# Third-party notices Licences were re-read from the primary sources on 2026-10-05 (repository LICENSE files, GitHub licence API, the `update.json` manifests in StevenBlack/hosts, and the header of each list file). Allowed in the app bundle: MIT, Apache-2.0, BSD, ISC, MPL-2.0, CC0, public domain (the Unlicense). Anything else is never bundled. ## Bundled with the app (converted to Safari rule lists at build time by `scripts/build-lists.sh`) | List | Built from | Licence | Read at | Allowed | |---|---|---|---|---| | Sweep Base (ads) | written by AZET LLC, `sweep-api.azet.io/sweep/v1/download/sweep-base.txt` | AZET original work | - | yes | | Sweep Trackers (trackers) | written by AZET LLC, `sweep-api.azet.io/sweep/v1/download/sweep-trackers.txt` | AZET original work | - | yes | | Sweep Annoyances | written by AZET LLC, `Resources/sources/annoyances-sweep.txt` | AZET original work | - | yes | | StevenBlack ad-hoc list (ads) | one file of StevenBlack/hosts: `data/StevenBlack/hosts`, "Hosts contributed by Steven Black". Not the unified `hosts` file | MIT, Copyright (c) 2023 Steven Black | https://github.com/StevenBlack/hosts/blob/master/license.txt and https://github.com/StevenBlack/hosts/blob/master/data/StevenBlack/update.json | yes | | Anudeep's Blacklist, ad servers (ads) | one file of anudeepND/blacklist: `adservers.txt`, header "Hosts contributed by Anudeep". The README names no other list as an input | MIT, Copyright (c) 2018 Anudeep ND | https://github.com/anudeepND/blacklist/blob/master/LICENSE | yes | | AdGuard CNAME disguised ads (ads) | AdguardTeam/cname-trackers: `data/combined_disguised_ads.txt`. Found by AdGuard DNS itself (README, "The Solution") | MIT, Copyright 2021 Adguard Software Ltd | https://github.com/AdguardTeam/cname-trackers/blob/master/LICENSE | yes | | AdGuard CNAME original trackers (trackers) | AdguardTeam/cname-trackers: `data/combined_original_trackers.txt` | MIT, Copyright 2021 Adguard Software Ltd | https://github.com/AdguardTeam/cname-trackers/blob/master/LICENSE | yes | | ShadowWhisperer Ads (ads) and Tracking (trackers) | ShadowWhisperer/BlockLists: `Lists/Ads`, `Lists/Tracking`. README: "Lists are made from a custom script and manual additions", "I will not merge other lists". Origin is the author's statement; it cannot be checked from outside | The Unlicense (public-domain dedication) | https://github.com/ShadowWhisperer/BlockLists/blob/master/LICENSE | yes | | Hush cookie-notice rules (ads extension, R-012) | oblador/hush commit `2e96f4f`: `data/generic.txt`, `data/site-specific.txt`, `data/third-party.txt` only, copied into `Resources/app/hush-cookie-rules.txt`. Written in the Hush repository (12 of 13 commits to `site-specific.txt` by the owner). Not `data/vendor/fanboy-cookiemonster.txt`, which the README marks CC BY 3.0 | MIT, Copyright (c) 2020 Joel Arvidsson | https://github.com/oblador/hush/blob/master/LICENSE (read 2026-10-05 22:40 KST) | yes | | Sweep Security | published by AZET at sweep-api.azet.io, built from one source: Phishing-Database/Phishing.Database, file `phishing-domains-ACTIVE.txt` | MIT | https://github.com/Phishing-Database/Phishing.Database/blob/master/LICENSE | yes | ## Code | Part | Where | Licence | Read at | |---|---|---|---| | SwiftBloomFilter (BloomFilter, FNV1aHash, Murmur3Hash) from Apple's "Filtering traffic by URL" sample | `Sources/SweepRules/AppleBloomFilter/`, unmodified, licence file kept | MIT-style Apple sample licence, Copyright 2026 Apple Inc. | `LICENSE.txt` in the sample zip (2026-10-06) | | Sweep Extra content scripts (`App/Extra/Resources/*.js`) | written by AZET LLC from the behaviour described in REFERENCE.md R-034/R-037. uBlock Origin and AdGuard Scriptlets (GPL-3.0) were read for behaviour only; no code copied | MIT, AZET LLC | - | | Lucide icons, including `brush-cleaning` in the app icon layers | `App/Assets.xcassets/Icons`, `App/AppIcon.icon/Assets` | ISC | lucide-static 0.544.0 | Server side tested locally, not shipped in the app: apple/pir-service-example and apple/swift-homomorphic-encryption (Apache-2.0), see docs/url-filter.md. ## Language lists (R-017): downloaded on the device, not bundled Used only when the language is among the device's preferred languages; credited in More, Help, Acknowledgements. LANE-RULES allows CC BY with attribution. Each licence was re-read on 2026-10-06. | List | URL | Licence | Read at | |---|---|---|---| | YousList (Korean) | github.com/yous/YousList `youslist.txt` | CC BY 4.0, Chayoung You | README "License" section | | hostsVN (Vietnamese) | github.com/bigdargon/hostsVN `filters/adservers-all.txt` | MIT, Copyright (c) 2026 BigDargon | LICENSE | | Hufilter (Hungarian) | github.com/hufilter/hufilter `hufilter.txt` | CC BY 4.0, Hufilter Team | GitHub licence API: CC-BY-4.0 | | ROad-Block Light (Romanian) | github.com/tcptomato/ROad-Block `road-block-filters-light.txt` | MIT, Copyright (c) 2019 ROad Block | LICENSE | | EasyList Thailand (Thai) | github.com/easylist-thailand/easylist-thailand | Apache License 2.0 | LICENSE | ## Bundled in Sweep Extra (R-046): page rules converted from the language lists `scripts/build-lists.sh` downloads the four lists below and `sweeprules extra` keeps only their element-by-text, element-by-style, extended-CSS and scriptlet lines, converted to data in `App/Extra/Resources/extra-rules.js` (Sweep changes their format, not their content). The scripts that run them (`engine.js`, `engine-main.js`) are written by AZET LLC under MIT; no code from uBlock Origin, AdGuard or other GPL scriptlet libraries. Credited in the app's Acknowledgements. | List | Licence | |---|---| | YousList | CC BY 4.0, Chayoung You | | Hufilter | CC BY 4.0, Hufilter Team | | ROad-Block Light | MIT, Copyright (c) 2019 ROad Block | | EasyList Thailand | Apache License 2.0 | Phishing.Database is a community database; its README names no third-party feed as an input and publishes the whole database under the MIT licence below. The repository that collects community submissions (Phishing-Database/phishing) has no licence file of its own. ``` MIT License Copyright (c) 2018-2025 Mitchell Krog - github.com/mitchellkrogza Copyright (c) 2018-2025 Nissar Chababy - github.com/funilrys Copyright (c) 2018-2025 Phishing.Database Contributors - github.com/Phishing-Database Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. ``` The MIT licence text above applies, each with its own copyright line, to the StevenBlack ad-hoc list (Copyright (c) 2023 Steven Black), Anudeep's Blacklist (Copyright (c) 2018 Anudeep ND) and the AdGuard CNAME lists (Copyright 2021 Adguard Software Ltd), and the Hush cookie-notice rules (Copyright (c) 2020 Joel Arvidsson). The AdGuard filters themselves (AdguardTeam/AdguardFilters) are GPL-3.0 and are not bundled; only the separate MIT repository AdguardTeam/cname-trackers is. ShadowWhisperer/BlockLists is released under the Unlicense: ``` This is free and unencumbered software released into the public domain. Anyone is free to copy, modify, publish, use, compile, sell, or distribute this software, either in source code form or as a compiled binary, for any purpose, commercial or non-commercial, and by any means. In jurisdictions that recognize copyright laws, the author or authors of this software dedicate any and all copyright interest in the software to the public domain. We make this dedication for the benefit of the public at large and to the detriment of our heirs and successors. We intend this dedication to be an overt act of relinquishment in perpetuity of all present and future rights to this software under copyright law. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. For more information, please refer to ``` ## Tracker and ad list candidates checked on 2026-10-05 Each licence was read at the URL in the table (repository LICENSE through the GitHub licence API, or the list header). | Source | Licence | Read at | Merged or derived from | Verdict | |---|---|---|---|---| | AdguardTeam/cname-trackers | MIT | https://github.com/AdguardTeam/cname-trackers/blob/master/LICENSE | AdGuard DNS's own observations | bundled: original trackers (93), disguised ads (11,739). Disguised trackers (224,825 hosts) are over Safari's 150,000-rule limit for one list and are not bundled | | anudeepND/blacklist `adservers.txt` | MIT | https://github.com/anudeepND/blacklist/blob/master/LICENSE | none named; "Hosts contributed by Anudeep" | bundled (ads). File last changed 2025-12-27 | | ShadowWhisperer/BlockLists | Unlicense | https://github.com/ShadowWhisperer/BlockLists/blob/master/LICENSE | none; author's script and manual additions | bundled: Ads, Tracking | | Frogeye first-party trackers | MIT (list header points to the generator's licence) | https://git.frogeye.fr/geoffrey/eulaurarien/src/branch/master/LICENSE | hand-picked tracker zones resolved against the Cisco Umbrella popularity list; the "multi-party" variants use EasyPrivacy and AdGuard and are excluded | licence allowed, not bundled: the app would download it from one person's server on every user's device; needs an AZET mirror first | | Perflyst/PiHoleBlocklist `SessionReplay.txt` | MIT | https://github.com/Perflyst/PiHoleBlocklist/blob/master/LICENSE | none named | licence allowed, not bundled: 24 hosts, unchanged since 2020-05-14 | | nextdns/native-tracking-domains | MIT | https://github.com/nextdns/native-tracking-domains/blob/main/LICENSE | none named | licence allowed, not bundled: device telemetry hosts, not web trackers; last pushed 2023 | | crazy-max/WindowsSpyBlocker | MIT | https://github.com/crazy-max/WindowsSpyBlocker/blob/master/LICENSE | - | licence allowed, not bundled: Windows telemetry, no use in Safari | | lightswitch05/hosts | Apache-2.0 | https://github.com/lightswitch05/hosts/blob/master/LICENSE | - | licence allowed, not bundled: archived, last pushed 2023-11 | | bigdargon/hostsVN | MIT | https://github.com/bigdargon/hostsVN/blob/master/LICENSE | none named | licence allowed, not bundled: regional ad list, not a tracker list | | brave/adblock-lists | MPL-2.0 | https://github.com/brave/adblock-lists/blob/master/LICENSE | Brave's additions on top of EasyList, EasyPrivacy and uBlock lists; `brave-firstparty-cname.txt` carries comments pointing at AdguardFilters (GPL-3.0) commits and EasyList issues | no: origin of single entries not separable | | DuckDuckGo tracker-radar | CC BY-NC-SA 4.0 | https://github.com/duckduckgo/tracker-radar/blob/main/LICENSE | - | no (non-commercial, share-alike) | | DuckDuckGo tracker-blocklists | CC BY-NC-SA 4.0 | https://github.com/duckduckgo/tracker-blocklists/blob/main/LICENSE | Tracker Radar | no (non-commercial, share-alike) | | Disconnect tracking protection | CC BY-NC-SA 4.0 | https://github.com/disconnectme/disconnect-tracking-protection/blob/master/LICENSE | - | no (non-commercial, share-alike) | | mozilla-services/shavar-prod-lists | MPL for the repository, CC BY-NC-SA for the Disconnect lists in it | https://github.com/mozilla-services/shavar-prod-lists/blob/master/LICENSE | Disconnect | no (non-commercial) | | Ghostery trackerdb | CC BY-NC-SA 4.0 | https://github.com/ghostery/trackerdb/blob/main/LICENSE | - | no (non-commercial, share-alike) | | WhoTracks.Me | MIT on the repository | https://github.com/whotracksme/whotracks.me/blob/master/LICENSE.md | tracker metadata comes from Ghostery trackerdb (CC BY-NC-SA 4.0) | no (built on non-commercial data) | | Peter Lowe's list (yoyo.org) | none stated on the list or its page; the site's own licence text forbids use "that could possibly be construed as making anybody any money" | https://pgl.yoyo.org/adservers/ and https://pgl.yoyo.org/license/ | - | no (no licence for the list) | | EasyList, EasyPrivacy | GPL-3.0-or-later or CC BY-SA 3.0-or-later | https://easylist.to/pages/licence.html | - | no (copyleft); optional subscription only | | AdGuard filters | GPL-3.0 | https://github.com/AdguardTeam/AdguardFilters/blob/master/LICENSE | - | no (GPL); optional subscription only | | HaGeZi DNS blocklists | GPL-3.0 | https://github.com/hagezi/dns-blocklists/blob/main/LICENSE | many | no (GPL) | | OISD | GPL-3.0 | https://github.com/sjhgvr/oisd/blob/main/LICENSE | many | no (GPL) | | uBlock Origin uAssets | GPL-3.0 | https://github.com/uBlockOrigin/uAssets/blob/master/LICENSE | - | no (GPL); optional subscription only | | EFF Privacy Badger (`seed.json`, yellowlist) | GPL-3.0-or-later for the project; the yellowlist file at eff.org carries no licence line | https://github.com/EFForg/privacybadger/blob/master/LICENSE | `cname_domains.json` is taken from AdguardTeam/cname-trackers (MIT) | no (GPL) | | NextDNS metadata, blocklists, cname-cloaking-blocklist | no LICENSE file (`nextdns/metadata`, `nextdns/blocklists`); `nextdns/cname-cloaking-blocklist` returned 404 | https://github.com/nextdns/metadata | - | no (no licence) | | blocklistproject/Lists | Unlicense | https://github.com/blocklistproject/Lists/blob/main/LICENSE | README: "Current Sources: ShadowWhisperer, zachlagden, Hagezi, and more" | no (merges GPL sources) | | AdAway hosts | CC BY 3.0 | header of https://raw.githubusercontent.com/AdAway/adaway.github.io/master/hosts.txt | - | needs an owner or legal decision (attribution licence, commercial use allowed, outside the allowed set) | | tiuxo/hosts | CC BY 4.0 | https://github.com/tiuxo/hosts/blob/master/LICENSE | - | needs an owner or legal decision (same reason) | ## Not bundled: compilations checked and taken out of the bundle on 2026-10-05 The StevenBlack unified hosts file and badmojr/1Hosts (Lite) carry a permissive licence on the repository (MIT and MPL-2.0), but each merges lists from other publishers, and several of those do not allow redistribution in a paid app. Entries cannot be separated by origin after merging, so neither file ships in the app. From StevenBlack/hosts the app now takes only Steven Black's own list, fetched from its own file. 1Hosts (Lite) remains available as an optional list that the device downloads from GitHub when the user turns it on. Sources merged into the StevenBlack unified hosts file (the `# Start ` sections of the file on 2026-10-05): | Source | URL | Licence | Read at | Allowed | |---|---|---|---|---| | Steven Black's ad-hoc list | https://github.com/StevenBlack/hosts/blob/master/data/StevenBlack/hosts | MIT | https://github.com/StevenBlack/hosts/blob/master/license.txt | yes | | AdAway | https://raw.githubusercontent.com/AdAway/adaway.github.io/master/hosts.txt | CC BY 3.0 | header of the list file | no (attribution licence outside the allowed set) | | add.2o7Net, add.Dead, add.Risk, add.Spam (FadeMind/hosts.extras, archived) | https://github.com/FadeMind/hosts.extras | StevenBlack manifest says MIT; the source's own README marks all four as mirrors of hostsfile.org under GPLv3+ | https://github.com/FadeMind/hosts.extras/blob/master/README.md | no (GPL) | | UncheckyAds (FadeMind/hosts.extras) | https://github.com/FadeMind/hosts.extras | MIT | same README | yes | | Badd-Boyz-Hosts | https://github.com/mitchellkrogza/Badd-Boyz-Hosts | MIT | https://github.com/mitchellkrogza/Badd-Boyz-Hosts/blob/master/LICENSE.md | yes | | hostsVN | https://github.com/bigdargon/hostsVN | MIT | https://github.com/bigdargon/hostsVN/blob/master/LICENSE | yes | | KADhosts | https://github.com/FiltersHeroes/KADhosts | CC BY-SA 4.0 | https://github.com/FiltersHeroes/KADhosts/blob/master/LICENSE | no (share-alike) | | minecraft-hosts | https://github.com/jamiemansfield/minecraft-hosts | CC0-1.0 | https://github.com/jamiemansfield/minecraft-hosts/blob/master/LICENSE.txt | yes | | MVPS hosts | https://winhelp2002.mvps.org/hosts.txt | CC BY-NC-SA 4.0, "free to use for personal use only" | header of the list file | no (non-commercial) | | Dan Pollock, someonewhocares.org | https://someonewhocares.org/hosts/zero/hosts | "free to copy and distribute this file for non-commercial uses" | header of the list file | no (non-commercial) | | Tiuxo hostlist, ads | https://github.com/tiuxo/hosts | CC BY 4.0 | https://github.com/tiuxo/hosts/blob/master/LICENSE | no (attribution licence outside the allowed set) | | URLhaus (abuse.ch) | https://urlhaus.abuse.ch/downloads/hostfile/ | StevenBlack manifest says CC0; the file header points to the terms at urlhaus.abuse.ch/api, which offer the data under fair-use principles and say commercial or for-profit use may require a paid subscription | https://urlhaus.abuse.ch/api/ | no (commercial use restricted) | | yoyo.org (Peter Lowe) | https://pgl.yoyo.org/adservers/ | no licence stated in the file or in the StevenBlack manifest; the page says "Feel free to combine this list with yours or lists from other sites and put it up on the web" | https://pgl.yoyo.org/adservers/ | no (no licence) | 1Hosts (Lite): the file header gives "Licence: MPLv2" and credits https://badmojr.github.io/1Hosts/-data/lists/assets.txt, which listed 324 lines of contributor list URLs on 2026-10-05. They were not all checked one by one; the list is excluded because it names, among others, `winhelp2002.mvps.org/hosts.txt` (CC BY-NC-SA 4.0, personal use only), `someonewhocares.org/hosts/zero/hosts` (non-commercial), `urlhaus.abuse.ch` (commercial use restricted), `big.oisd.nl` (GPL-3.0, https://github.com/sjhgvr/oisd/blob/main/LICENSE) and AdGuard filters at `filters.adtidy.org` (GPL-3.0, https://github.com/AdguardTeam/AdguardFilters/blob/master/LICENSE). ## Not bundled: optional runtime subscriptions (downloaded on the user's device from the publisher) - badmojr/1Hosts (Lite) - MPL-2.0 compilation with the mixed sources above. https://github.com/badmojr/1Hosts - EasyList, EasyPrivacy - GPL-3.0-or-later or CC BY-SA 3.0-or-later. https://easylist.to - AdGuard Base, Tracking Protection, Annoyances filters - GPL-3.0. https://github.com/AdguardTeam/AdguardFilters - uBlock filters - GPL-3.0. https://github.com/uBlockOrigin/uAssets Icons (App/Assets.xcassets/Icons and the app icon mark, vendored by scripts/make-assets.sh) - Lucide 0.544.0 - ISC License. Copyright (c) for portions of Lucide are held by Cole Bemis 2013-2023 as part of Feather (MIT). All other copyright (c) for Lucide are held by Lucide Contributors 2025. https://lucide.dev (LICENSE re-read from the npm package on 2026-10-05). The app shows this notice under Settings, Open-source notices. Code: no third-party code is linked. The converter is original (AdGuard SafariConverterLib is GPL-3.0 and is not used).