Privacy and data
systemBlue receives nothing from Blue Guard. Not your browsing, not your settings, not an identifier, not a crash report, not a count of anything.
That is a property of how the app is built rather than a promise on its own. There are no accounts and no sign-in, no analytics or advertising code, and no systemBlue server for the app to talk to, because systemBlue operates none. There is no route by which your data could reach systemBlue.
This page is a summary written for someone using the app. The privacy policy is the complete and authoritative statement, and it is the one to read if you need the full detail.
What stays on the device
Blue Guard keeps its data in its own sandboxed container, and in a container shared between the app and its extensions. Among what it holds:
- Your allowed sites. The domains you have exempted, held as exception rules inside the filter rules.
- Your custom rules. The rules you wrote, as text, alongside the Safari rule each was translated into.
- The filter rules. The lists the app prepares for Safari.
- Blocked counts. Where app-wide blocking runs, a daily total of the lookups it refused. A total is a number and a date. No domain, address or page is recorded with it. Totals are kept for 30 days.
- Diagnostic reports. Reports of crashes, hangs and launch times that iOS hands the app through Apple's MetricKit. They are call stacks, the operating system version and the app's build number, and hold no browsing data. The 50 most recent are kept, for up to 30 days.
None of it is transmitted. The diagnostic reports in particular have no send path: the app provides no means of transmitting them, and systemBlue never receives them. Deleting the app removes all of it.
Nothing is synchronised
Blue Guard does not use iCloud. It declares no iCloud or CloudKit entitlement and stores nothing in an iCloud container. Your allowed sites, your custom rules and your settings exist only on the device where you made them, and are not copied to your other devices.
An earlier version of the app offered iCloud synchronisation. That feature and its entitlements were removed on 24 July 2026.
The two things that involve the network
Neither of them involves systemBlue.
A tip, if you leave one. Apple handles the whole transaction through the App Store. systemBlue never receives your payment details, card number or billing address.
Domain lookups, if app-wide blocking is on. Lookups for blocked domains are answered on the device and go nowhere. Everything else is forwarded to Cloudflare (1.1.1.1) or Quad9 (9.9.9.9) so it can be answered, over DNS over TLS with the resolver's certificate verified first. A resolver receives the domain and the network address the lookup came from, and each acts as an independent controller under its own privacy policy. systemBlue does not proxy, observe, log or retain any of it. Switching app-wide blocking off ends it.
Safari blocking involves no network activity at all. The content blocker hands Safari a rule list and is not invoked again as you browse.
What the app cannot see
The Safari content blocker receives no page content and no record of the pages you visit. Safari does the matching against the rule list and reports nothing back. This is why the counts on the home screen come from app-wide blocking only: there is no equivalent figure for Safari to give.
Blue Guard does not track you across other companies' apps or websites. It does not access the advertising identifier and shows no App Tracking Transparency prompt, because it does nothing that would need one.
Third-party code
No analytics, advertising or tracking SDK is compiled into Blue Guard.
The Safari content blocker, the network extension and the widget contain no third-party code at all. They are Apple's frameworks and code written by systemBlue, and they are the parts that see your browsing and your domain lookups.
The privacy policy is the authoritative statement on what is compiled into the app.