# What current evidence suggests Apple is actually private

**URL:** https://discuss.privacyguides.net/t/what-current-evidence-suggests-apple-is-actually-private/40015
**Category:** General
**Created:** 2026-08-19T06:27:56Z
**Posts:** 26

## Post 1 by @not-wittingly — 2026-08-19T06:27:56Z

My question relates to privacy, not security.

Not trying to start a war here - _drops grenade_ - but the community often mentions how Apple is a good place to be, or at the very least, not a bad place to be. What sort of evidence do we have available that can verify this, since everything is proprietary?

Safari’s anti-fingerprinting is great, but how can you trust a closed-source browser run by a US company? I _assume_ that macOS is a lot more private than Windows, but what evidence is there to back this? ADP is great, but how do we know it’s not backdoored?

Various people who I follow and respect say Apple is private, but what hard evidence is there to suggest this, and how can we be sure.

---

## Post 2 by @sha123 — 2026-08-19T08:14:32Z

> [@not-wittingly](#):
>
> Various people who I follow and respect say Apple is private

Source? What makes you think that a company itself is private?

> [@not-wittingly](#):
>
> Safari’s anti-fingerprinting is great, but how can you trust a closed-source browser run by a US company?

How can you trust any software product with 10s of millions lines of code? Why would you trust iOS/MacOS, but not Safari?

> [@not-wittingly](#):
>
> ADP is great, but how do we know it’s not backdoored?

FUD

> [@not-wittingly](#):
>
> Safari’s anti-fingerprinting is great

It does not have some super advanced anti-fingerprinting mitigations. Its anti-fingerprinting strength comes from the fact that software and hardware are quite homogeneous in the Apple universe, with a relatively big user base per setup.

---

## Post 3 by @pine — 2026-08-19T08:44:54Z

There is certainly the point to be made that privacy hinges on security, and that macOS is commonly understood to provide some of the better desktop security out there. It’s also true that PG at present only [officially recommends Linux](https://www.privacyguides.org/en/desktop/), not macOS.

Here’s PG’s official guidance on macOS: [macOS Overview - Privacy Guides](https://www.privacyguides.org/en/os/macos-overview/#recommended-configuration)

> **On previously discussed threads**
>
> Not agreeing with the previous poster’s tone, but I do think it would be helpful if you could link to previous threads discussing this. Both to support your points, to help others get an overview of the topic, reduce general forum clutter, and to show you’ve done the work before others do as well.
> 
> With that said, I recommended people flag posts they feel break forum guidelines over direct public criticism when the post is not in obvious bad faith.

---

## Post 4 by @not-wittingly — 2026-08-19T09:08:35Z

> [@sha123](#):
>
> Source? What makes you think that a company itself is private?

Apple products that we use, such as Apple hardware and Apple software, from the company Apple.

> [@sha123](#):
>
> How can you trust any software product with 10s of millions lines of code? Why would you trust iOS/MacOS, but not Safari?

Well, it can be vetted, that’s the point. This just gets into the argument of FOSS vs proprietary and “do you even read the code”. I obviously don’t read 10 million lines of code every time I update an app, but I like to know that someone can as a matter of principle. Isn’t that why this community mostly uses FOSS tools? I don’t trust MacOS, but I _assume_ it’s more private than Windows. But I agree, this is an assumption, that I’m trying to challenge and understand where it comes from, hence the post.

> FUD

It’s a genuine question - why is a closed source piece of software considered so trusted? I’m not suggesting for a second it is backdoored, but I’m just saying we can’t be sure. It’s a pretty deep belief I see in the community and I’m curious what it’s backed by.

> [@sha123](#):
>
> Yet another low-effort controversial post by you, with here-say, no sources and topics which have already been discussed quite a few times.

Yeah I mean, I’m asking for sources for the widely held belief. What would you like a source for, based on this post?

---

## Post 5 by @Expert4870 — 2026-08-19T12:49:08Z

> [@not-wittingly](#):
>
> It’s a genuine question - why is a closed source piece of software considered so trusted? I’m not suggesting for a second it is backdoored, but I’m just saying we can’t be sure. It’s a pretty deep belief I see in the community and I’m curious what it’s backed by.

I’m also curious about this. People say open source doesn’t matter so much for security but what about cryptography. Can that be inspected in closed source software?

---

## Post 6 by @Shampoo — 2026-08-19T13:15:46Z

Apple open sources most of their cryptography iirc.

> **[GitHub - apple/corecrypto: Apple corecrypto](https://github.com/apple/corecrypto)**
>
> Apple corecrypto

> **[Apple Open Source](https://opensource.apple.com/)**

Some more of it is in the open source releases as well I believe.

---

## Post 7 by @fria — 2026-08-19T13:17:04Z

I think the claim here is too broad to be proven true or false. We can look at if Apple provides specific privacy features but we would need to define what specifically you want to see from them to be counted as “private.”

> [@not-wittingly](#):
>
> Safari’s anti-fingerprinting is great, but how can you trust a closed-source browser run by a US company?

You don’t really need to see the source code to test the anti-fingerprinting capabilities, you can just see what it reports to you from various APIs. If you mean can we trust other parts like encryption/security etc, security research is performed on closed-source software all the time, source code isn’t needed in order to see what it’s doing, security researchers examine the binary. There’s a really great [article](https://seirdy.one/posts/2022/02/02/floss-security/) about this you can read that explains this.

It’s also worth noting that the underlying browser engine, WebKit, is [open source](https://github.com/WebKit/WebKit), so it’s not quite accurate to say everything is proprietary. You can’t verify that WebKit wasn’t modified or something before it’s compiled but that’s a problem with all open source software that you download as a binary and don’t support reproducible builds as well.

> [@not-wittingly](#):
>
> I _assume_ that macOS is a lot more private than Windows, but what evidence is there to back this?

You’d have to be more specific about what specifically we’re comparing, we can compare specific features but it’s hard to make an overall judgement like that I think.

> [@not-wittingly](#):
>
> ADP is great, but how do we know it’s not backdoored?

Apple actually recently released the [source code](https://github.com/apple/corecrypto) for their cryptography so researchers can verify it works correctly. While it’s not technically open source because you aren’t allowed to use it in your own code, it’s nice that it’s out there.

It doesn’t prove it’s not backdoored though, but that’s the same issue you have when you download a binary for an open source project: it could’ve been tampered with before they compiled it.

Apple devices are very highly scrutinized by security researchers though, if there’s a backdoor you’d think it would’ve been found at this point.

---

## Post 8 by @anonymous644 — 2026-08-19T14:43:04Z

Apple has shown it is clearly fine with [massive surveillance](https://www.eff.org/deeplinks/2021/08/apples-plan-think-different-about-encryption-opens-backdoor-your-private-life) and its only via massive [public pressure](https://www.eff.org/pages/apple-must-abandon-its-surveillance-plans) that it does not do more of it.

---

## Post 9 by @Gersand — 2026-08-19T15:07:25Z

I think one single fact dismisses any claim of privacy from Apple : they refuse to implement WKD in Apple Mail, whereas it’s literally one line of code (OK, one line of code in the back-end, then a load of code in the GUI to integrate it in the super-smooth Apple UX).

Part of their business model is profiling Apple Mail users through their email contents, in order so sell personal data to data brokers and the advertisement industry.

Note: I use “personal data” in the sense of the GDPR, meaning even though their clients are not able to directly identify data subjects, it is still data about people that can be reidentified in some way.

---

## Post 10 by @any1 — 2026-08-19T15:18:39Z

> [@fria](#):
>
> You don’t really need to see the source code to test the anti-fingerprinting capabilities, you can just see what it reports to you from various APIs.

Technically, yes, but there could also be hard‑coded exceptions added, [which Brave used to have for Google Maps, exempting it from the canvas protections in the actual source code.](https://github.com/brave/brave-core/commit/46cff7013b876400a7bf0ee9ebafd3760c73380c)

---

## Post 11 by @Expert4870 — 2026-08-19T18:21:25Z

Apple has the most comprehensive E2EE cloud suite I’m aware of, so that’s pretty good by them.

---

## Post 12 by @TheDoc — 2026-08-19T20:45:00Z

> [@not-wittingly](#):
>
> Various people who I follow and respect say Apple is private, but what hard evidence is there to suggest this, and how can we be sure.

Apple is generally believed to have a [better privacy policy](https://privacyspy.org/product/apple/) than their main competitors such as [Google](https://privacyspy.org/product/google/), [Microsoft](https://privacyspy.org/product/microsoft/), etc. Apple can also sometimes develop relatively better security or privacy features such as E2EE on iMessage & FaceTime, Advanced Data Protection, and arguably slightly better privacy protections against invasive apps (compared to Windows and Android). Their reputation for robust security features also gets laundered as “better privacy” even though these are distinct concepts which have overlap but are unique nonetheless.

The bar is in hell and being better than the competition in some areas doesn’t make them good, but unfortunately some people buy into the idea that Apple can be considered private or at least good enough. I’m not aware of anyone who’s done a deep dive on the subject but IIRC The Hated One had decent videos on some of the privacy issues with [Apple](https://inv.nadeko.net/watch?v=r38Epj6ldKU) and [iPhones](https://inv.nadeko.net/watch?v=nQ9LR8homt4).

> [@not-wittingly](#):
>
> What sort of evidence do we have available that can verify this, since everything is proprietary?

Reviewing source code isn’t the only way to verify whether something works as intended (and doing that alone would be insufficient), but open source is essential for full transparency and granting users the freedom to remove malicious code as well as add their own improvements to the code.

Apple’s proprietary and walled garden ecosystem creates major privacy and security issues. At the same time, there is no fully open source alternative and most alternatives who are relatively more open (such as Linux, LineageOS, etc) also tend to suffer from a lack of security features. So in practice, which device and OS someone should use heavily depends on ones unique threat model and preferences.

---

## Post 13 by @_TrustyRocinante — 2026-08-19T23:01:26Z

Apple does _a lot_ of Privacy things right. They also are good at getting a privacy tool into the hands of the non-tech savvy (mail relay, E2EE, ADP, permission access control).

My issue with their privacy standards is more philosophical and cultural. User freedom of choice is a problem for them and often is a detriment for privacy. Things like, sourcing apps outside the appstore, WebKit, device lock-in, iMessage device restriction, Linux on Macs…etc.

We should prioritize being able to ditch a service or company for any reason as laws and privacy policies change all the time. I like their hardware, but I can no longer just run Fedora on their Macs, and garden lock-in is a real pain point for their users.

Also, the whole “sideloading” thing has been a problem with getting access to VPNs or comms apps in dictatorship countries.

Apple frustrates me because I really like their hardware, and they do so many things right that competitors won’t/can’t do. I just wish they’d relax and let the power users harden the products as they wish.

---

## Post 14 by @Expert4870 — 2026-08-20T00:35:23Z

> [@fria](#):
>
> It doesn’t prove it’s not backdoored though, but that’s the same issue you have when you download a binary for an open source project: it could’ve been tampered with before they compiled it.

GrapheneOS, Signal, SimpleX, and my crypto wallet all have reproducible builds.

So the cryptography’s open but if the clientside apps still aren’t, can security researchers analyze them at that point for E2EE flaws?

I just don’t really know anything about poking goop with a stick and it makes sense to me that stuff related to networking can be poked but the crypto? I mean it would make sense if badly written apps you can check the crypto but Apple?

---

## Post 15 by @No_Name — 2026-08-20T09:27:31Z

> [@not-wittingly](#):
>
> I don’t trust MacOS, but I _assume_ it’s more private than Windows

I don’t trust Apple either really. I know a lot of people do, but I’ve always found it suspect that whenever you hear about government officials having their text messages leaked, phone conversations, emails, etc, that it always seems to be an Apple device they’re using.

I also never bought into their dog & pony show with the FBI back when the FBI was trying to get into the terrorists phones in California. I’ve always believed that was just a way to get people to believe that Apple will fight the FBI for you, which I don’t believe even a little bit.

Just my opinion though. I have no proof of this. And yes, I know I’m paranoid.

---

## Post 16 by @madialumbaugh — 2026-08-20T10:48:39Z

Apple positions itself as a company committed to protecting user privacy, while Google’s approach is focused on collecting and using our data. Take Safari and Chrome, for example. Chrome encourages users to sync their browsing activity to Google’s servers with no encryption, where it can be used for advertising, personalization, and data sharing with other technology companies. Apple doesn’t operate that way, which makes it the better choice if you care about privacy.

> [@fria](#):
>
> Apple devices are very highly scrutinized by security researchers though, if there’s a backdoor you’d think it would’ve been found at this point.

That’s the thing. If someone mentions that Androids spy on you, everyone’s just like, “What did you think was happening?”

---

## Post 17 by @No_Name — 2026-08-20T12:57:06Z

Maybe Apple doesn’t operate that way, but even if they’re not selling your data to the ad company across the street, it doen’t mean that they don’t have the data to give/sell.

---

## Post 18 by @JibJab — 2026-08-23T20:29:15Z

If “iPhone Findable After Power Off” is enabled an iPhone can still be tracked for up to 24 hours even with a dead battery using BLE as long as any other powered up Apple device is within ~25ft. Must use faraday bag same as a powered off Android 8 or higher.

Email, Contacts and Calendar are not E2EE even with ADP . But “Trust me 'Bro” privacy might be better than “We Sell It All” like consumer Gmail does.

The app store is not quite as susceptible to malware as Google but they both reject a couple million submissions a year so hundreds probably still get past review on both.

---

## Post 19 by @curious78 — 2026-08-23T21:30:23Z

Lifelong, past, Apple user here, attended Macworlds in SF, made the trek to the old “[Company Store](https://apple.fandom.com/wiki/Apple_Company_Store)” in Cupertino and kissed the ground, shed a tear when Steve died, etc.

I left the ecosystem 5-7 years ago as too much was piling up (some examples):

-Closed-source ecosystem beholden to shareholders.

-Whistleblowers like [Thomas Le Bonniec](https://whistleblowersblog.org/whistleblower-of-the-week/apple-whistleblower-thomas-le-bonniec/) willing to put themselves on the record.

-Some security people like Jeffrey Paul putting up [some](https://sneak.berlin/20220409/apple-is-still-tracking-you-without-consent/) [posts](https://sneak.berlin/20230115/macos-scans-your-local-files-now/) [like](https://sneak.berlin/20231005/apple-operating-system-surveillance/) [these](https://sneak.berlin/20201112/your-computer-isnt-yours/) [five](https://sneak.berlin/20201204/on-trusting-macintosh-hardware/).

-appeared in the Snowden [comments](https://edwardsnowden.substack.com/p/all-seeing-i) (including [Prism](https://www.theguardian.com/world/2013/jun/06/us-tech-giants-nsa-data)). His comments on Apple are numerous.

-Apple [only lasted approximately a year or so](https://finance.yahoo.com/news/apple-warrant-canary-disappears-suggesting-151751546.html)with a Warrant Canary. [Qubes](https://www.qubes-os.org/security/canary/) and [Purism](https://puri.sm/warrant-canary/) still maintain canaries. I still like Warrant Canaries, not everyone does.

I don’t think there is adequate evidence that they actually carry out what they say they do until their code is reviewable as a minimum. Relying on Apple requires a great deal of estimation, assumption and faith.

---

## Post 20 by @securitybrahh — 2026-08-24T12:31:29Z

I believe the only secure bootloader / firmware is by Mac m series

You can argue that HSI certified laptops are better but the fwupd updates are not that great.

You need to be vertically integrated to have a secure supply chain which Mac m series are.

---

## Post 21 by @Gersand — 2026-08-24T15:33:38Z

This is security, for which I think nobody doubts Apple is good. The question was about privacy.

---

## Post 22 by @securitybrahh — 2026-08-24T17:23:39Z

Without security privacy means shit.

You can boot up Asahi

Block apple via little snitch

Boot SecureBlue on UTM

Etc

---

## Post 23 by @Cork — 2026-08-24T20:28:29Z

I don’t think that’s right. Apple does run an ad business, but it targets off App Store search history and basic account info like age and region, not the contents of your mail. It’d also be a strange move given they shipped Mail Privacy Protection, which blocks tracking pixels and proxies image loads. That feature wrecked open-rate tracking for the entire email marketing industry, which isn’t what you’d expect from a company selling email-derived profiles.

The fair criticism is that iCloud Mail isn’t end to end encrypted, even with Advanced Data Protection turned on. Apple holds the keys and can hand contents to law enforcement with a warrant. Real weakness, but a different thing from profiling people for ad revenue.

Do you have a source on the data broker part? Curious whether I’ve missed something.

---

## Post 24 by @Gersand — 2026-08-24T21:20:30Z

Security is required for privacy, but not sufficient. You also need a good data protection (compliance to GDPR is not enough to me).

Microsoft and Google have very good security. Try to hack into someone’s Google drive or MS OneDrive without phishing, and you’ll see. However, they have a terrible data protection. Even if they can prevent almost anyone to enter their fortress, their practice is a giant breach to privacy and they are themselves the prying eyes.

So very good security is great and needed, but not enough to speak of privacy.

The other way around is also true : having a thorough data protection for full respect of client privacy is required, but without security, privacy won’t be achieved.

That being clarified, Apple has a great security and seems to have a better data protection than Google or Microsoft, but to me, their data protection is still far from great.

---

## Post 25 by @Gersand — 2026-08-24T21:35:49Z

You’re right, I just assumed that the reason for refusing OpenPGP and WKD was the same as Google and Microsoft : scanning email contents.

Maybe it’s not the case for Apple. But if it were, it wouldn’t contradict that much the other moves you mention. Many service providers defend their users against ads except their own ad channels (Brave, now maybe Firefox, some alternative search engines…)

---

## Post 26 by @JibJab — 2026-08-25T17:17:09Z

This article reveals something about Apple’s approach to privacy.

> **[The privacy myth crumbles: Inside the iCloud+ flaws threatening Apple's most...](https://www.techradar.com/vpn/vpn-privacy-security/the-privacy-myth-crumbles-inside-the-icloud-flaws-threatening-apples-most-valuable-promise)**
>
> Recently uncovered bugs in Private Relay and Hide My Email have exposed a glaring truth: no single company can act as your sole privacy shield
