Privacy First

Security & Privacy
Built In

Your data never leaves your machine. No telemetry, no cloud sync, no tracking. XMethod is built from the ground up to keep your information private β€” with 15+ security features built into the browser.

Security by design

Three pillars that guide every decision we make about how XMethod handles your data.

πŸ’Ύ

Local-First

All data lives in ~/.xmethod/ on your machine. Zero cloud dependency. You own your data completely.

🚫

Zero Telemetry

No tracking, no analytics, no data collection. We never phone home with your browsing data.

πŸ”

Encrypted Vault

Passwords and secrets secured with AES-256-GCM encryption and Touch ID biometric unlock.

Password Manager

A full vault, built into your browser

AES-256-GCM encrypted password vault with password generation, auto-fill, breach monitoring via Have I Been Pwned, and strength auditing. Unlock with Touch ID, store TOTP 2FA codes and secure notes, organize with categories, and import from Chrome or sync with Google Drive.

  • AES-256-GCM encryption
  • Password generator and auto-fill
  • Breach monitoring (HIBP)
  • Strength audit dashboard
  • Auto-lock and Touch ID unlock
  • TOTP 2FA and secure notes
  • Categories and Chrome import
  • Google Drive sync
  • Auto-popup password generator on password fields
πŸ”’
Screen Lock

Lock your browser, not just your screen

Set a PIN, use Touch ID, or pair your Apple Watch to lock the entire browser when you step away. Screen Lock adds a layer of protection beyond your OS login β€” preventing anyone with physical access from seeing your tabs, passwords, or app data.

  • PIN code lock
  • Touch ID biometric unlock
  • Apple Watch proximity unlock
  • Auto-lock on inactivity
  • Toggle from Settings > Privacy
πŸ”
Ad & Tracker Blocking

Clean browsing, no extensions needed

Built-in content blocker that removes ads and trackers across every tab. No extensions to install or manage. The Privacy Panel shows a tracker heatmap and privacy score per site, so you can see exactly what's being blocked.

  • Built-in content blocker
  • Removes ads and trackers
  • No extensions required
  • Works across all tabs automatically
  • Privacy Panel with tracker heatmap
  • Per-site privacy score
  • Fingerprint protection
πŸ›‘οΈ
URL Cleaning & HTTPS

Strip trackers, enforce encryption

URL Cleaning automatically strips tracking parameters (utm_*, fbclid, gclid, and more) from every navigation β€” no extension needed. HTTPS Upgrade auto-promotes all http:// navigations to https://. Mixed Content Blocker prevents insecure sub-resources on HTTPS pages with an amber warning banner.

  • Auto-strip utm_*, fbclid, gclid, and more
  • Enabled by default in Settings > Privacy
  • HTTPS auto-upgrade on all navigations
  • Mixed Content Blocker with amber banner
  • No configuration needed
🧹
Threat Protection

Stay safe from phishing and malware

The Phishing Detector analyzes page content and displays a warning banner when you visit a suspicious site. The Download Scanner shows a confirmation dialog for potentially dangerous file types before you open them.

  • Phishing Detector with warning banners
  • Download Scanner for suspicious files
  • Confirmation dialog before opening risky downloads
  • Automatic protection β€” always on
⚠️
Private Browsing

Incognito tabs, windows, and guest mode

Open a single Incognito Tab for quick private browsing, or launch a full Incognito Window (Cmd+Shift+N) with a completely isolated session and ephemeral storage. Guest Mode creates a temporary profile with no history, cookies, or data persistence β€” perfect for shared computers.

  • Incognito Tab β€” single private tab
  • Incognito Window (Cmd+Shift+N) β€” fully isolated BrowserWindow
  • Ephemeral session with purple badge
  • Guest Mode β€” full temporary profile
  • No history, cookies, or data persistence
πŸ‘€
Authentication

Secure sessions, on and offline

Portal authentication with JWT tokens stored in Electron safeStorage. A 7-day offline grace period means you can keep working without an internet connection. Secure session management protects your account at every layer.

  • JWT token-based authentication
  • Electron safeStorage for token storage
  • 7-day offline grace period
  • Secure session management
  • Sign in with Apple (iCloud auth)
πŸ”‘
Permission Controls

You decide what sites can access

Custom permission prompts for camera, microphone, notifications, geolocation, clipboard, and MIDI β€” never a confusing browser dialog. Per-site settings let you save preferences per domain. Family Profiles add parental controls with screen time limits and content blocking.

  • Custom permission prompt UI
  • Camera, mic, notifications, geolocation, clipboard, MIDI
  • Per-site settings and preferences
  • Family Profiles with parental controls
  • Screen time limits and content blocking
πŸŽ›οΈ
Widevine DRM

Stream protected content natively

Built on the Castlabs Electron fork with Widevine CDM support. Stream Netflix, Disney+, and other DRM-protected content directly in the browser without workarounds.

  • Widevine CDM built in (Castlabs fork)
  • Netflix, Disney+, and more
  • DRM-protected streaming natively
  • No extensions or plugins needed
🎬
Data Sovereignty

Your data never touches our servers

No server stores your browsing data, passwords, settings, or app data. Everything lives locally in ~/.xmethod/. Google services and iCloud backup are opt-in only β€” you choose what to connect. Cloud sync is available but always under your control.

  • No server-side data storage
  • Settings, passwords, app data β€” all local
  • Google services opt-in only
  • iCloud backup opt-in only
  • Full control over your data
  • Google Drive and iCloud cloud sync (optional)
πŸ’Ύ

Where your data lives

Every piece of data XMethod stores, where it goes, and how it is protected.

Data Type Location Protection
Settings~/.xmethod/settings.jsonUser preferences
Passwords~/.xmethod/passwords.json.encAES-256-GCM
Auth Token~/.xmethod/api-tokenElectron safeStorage
App Data~/.xmethod/storage/JSON key-value
Biometric Key~/.xmethod/vault-bio.encTouch ID encrypted
Downloaded Apps~/.xmethod/apps/SHA-256 verified
Screen Lock PIN~/.xmethod/storage/Encrypted
iCloud Tokens~/.xmethod/storage/Electron safeStorage

Ready to get started?

Download XMethod Browser and experience a browser that actually works for you.

Download for macOS