Privacy Policy
Effective 30 July 2026
The short version
systemBlue collects nothing from Blue Guard. Not your browsing, not your settings, not an identifier, not a crash report, not a count of anything.
That is not a promise we are asking you to take on trust. The Application has no accounts, no analytics code, and no systemBlue server to talk to, because systemBlue operates none. There is no route by which your data could reach us, nothing on our side to lose or sell, and nothing to hand over if somebody came asking for it.
Two things do involve the network, and neither of them involves us. If you choose to tip, Apple handles that transaction, as Section 6 sets out. And the Application contains an app-wide blocking feature which, when you switch it on, sends your device’s domain lookups to public resolvers so that they can be answered. It is off until you enable it. Section 4 describes it in full.
1. Introduction and scope
This Privacy Policy (the “Policy”) describes how Blue Guard handles information. Blue Guard (the “Application”) is published by systemBlue (“systemBlue,” “we,” “us,” or “our”), an independent software studio based in the United States.
The Application is a content blocker for iPhone and iPad. It comprises a containing app, a Safari content blocker, a home screen widget, and a network extension that provides the app-wide blocking described in Section 4. Section 4 states what each of them is able to observe.
This Policy applies to the Application and to this website (the “Site”). It states, completely, what data the Application stores, what data leaves your device, and what data systemBlue receives. By installing or using the Application, you acknowledge the practices described in this Policy.
The Site is served as static files by a third-party static host. It sets no cookies, runs no analytics, and loads no third-party resources; every page is plain HTML and one stylesheet, served from this domain. As with any web host, that host processes the network request which serves each page, including the address it came from. systemBlue does not receive, review, or retain that information.
2. Information we collect
systemBlue collects no personal information through the Application. In particular, the Application transmits to systemBlue none of the following:
- browsing history, the content of any page you visit, or the domains your device resolves;
- the blocking decisions the Application makes;
- your allowlist, your custom rules, or any other setting;
- your name, email address, contacts, or location;
- device identifiers or the advertising identifier; or
- crash reports, diagnostic data, or telemetry of any kind.
This is a property of the Application’s architecture rather than a policy commitment alone. The Application has no user accounts and no sign-in, contains no analytics or advertising code, and communicates with no systemBlue server; systemBlue operates none. The network activity associated with the Application is limited to two things, and neither of them reaches systemBlue: Apple’s own App Store transaction, if you choose to tip, described in Section 6; and the domain lookups that app-wide blocking forwards to the public resolvers named in Section 4, where you have enabled that feature. There is accordingly no mechanism by which the Application could transmit personal information to us, and nothing for us to store, disclose, sell, or produce in response to legal process. The privacy manifests filed with Apple declare no collected data types and no tracking, and they are accurate.
3. Information stored on your device
The Application stores the following on your device, in its own sandboxed container and in a container shared between the Application and its extensions. None of it is transmitted to systemBlue, and none of it is copied to any of your other devices.
- Your allowlist. The domains you have chosen to exempt from blocking, held as exception rules within the Application’s filter rules.
- Your custom rules. The filter rules you have written yourself, held as text together with the Safari rule each one was translated into.
- Filter rules. The rule lists the Application prepares for Safari.
- Reading state. Which of the Application’s built-in help articles you have read.
- Setup state. A single flag recording whether initial setup has been completed.
- Blocked counts. Where app-wide blocking runs, a daily total of the lookups it refused, shown on the home screen and in the widget. A total is a number and a date. No domain, address, or page is recorded with it. Totals are kept for 30 days and are not transmitted. Safari blocking contributes nothing to this count, because a content blocker reports nothing back to the Application.
- Diagnostic reports. Reports of crashes, hangs, and launch times supplied to the Application by iOS through Apple’s MetricKit framework. They consist of call stacks, the device model, and the operating system version, and contain no domain, address, page, or other browsing data. They are written with file protection applied, are limited to the 50 most recent reports and to 30 days, and are never transmitted. systemBlue does not receive them, and the Application provides no means of sending them.
This is the complete list. Deleting the Application removes all of it from the device.
4. Blocking, and where domain lookups go
The Safari content blocker supplies Safari with a list of rules, and Safari applies those rules itself. The content blocker is not invoked as you browse, receives no page content, and receives no record of the pages you visit. Neither it nor systemBlue can observe your browsing in Safari.
The content blocker is supplied disabled and takes effect only once you enable it in the Settings app. The Application contains no component that reads the content of any page.
The Application also contains an app-wide blocking feature, which filters the domain lookups your device makes so that trackers are refused in every app rather than in Safari alone. It is supplied off and runs only after you switch it on in the Application’s Settings screen. What follows describes how it operates when enabled.
When it runs, the filter operates on your device. Lookups for domains on the block list are answered there and are never sent anywhere. Every other lookup is forwarded to a public resolver so that it can be answered: Cloudflare (1.1.1.1) and Quad9 (9.9.9.9), and the Application offers no other. A resolver receives the domain looked up and the network address the lookup came from. systemBlue does not receive, proxy, observe, log, or retain any lookup or any answer, and each resolver acts as an independent controller under its own privacy policy, for which systemBlue is not responsible and gives no undertaking.
Lookups reach those resolvers over DNS over TLS on port 853. The connection is encrypted and the resolver’s certificate is verified before any lookup is sent, so an operator of a network between your device and the resolver cannot read the domains you look up. There is no unencrypted fallback: where an encrypted connection cannot be established or verified, the lookup is not sent and resolution fails rather than being retried in the clear.
Switching app-wide blocking off ends all of this. Safari content blocking is unaffected either way, and transmits nothing.
5. iCloud and synchronisation
The Application does not use iCloud. It declares no iCloud or CloudKit entitlement, contains no code reachable from the Application that reads from or writes to an iCloud container, and stores nothing in iCloud.
Nothing described in Section 3 is synchronised. The allowlist, the custom rules, the filter rules, the extension settings, the reading state, the setup state, and the diagnostic reports exist only on the device on which they were created.
A previous version of this Policy described an optional synchronisation of settings and allowlist entries through iCloud. That feature, and the entitlements it required, were removed from the Application on 24 July 2026. Should synchronisation be introduced in future, this Policy will be updated before the feature ships.
6. Price and support
Blue Guard is free. Its features are provided at no charge, with no account and no subscription. The Application offers an optional tip jar through which you may support its development using Apple’s App Store; Apple processes the entire transaction, and systemBlue never receives your payment details, card number, or billing address. A tip grants no additional features and is not required to use any part of the Application. Use of the Application is governed by Apple’s standard End User License Agreement.
7. Apple as platform provider
The Application runs on Apple operating systems and is distributed through the App Store. Apple consequently holds information that systemBlue does not, including the fact of your download and your purchase history. That relationship is between you and Apple and is governed by Apple’s Privacy Policy. systemBlue receives from it only aggregate, non-identifying sales reporting.
8. Third-party software components
The Application contains no analytics, advertising, or tracking software development kit, and no third-party service receives any data from it. The software compiled into the Application and its extensions consists of Apple’s own frameworks and libraries written by systemBlue. No third-party library is compiled into any part of the Application.
9. Security
Data stored by the Application resides in its sandboxed containers and is protected by the data-protection and encryption-at-rest mechanisms built into iOS and iPadOS; the diagnostic reports described in Section 3 are written with file protection applied in addition. Because systemBlue operates no servers and receives no data, there is no server-side copy of your information to secure, breach, or disclose, and no traffic of ours to intercept. The domain lookups that app-wide blocking forwards, where you have enabled it, are encrypted in transit as Section 4 describes.
10. Tracking
The Application does not track you across other companies’ apps or websites. It does not access the advertising identifier and does not present an App Tracking Transparency prompt, as it performs no activity that would require one.
11. Children’s privacy
The Application collects no personal information from any user, including children, and is not directed to children. We do not knowingly hold data about a child, because we do not hold data about any user. A parent or guardian who believes otherwise may contact us at the address in Section 17.
12. Data retention and deletion
systemBlue retains no user data, because it receives none. On the device, diagnostic reports are deleted after 30 days, and only the 50 most recent are kept; the allowlist, custom rules, filter rules, extension settings, reading state, and setup state persist until you change them. Deleting the Application removes all locally stored data. No copy exists elsewhere.
13. International data transfers
systemBlue transfers no personal data across borders, because it holds none. Where app-wide blocking can be switched on and you switch it on, the lookups described in Section 4 are sent by your device to the resolvers named there, which may answer them outside the United Kingdom and the European Economic Area. That transmission is made by your device, at your election, and systemBlue is not a party to it.
14. Legal bases for processing
To the extent the EU General Data Protection Regulation (“GDPR”) or equivalent legislation applies: systemBlue does not collect or process personal data, and therefore requires no legal basis for processing. All processing the Application performs happens on your device, at your direction, and stops when you turn the feature off or remove the app.
15. Your privacy rights
Privacy laws, including the GDPR and the California Consumer Privacy Act (“CCPA”), grant you rights over personal data an organisation holds about you. These include, depending on your jurisdiction: the right to access; the right to rectification or correction; the right to erasure or deletion; the right to data portability; the right to restrict or object to processing; the right to know the categories of personal information collected, sold, or shared; and the right not to be discriminated against for exercising any of these rights.
Because systemBlue holds no personal data about you, there is no data on which these rights can be exercised, and no means by which we could identify you in order to fulfil a verifiable request. If you believe systemBlue holds personal data about you, contact us at the address in Section 17. We will investigate and respond within the period required by applicable law.
For California residents. systemBlue does not sell personal information, does not share personal information for cross-context behavioural advertising, and has never done either. In the twelve months preceding the effective date of this Policy, systemBlue collected no categories of personal information. No opt-out mechanism is provided because no sale or sharing occurs.
For EEA, UK, and Swiss residents. You have the right to lodge a complaint with your local supervisory authority. Because systemBlue processes no personal data, we expect any inquiry to conclude accordingly, and we will cooperate fully with any authority that contacts us.
16. Do Not Track
The Site does not respond to Do Not Track or Global Privacy Control signals, because it performs no tracking that such signals could disable.
17. Contact
Questions regarding this Policy, or requests under Section 15, may be directed to legal@systemblue.app.
18. Changes to this policy
If this Policy changes, the revised version will be published at this address with an updated effective date. If a change is material, meaning it alters what data leaves your device or who may access it, we will provide notice in the Application or in the release notes accompanying the relevant update. Continued use of the Application after a revised Policy takes effect constitutes acknowledgement of the revision.