A browser is not a VPN and does not hide your IP address. Tracking protection is list-based and not absolute: known ads, analytics, and social trackers from bundled lists are blocked on the device, but no blocker catches everything. Private Browser Incognito is rated 17+ for unrestricted web access and is intended for adults.
Ad blocking on iPhone is often described as a Safari extension you toggle in Settings, a DNS filter you install as a profile, or a VPN that claims to strip ads in the cloud. Those are different machines. A private browser can do the job in a fourth way: content-blocking rules that ship inside the app and run on the device while you browse, with no list server in the path and no account behind a dashboard.
Private Browser Incognito uses that fourth way. Ads, analytics, and social trackers are stopped by rules powered by the open Disconnect lists. The lists live in the app. This article explains why that location matters, what the categories actually catch, and the gap no honest blocker will close. History is a separate design choice, covered in A Browser With No History File at All. Blocking does not replace a forgetful session, and a forgetful session does not replace blocking.
Why the lists should live on the device
Every extra network hop is a place a privacy product can see you. If block lists are downloaded as you browse, the updater learns that the app is open. If blocking happens on a remote filter, that filter sees destinations. On-device lists remove our servers from the story. Private Browser Incognito has no app server for browsing. Block lists are not downloaded at runtime. They ship inside the app. The App Store privacy label is Data Not Collected.
That is also why this is not a VPN and not a proxy we market. Page loads still go to the sites you visit. Search still goes to the engine you chose. Suggestions stay off until you agree to share a keystroke. The blocker does not insert a tunnel in front of those connections. iOS content blocking has limits: it is rule matching, not a human reading the page. A first-party script served from the same site you opened may not look like a tracker. That is one reason blocking is not 100 percent.
What the Disconnect lists catch
The open Disconnect lists are a well-known set of categories used by many privacy tools. In this app they power content-blocking rules for three buckets: ads, analytics, and social trackers. We describe those buckets with generic labels. An ad request tries to load a creative or an auction. An analytics beacon reports that a page viewed. A social widget tries to attach a share button or a comment count from a network you did not open as the main page.
The lists ship in the binary. When you tap a link, matching requests are not sent. You may see fewer banners, fewer popovers, and fewer third-party scripts. Pages can also look different or miss a module that was actually an ad slot. That is the visible half of blocking. The invisible half is the request that never left the phone.
We do not publish a percentage of trackers caught. We do not invent a count of blocked items as a scientific result. A counter in a demo can illustrate the idea. It is not a lab study. New names appear constantly. A list that shipped in the last app update will miss something that was registered this week. That sentence belongs next to the feature, not in a footnote nobody reads.
Disconnect is the source of the lists, not a tracker we are calling out as a villain, and not a company whose products we are ranking. If you need the rest of the private-browser checklist (history, erase, lock, accounts), it is in The Best Private Browser for iPhone: What Actually Matters.
Ads, analytics, and social trackers
These three labels are enough for most pages. Ads are the obvious ones: banners, interstitials, sponsored units injected beside an article. Analytics is quieter: a script that records that you loaded the page, how long you stayed, which button you touched. Social trackers are the widgets that pull in a follow button or an embed from a network you are not using as the destination.
Blocking them is useful even when you are already in a session with no history file. The site you meant to visit still sees you. The extra companies behind the widgets may not. That is a reduction, not invisibility. If you log into a site, that site knows you. If you pay on a site, that site knows the purchase. Blocking does not rewrite those relationships.
HTTPS-Only Mode is adjacent, not identical. It is on by default so connections upgrade to encrypted HTTPS where the site supports it, and the app asks before falling back to insecure HTTP. Encryption hides contents from a listener on the local network. It does not hide the fact that you contacted a host, and it does not replace a block list.
What blocking cannot do
No blocker catches everything. Say it before the marketing sentence, not after. Lists lag. Some trackers are built into first-party code. Fingerprinting can use fonts, canvas, and other signals we do not claim to spoof. We do not sell anti-fingerprinting as a product. We do not claim you are anonymous or untraceable.
Your IP address remains visible to the site and to the network operator. A workplace gateway can still log destinations. A cafe router can still see that a connection happened. On-device blocking does not move your traffic to another country and does not assign you a new address. If you need that, you are shopping for a VPN, which this app is not.
Pages will break. A paywall script, a comment loader, or a video player may live on a host that is also used for ads. When that happens, a per-site exception is the honest fix: allow that site to load what it needs, finish the task, and erase the session if you do not want the cookies to linger. Exceptions are local. They do not phone home.
Blocking also does not empty a history file that a different browser wrote. If you still use Safari for everyday tabs, Safari’s stores are Safari’s. A private browser with on-device lists only governs its own sessions. Mix products if you want. Do not assume one app retroactively cleans another.
How this differs from a VPN or a DNS filter
A VPN encrypts traffic to a remote hop and, in typical consumer use, changes the IP address sites see to the VPN exit. That is a network product. It can be paired with a browser. It is not what Private Browser Incognito is. We do not hide IP addresses. We do not route browsing through our servers. We do not market a proxy.
A DNS filter intercepts name lookups and can refuse known ad domains. It often requires a profile or a local VPN shell so iOS will send lookups to that resolver. It can work across apps. It also places a resolver in the path. Our blocker is scoped to this browser’s content-blocking rules. It does not claim to clean other apps.
A Safari content blocker is another valid design: a separate app supplies rules, you enable them in Settings, and Safari applies them. That is a different installation ritual, and it still leaves you in Safari, which is a general browser with a history file for ordinary tabs. A dedicated private browser keeps lists, session, and erase in one place.
If the threat you actually have is a person holding your phone, blocking will not help you. App Lock, erase, and a decoy passcode will. The decoy is Stealth Suite, documented in Decoy Passcode: A Second Browser That Shows Nothing. Use the right tool for the audience: websites versus a person in the room.
On-device blocking is one column of a private browser. Combined with a session that never writes a history file, one-tap erase, HTTPS-Only Mode, and no accounts, it is a coherent local stance: less residue on the phone, fewer extra requests, nothing to trust us with. It is still a 17+ web browser. You choose the URLs. You are responsible for using the app lawfully. When a page needs an exception, grant it, finish, erase. When you are done with the session, destroy it. When someone else might open the app, lock it. Those are separate switches.
Frequently asked questions
Does an iPhone private browser block ads on the device?
Private Browser Incognito does. Ads, analytics, and social trackers are stopped by content-blocking rules that run on your iPhone. The open Disconnect lists ship inside the app. They are not fetched from a list server while you browse, and your traffic is not sent through our servers. Blocking is list-based and not absolute.
What block lists does Private Browser Incognito use?
The app uses content-blocking rules powered by the open Disconnect lists. Those lists cover known ads, analytics, and social trackers. They ship in the binary and run on the device. We do not name individual tracker companies in examples. Treat the labels as categories: an ad request, an analytics beacon, a social widget.
Is tracker blocking complete on iPhone?
No. No blocker catches everything. Lists go stale as new trackers appear. Some requests are first-party and will not match a third-party rule. Pages can break, which is why per-site exceptions exist. Tracking protection reduces known noise. It is not a guarantee, and it is not a VPN.
Do the block lists download from a server?
No. Block lists are not downloaded at runtime. They ship inside the app and run on your device. The network the app makes for browsing is the pages you open, search you send to a chosen engine if you search, optional search suggestions if you opt in, downloads you start, and StoreKit if you purchase. Nothing else.
Can I allow a site through the blocker?
Yes. Per-site exceptions exist when a page needs a blocked resource to work. Turning an exception on is a local choice on that device. It does not send a report to us. It also does not disable the rest of tracking protection on other sites. Use exceptions sparingly, then erase the session if you want the cookies from that visit gone.