Last updated: September 23, 2026 · Applies to Pryglass version 1.2 and later
The short version
- Pryglass analyzes web pages on your device. It has no server, no account, no analytics, no advertising and no crash-reporting code, and it makes no network requests of its own.
- The developer receives nothing about you or your browsing from the app or the extension, and shares nothing with anyone, because there is nothing to share.
- What it keeps is stored in Safari's storage for the extension on the same device. Live page details are temporary. Saved site history is capped, holds site names and page paths but no query strings, no request addresses and nothing you typed, and is removed after 90 days.
- Private Browsing tabs are analyzed live, but nothing from them is saved.
- You can delete the saved history at any time with More > Your data > Delete saved history, and remove the extension by removing the app.
Using version 1.1 or earlier (named Signal/Block)? This policy describes version 1.2. Earlier versions also keep everything on your device and send nothing to the developer, but they differ in these ways:
- Saved site history can include page paths with their query strings, which sometimes contain search terms or IDs.
- Private Browsing tabs are saved like normal tabs.
- Saved history has no time limit and no limit on the number of sites.
- There is no Delete saved history option.
- Blocking is done by the extension inside the page, not by Safari, and the extension also asks for the "tabs" permission.
Updating to version 1.2 deletes the history saved by earlier versions and keeps your block list, watched sites and settings. Updating is the most reliable way to remove that older history.
Contents
- Who is responsible
- What Pryglass processes on your device
- What is not collected
- Permissions and why they are needed
- Blocking
- Private Browsing
- How long data is kept
- How to delete your data
- Things you choose to share
- Apple, purchases and the App Store
- If you contact support
- This website
- Your rights (GDPR)
- Children
- Changes to this policy
- Contact
1. Who is responsible
Pryglass (the iPhone, iPad and Mac app and its Safari extension) is made by Andreas Nelvik Engebretsen (shown on the App Store as Andreas Engebretsen), an independent developer in Norway ("I", "me", "the developer"). For any personal data I do receive, which is only what you send me yourself (section 11), I am the data controller under the EU General Data Protection Regulation (GDPR) as it applies in Norway through the EEA Agreement and the Norwegian Personal Data Act.
Contact: andreas.nelvik.engebretsen@gmail.com
2. What Pryglass processes on your device
To show what a page does, Pryglass has to look at the pages you open in Safari. This happens entirely on your device, in Safari's extension process. The results are kept in Safari's storage for the Pryglass extension on that device. They are not sent to the developer or to anyone else, and they are not synced between your devices: each iPhone, iPad or Mac keeps its own data.
| Data | What it contains | Where and how long |
|---|---|---|
| Live page analysis |
For each open tab: the page and frame addresses without their query strings; the addresses of requests the
page makes (including query strings, never the part after #, cut at 512 characters); the names of cookies and storage keys a page reads or
writes (never their values); which browser features it used (for example canvas, location or clipboard); for
form fields you focus or type in, the field's type category and its name or id attribute (never what you type);
and the script location that triggered each item. At most 400 items per tab.
|
Safari's temporary session storage for the extension. Replaced when the tab loads a new page, and removed when you close the tab, when you choose Clear list, and when Safari quits. Private Browsing tabs are kept in memory only. |
| Saved site history | Saved only for pages where you open Pryglass. Per site: the site name and page paths with ID-like parts removed (no query string, no fragment); a few snapshots per page with counts per category, the domains of third-party companies and their purposes, and the trust score; daily points for the last 30 days; change alerts, and whether you muted alerts or marked a change as expected; companies seen on that site. It never contains a query string, a request address, a form field name or anything you typed. | Safari's local storage for the extension on this device. At most 50 sites (the least recently used site is removed first), 30 pages per site and 5 snapshots per page. Entries older than 90 days are removed. |
| Tracker overview | For the site counts in "Top trackers": tracker domains, the company name, and the sites you inspected where each one appeared, with the date last seen. | Local storage on this device. Entries older than 30 days are removed. At most 300 trackers and 50 sites each. |
| Unusual visit check | Statistical samples (counts per visit) used to spot a visit to a page that differs from your earlier visits to it. No AI model is involved. | Local storage, at most 30 samples per page, same 90-day limit. Turning off Spot unusual visits (in More > Options) deletes the samples and stops new ones. |
| Watched sites | The site names you chose to watch. | Local storage, until you remove them. |
| Blocked domains | The tracker domains you chose to block, the sites where each rule applies or is lifted, and when each rule last changed (at most 1,000 blocked domains). | Local storage, and handed to Safari as content-blocking rules (section 5). Until you remove them. |
| Settings | Your choices in More > Options (Group repeats, Hide minor items, Expand all cards, Spot unusual visits), and the filter, tab and comparison you last chose. | Local storage, until you change them or remove the app. |
The Pryglass app (the one you open from the Home Screen or Applications folder) explains how to set up the extension. On a Mac, and on iPhone and iPad with iOS or iPadOS 26.2 or later, it asks Safari whether the Pryglass extension is turned on, so it can show you. It makes no network requests and never sees your browsing or the extension's data. In its own settings on the device it keeps three small values used only to decide when to ask Apple to show its standard rating request (section 10): how many times the app has been opened, the launch on which it first saw the extension turned on, and the app version it last asked for a rating on. They never leave the device and are removed when you delete the app.
When you update to version 1.2, Pryglass deletes the site history saved by earlier versions, because that older format could contain full addresses. Your block list is carried over.
3. What is not collected
- Nothing leaves your device. Pryglass has no server and contains no code that sends data anywhere. Its knowledge of trackers and companies is built into the app; it downloads no lists.
- No account, no name, email address or other identifier is asked for or created.
- No analytics, advertising, tracking, crash-reporting or third-party SDKs.
- Nothing you type. Pryglass never reads the contents of form fields, passwords, payment details or messages.
- No cookie or storage values. It records which cookie or storage key a page used, not what is stored in it.
- No page contents such as text, images or media.
- No selling or sharing. Because the developer receives no data from the app, no data is sold, shared or passed to advertisers, data brokers or any other third party.
This matches the "Data Not Collected" privacy label on the App Store: nothing is transmitted off your device to the developer or to third parties.
4. Permissions and why they are needed
When you allow a Safari extension on all websites, Safari warns that it can read and change web pages, including things like passwords, phone numbers and credit card numbers. That warning describes what the permission would allow. Here is what Pryglass actually does with each permission:
- Website access (all websites). Pryglass audits whatever site you visit, so it runs its content scripts on the pages and frames you open once you allow it there. The scripts watch which browser features the page calls and which resources it loads, and report that to the extension on your device. They do not change what the page shows, do not read field contents, and do not send anything to the network. You choose the access in Safari and can limit it to certain sites or remove it at any time (see Support).
- Storage. Keeps the data described in section 2 in Safari's storage for the extension on your device.
-
Declarative content blocking (
declarativeNetRequest). Lets Pryglass hand your block list to Safari as rules, and Safari itself applies them. This permission does not let Pryglass read your requests or their contents.
Pryglass does not ask for access to your location, camera, microphone, contacts, photos, clipboard or notifications. When the popup says a page used one of these, it means the page asked Safari for it.
5. Blocking
When you block a tracker, Pryglass turns your choice into a content-blocking rule and gives it to Safari, which stops matching requests before they are made. The rules contain only the tracker domain and the site domains you chose. Pryglass ships with no block list of its own and downloads none; nothing is blocked until you choose to. Removing a rule, or removing the app, removes the rule from Safari.
6. Private Browsing
Safari turns extensions off in Private Browsing unless you allow them there. If you allow Pryglass, it analyzes private tabs live so you can see what the page does, but it keeps that analysis in memory only and saves nothing from private tabs: no site history, no tracker overview entries and no unusual-visit samples. The popup marks a private tab with "Private tab · nothing saved". The live analysis disappears when you close the tab or quit Safari.
7. How long data is kept
- Live page analysis: until the tab loads a new page or is closed, you choose Clear list, or Safari quits.
- Saved site history and unusual-visit samples: up to 90 days, within the limits in section 2. Older entries are removed the next time Pryglass saves history.
- Tracker overview: up to 30 days.
- Watched sites, block rules and settings: until you remove or change them, or remove the app.
- The Pryglass app's rating-prompt values: until you delete the app.
8. How to delete your data
All data is on your device, so you delete it there. The developer has no copy to delete.
- Clear the current tab. Open Pryglass on the page, choose More, and under This page choose Clear list.
- Delete saved history. Open Pryglass in Safari, choose More, and under Your data choose Delete saved history. This removes all saved site history, change alerts, the tracker overview and unusual-visit samples on that device. It keeps your blocked domains, watched sites and settings, and tells you so before you confirm.
- Remove blocked domains in More > Blocked domains, one by one with Unblock or all at once with Unblock all. Remove watched sites in More > Watched sites with Remove.
- Turn off Spot unusual visits in More > Options to delete its samples and stop collecting them.
- Remove the app. On iPhone and iPad, delete the Pryglass app. On Mac, choose Safari > Settings > Extensions, select Pryglass and click Uninstall, or move the app to the Trash. This removes the extension and its block rules from Safari. To be sure no saved history is left behind, use Delete saved history first.
- Safari's own data. Clearing Safari's history and website data removes what websites stored in Safari, such as their cookies. It is not a reliable way to delete Pryglass's saved history; use Delete saved history for that.
To stop Pryglass seeing a site, or any site, change or remove its website access in Safari's extension settings, or turn the extension off. This is how you withdraw permission for the processing described here.
9. Things you choose to share
- Summaries and data you copy or save. Copy summary puts a readable summary of the current page on your clipboard; Copy data (JSON) copies the recorded events for the current tab; Copy URL copies one request address; and Copy check details or Save check details copies or saves the unusual visit check as a file (on iPhone and iPad through the share sheet). Pryglass does this only when you ask and sends it nowhere. A summary contains the page's full address and the names of form fields you used; the JSON data also contains full request addresses. Addresses can include query strings, which sometimes carry identifiers. Check what you copied before you share it with anyone.
- Links you open. Help and support, Privacy policy, How to allow Pryglass and Rate Pryglass in the extension open these pages or the App Store in a new Safari tab, like any other link. The Pryglass app's links open Safari, Mail or the App Store. Pryglass never opens a request address itself, because that would send the request again; it only lets you copy it.
- Emails to support are covered in section 11.
10. Apple, purchases and the App Store
You buy and download Pryglass through Apple's App Store. Apple handles the payment, your Apple Account and any refund as an independent controller under Apple's privacy policy. The developer does not receive your name, email address or payment details. Apple gives developers sales and download reports, and, only if you have chosen in your device settings to share analytics or crash data with app developers, statistics and crash reports that Apple prepares. The developer uses these only to understand sales and fix problems. Pryglass itself sends Apple nothing.
Now and then, after you have set Pryglass up, the Pryglass app may ask Apple to show its standard rating request, at most once per app version. Apple decides whether to show it, and the developer does not learn whether it appeared. If you rate or review Pryglass, that happens in Apple's App Store under Apple's terms, and the developer sees only what the App Store publishes. The extension never asks for a rating.
11. If you contact support
If you email andreas.nelvik.engebretsen@gmail.com, I receive your email address, your message and anything you attach, such as screenshots or a copied summary. I use this only to answer you and to fix the problem you describe. Writing to me is voluntary, but I need your email address to reply. The legal basis is my legitimate interest in answering your request and improving the app (GDPR Article 6(1)(f)), or, where your message concerns something you bought, providing the product you paid for (Article 6(1)(b)).
Emails are kept in my mailbox, which is hosted by an email service provider acting on my behalf. I delete support conversations no later than 24 months after the last message, unless you ask me to delete them sooner or I need them to handle a legal claim. If the email provider stores messages outside the EEA, the transfer is protected by safeguards required by the GDPR, such as the EU Standard Contractual Clauses. I never share your emails with anyone else and never use them for marketing. If you file an issue on GitHub instead, it is public and handled under GitHub's privacy statement.
12. This website
These pages are hosted on GitHub Pages. They use no cookies, analytics or scripts. GitHub logs the IP address of visitors to GitHub Pages sites for security purposes, under GitHub's privacy statement. The developer does not receive these logs.
13. Your rights (GDPR)
If you are in the EEA, the UK or a country with similar laws, you have the right to access, correct and delete personal data about you, to restrict or object to its processing, and to data portability. Because the data Pryglass records never leaves your device, the developer cannot see, export or delete it; you are in full control of it through the options in section 8. For support emails, write to andreas.nelvik.engebretsen@gmail.com and I will answer within one month. For data Apple holds about your purchase or Apple Account, contact Apple.
The developer makes no automated decisions about you and does no profiling of you. The trust score and labels describe websites, are worked out on your device, and are never seen by the developer.
You can also complain to a data protection authority. In Norway this is Datatilsynet, the Norwegian Data Protection Authority (datatilsynet.no). You can also contact the authority in the country where you live or work.
14. Children
Pryglass is not directed at children, but it collects no personal data from anyone, including children under 13 (or the minimum age in your country). If a child sends a support email, it is handled as described in section 11, and a parent or guardian can ask me to delete it.
15. Changes to this policy
If Pryglass starts handling data differently, I will update this page before the new version is released and change the effective date at the top. If a change would mean any data leaves your device, it will be described here and in the App Store release notes first. Earlier versions of this policy are kept in the public history of the GitHub repository that publishes this website.
16. Contact
Andreas Nelvik Engebretsen, Norway
Email: andreas.nelvik.engebretsen@gmail.com
Support: andreasne89.github.io/pryglass/support.html