Privacy Policy
Pelorus · Shadowfax Holdings, LLC
Last updated: 23 August 2026
The short version
The Pelorus app never contacts a server we run. There is no account to create, nothing to log into, and no analytics of any kind in the app. We do not know who you are, what you search for, or what you do inside Pelorus.
Two clarifications, because a blanket claim would be overstating it:
Apple tells us some things. As with every App Store app, Apple reports how many people downloaded and purchased Pelorus, and — for users who chose to share analytics with developers in their iOS settings — aggregate figures like session counts. These are numbers, not people. They carry no names, no email addresses, no device identifiers, and nothing whatsoever about what you searched for. We could not identify a single Pelorus user if we tried.
We do run a website. pelorussearch.app exists so you can read about the app and find help. The Pelorus app never contacts it, never sends anything to it, and does not need it to function. Visiting the website in a browser is a visit to a website, subject to that site's own notice — it has nothing to do with the app on your phone.
The rest of this document explains the parts that are more complicated than that, because there are a few, and you should know about them.
What Pelorus collects
Nothing.
Not your searches. Not the pages you visit. Not your device identifier, your location, your IP address, or your usage patterns. There is no analytics library in the app, no crash reporting, and no telemetry. We deliberately did not build a way to count how many people use Pelorus, because doing so would have required sending something from your device to ours.
The aggregate figures Apple reports to us, described above, are the only numbers we have, and they come from Apple rather than from the app.
What leaves your device, and when
This is the part worth reading carefully. Pelorus is a search app, and searching means talking to search engines. Here is every case where information leaves your phone.
When you search
Your query goes to each search engine you have enabled. Those engines receive your search terms and your IP address, exactly as they would if you visited them in any browser. Pelorus does not add anything to that request and does not send a copy anywhere else, but it cannot make the request private — the engine has to know what you searched for in order to answer.
Each search engine's own privacy policy governs what they do with that. If this matters to you, the engines you enable are entirely your choice, and some are considerably more private than others.
When you use AI Synthesis
There are two modes and they behave very differently.
On-device (Apple Intelligence) runs the model on your phone. Your query and the search results never leave the device. Nothing is sent to Apple, to us, or to anyone else.
Your own API key sends your query and the text of your search results to the provider you chose — Anthropic, OpenAI, or whichever you configured — using your own account with them. That provider's terms govern what happens to it. Pelorus never sees this traffic; the request goes directly from your phone to them.
Your API keys are stored in the iOS Keychain. By default they sync to your other devices through iCloud Keychain, which is end-to-end encrypted and tied to your hardware — unreadable by both Pelorus and Apple. You can turn syncing off for a key in Settings, in which case it stays on the device where you entered it. Either way, a key never leaves your devices except in the request to the provider you chose.
When search suggestions are on
This setting is off by default. When you turn it on, what you type is sent to your default search engine as you type it, before you press return. The setting's description says exactly this, because it is the one feature in Pelorus that sends anything anywhere without you finishing a deliberate action.
When you use a search API
This setting is off by default. When enabled, your query goes to the search API provider you configured, using your own key with them, instead of loading their web page.
When you import a blocklist
If you import a blocklist from a URL, Pelorus fetches that URL once, at the moment you tap import. Lists never update themselves — there is no scheduled request, no background refresh, and no field in the app that could drive one. Checking for updates is something you do by tapping a button.
When you buy Pelorus Unlimited
Purchases are handled entirely by Apple. Your payment information goes to Apple, never to us. We receive no transaction record, no receipt, and no identifying information — the app asks Apple's local system whether this device has the purchase and gets back yes or no.
Apple provides us with aggregate sales figures, the same as for any App Store app. Those figures contain no personal information.
When you turn on iCloud settings sync
This setting is off by default and Pelorus never asks you to enable it.
When you do, your settings — your engine list, domain rules, filters, appearance choices — sync through your own iCloud account so you do not have to set them up again on another device. This uses Apple's iCloud, not any server of ours, and is covered by your iCloud account's encryption.
Your API keys are not part of this settings sync. They sync separately through iCloud Keychain's end-to-end-encrypted channel (described above), or stay on one device if you turn that off. Nothing about what you search or visit is ever synced, because Pelorus never records it in the first place.
What is stored on your device
Two things:
Your settings. Your engine list and order, domain rules, engine weights, filters, appearance choices, and preferences. These are stored so the app works the way you set it up.
Your API keys, if you entered any, in the iOS Keychain as described above.
That is the complete list.
What is never stored
Browsing history. There is none. Pelorus does not have a history feature, and this is not a setting you can turn on.
Cookies, caches, local storage, or any other web data. Every page Pelorus loads runs in an ephemeral, non-persistent store. Tapping Erase does not clear those stores — it destroys them, along with the browser instances that owned them, and builds new ones.
Search queries. When you erase, or close the app with erase-on-close enabled, your queries are gone from memory and were never written to disk.
The tracker counter
Pelorus offers a counter of how many trackers have been blocked. We include it because some people find the statistic useful, and because it is the only user-visible proof that blocking works at all.
The counter works by observing every request a page makes, from inside that page, and tallying the ones our blocklist stops. That is the only way to count them. A side effect is that a website could, with effort, detect that instrumentation is present. It cannot see your searches, your settings, or anything else.
Eliminating the counter would not buy much, though. A page can already detect the behavioral signatures of any content-blocking browser by checking whether its own tracker scripts loaded. Perfect invisibility is not possible to any privacy browser, so giving up the feature would not achieve it either. But we can make Pelorus harder to identify. The counter's marker is given a new, random name every single time the app launches and every single time you tap Erase, so it cannot serve as a stable identifier across sessions.
Fingerprint randomization
This setting is off by default. When enabled, Pelorus varies some of the details websites use to recognize your device, and rotates them every time you erase.
We are honest about the limits: this reduces one category of tracking and does not eliminate fingerprinting. Some sites will render incorrectly with it on, which is why it is off unless you choose it.
Children
Pelorus is a search app that loads the open web. It applies no content filtering of its own, and the search engines you enable have their own safety settings. It is not designed for children and we do not knowingly collect information from anyone, including children, because we do not collect information from anyone at all.
Your rights
Laws in California, the European Union, and elsewhere give you rights to access, correct, delete, and port the personal information a company holds about you.
We hold none. There is nothing to access, nothing to correct, nothing to delete, and nothing to port. If you want to remove everything Pelorus has stored, tap Erase everything now in Settings, or delete the app — both remove all of it, from your device, which is the only place it ever was.
We do not sell personal information. We do not share it. We do not have any.
Changes to this policy
If this policy changes, the updated version will appear here and in the app, with a new date at the top. If a change ever means Pelorus starts collecting something it does not collect today, we will say so plainly at the top of the document rather than burying it.
Contact
Questions about this policy: hello@shadowfaxholdings.com
Shadowfax Holdings, LLC
6754 Bernal Ave Ste 740
Pleasanton, CA 94566
United States