Pickmark — Bookmark the part you want
2026-09-07
Eurekable does not receive your browsing history or VPN traffic. Pickmark has no account, analytics SDK or advertising identifier. Filtering and activity records are handled on your device. When you enable Network Protection, allowed DNS questions are sent to Cloudflare as described below.
Pickmark stores the following locally in its sandbox/App Group. The app does not upload these records or provide cloud synchronization for them.
| Item | Purpose |
|---|---|
| Filter rule lists | Used by Safari and DNS protection to identify ads |
| Blocked and allowed counts | Shown as numbers in the app |
| Recent DNS domain records (up to 50 blocked and 50 allowed names) | Blocked names show what was blocked. Allowed names are recorded only when you enable diagnostic logging, which is off by default, to diagnose missed blocking or site breakage. Turning diagnostics off clears these records. You can also reset statistics in the app. |
| Allowlist, Cleaner rules, your own rules | Settings you chose |
| Diagnostic log | For troubleshooting. Visible only inside the app; never transmitted |
Deleting the app deletes all of it.
Filtering-related network requests include filter downloads and optional DNS resolution. The receiving service can see the connection's public IP address. This is separate from the local records above.
Once a day, Pickmark fetches public filter lists over HTTPS from EasyList, AdGuard, uBlock Origin filters, malware-filter, pgl.yoyo.org, List-KR, with packaged distributions served from GitHub. As with any web request, those servers see your IP address and the time of the request. We neither receive nor retain that information.
We want to be explicit about this one. With Network Protection on, your device's DNS queries pass through Pickmark. Ad domains are blocked on the device and go nowhere. However, queries that are not blocked are forwarded to Cloudflare's encrypted DNS (DNS over HTTPS, 1.1.1.1) — meaning Cloudflare sees the domain names you look up.
Cloudflare's privacy terms apply to those queries; see the Cloudflare Public DNS Resolver privacy policy. Cloudflare receives the DNS question, including the domain name and query type, and sees the connection's public source IP. DNS responses are temporarily cached in device memory. This DNS feature does not send page contents, full URLs or passwords to Cloudflare. Processing and any provider-side logs occur on Cloudflare infrastructure; Pickmark does not select a storage country. Eurekable does not receive these queries. Local diagnostic logging is described in section 2.
Network Protection is optional and off by default. With it off, DNS goes to your carrier or whichever resolver you have configured, exactly as before.
Network Protection uses Apple's VPN APIs for local DNS filtering. Before activation, the app explains DNS transmission and local records, and iOS asks permission for a VPN configuration. Pickmark has no remote VPN server. The tunnel terminates on your device, and only one address — the resolver — is actually routed into it. Everything else takes its normal path and never touches Pickmark.
iOS cannot run a VPN and iCloud Private Relay at the same time, so turning on Network Protection turns Private Relay off.
The content blockers hand rule lists to Safari; Safari does the matching. Safari does not tell us what you browse.
The helper extension (Cleaner) reads page content in order to hide elements. That happens entirely on your device; page content is never sent anywhere.
Eurekable does not sell, rent or disclose VPN traffic or local activity records to advertisers or data brokers. Allowed DNS questions are sent to Cloudflare for resolution, as described in section 3.2. The provider's linked policy describes its own processing, retention and research access. Local records are used only for filtering, activity display and user-directed troubleshooting.
The local-processing and DNS-transmission practices described above apply to all users, including children.
Changes appear on this page with a new date. If how we handle data changes materially, we will say so inside the app as well.
Selected area URLs, selectors, titles, text and links, groups and snapshots are stored in the app's on-device storage. Refreshing or opening source content connects directly to the original site, which can see the IP address and ordinary web request data. Text for voice synthesis is not sent to the developer's server. Supported devices download voice files through Apple's resource delivery. Purchases and restoration use Apple StoreKit; the app checks verified transactions on device for access. Device backup and restoration depend on the user's Apple settings.
2026-09-27