Honest limits

A browser is not a VPN and does not hide your IP address. HTTPS encrypts the connection; it does not hide that you contacted a host. Tracking protection is list-based and not absolute: known ads, analytics, and social trackers from bundled lists are blocked on the device, but no blocker catches everything. Private Browser Incognito is rated 17+ for unrestricted web access and is intended for adults.

A private browser can forget locally and still send a page in the clear. History, cookies, and cache are one problem. The path between the phone and the host is another. HTTPS-Only Mode is the default that keeps that path encrypted unless you agree otherwise. It is not a slogan on a lock icon. It is a rule about which scheme the app will use, and a prompt when the only answer is insecure HTTP.

Private Browser Incognito turns that rule on by default. The app asks before falling back to HTTP. Encryption hides contents from a listener on the local network. It does not hide your IP. It does not replace on-device blocking, a forgetful session, or erase. This article separates those jobs so the padlock is not asked to do work it cannot do.

What HTTPS-Only Mode actually does

HTTPS is ordinary web encryption. The browser and the site agree on a protected channel. A cafe router, a workplace gateway, or someone on the same Wi-Fi does not get a readable copy of the HTML, the cookies on that request, or the form you submit. DNS and the fact of a connection can still be visible to the network. The site at the other end still sees you as a client with an address.

HTTP is the older scheme without that channel. The same page, the same headers, and the same body travel as data a local observer can inspect. Plenty of the web has moved. Some hosts have not: old printers, lab pages, internal tools, and a long tail of forgotten servers. A browser that silently downgrades will load those pages and will also load traps that look like the site you typed.

HTTPS-Only Mode prefers the encrypted scheme. When a URL is entered without a scheme, or when a link is written as HTTP, the browser tries HTTPS first. If the host cannot serve HTTPS, the mode does not invent a certificate. It stops and asks. That pause is the product. A private browser that skipped the pause would still be private on disk and noisy on the wire.

This is not certificate pinning as a marketing feature, not a custom root we control, and not a claim that every site is honest. A valid HTTPS page can still be a phishing page. Encryption binds you to a host. It does not vouch for the host’s intentions. You remain responsible for what you visit. The 17+ rating exists because this is a real web browser with unrestricted access.

Default on, and the HTTP fallback prompt

Defaults matter more than settings pages. A switch that starts off will stay off for most people. Private Browser Incognito ships HTTPS-Only Mode enabled. You can still reach an HTTP resource. You do it on purpose, after the app asks. The prompt is a choice, not a lecture. It tells you the next hop will not be encrypted, and it waits.

That design matches the rest of the app’s caution about extra network. Search suggestions stay off until you agree to share a keystroke. Camera permission for Intruder Photo is asked when you enable the feature, never at the lock screen. HTTP fallback belongs in the same family: an action that leaves the device should be explicit. We do not download block lists at runtime. We do not run an app server for browsing. We also do not quietly load a cleartext page because it was faster.

If you confirm the fallback, the page loads as HTTP for that decision. If you cancel, you stay off that host until you have another URL. There is no silent retry that hopes the next redirect will be fine. There is also no scare copy that calls every HTTP site a crime. Some HTTP destinations are machines you own. The prompt exists so ownership and risk stay in your hands.

HTTPS-Only Mode does not log the prompt to us. There is no account and no dashboard. The App Store privacy label is Data Not Collected. Your traffic for this feature is the page you open, the same as any other navigation. If you later erase the session, that page is gone from the phone. The network that already saw the connection cannot be erased by a trash button.

Private Browser IncognitoHTTPS-Only Mode on by default. Asks before insecure HTTP. Get the app

Encryption is not anonymity

People collapse three ideas into one padlock: the connection is encrypted, the phone forgot the visit, and nobody can tell who you are. Only the first belongs to HTTPS. The second belongs to a session with no history file and to one-tap erase. The third is a VPN or something stronger, and this app is neither. Sites you visit and your network operator can still see your IP address.

A workplace network can still log that you contacted a host. A school filter can still see destinations. A cafe can still count devices. HTTPS makes the payload harder to read. It does not move you to another country and does not assign you a new address. If the threat you have is a person reading your screen, use App Lock and erase. If the threat is a network that should not see destinations, you are shopping for a different product.

We do not claim fingerprint spoofing, Tor, or a proxy we market. iOS can honor a system VPN you installed yourself. That is your network, not a feature we sell. Private Browser Incognito is iOS only. It is a forgetful browser with on-device lists, not a tunnel. For the checklist that keeps those columns separate, see The Best Private Browser for iPhone: What Actually Matters.

How HTTPS sits next to on-device blocking

Blocking and encryption answer different requests. A tracker that loads over HTTPS is still a tracker. An ad slot served from an encrypted host is still an ad slot. Content-blocking rules powered by the open Disconnect lists stop known ads, analytics, and social trackers on the device. Those lists ship inside the app. They are not downloaded at runtime. HTTPS-Only Mode does not decide whether a third-party script is allowed. The lists do.

The two features stack. A blocked request never leaves. An allowed request, when it does leave, prefers HTTPS. Neither feature is absolute. New trackers appear. Some requests will never match a rule. Per-site exceptions exist when a page needs a blocked resource to function. Encryption can also fail if you accept HTTP. Honesty about both gaps belongs in the same article as the defaults. The longer version of the blocking gap is in Tracker Blocking Is Not Absolute.

Where the lists live is a third question. A DNS filter or a VPN adblocker sits in the network path. Our blocker does not. For how bundled Disconnect rules match on the phone, read How On-Device Block Lists Work. HTTPS-Only Mode would still matter if blocking were off. Blocking would still matter if every page were HTTPS. Do not treat one as a substitute for the other.

What the prompt is asking you to decide

The fallback dialog is a narrow question: load this host without encryption, or do not. It is not asking whether the site is trustworthy, whether you should log in, or whether the page is suitable. Those remain your decisions as an adult using a 17+ browser. The prompt only refuses to make the encryption decision for you in the background.

Useful reasons to accept: a device on your desk that never grew a certificate, a local documentation server, a page you already understand. Useful reasons to refuse: a link from a message you did not expect, a URL that almost matches a brand you know, a public network you do not control. We will not pretend a flowchart covers every case. The architecture is the pause. Your judgment is the rest.

Mixing this with a forgetful session is the point of putting HTTPS-Only Mode in a private browser instead of only in a general one. Every tab is already a private session in memory. There is no history file to clear. If you load an HTTP page by mistake, erase still destroys cookies, cache, and site data for the session. It cannot unsay the packets. It can stop the residue from sitting on the phone. For that memory model, see A Browser With No History File at All.

A session that starts encrypted and still forgets

The compact comparison is the one worth keeping when a listing says “secure browser” and means three different things.

Job HTTPS-Only Mode Not this feature
Connection contents Encrypted unless you accept HTTP A VPN tunnel or a new IP
Default On. Asks before HTTP fallback A setting you have to hunt for
Ads and trackers Unrelated. Lists handle those A guarantee of complete blocking
History Unrelated. No history file anyway Anonymity on the network

Start encrypted. Ask before a downgrade. Block known extra requests on the device. Keep the session in memory. Erase when you are done. Lock the app if someone else can pick up the phone. None of those steps hide your IP. Together they are a local stance: less residue, fewer cleartext pages, nothing to trust us with. Rated 17+. You choose the URLs. You are responsible for using the app lawfully. The padlock is the first switch, not the whole product.

Private Browser IncognitoFree on the App Store. No history, on-device blocking, one-tap erase. Get the app

Frequently asked questions

What is HTTPS-Only Mode on iPhone?

HTTPS-Only Mode prefers an encrypted HTTPS connection for the pages you open. In Private Browser Incognito it is on by default. If a site only answers on insecure HTTP, the app asks before falling back. The mode encrypts the contents of the connection. It does not hide your IP address, and it is not a VPN.

Does HTTPS-Only Mode hide my IP address?

No. Encryption hides the contents of the request from a listener on the local network. The site you visit still sees your IP address, and your network operator still sees that a connection happened. A private browser with HTTPS-Only Mode is not a VPN and does not change your public IP.

Why does a private browser ask before using HTTP?

Plain HTTP sends page contents without that encryption. The fallback prompt is a pause so you can decide whether the destination is worth an unencrypted hop. It is not a scare screen and not a block of the entire web. You choose. The default remains encrypted until you agree to fall back.

Is HTTPS-Only Mode the same as a VPN?

No. A VPN typically tunnels traffic through a remote hop and, in consumer use, changes the IP address sites see. HTTPS-Only Mode only upgrades or holds the connection type to the host you typed. Page loads still go to that host. Private Browser Incognito does not route browsing through our servers.

Does HTTPS-Only Mode block ads and trackers?

No. HTTPS and blocking are different machines. Ads, analytics, and social trackers are stopped by on-device content-blocking rules powered by the open Disconnect lists. Those lists ship inside the app. HTTPS-Only Mode only concerns whether the connection is encrypted. List-based blocking is not absolute.