Honest limits

A browser is not a VPN and does not hide your IP address. Tracking protection is list-based and not absolute: known ads, analytics, and social trackers from bundled lists are blocked on the device, but no blocker catches everything. Private Browser Incognito is rated 17+ for unrestricted web access and is intended for adults.

A page you opened for an article can still try to phone a social network you never tapped. The extra request is often tiny: a one-pixel image, a share button that pulls a count, a script that reports the view. Those extras are social tracker pixels in the ordinary sense: third-party chips that ride along with first-party content. This article is about that bucket on iPhone, how Private Browser Incognito stops many of them on the device, and why many is not all.

We describe the extras with generic labels only: ads, analytics, and social trackers. We will not name tracker companies as villains in a demo. Naming a brand does not make a rule smarter, and it turns a mechanics page into a hit list. The useful facts are where the lists live, what a match does, and the gap no list closes.

What a social tracker pixel is doing

You type a URL or follow a link. The browser loads the document from that host. Subresources try to follow: scripts, images, frames, beacons. Some of those subresources belong to the article. Some belong to an advertising auction. Some belong to an analytics beacon that reports a page view. Some belong to a social widget: a share button, a comment count, a like module, or a silent pixel whose only job is to say this URL loaded, on this client, around now.

The last group is the subject here. You did not open that social network as the main page. The article still attempted to attach it. If the request completes, the extra party can learn that the page was viewed, often with the same addressing facts any request carries: an IP, ordinary headers, and a real iPhone browser. Blocking the extra request does not hide you from the article’s own host. It can stop a second company from riding along.

Pixels are ordinary HTTP requests with a small payload. Matching is mechanical. If the destination of the subresource is on the bundled list, the request can be stopped before it leaves. If it is not on the list, it can pass.

Lists that ship in the binary

Private Browser Incognito blocks ads, analytics, and social trackers with content-blocking rules powered by the open Disconnect lists. The lists ship inside the app and run on the device. They are not downloaded at runtime. Opening a tab does not check a list server. The rules are already there, next to the rest of the binary, which is why there is no list fetcher that learns the app is open.

That location is a privacy choice. There are no accounts, no sign-in, and no app server for browsing. The App Store privacy label is Data Not Collected. There is no analytics SDK, no ads in the app, and no third-party SDKs. A runtime list download would have been a quiet exception to that story. We did not add one. Updates arrive as App Store updates to the app that contains the lists. The copy you install is the copy you browse with. How that file lives on the phone is the subject of How On-Device Block Lists Work.

The app does not sit in the middle of your traffic as a proxy. It is not a VPN. It is not a DNS filter that claims to clean Mail, Safari, or a game’s web view. Rules apply to this browser. A matched extra request never starts. A non-match goes out on the usual HTTPS path when the site supports it. HTTPS-Only Mode is a separate default. It encrypts the hop. It does not decide whether a social pixel is allowed.

The product-level overview of built-in blocking, including ads and analytics in the same engine, is On-Device Ad and Tracker Blocking on iPhone. This page stays with the social-tracker slice: widgets and pixels that try to attach a network you did not open as the destination.

Many, not all, and not 100 percent

Lists catch known names. They do not catch tomorrow’s names. A host that appeared after this app version shipped can miss until you install an update. That freeze is the cost of not phoning home. We would rather miss a new pixel than run a feed that watches you in order to stay current. The longer honesty note on the gap is Tracker Blocking Is Not Absolute.

First-party copies are another miss. If the pixel is served from the same site you typed, it may not look like a third-party tracker. Sites fold beacons into their own origin because it survives blockers. That is legal web architecture. It is also why “we blocked social trackers” can be true in the third-party sense and false in the “nobody learned that you loaded this” sense. The destination still learned it. Extra companies might not.

We do not publish a catch rate. A number would go stale on the same day we printed it, and it would invite a comparison we cannot police. A demo counter can show that rules fired. It is not a study. We will not invent a percentage of social pixels stopped on iPhone. Treat the feature as coverage of a known set, not as a census of every share button on the web.

Fingerprinting is a different gap. Fonts, canvas, and similar signals can distinguish a client without a named tracker host. We do not spoof those surfaces. Blocking a listed social widget does not make the remaining page look like a stranger. If a site still wants to recognize the browser, it often can. That limit, including why we will not invent a uniqueness score, sits in Browser Fingerprinting and Honest Limits. Whether the destination can tell you are in a private session at all is Can Websites Tell You Are in a Private Browser?: often yes, and not a stealth cloak.

Private Browser IncognitoSocial trackers blocked on device. Lists ship in the app, not at runtime. Get the app

Per-site exceptions when a page needs the widget

A blocker that never breaks a page is a blocker that is not matching much. When a comment thread, a login with a social button, or a share sheet lives on a host the lists also use for tracking, the page can fail. Per-site exceptions exist so you can finish the task. Turning an exception on is a local choice. It does not report to us. It does not disable tracking protection everywhere else.

Use exceptions sparingly. Finish. Erase if you do not want that site’s cookies to linger for the rest of the session. One-tap erase closes every tab and destroys cookies, cache, and site data. There is a home-screen quick action. The exception does not survive as a cloud preference because there is no account. It lives on that device, for that app. That is the same local stance as the lists themselves.

Exceptions are also why a sealed-shield status line would be dishonest. If you allowed a site through, you allowed it. The UI should not pretend every social chip still bounces off. We would rather show a gap than invent a perfect score. You are trading a working module for extra requests. Name the trade. Then throw the session away if the working module was temporary.

Not a VPN, not a company hit list

Stopping a matched pixel means that request did not leave the phone. The article you meant to read still saw your IP address. Your network operator still saw that a connection happened, and often which host you contacted. On-device lists do not assign you a new address. They do not tunnel traffic. They do not rewrite headers into fiction. A browser is not a VPN.

Company names do not belong in the examples. The buckets are enough: ads, analytics, social trackers. If a request sits in those buckets and on the list, it can be stopped. If it sits outside, it can pass. There is no fourth bucket called everything a company might learn. Rated 17+ still applies. This is a real web browser with unrestricted access. Tracker blocking will not make a site appropriate and will not hide you from a network administrator. You are responsible for what you visit and for using the app lawfully.

How to use a reduction without a myth

The useful posture is small. Keep blocking on. Keep HTTPS-Only Mode on (it is the default; the app asks before HTTP). Keep suggestions off until you want them. Do not log into a site you wanted to be a stranger to. Erase when the session should die. Lock the app if someone else can pick up the phone. None of those steps is absolute. Together they are a local reduction: fewer extra social requests, less residue, nothing to trust us with.

What you wanted What lists can do What still happens
Fewer social widgets and pixels Stop known names on the device New or first-party names can pass
No extra company riding along Stop listed third-party chips The main site still sees you
A list that updates while you browse Nothing. Lists ship in the binary App updates thaw the freeze
Hidden IP Nothing. Not a VPN Sites and the network still see it
A page that always works Exceptions when a widget is required Some modules never load

Use the table on this app and on anything else you install. If a listing cannot say that lists ship on device, that blocking is not 100 percent, and that a private browser is not a VPN, it is not finished explaining the feature. Private Browser Incognito is built so there is nothing to trust us with: no accounts, lists in the binary, passcode as the key, session you can throw away. Social tracker pixels are one extra-request bucket. Catching many of them is a real feature. Catching all of them is a claim we will not make.

Private Browser IncognitoFree on the App Store. No history, on-device blocking, one-tap erase. Get the app

Frequently asked questions

What are social tracker pixels on iPhone pages?

They are extra requests a page tries to fire so a social network you did not open as the main site can still learn that the page loaded. Typical shapes are a one-pixel image, a share widget, or a comment count pulled from elsewhere. Private Browser Incognito describes them with generic labels only: ads, analytics, and social trackers.

Do Disconnect lists catch every social tracker pixel?

No. Lists catch many known names, not all. New hosts appear. Some pixels live on the same site you typed and may not look like a third-party tracker. Per-site exceptions exist when a page needs a blocked resource to function. Treat blocking as a reduction of known noise, not as 100 percent coverage.

Are social tracker block lists downloaded while I browse?

No. Content-blocking rules powered by the open Disconnect lists ship inside the app and run on the device. They are not downloaded at runtime. Opening a tab does not check a list server. Updates arrive as App Store updates to the app that contains the lists.

Can I allow a site that needs a blocked social widget?

Yes. Per-site exceptions exist when a page needs a blocked resource to function. The exception is local on that device. It does not report to us. It does not disable tracking protection on other sites. Finish the task, then erase the session if you want those cookies gone.

Does blocking social tracker pixels hide my IP address?

No. A browser is not a VPN. Blocking a matched extra request means that request does not leave the phone. The site you meant to visit still sees your IP address, and your network operator still sees destinations. On-device lists do not assign you a new address.