Guide · Privacy · iPhone
How to Check If an iPhone App Is Secretly Uploading Your Data (Free, 15 Minutes)
October 2026
The privacy label on an app's App Store page is something the developer fills in about their own app. It's a statement, not a measurement. The only way to know what an app actually sends is to watch its network traffic while you use it.
You can do that on your own iPhone with a free tool. Plan on around 15 minutes the first time, mostly spent on setup. After that, checking another app takes a few minutes.
What you need
- A computer on the same Wi-Fi network as your iPhone (we used a Mac)
- Proxyman, a traffic inspection tool with a free version
- The app you want to check, installed on the iPhone
Step by step
- Install and open Proxyman. It starts capturing traffic from the computer straight away. That's fine; you'll connect the phone next.
- Connect the iPhone. Proxyman has a guided setup under its Certificate menu for installing its certificate on a physical iPhone. It shows your computer's IP address and a port. On the iPhone, set your Wi-Fi network's proxy to manual and enter those two values.
- Install and trust the certificate. Open the address Proxyman gives you in Safari to download the certificate profile, install it, then switch on full trust for it in Settings under General, About, Certificate Trust Settings. Without this step you only see which servers were contacted, not what was sent.
- Turn on SSL proxying for the app's domains. In Proxyman, right-click a domain in the list and enable SSL proxying for it. This lets you open individual requests and look inside.
- Use the app properly. Don't just open it and look. Run its main feature from start to finish: import a file, process it, export it. Many apps only make interesting connections when you do something.
- Clean up afterwards. Switch the Wi-Fi proxy back to off and delete the certificate profile in Settings. A trusted certificate lets that tool read your traffic, so it shouldn't stay installed.
Menu names change between versions, so follow Proxyman's own on-screen guide if something looks different.
How to read what you see
A long list of requests looks alarming, but most of it is harmless. Sort what you find into four groups.
Connections to Apple's own domains are background noise from iOS and the App Store. They're normal. Some are protected by certificate pinning, so you'll see the domain but not the contents.
Small, frequent requests to domains belonging to analytics, attribution or advertising companies. They usually describe how you use the app rather than carrying your files, but they mean a third party is involved. Worth noting.
A small request followed by a large response is the app fetching something: an update, media, or an AI model. Direction and size matter here. Downloading a model file is not the same as sending your data out.
This is the group to look at closely. Open a POST or PUT request to a domain you don't recognise and check its size and body type. If it's audio, images or documents you just handled in the app, the app is uploading them.
The question to ask of every entry is: what went out, how big was it, and to whom? A tiny request to an analytics domain and a multi-megabyte upload to a storage domain are very different things, even though both show up as "the app talked to the internet."
Analytics deserves its own note. As one reader pointed out to us, an app that includes analytics tools is technically collecting data about its users, even if that data is anonymised. Whether that matters to you is your call. The point of checking is that you get to make it with facts.
What this check can't tell you
- Pinned connections stay opaque. Some services use certificate pinning, so a proxy can see the domain but not the contents.
- It only covers what you did. A feature you didn't try might behave differently.
- It's a snapshot. An update can change the app's behaviour, so re-check after major versions.
- Seeing nothing isn't proof. It's evidence, and a good deal stronger than a label, but it isn't a formal audit.
What we found when we did this to our own apps
We ran this exact method on OffgridStem and OffgridScribe. OffgridStem made no connections of its own, and OffgridScribe's only notable traffic was a one-time download of its transcription model. The full write-up, including the parts that looked suspicious at first, is in We Ran Our Own Network Audit. Here's What We Found.
Frequently asked questions
Do I need to jailbreak my iPhone to check what an app sends?
No. A traffic inspection tool such as Proxyman works through your normal Wi-Fi connection with a proxy setting and a trusted certificate. Remove both when you are finished.
Does a request to an analytics domain mean the app uploads my data?
Not necessarily. Analytics requests are usually small and describe usage, not your files. They still mean the app is talking to a third party, so they are worth noting. A large outgoing request with a file-like body to an unfamiliar domain is a stronger warning sign.
What if I can see the domain but not the contents of a request?
Some apps and Apple's own services use certificate pinning, which stops a proxy from decrypting the traffic. You can still see which domain was contacted and roughly how much data moved, which is often enough to judge it.
Is this the same as an independent privacy audit?
No. It is a spot check of one device, one app version and the features you used. It can show that something is happening, but not prove that nothing ever happens.
More from Offgrid Studio
Also read: What Popular Transcription Apps Actually Do With Your Recordings and Why Most Album Leaks Start in the Cloud, Not the Studio.