Desktop v0.7.1 · production length 92858 · preview builds live · macOS · Windows · Linux

PearBrowser the browser that doesn't track you.

No telemetry. No analytics. No ads. No tracking SDKs. No central account. Open the browser and search without a PearBrowser profile, while privacy protections block common tracking across the regular web. Private by default, open source, and built for people—not profiles.

0 telemetry events 0 advertising profiles 0 tracking SDKs
Free and open source for macOS, Windows, and Linux. Current desktop downloads are unsigned preview builds.
This website is also served peer-to-peer at hyper://03f0060a35451cfb6b68ad1dda1b8474ebb43fd9100071ccf7d67679a83ebb4f/.
No PearBrowser telemetry or analytics History and local search are off by default Content Shield is on by default Open-source code you can inspect
No surveillance business modelPearBrowser does not collect usage telemetry or build a profile to sell ads.
Private search on launchThe first tab opens to DuckDuckGo search. PearBrowser sends no search analytics and skips its optional persistent visit log.
Everyday web protectionHTTPS-only navigation, tracking-link cleanup, third-party cookie blocking, fingerprint farbling, and Content Shield.
Peer-to-peer powerBrowse hyper:// sites, run Pear apps, search people you trust, and publish without a central platform account.
The privacy promise

PearBrowser doesn't track you.

That means something specific: the browser has no telemetry collector, no remote analytics, no ad network, and no tracking SDK. It never uploads your browsing history to an analytics, advertising, or profiling service.

No telemetry. Ever.

Telemetry is hard-disabled in the browser. There is no collector endpoint, and the setting cannot be switched on.

Your history starts off.

Browsing history and local page indexing are opt-in. If you enable them, they are stored locally rather than sent to PearBrowser.

Trackers start blocked.

Content Shield is on by default, alongside HTTPS-only navigation, tracking-parameter stripping, third-party cookie blocking, and fingerprint farbling.

No central account.

Your identity and app permissions are yours. PearBrowser does not require a central profile to browse, search, publish, or run P2P apps.

What to demo

Show the loop, not the protocol.

PearBrowser is easiest to understand when people see a complete path: open a live P2P site, search it with proof, publish something new, then inspect what the browser knows about trust.

1 · Fresh launch

Start with private search.

Open the app and the active PearBrowser Home tab is ready to search, with the product site, P2P Builders, and peerit beside it.

2 · Search

Search with provenance on every result.

Run a query against Library or P2P Sites. The important part is not just that results appear; it is that the UI explains where each one came from and how it was verified.

3 · Publish

Publish a page that survives your laptop closing.

Create a tiny site in the block editor, click Publish & Pin, then show the replication row. This is the clearest aha moment in the whole app.

hyper://1868916a…02709e25d/
4 · Apps & trust

Run apps, then inspect why they are trustworthy.

Show the app catalog as a decentralized app store: source chips, launch mode, release history, permissions, relay availability, and the path for builders to publish their own pinned apps into a catalogue.

What it is

One desktop, four P2P product loops.

No P2P module bolted onto Chromium. PearBrowser is built bottom-up on the Holepunch / Pear stack: Hyperswarm for discovery, Hyperdrive for storage, Hyperbee for local data, Autobase for shared logs, and Ed25519 identities for user-owned trust.

Browse hyper://

Paste a drive key, a z-base-32 key, a friendly name, or a clearnet address. PearBrowser streams P2P content directly from peers, routes clearnet tabs through its privacy proxy by default, applies Content Shield before requests leave, and shows site keys plus catalog provenance when you inspect what you opened.

Run Pear apps

The Apps tab is a decentralized app store: curated, community, personal, Hyperbee, schema-sheets, and relay-index catalogues merge into one view. Publishers can seed an app to HiveRelay, pin it for availability, and publish the entry to a catalogue; users inspect provenance before launching.

Publish and pin

The site editor publishes Hyperdrives and auto-pins them to HiveRelay. App publishers use the same loop: package the app, seed it to a relay, pin it, then publish the catalogue entry so it can be discovered from the Apps tab.

Inspect trust

Apps, sites, search results, and permissions carry calm proof surfaces: catalogue source chips, signed/unsigned status, relay pins, live peers, release history, profile grants, and swarm-topic grants.

Trust surfaces

Proof without protocol homework.

The product keeps trust visible but calm. You can use the app normally, then open details when you want to know what is signed, pinned, local, federated, or permissioned.

BIP-39 identity + per-app keys

A 12-word backup phrase restores your identity on a new device. Each site receives a different appPubkey, and Settings groups sign-in, profile, contact, and arbitrary swarm-topic grants by app for revocation.

Trusted-contact Nostr bridge Phase 3

Settings shows your npub, lets you link or revoke a cross-curve attestation, and can post NIP-01 notes signed with that key. The feed is trust-graph scoped: contact notes must match the contact's attested Nostr key. No public wss:// relay client by default.

Search, names, and feeds from verified contacts

Signed contact invites build the trusted frontier. Those contacts can enrich search, assert names, and contribute Nostr notes, but each surface preserves provenance so a local petname, contact claim, and curated default never look equivalent.

On the dev line

Experimental features, honestly labeled.

The early surfaces stay opt-in and explicit. They are useful today, but the UI tells you where the edges are.

P2P names & petnames Experimental

Type pearname://name or a bare word in the URL bar. Resolution checks your private petnames, your own registry records, trusted-contact claims, and curated defaults, while Unicode guardrails block confusable look-alikes.

Encrypted device sync Experimental

Pair your own devices with a sync://<key>:<encKey> invite. The current sync surface covers bookmarks, open-tab snapshots, allowlisted settings, profile fields, recent history, contacts, and app grants, with rotate/forget recovery controls.

Diagnostics that explain the network

Settings exposes boot timing, proxy fetch mix, cache hit rate, P2P/relay split, storage usage, and live relay capability pills. It is product UX for a network that should be inspectable.

The promise

Every site you visit, stays visitable.

Today's web is rented. The site you bookmarked five years ago is probably a 404 by now — the domain expired, the company pivoted, the host shut down, and your link died with it.

PearBrowser sites are Hyperdrives addressed by public key — no central account or DNS dependency — replicated peer-to-peer and pinned 24/7 on the HiveRelay backbone. The publisher being offline doesn't take the site down, because peers and relays can carry the bytes.

When you bookmark a hyper:// URL, you bookmark a thing that exists — not a thing that resolves to a thing if a company keeps paying for it.

You publish — block editor, signed seed-request, hyper://key/ in hand.
HiveRelay pins it automatically and only reports “published” once a relay confirms replication.
You close your laptop. The site stays reachable.
Anyone with the key opens it in PearBrowser — or any web browser via hyper-fetch.
The ecosystem

Part of a P2P stack, not a silo.

PearBrowser sits alongside the HiveRelay backbone, a mobile sibling that speaks the same catalog and gateway contract, and a growing set of real companion apps.

Pear POS Pear Tickets pearpaste Pear Dealroom
Quickstart

Get PearBrowser.

v0.7.1 fixes the renderer/backend handoff behind the cluster of unrelated RPC timeout messages some users saw after a reload or live update. Calls now fail immediately if the local socket closes, the authenticated renderer reconnects during a bounded grace window, and the shell shows a clear resume state. It retains the P2P Content Shield lists, capability-gated Pear Plugins, and one-click plugin catalogue from v0.7.0. Desktop preview builds are attached for macOS, Windows, and Linux; the download page has per-platform builds with SHA-256 checksums.

PearBrowser v0.7.1 downloads
# Unsigned preview builds (verify with SHA-256)
macOS: PearBrowser-0.7.1-macos-arm64.app.zip · -x64.app.zip
Windows: PearBrowser-0.7.1-windows-x64.msix
Linux: PearBrowser-0.7.1-linux-x64.AppImage

# Or launch over P2P — no download, no signing caveats
npm i -g pear
pear run pear://tco5k7h38uoxatedp1wongdbhjxow1x7jiwm3t1i9cujbebhsbty
pear run pear://tco5k7h38uoxatedp1wongdbhjxow1x7jiwm3t1i9cujbebhsbty
Legacy fallback: the pear run pear://… path hot-syncs the current release from the swarm and works on every desktop today. Pear runtime v2.4.0 deprecates pear run, so it is a compatibility path while signed native installers become the primary distribution story.
  1. Pick your platform on the download page — it auto-detects your OS and shows a verifiable SHA-256 for each build.
  2. Unsigned today — macOS needs a right-click → Open the first time; a signed Windows installer and notarized macOS build are in progress.
  3. First-launch onboarding generates a BIP-39-backed identity and helps you pick a first site to visit.
  4. P2P updates still apply — the shell carries the app while the stable Pear release keeps hot-syncing current app bytes from the swarm.
Tech

The grown-up table.

For the people who scroll to the bottom first.

Desktop versionv0.7.1 · production length 92858 · pinned on the HiveRelay backbone
DistributionUnsigned preview builds attached to v0.7.1: macOS .app.zip (arm64 + x64), Windows .msix, Linux .AppImage; signed/notarized installers in progress; pear run pear://… P2P launch path works today
RuntimePear (Bare + Chromium via pear-electron); pear run is legacy because Pear runtime v2.4.0 deprecates it
Core librarieshyperswarm, hyperdrive, hyperbee, corestore, hypercore, autobase, p2p-hiverelay
SearchLighthouse — local Hyperbee full-text index, signed by a per-app search subkey; opt-in federation over Hyperswarm (smoke-validated)
IdentityBIP-39 → Ed25519 root with per-app sub-keys; opt-in Nostr (secp256k1/BIP-340) — Phase 3: attested binding, post notes, federated feed over your trust graph (no public relays yet)
Bridge surfacewindow.pear.swarm.v1 — three trust tiers, per-app rate limits, 1 MB/s/peer cap (SWARM-V1.md)
SyncExperimental, opt-in: sync:// Autobase device pairing for bookmarks, tabs, settings, profile, history, contacts, and app grants
PlatformsmacOS, Windows, Linux — preview builds on the download page; Android and iOS (App Store / TestFlight) in progress
LicenseApache-2.0
Legacy launch keypear://tco5k7h38uoxatedp1wongdbhjxow1x7jiwm3t1i9cujbebhsbty
This site (P2P)hyper://03f0060a35451cfb6b68ad1dda1b8474ebb43fd9100071ccf7d67679a83ebb4f/ — the same page, pinned 24/7 on HiveRelay
FAQ

Honest answers.

Does PearBrowser collect or sell my browsing data?

No. PearBrowser ships without telemetry, remote analytics, an ad network, or tracking SDKs. It does not upload your browsing history to PearBrowser or sell it to advertisers. History and local page indexing are off by default; if you enable them, the data stays local unless you explicitly choose device sync.

Is PearBrowser anonymous?

No. PearBrowser is private by default, but it is not an anonymity network. Websites, relay operators, and P2P peers may receive the network information required to serve your request, including your IP address and requested content. Some HiveRelay operators can expose Tor endpoints, but PearBrowser Desktop does not yet route browser traffic through Tor automatically.

What privacy protections are on by default?

Content Shield, HTTPS-only navigation, common tracking-parameter stripping, third-party cookie blocking, and fingerprint farbling are enabled by default. Browsing history and local full-text search indexing are disabled until you opt in. Telemetry stays off and cannot be enabled.

Does PearBrowser include private web search?

Yes. The first tab and every blank new tab include DuckDuckGo search. PearBrowser sends no search analytics and does not add submitted queries to its optional persistent visit log. DuckDuckGo still receives the query and your network address to return results; its policy says it does not save or share search history. This is private search, not anonymity.

Is Lighthouse search a global crawler?

No — that's the whole point. Lighthouse is a local-first personal index: pages you browse are tokenized, signed by a per-app search subkey, and stored in a local Hyperbee. Library search returns in under 5ms with zero network. If you opt in to “include trusted peers,” the query also fans out to your trust graph over Hyperswarm — never to a central crawler.

How can I trust results coming from other people?

Every federated row is re-verified client-side against the contact's identity binding and dropped on failure before it can affect ranking. Contacts only enter your trust graph through signed invite URLs that are verified at import and rejected if forged. The ranker is deterministic and clock-free, so the same inputs produce identical ordering on every device. The room is an index, not an authority.

How production-ready is federated search?

The local index is live and wired. Federation is smoke-validated by a two-node federation test — meaning the path works end-to-end, not that it's been run at production scale. Treat the opt-in toggle as the early-access feature it is.

Does the Nostr support mean I can post to relays from PearBrowser?

Not to public wss:// relays — not yet. What works today (Phase 3): Settings displays your npub and a one-click “Link (attested)” / Revoke control that cross-curve-binds your Nostr (secp256k1/BIP-340) key to your Pear Ed25519 root. You can post NIP-01 notes signed with that key, and read notes your verified contacts authored with their attested keys — all replicated peer-to-peer over your trust graph, with no relay servers in the middle. Public relay transport is a later, opt-in phase.

What exactly does device sync cover?

Device sync is still experimental and opt-in, but it now covers more than bookmarks: open-tab snapshots, allowlisted settings, profile fields, bounded browsing history, trusted contacts, and app grants. You pair devices with a sync://<key>:<encKey> invite, and rotate or forget the sync group when a device should stop receiving future state.

What happens to my site when I close my laptop?

Nothing — that's the point. When you publish, the block editor signs a seed-request and HiveRelay pins the drive; PearBrowser only reports “published” after a relay confirms replication. The publisher can then be offline indefinitely while the relays serve the bytes to anyone with the key.

Can I read hyper:// from a regular browser?

Yes, via hyper-fetch — a small drop-in JS library that talks to the HiveRelay HTTP gateway. The full peer experience (publishing, identity, Lighthouse search, signed grants) still requires PearBrowser.

How do I install it — and what about pear run?

Desktop builds are attached to the v0.7.1 release and listed on the download page: macOS .app.zip, Windows .msix, and Linux .AppImage. They are unsigned preview builds today, so pear run pear://… stays available as a friction-free P2P launch path while signed/notarized installers land; Pear runtime v2.4.0 deprecates that command, so it is a compatibility path, not the finished story.

What if I lose my device?

If you backed up your 12-word BIP-39 phrase, you restore your identity on a new machine and your grants and per-app sub-keys come back with it. If you didn't back up, drives you published stay alive on the relays — but you can never update or unseed them. Write the phrase down.

Browse without becoming the product.

Get a browser with no telemetry, no ad profile, and local-first data—plus direct access to the peer-to-peer web.