A browser is not a VPN. Sites you visit and your network operator can still see your IP address. On employer Wi-Fi, that operator can still see destinations. Tracking protection is list-based and not absolute: known ads, analytics, and social trackers from bundled lists are blocked on the device, but no blocker catches everything. Private Browser Incognito is rated 17+ for unrestricted web access and is intended for adults.
Workplace Wi-Fi is someone else’s network. The employer, or the contractor who runs the access points, sits on the path before the public internet. A private browser does not move that path. It does not issue a new address. It does not hide the hosts you contacted. Private Browser Incognito is an iPhone web browser we build. It is not a VPN. It will not help anyone evade workplace policy.
People type the question because private sounds like a cloak, and because a missing history list on the phone feels like the whole story. Those are different jobs. This page keeps them apart: what a network operator can still see, what HTTPS actually covers, what the app changes on the device, and what we will not claim. Use it to decide whether a forgetful session is the tool you needed, or whether you needed a different conversation with the people who own the network.
What the network operator still sees
When you request a URL, packets leave the phone, cross the workplace network, and reach a server. The server has to know where to send the response. That return path is your public IP, or the address of whatever NAT the office uses. The site can log it. The operator who handed you the connection can log that the device was online, and often which hosts you contacted. A private tab does not negotiate a different address. Omitting a history file on the phone does not either.
Depending on the network, that operator may see destinations through DNS, through SNI or similar host hints on TLS connections, or through a gateway log that simply records who talked to whom. We will not write a field guide. We will not invent MDM or proxy detection claims. Some workplaces inspect more, some less. The constant is that the browser is a client on their path. Deleting or never writing a local history database does not reach their log.
This is ordinary internet plumbing. Safari private browsing, a forgetful browser, and a private mode in any other app all still originate requests from the same connection unless you have separately configured a VPN in iOS. We do not ship that tunnel, and we will not coach anyone on turning one on at work. The short IP article, without the office framing, is Does a Private Browser Hide Your IP Address?. The answer there is the same answer here: no.
HTTPS hides contents, not the host
HTTPS encrypts the contents of the conversation between the phone and the site. A listener on the path should not be able to read the page body or the form you submitted. That is a real protection. It is also a narrow one. Encryption does not hide the fact that you contacted a host. The gateway can still see a destination. Treat HTTPS as privacy of the payload, not privacy of the appointment.
Private Browser Incognito turns HTTPS-Only Mode on by default. The app asks before falling back to insecure HTTP. That default is about not leaking page contents on an open radio. It is not a claim that the office cannot see the name of the site. If you accept an HTTP fallback, more of the conversation can be visible on the path. The ask exists so that fallback is a choice, not a surprise. The longer default note is HTTPS-Only Mode: Why a Private Browser Starts Encrypted.
On-device blocking is another local control people fold into “the office cannot see.” Ads, analytics, and social trackers can be stopped by content-blocking rules powered by the open Disconnect lists. The lists ship inside the app and run on the device. They are not downloaded at runtime. The app does not sit in the middle of your traffic as a proxy. Blocking can reduce extra third-party requests. It does not hide the first-party host you typed. It is not 100 percent. Per-site exceptions exist.
Search is the same split. You can use Google, Bing, DuckDuckGo, Wikipedia, or a custom engine. A query you submit goes to that engine. We do not proxy it. We do not harvest it. Suggestions stay off by default. The engine still sees an IP. The workplace path still sees a destination. Choosing a different preset changes who receives the query. It does not hide the lookup from the gateway. The picker is Bring Your Own Search Engine.
Device residue is a different job
A forgetful browser holds every tab as a private session in memory. There is no browsing history feature and no history file to clear. Cookies and cache exist for the life of the session so pages can work. One-tap erase closes every tab and destroys that session data. There is a home-screen quick action so you do not have to open the app first. Erase is permanent. Erased data cannot be recovered, by you or by us.
That job is about the phone in a bag, on a desk, or in someone else’s hand. It is about what a Settings pane would have listed, what a Recents row would have kept, what a borrowed device can show. It is not about the gateway. A clean phone can sit next to a complete operator log. Both facts can be true at once. The architecture of the missing file is A Browser With No History File at All.
App Lock with a six-digit passcode and Face ID is free in the shipping default. The passcode is never stored. It becomes the key. Forgotten passcodes cannot be recovered. The lock hides the session from a person who picks up the phone. It does not hide the session from the network that already carried it. Stealth Suite can add a decoy passcode, a panic code, a break-in log, self-destruct, and an encrypted vault. Those are still device controls. A decoy that shows an empty browser does not unsend a request that already crossed the office Wi-Fi.
Session erase does not empty the vault. Downloads that went into the vault are a separate store. Panic can wipe the vault. None of that edits a network log. Keep the layers named so a trash icon is not mistaken for a tunnel.
What we will not tell you to do
We will not tell people how to evade workplace policy. Users are responsible for what they visit and for using the app lawfully. Workplace rules are part of that duty. If the network is provided for work, and the policy says not to browse certain destinations, a private browser is not a license. Rated 17+ means unrestricted web access for adults, not a special exception on someone else’s access point.
We do not invent MDM or proxy detection claims. We do not claim the app can see a management profile, fingerprint a proxy, or warn you that inspection is on. We do not claim it can bypass those things. If the phone is managed, the manager’s tools are outside this product. If a proxy is configured in iOS, the system may honor it. We do not market proxy as a feature, and we will not document a workaround.
Incognito language in other browsers has the same gap. A private tab in a general browser is usually a lane that keeps local traces tighter. The rest of that app still remembers. The network still sees destinations. What incognito does not hide, in general, is What Incognito Mode Does Not Hide. Workplace Wi-Fi is one concrete instance of that map: IP visible, hosts visible, accounts you open still you, local residue as the only job the browser can honestly take.
There are no accounts and no app server for browsing. The App Store privacy label is Data Not Collected. We do not see a workplace dashboard of your sessions because we do not run one. The operator of the Wi-Fi might. That distinction is the whole article in one contrast.
A table of observers
If you only needed the split:
| Observer | What they can still see | What this app changes |
|---|---|---|
| Workplace Wi-Fi operator | Your IP, and typically destinations | Nothing on their gateway |
| The site you opened | Your IP, headers, whatever you typed | Nothing about their logs |
| A listener on the path | Hosts. Contents if the load is plain HTTP | HTTPS-Only asks before HTTP |
| Someone holding the phone | Whatever the session still shows | No history file, lock, erase, optional decoy |
| Us | Nothing. No browsing server | We do not harvest the session |
Use that table before you assume a private session is a private commute. If the threat is a coworker glancing at the screen, lock and erase matter. If the threat is a history row in another browser, a forgetful client matters. If the threat is an employer log, you are looking at a network problem this app does not solve. Saying so is the product being finished, not the product being weak.
What to do on the device, honestly
Stay inside the controls that are real. Lock the app if other people can pick up the phone. Erase when the session should die. Leave suggestions off unless you want prefixes to leave while you type. Prefer HTTPS and read the ask if a site wants HTTP. Do not treat a quieter home-screen color as cover on a network. If you should not use that Wi-Fi for a destination, do not use it for that destination. Cellular is a different operator, not invisibility.
Private Browser Incognito is iOS only. It is free for the forgetful session, on-device lists, erase, App Lock, and HTTPS-Only Mode. Stealth Suite is optional: monthly $4.99, yearly $19.99 with a 7-day trial, or lifetime $49.99. Paying does not hide an IP. The honest product on workplace Wi-Fi is a phone that can forget, locked if you set a code, still visible on the path it used. That is enough for some people and the wrong tool for others.
Frequently asked questions
Can my employer see what I browse on workplace Wi-Fi?
The network operator can still see your IP and destinations. A private browser does not hide those from the gateway. HTTPS can hide page contents from a listener on the path. It does not hide the host you contacted. This app is not a VPN and will not help anyone evade workplace policy.
Does HTTPS hide the sites I visit from workplace Wi-Fi?
HTTPS hides contents from a listener, not the host you contacted. The operator can still see that a destination was reached. HTTPS-Only Mode in this app asks before falling back to insecure HTTP. Encryption is not invisibility on the local network.
Does a private browser hide my IP on work Wi-Fi?
No. A browser is not a VPN and does not hide your IP address. Sites you visit and your network operator can still see it. Private browsing on iPhone is about residue on the device, not about a new address on the wire.
What does Private Browser Incognito actually change on a work network?
It changes what the phone keeps. There is no history file. One-tap erase destroys the session. App Lock can keep tabs closed to someone who picks up the device. None of that edits the employer gateway log. Device residue and network visibility are different jobs.
Will this app help me evade workplace policy?
No. Users are responsible for using the app lawfully, including workplace rules. We do not tell people how to evade policy. We do not claim to detect or bypass MDM or a proxy. If the network is not yours to use that way, do not use it that way.