Privacy policy.
Browsing on this device
WebKit stores website cookies, cache, credentials, and related website data in the profile you choose. Regular profiles use separate persistent stores. Private spaces use nonpersistent stores and are not included in tab restore or history.
iCloud
When iCloud is available, Xanh uses your private CloudKit database to sync profile metadata, spaces, regular tabs (including pin state), bookmarks, settings, exact hostnames where you paused Shields, and the URL/title, source-space and prior pin metadata of regular tabs kept in Archive. Archive entries expire after 30 days and are limited to 200 per profile. The automatic Archive setting may be off or move inactive regular tabs after 1, 7, or 30 days; active, pinned, private, and home tabs are excluded. Xanh does not sync cookies, cache, website passwords, biometric state, page snapshots, private tabs, or private-space Shields exceptions.
History sync is off by default. If you explicitly enable it, visited URLs, page titles, and visit times are stored in your private iCloud database and removed after 90 days. Xanh continues with a local replica when iCloud is unavailable.
Search and websites
Your search terms and web requests are sent directly to the search provider or website you choose. Brave Search is the default; DuckDuckGo, Google, and Bing are optional. Those services apply their own privacy policies.
Content blocking
Xanh derives blocking rules from EasyList and EasyPrivacy. The app checks Xanh's signed rule manifest at most once every 24 hours, or when you request an update. The request exposes normal network metadata such as your IP address to the hosting provider; Xanh does not attach browsing history or a user identifier.
You can pause Shields for one exact hostname in the active profile. The exception does not automatically include subdomains and takes effect only after your next navigation or explicit reload. Exceptions in a regular profile are browser settings in your private CloudKit database; exceptions in a private space stay in memory and are removed with that space.
Biometric protection
Profile protection is opt-in. Authentication is performed by Apple LocalAuthentication and Keychain services on your device. Xanh uses it to lock the interface; it does not claim to encrypt WebKit's website data store.
Contact and changes
Questions can be filed through the support page. Material policy changes will be published here with a new effective date.