For iPhone & iPad · iOS 26 · Open source

Blocks ads everywhere.
Sees nothing.

Phosphor filters ads, trackers, malware and adult content across Safari and every app on iOS 26. It runs on Apple's Private Information Retrieval, so the URLs you visit stay encrypted — even from us.

7-day free trial · then $12.99/year or $1.99/month · cancel anytime

123,211domains on the built-in lists
~99.9%of URLs cleared on-device, zero network
0analytics SDKs, crash reporters, telemetry
MITlicensed — the whole app is on GitHub

What it blocks

Four lists. Every app on the phone.

Filtering happens at the system level, so it covers Safari, in-app browsers and any app that uses URLSession — not just one browser. Add your own hosts-format lists, or block and allow single domains by hand.

Ads

Remove ads across Safari and every app on your device.

Peter Lowe3,526 rules
Trackers

Prevent cross-site tracking and fingerprinting.

EasyPrivacy42,556 rules
Malware

Protection from known malicious domains.

URLhaus451 rules
Adult content

Block adult and explicit content domains.

StevenBlack76,678 rules

How it works

Most URLs never leave your phone.

A request is checked in four stages. Only the rare potential match goes to the network — and it goes encrypted, through a relay that hides who asked.

01
Bloom filter, on device

A compact bit array instantly checks if a URL might be blocked. ~99.9% of URLs are cleared here with zero network traffic.

02
Encrypted PIR query

For a possible match, the system sends a homomorphically encrypted query. The server answers it without ever decrypting it.

03
Apple's OHTTP relay

Queries route through Apple's Oblivious HTTP relay. Your IP is hidden from our server; the query is hidden from Apple. Neither sees both.

04
Block or allow

The encrypted response is decrypted on your device. The app never learns which URL was checked.

// the common case
GET apple.com/…
└─ bloom filter ·········· miss → allow
   0 bytes sent · 0 ms
// a possible match
GET ads.example/track.js
├─ bloom filter ·········· hit
├─ PIR query ············· encrypted, via OHTTP relay
└─ verdict ··············· BLOCK · decrypted on device

Privacy

Nobody sees both.

This is not a policy promise — it is how the pieces are arranged. Each party in the chain holds one half of the picture and cannot get the other.

Your device
SEES
The URL, the Bloom filter, the decryption key
NEVER
Sends anything home. There is no telemetry to send.
Apple's relay
SEES
Your IP address and an opaque encrypted blob
NEVER
What is inside the query — Oblivious HTTP strips it of meaning.
Our PIR server
SEES
A homomorphically encrypted query it computes on blind
NEVER
Your IP, the URL, or the answer. Logs hold timestamps and sizes only.
Zero telemetry, by construction

Aggregate block counts live only on your device, are not backed up to iCloud, and are deleted with the app.

no analytics SDKs no crash reporters no device IDs no location read the policy

Compared

System-wide, without a VPN.

Other blockers route your traffic through a DNS resolver or a VPN you have to trust. Phosphor uses the iOS 26 URL-filter API, so nothing is rerouted and no one is trusted with your history.

PhosphorNextDNSAdGuard ProLockdown1.1.1.1 + WARP
System-wide filteringYesYes (DNS)Yes (DNS/VPN)Yes (VPN)Partial (DNS)
No VPN requiredYesNo*NoNoNo
Privacy modelPIR + HETrust DNSTrust VPNOn-deviceTrust Cloudflare
App sees your URLsNeverYes (DNS)Yes (VPN)NoYes (DNS)
Open sourceYesNoPartialYesNo
Custom filter listsYesYesYesLimitedNo
iOS 26 native APIYesNoNoNoNo

* NextDNS can use DNS-over-HTTPS without a VPN profile, but this doesn't cover all app traffic.

Pricing

One plan. Seven days free.

Filtering requires Phosphor Premium. The price funds the PIR server that answers encrypted queries — there are no ads or data to sell instead.

Without a subscription you can still browse and manage filter lists, read the privacy documentation and complete onboarding.

Phosphor Premium
7 days free
$1.99 / month

Or $12.99 a year — about 45% less.

$12.99 / year

Works out to about $1.08 a month, billed once a year.

  • Block ads & trackers across all apps
  • Malware & adult content filtering
  • Zero-knowledge privacy — encrypted PIR queries
  • Custom filter lists & manual entries
  • A reminder 2 days before your free trial ends
Start free trial

Support

Questions

Not answered here? Email support@phosphor.online or open an issue on GitHub.

Support page
How does Phosphor protect my privacy?

Phosphor uses Apple's Private Information Retrieval (PIR) with homomorphic encryption. URLs are checked locally on your device. For potential matches, encrypted queries go through Apple's relay. Neither the app, our server, nor Apple can see which URLs you visit.

Why does the filter show as "Invalid" or "Not Active"?

The URL filter requires Apple's OHTTP relay approval and a stable internet connection to our PIR server. If the filter shows as invalid, try: (1) Delete and reinstall the app, (2) Restart your device, (3) Check that you have an active subscription.

How do I cancel my subscription?

Go to Settings > [Your Name] > Subscriptions > Phosphor > Cancel Subscription. You'll continue to have access until the end of your billing period.

Does Phosphor work with all apps?

Phosphor filters URLs across Safari, in-app browsers (WebKit), and apps using URLSession. Some apps using custom networking stacks may not be filtered.

Read every line, then turn it on.

The app, the filter extension and the shared Bloom filter are MIT-licensed on GitHub. The architecture and threat model are written down. Nothing is hidden behind a marketing page — including this one.