Privacy Policy
- Blockr watches network connections entirely on your Mac. What it sees — which app connected, to which host and port — is recorded only on your machine and is never uploaded.
- No usage analytics, no accounts. The app never reports what you do with it, and never sends your traffic anywhere.
- Blockr does not read your traffic, with one narrow exception. It decides at the moment a connection opens and never decrypts or proxies what flows through. If you switch a blocklist on, it also reads DNS replies — port 53 only — so that connections arriving as bare IP addresses can be matched against lists written as names. That happens in memory, is never written down or sent anywhere, and can be turned off.
- If you subscribe to a blocklist, Blockr downloads it straight from that list's own publisher — StevenBlack, oisd, HaGeZi or 1Hosts — at most once a day. Those requests go to their servers, not ours: they see your IP address as any website you visit would, and we never learn that you subscribed or which list you picked. Nothing is subscribed by default.
- Two other things leave your Mac. An optional reverse-DNS lookup asks your normal DNS resolver — not us — for the hostname of an address you are already connecting to; you can turn it off. And Blockr checks for a new version about once a week; that check reaches our server and we count it, which is described in full in section 5. You can turn that off too.
- Encrypted DNS is off unless you turn it on. Switched on, Blockr resolves names over HTTPS through the resolver you pick — Cloudflare, Quad9, Google or your own endpoint. Those lookups go to them, never to us; we run no resolver and cannot see them. See section 4.
- Network profiles are recognised by your router, not by your Wi‑Fi name. Blockr never asks for Location permission, so it cannot read an SSID; it uses the router's address instead, keeps that on your Mac, and lets you name the network yourself.
- If you buy a commercial license, that purchase happens here on the website (payment handled by Stripe) — not in the app.
1. Who We Are
Blockr is made by twoplus11 LLC, a Missouri limited liability company (twoplus11.com). When this policy says "we," "us," or "our," it means twoplus11 LLC.
Questions about this policy? Email us at jeremy@twoplus11.com.
2. Data We Do Not Collect
Blockr sees a great deal about your Mac by design — so it is worth being precise about where that stays:
- Nothing is uploaded, ever. The record of which apps connected where lives only on your Mac. It is never sent to us or to anyone else, and Blockr has no way to transmit it.
- Blockr does not read the contents of your traffic, apart from DNS. It makes its decision when a connection is first opened, based on the app, the host and the port, and it never decrypts, records or proxies what flows through — after the verdict the data path is untouched. The single exception: with a blocklist enabled, Blockr reads the question and the answer addresses of DNS replies on port 53, in memory, so that an address-only connection can be matched against a list of names. Nothing from it is written to disk or transmitted, what it remembers is discarded within minutes, and it can be switched off in Settings ▸ Blocklists.
- No usage analytics. Blockr does not report what you do in the app, what rules you write, or what connections it sees. The only thing it sends us is the weekly update check described in section 5, and that carries none of the above. Encrypted DNS (section 4) sends nothing to us either — those lookups go to the resolver you chose.
- No accounts at all. Blockr needs no sign-up and no key — there is no login screen and no activation step, for personal or commercial use.
- Nothing Blockr records can be uploaded. The log, the totals and your rules stay on your Mac; the app has no code path that transmits them.
3. What Blockr Stores On Your Mac
Blockr keeps a few things on your own machine so that it is useful across launches. None of it is transmitted anywhere. All of it is yours to delete.
- A connection log — the app, executable path, remote host, port, verdict and time for each connection Blockr observed, capped at a limit you choose in Settings (5,000 by default). Stored at
~/Library/Application Support/Blockr/history.json. - Per-app totals — how many connections each app made, how many were blocked, and when it was first and last seen. Stored alongside the log in
stats.json. - Your rules — the per-app and per-host decisions you have made, kept in Blockr's preferences so the filter can enforce them.
- Your settings — such as the default action, the alert timeout, and whether hostname lookups are enabled.
- Your network profiles, if you make any — the name you gave a network and how to recognise it again: its router's gateway address (e.g.
192.168.86.1), that router's hardware address from your Mac's ARP table, the kind of link (Wi‑Fi, Ethernet, cellular) and the interface name. There is deliberately no Wi‑Fi network name. Reading an SSID on macOS 14 and later requires Location authorization, and Blockr does not ask for Location — the router identifies a network without any permission at all, and you supply the name yourself. None of this leaves your Mac.
You can clear the log and the totals at any time from Settings ▸ History ▸ Clear History, which deletes both files; your rules are kept separately and can be removed from the Rules screen. Deleting the app and those files removes everything Blockr has recorded.
Hostname lookups. To show apple.com instead of 17.253.144.10, Blockr can perform a reverse-DNS lookup for addresses that appear on screen. That query goes to whichever DNS resolver your Mac is already configured to use — not to us — and only for addresses your Mac was already connecting to. Results are cached, and the whole feature can be switched off in Settings ▸ History.
4. Encrypted DNS
Blockr can act as your Mac's DNS resolver and carry those lookups over HTTPS instead of plain text. This is off until you turn it on, in Settings ▸ Encrypted DNS. With it off, nothing in this section happens and your Mac resolves names exactly as it did before.
Where the queries go. To the resolver you choose — Cloudflare (1.1.1.1), Quad9 (9.9.9.9), Google (8.8.8.8), or any endpoint you type in yourself. They do not come to us. twoplus11 operates no resolver, receives none of these lookups, and has no way to see them. What the resolver you picked does with a query is governed by their privacy policy, not this one, and they will see your IP address as any site you visit would.
What this changes about who can see your lookups. Normally every name your Mac looks up travels in plain text to whatever resolver the network handed you, where the network operator can read and answer it. Turning this on takes that away from them and gives it to the resolver you named instead. It is a deliberate trade, which is why it is off by default and why the choice of resolver is yours.
Nothing extra is stored or sent to us. Lookups are resolved and answered; the existing connection log records connections as it always has, and this feature adds no new record of its own. If the resolver stops answering, Blockr steps out of the path and lets macOS resolve normally rather than leaving you offline.
5. Update Checks
Blockr checks whether a newer version exists — automatically about once a week, and whenever you choose Check for Updates…. You can switch the automatic check off in the updater's own window. Apart from this, the app never contacts us.
What the check sends. The request goes to api.twoplus11.com and identifies the app and the version you are running (Sparkle, the update framework Blockr uses, puts both in the request's user-agent string). Like any web request, it also carries your IP address. It contains nothing about your rules, the apps on your Mac, or the connections Blockr has seen.
What we record. We log each check, so that we can tell roughly how many people still use the app: which app it was, the version reported, the date, the user-agent string, and a salted hash of your IP address. We do not store the IP address itself, the salt changes every day, and nothing in the record is tied to your name, an account, or a license. If you go on to install the update, that download is counted the same way.
This is deliberately coarse. It tells us whether an app is still worth maintaining; it cannot tell us who you are, and it cannot be assembled into a picture of how you use Blockr.
6. If You Contact Us
If you email us — for support or a question about your commercial license — we receive your email address and whatever you choose to put in your message. We use that information only to reply to you. We do not sell or share it.
7. Downloading the App
Blockr is downloaded from our website, which is hosted by a third-party web host. Like any website, the host may keep standard server access logs (such as IP address) for security and operational purposes. This happens at the web-server level when you visit the download page — the Blockr application itself does not transmit anything.
8. Children's Privacy
Blockr is not directed at children under 13, and we do not knowingly collect personal information from children under 13.
9. Your Rights
If you are in the European Union, United Kingdom, or California, you may have the right to access, correct, or delete personal data we hold about you. The only personal data we hold is what you send us by email and, for commercial-license holders, the company name and email tied to your purchase. You can exercise these rights by contacting jeremy@twoplus11.com. We will respond within 30 days. Your commercial-license record is what evidences the license, so deleting it also ends the license.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the "Effective date" at the top of this page when we do. We encourage you to review this page periodically.
11. Contact
Questions or concerns about this Privacy Policy? Contact us at:
twoplus11 LLC
jeremy@twoplus11.com