rendering pipeline.
What we refuse to claim
We do not claim anti-fingerprint magic. We do not claim spoofing. We do not claim randomization. Those words show up in comparison charts because they sound like a shield. They are not a shield we ship. If another app markets a fingerprint score, ask what the number measures, who generated it, and whether it was measured in this app at all. We will not invent a competing score. A number without a method is advertising.
We also do not claim anonymity, untraceable browsing, Tor, a proxy we operate, or IP hiding. A browser alone does not make you anonymous. The site you typed still sees a connection. Your network operator still sees that a device used the network, and often which hosts were contacted. HTTPS-Only Mode, on by default, asks before falling back to insecure HTTP. Encryption hides content from some observers on the path. It does not hide that you talked to that host, and it does not hide your IP from the host.
Search is the same kind of limit. You can use Google, Bing, DuckDuckGo, Wikipedia, or a custom engine. A query you send is a request that engine can log, from an address it can see. Suggestions stay off by default. The app asks before sharing a keystroke. Choosing an engine changes who receives the query. It does not erase fingerprinting on the pages you open afterward, and it does not hide the IP from that engine.
List-based blocking is not a disguise
Ads, analytics, and social trackers can be stopped when they match content-blocking rules powered by the open Disconnect lists. The lists ship inside the app and run on the device. They are not downloaded at runtime. The app does not sit in the middle of your traffic as a proxy. Blocking is local: a request that matches a known name does not go out. That reduces third-party noise. It is not a new identity.
List-based blocking is not absolute. New names appear. Some requests will never match a rule. First-party scripts that live on the site you typed are often not on a third-party list. You can add per-site exceptions when a page needs a blocked resource to function. Those exceptions are a trade: the page may work, and more of its requests may complete. The longer mechanics of that gap are in Tracker Blocking Is Not Absolute. How the lists live on the phone, rather than in a profile you enable elsewhere, is in On-Device Ad and Tracker Blocking on iPhone.
Do not read a blocked analytics endpoint as a blank fingerprint. The first-party page still ran. The first-party page can still look at fonts and canvas. Blocking a known tracker domain is useful. It is a reduction of known noise. It is not a claim that the remaining client looks like everyone else, or like no one.
IP, headers, and the network you did not rewrite
Fingerprinting talk often swallows the simpler fact: the site still received a request from an IP address. That address is how the response finds you. A private tab does not negotiate a different one. A missing history file does not either. Sites you visit and your network operator can still see it. The dedicated answer is Does a Private Browser Hide Your IP Address?: no.
Ordinary headers still travel with the request. A server that wants to know it is talking to a mobile browser will usually be able to tell. We do not market header fiction. If you configured a VPN yourself in iOS, the system routes traffic; we do not sell that tunnel, and we do not describe this app as one. Workplace and school networks add their own logs. None of those observers live inside the app’s session store. Erase cannot reach them.
There are no accounts and no app server for browsing. The App Store privacy label is Data Not Collected: no analytics SDK, no ads in the app, no third-party SDKs. We do not see a fingerprint dashboard because we do not run one. The sites you visit still might. That split is the whole point of staying off a browsing server. It is not a promise about what those sites compute.
Session residue is a different job
Local privacy is still real. Every tab is a private session held in memory. There is no browsing history feature and no history file to clear. Cookies and cache exist for the life of the session so pages can work. One-tap erase closes every tab and destroys that session data. There is a home-screen quick action so you do not have to open the app first. Erase is permanent. Erased data cannot be recovered, by you or by us.
That architecture answers a borrowed phone, a Recents row that should not exist, and a Settings pane you should not have to remember to open. It does not answer a site that recognized the client while the tab was open. What a private session is, and how it differs from a mode inside a browser that also keeps history, is the subject of Private Browsing on iPhone, Explained Without Myths.
App Lock with a six-digit passcode and Face ID is free in the shipping default. The passcode is never stored. It becomes the key. Forgotten passcodes cannot be recovered. The lock keeps someone from opening the session. It does not change fonts, canvas, or IP. Stealth Suite is optional Apple IAP for a decoy, a panic code, a break-in log, self-destruct, an encrypted vault, and icon colors. Paying for that kit does not buy fingerprint spoofing. There is none to buy.
How to read a comparison that scores you
If a table ranks browsers by a fingerprint grade, treat the grade as someone else’s experiment, not as a feature of this app. Tests differ by site, by script, by OS version, and by what they chose to measure. We will not publish a counter-grade. We will publish the architecture:
- No history file, because the file is never created.
- Disconnect lists on device, not a proxy and not a VPN.
- Blocking that is list-based and not 100 percent.
- No spoofing or randomization of fonts, canvas, or similar signals.
- No accounts, no browsing server, Data Not Collected.
- IP still visible. Rated 17+ for unrestricted web access.
Those bullets are enough to disqualify a lot of marketing, including any of ours that drifted. A forgetful browser is for people who want the phone to forget. A fingerprint product would be for people who want the site to be unsure. We build the first. We will not pretend we built the second.
| Layer | What this browser changes |
|---|---|
| History file on the phone | None. No feature and no file to clear |
| Known ads, analytics, social trackers | Blocked when they match bundled lists |
| Fonts, canvas, similar signals | Not spoofed. Sites can still use them |
| Public IP at the site | Unchanged. Not a VPN |
| A uniqueness score we publish | None. We will not invent one |
Use the table on this app and on anything else you install. If a product cannot say whether it spoofs rendering, whether lists live on the device, or whether it hides IP, it is not finished explaining itself. Private Browser Incognito is built so there is nothing to trust us with: no accounts, lists on device, passcode as the key, session you can throw away. Sites still see requests. Scripts still run. Lists still miss names. Fingerprinting remains a site technique. Our honest limit is that we do not claim to erase it.
Frequently asked questions
Does Private Browser Incognito stop fingerprinting?
No. We do not claim anti-fingerprint magic, spoofing, or randomization as a product. Sites can still use fonts, canvas, and other signals. Private browsing here is about residue on the phone: no history file, session cookies, and list-based blocking. It is not a disguise for the browser that loaded the page.
Does a private browser hide my IP address?
No. A browser is not a VPN and does not hide your IP address. Sites you visit and your network operator can still see it. Fingerprinting and IP addressing are different layers. Omitting a history file does not change the address your network presents to a server.
Is tracker blocking in a private browser 100 percent?
No. Tracking protection blocks known ads, analytics, and social trackers from bundled Disconnect lists that ship inside the app and run on the device. No blocker catches everything. New names appear, some requests never match a rule, and per-site exceptions exist when a page needs a blocked resource.
Can websites still use fonts and canvas to recognize a browser?
Yes. Fonts, canvas, and similar signals remain available to pages that look for them. We do not spoof those surfaces or randomize them as a feature. Treating a private session as a new identity on the site is a myth. The site still sees a real iPhone browser making a real request.
Does blocking trackers make me anonymous?
No. List-based blocking reduces known third-party noise. It does not make you anonymous on the network. The first-party site you typed still sees the visit. Your IP stays visible. Rated 17+ means unrestricted web access: you are responsible for what you visit and for using the app lawfully.