No telemetry. Ever.
Telemetry is hard-disabled in the browser. There is no collector endpoint, and the setting cannot be switched on.
No telemetry. No analytics. No ads. No tracking SDKs. No central account. Open the browser and search without a PearBrowser profile, while privacy protections block common tracking across the regular web. Private by default, open source, and built for people—not profiles.
hyper://03f0060a35451cfb6b68ad1dda1b8474ebb43fd9100071ccf7d67679a83ebb4f/.
hyper:// sites, run Pear apps, search people you trust, and publish without a central platform account.PearBrowser now opens on a browser-owned home page with DuckDuckGo search. PearBrowser sends no search analytics, adds no submitted query to its optional persistent visit log, and keeps Content Shield on for the results page.
The honest boundary: DuckDuckGo receives the query and your network address to return results. Its published policy says it does not save or share search history. Private search improves privacy; it is not anonymity.
Content Shield stays on. DuckDuckGo receives your query and network address. Private search is not anonymity.
That means something specific: the browser has no telemetry collector, no remote analytics, no ad network, and no tracking SDK. It never uploads your browsing history to an analytics, advertising, or profiling service.
Telemetry is hard-disabled in the browser. There is no collector endpoint, and the setting cannot be switched on.
Browsing history and local page indexing are opt-in. If you enable them, they are stored locally rather than sent to PearBrowser.
Content Shield is on by default, alongside HTTPS-only navigation, tracking-parameter stripping, third-party cookie blocking, and fingerprint farbling.
Your identity and app permissions are yours. PearBrowser does not require a central profile to browse, search, publish, or run P2P apps.
PearBrowser is easiest to understand when people see a complete path: open a live P2P site, search it with proof, publish something new, then inspect what the browser knows about trust.
Open the app and the active PearBrowser Home tab is ready to search, with the product site, P2P Builders, and peerit beside it.
Run a query against Library or P2P Sites. The important part is not just that results appear; it is that the UI explains where each one came from and how it was verified.
Create a tiny site in the block editor, click Publish & Pin, then show the replication row. This is the clearest aha moment in the whole app.
hyper://1868916a…02709e25d/
Show the app catalog as a decentralized app store: source chips, launch mode, release history, permissions, relay availability, and the path for builders to publish their own pinned apps into a catalogue.
No P2P module bolted onto Chromium. PearBrowser is built bottom-up on the Holepunch / Pear stack: Hyperswarm for discovery, Hyperdrive for storage, Hyperbee for local data, Autobase for shared logs, and Ed25519 identities for user-owned trust.
hyper://Paste a drive key, a z-base-32 key, a friendly name, or a clearnet address. PearBrowser streams P2P content directly from peers, routes clearnet tabs through its privacy proxy by default, applies Content Shield before requests leave, and shows site keys plus catalog provenance when you inspect what you opened.
The Apps tab is a decentralized app store: curated, community, personal, Hyperbee, schema-sheets, and relay-index catalogues merge into one view. Publishers can seed an app to HiveRelay, pin it for availability, and publish the entry to a catalogue; users inspect provenance before launching.
The site editor publishes Hyperdrives and auto-pins them to HiveRelay. App publishers use the same loop: package the app, seed it to a relay, pin it, then publish the catalogue entry so it can be discovered from the Apps tab.
Apps, sites, search results, and permissions carry calm proof surfaces: catalogue source chips, signed/unsigned status, relay pins, live peers, release history, profile grants, and swarm-topic grants.
The product keeps trust visible but calm. You can use the app normally, then open details when you want to know what is signed, pinned, local, federated, or permissioned.
A 12-word backup phrase restores your identity on a new device. Each site receives a different appPubkey, and Settings groups sign-in, profile, contact, and arbitrary swarm-topic grants by app for revocation.
Settings shows your npub, lets you link or revoke a cross-curve attestation, and can post NIP-01 notes signed with that key. The feed is trust-graph scoped: contact notes must match the contact's attested Nostr key. No public wss:// relay client by default.
Signed contact invites build the trusted frontier. Those contacts can enrich search, assert names, and contribute Nostr notes, but each surface preserves provenance so a local petname, contact claim, and curated default never look equivalent.
The early surfaces stay opt-in and explicit. They are useful today, but the UI tells you where the edges are.
Type pearname://name or a bare word in the URL bar. Resolution checks your private petnames, your own registry records, trusted-contact claims, and curated defaults, while Unicode guardrails block confusable look-alikes.
Pair your own devices with a sync://<key>:<encKey> invite. The current sync surface covers bookmarks, open-tab snapshots, allowlisted settings, profile fields, recent history, contacts, and app grants, with rotate/forget recovery controls.
Settings exposes boot timing, proxy fetch mix, cache hit rate, P2P/relay split, storage usage, and live relay capability pills. It is product UX for a network that should be inspectable.
Today's web is rented. The site you bookmarked five years ago is probably a 404 by now — the domain expired, the company pivoted, the host shut down, and your link died with it.
PearBrowser sites are Hyperdrives addressed by public key — no central account or DNS dependency — replicated peer-to-peer and pinned 24/7 on the HiveRelay backbone. The publisher being offline doesn't take the site down, because peers and relays can carry the bytes.
When you bookmark a hyper:// URL, you bookmark a thing that exists — not a thing that resolves to a thing if a company keeps paying for it.
hyper://key/ in hand.
PearBrowser sits alongside the HiveRelay backbone, a mobile sibling that speaks the same catalog and gateway contract, and a growing set of real companion apps.
hyper://.hyper:// drives from any browser via the HiveRelay HTTP gateway. Drop it into a blog, a PWA, or a link previewer.hyper:// pages with three trust tiers, per-app rate limits, a 1 MB/s/peer cap, and persistent grants.v0.7.1 fixes the renderer/backend handoff behind the cluster of unrelated RPC timeout messages some users saw after a reload or live update. Calls now fail immediately if the local socket closes, the authenticated renderer reconnects during a bounded grace window, and the shell shows a clear resume state. It retains the P2P Content Shield lists, capability-gated Pear Plugins, and one-click plugin catalogue from v0.7.0. Desktop preview builds are attached for macOS, Windows, and Linux; the download page has per-platform builds with SHA-256 checksums.
pear run pear://tco5k7h38uoxatedp1wongdbhjxow1x7jiwm3t1i9cujbebhsbty
pear run pear://… path hot-syncs the current release from the swarm and works on every desktop today. Pear runtime v2.4.0 deprecates pear run, so it is a compatibility path while signed native installers become the primary distribution story.
For the people who scroll to the bottom first.
| Desktop version | v0.7.1 · production length 92858 · pinned on the HiveRelay backbone |
|---|---|
| Distribution | Unsigned preview builds attached to v0.7.1: macOS .app.zip (arm64 + x64), Windows .msix, Linux .AppImage; signed/notarized installers in progress; pear run pear://… P2P launch path works today |
| Runtime | Pear (Bare + Chromium via pear-electron); pear run is legacy because Pear runtime v2.4.0 deprecates it |
| Core libraries | hyperswarm, hyperdrive, hyperbee, corestore, hypercore, autobase, p2p-hiverelay |
| Search | Lighthouse — local Hyperbee full-text index, signed by a per-app search subkey; opt-in federation over Hyperswarm (smoke-validated) |
| Identity | BIP-39 → Ed25519 root with per-app sub-keys; opt-in Nostr (secp256k1/BIP-340) — Phase 3: attested binding, post notes, federated feed over your trust graph (no public relays yet) |
| Bridge surface | window.pear.swarm.v1 — three trust tiers, per-app rate limits, 1 MB/s/peer cap (SWARM-V1.md) |
| Sync | Experimental, opt-in: sync:// Autobase device pairing for bookmarks, tabs, settings, profile, history, contacts, and app grants |
| Platforms | macOS, Windows, Linux — preview builds on the download page; Android and iOS (App Store / TestFlight) in progress |
| License | Apache-2.0 |
| Legacy launch key | pear://tco5k7h38uoxatedp1wongdbhjxow1x7jiwm3t1i9cujbebhsbty |
| This site (P2P) | hyper://03f0060a35451cfb6b68ad1dda1b8474ebb43fd9100071ccf7d67679a83ebb4f/ — the same page, pinned 24/7 on HiveRelay |
No. PearBrowser ships without telemetry, remote analytics, an ad network, or tracking SDKs. It does not upload your browsing history to PearBrowser or sell it to advertisers. History and local page indexing are off by default; if you enable them, the data stays local unless you explicitly choose device sync.
No. PearBrowser is private by default, but it is not an anonymity network. Websites, relay operators, and P2P peers may receive the network information required to serve your request, including your IP address and requested content. Some HiveRelay operators can expose Tor endpoints, but PearBrowser Desktop does not yet route browser traffic through Tor automatically.
Content Shield, HTTPS-only navigation, common tracking-parameter stripping, third-party cookie blocking, and fingerprint farbling are enabled by default. Browsing history and local full-text search indexing are disabled until you opt in. Telemetry stays off and cannot be enabled.
Yes. The first tab and every blank new tab include DuckDuckGo search. PearBrowser sends no search analytics and does not add submitted queries to its optional persistent visit log. DuckDuckGo still receives the query and your network address to return results; its policy says it does not save or share search history. This is private search, not anonymity.
No — that's the whole point. Lighthouse is a local-first personal index: pages you browse are tokenized, signed by a per-app search subkey, and stored in a local Hyperbee. Library search returns in under 5ms with zero network. If you opt in to “include trusted peers,” the query also fans out to your trust graph over Hyperswarm — never to a central crawler.
Every federated row is re-verified client-side against the contact's identity binding and dropped on failure before it can affect ranking. Contacts only enter your trust graph through signed invite URLs that are verified at import and rejected if forged. The ranker is deterministic and clock-free, so the same inputs produce identical ordering on every device. The room is an index, not an authority.
The local index is live and wired. Federation is smoke-validated by a two-node federation test — meaning the path works end-to-end, not that it's been run at production scale. Treat the opt-in toggle as the early-access feature it is.
Not to public wss:// relays — not yet. What works today (Phase 3): Settings displays your npub and a one-click “Link (attested)” / Revoke control that cross-curve-binds your Nostr (secp256k1/BIP-340) key to your Pear Ed25519 root. You can post NIP-01 notes signed with that key, and read notes your verified contacts authored with their attested keys — all replicated peer-to-peer over your trust graph, with no relay servers in the middle. Public relay transport is a later, opt-in phase.
Device sync is still experimental and opt-in, but it now covers more than bookmarks: open-tab snapshots, allowlisted settings, profile fields, bounded browsing history, trusted contacts, and app grants. You pair devices with a sync://<key>:<encKey> invite, and rotate or forget the sync group when a device should stop receiving future state.
Nothing — that's the point. When you publish, the block editor signs a seed-request and HiveRelay pins the drive; PearBrowser only reports “published” after a relay confirms replication. The publisher can then be offline indefinitely while the relays serve the bytes to anyone with the key.
hyper:// from a regular browser?Yes, via hyper-fetch — a small drop-in JS library that talks to the HiveRelay HTTP gateway. The full peer experience (publishing, identity, Lighthouse search, signed grants) still requires PearBrowser.
pear run?Desktop builds are attached to the v0.7.1 release and listed on the download page: macOS .app.zip, Windows .msix, and Linux .AppImage. They are unsigned preview builds today, so pear run pear://… stays available as a friction-free P2P launch path while signed/notarized installers land; Pear runtime v2.4.0 deprecates that command, so it is a compatibility path, not the finished story.
If you backed up your 12-word BIP-39 phrase, you restore your identity on a new machine and your grants and per-app sub-keys come back with it. If you didn't back up, drives you published stay alive on the relays — but you can never update or unseed them. Write the phrase down.
Get a browser with no telemetry, no ad profile, and local-first data—plus direct access to the peer-to-peer web.