For families who take both deen and privacy seriously
Every filter says “trust us.”
Ours says check the math.
Sitr blocks adult, gambling and dating sites and locks in SafeSearch — entirely on your device, in your browser and across every app on your Android phone. Your history has nowhere to go, because we built nowhere for it to go.
The premise
Most “family safety” software works by routing your browsing through someone else's computer — so the thing protecting your family is also the thing watching it. We think that trade is haram-adjacent at best. Sitr is architected so that watching you is structurally impossible, and every claim below is written so you can go falsify it.
The filter runs on your device. Full stop.
In the browser, Sitr compiles its blocklist into native declarativeNetRequest rules, so requests to blocked sites die inside the browser. On Android it answers DNS lookups on the phone itself, for every app, and passes allowed ones to the DNS server your network already uses. Either way: no call home, no lookup service, and Sitr cannot read page contents.
One blocklist, identical for everyone, in public.
Every rule lives in a public Git repository with an inclusion policy and an appeals process. Because every user ships the same list, there is no per-user configuration for us to learn anything from.
No telemetry. Not opt-out — absent.
No analytics SDK, no crash reporter, no ad network, no “anonymous usage statistics.” The data-flow document enumerates every network endpoint the extension and apps may contact. See §2 for that list, reproduced in full.
Builds are byte-reproducible.
A deterministic compiler turns the public domain lists into the shipped rulesets. CI publishes SHA-256 checksums; anyone can rebuild from source and diff against what's shipped. See §3 for the exact commands.
Failure is loud, never silent.
If protection isn't provably active, Sitr shows a red “Protection INACTIVE” badge. A filter that quietly fails is worse than no filter — so ours refuses to pretend.
SafeSearch, held in place.
Google, Bing and DuckDuckGo SafeSearch and YouTube Restricted Mode are enforced by the filter itself — at the request layer in the browser, at DNS on Android — not by asking nicely in a settings page that anyone can flip back.
Exhibit A — every endpoint we call
Reproduced from docs/data-flow.md, the canonical inventory of network traffic the extension and apps may generate while filtering. (The Android app relays your phone's own DNS lookups to the resolver your network already uses; it originates no traffic of its own.)
// If a future version ever adds a row to this table, it will be visible in the public repo before it ships, with the diff to prove it.
Trust no one. Run this.
“Open source” is a claim; reproducibility is a proof. The rulesets Sitr ships are a pure function of the public blocklist — rebuild them yourself and compare checksums with what's published.
The compiler is deterministic on purpose: same input lists, same bytes out, on your machine or ours. CI publishes the SHA-256 of every shipped ruleset alongside each release.
If your checksums ever disagree with ours, you've either caught a build bug or caught us — and either way we want the issue filed.
Audits welcome: architecture & threat-model docs live in docs/.
$ git clone https://github.com/terrancoder/sitr $ cd sitr && npm ci && npm test # builds compiler → rulesets → extension, runs tests $ shasum -a 256 extension/rulesets/*.json # compare against the checksums CI publishes ✓ adult.json …matches release ✓ gambling.json …matches release ✓ safesearch.json …matches release ✓ reproducible build verified — nothing up our sleeves
The same covenant, pocket-sized
Sitr for Android is on Google Play, and Sitr for iOS is being built, on the identical constitution: filtering on-device, the same public blocklist, and a data-flow table that stays empty. On Android it covers every app on the phone, not only the browser. If a platform won't let us keep those promises, we won't ship on it.
Managing more than your own devices? See Sitr Family for households and Sitr for Institutions for schools, masajid and networks.
Anticipated objections
Longer answers live in the public docs; these are the short forms.
5.1 What does “Sitr” actually mean?
Sitr (سِتْر) is Arabic for covering, veiling, protection — the shielding of what ought to stay shielded. We chose it because it describes the product twice: it covers your family from harmful content, and it covers your browsing from everyone. Including us.
5.2 Can you see my browsing history?
No — and notice we didn’t say “we don’t look.” Filtering happens on your device — in the browser or in the Android app — with rules shipped ahead of time. There is no request to our servers to log, because there is no request to our servers.
5.3 Free and open source? Where’s the catch?
There isn’t one you can’t inspect. No ads, no analytics, no data to sell — the code is public under MPL-2.0, so this is a checkable statement, not a marketing one. Sitr is built by Dooplin Apps as a service to the community.
5.4 You blocked a site wrongly. Now what?
Every listing must satisfy a public inclusion policy, and there’s a documented appeals process — open an appeal in the repository and it gets reviewed against the published criteria, in the open, like everything else here.
5.5 Can it be bypassed with a VPN?
In the browser, no: the extension blocks inside the browser, before the request leaves the device, so the block happens whether or not a VPN is on. Its limit is elsewhere — it protects the browsers it’s installed in, so a different browser without the extension isn’t filtered. On Android the honest answer is different. Sitr filters DNS through Android’s local VPN slot, and Android runs one VPN at a time, so another VPN app taking over stops the filtering; so does a strict Private DNS hostname or a browser’s own “Secure DNS”. Sitr shows a red “protection inactive” warning when another VPN or Private DNS takes over; a browser’s Secure DNS it cannot detect. Pair either one with your device’s parental controls, or with managed policy on fleets. We publish these limits in the threat model rather than pretend they don’t exist.
5.6 Where does it work today?
As an extension in any Manifest V3 Chromium browser — Chrome, Edge, Brave, Opera, Vivaldi and friends — and as an Android app on Google Play, where it filters every app on the phone, not only the browser. The iOS app is in development (see §4).
5.7 Why does Android show a VPN key icon?
Android’s only system-wide filtering mechanism is a local VPN, so the key icon appears while Sitr is on. Sitr’s VPN is DNS-only: the tunnel carries nothing but DNS lookups, and the app cannot see, proxy or inspect any other traffic. There is no TLS interception and no Sitr server in the path. The app explains this on its own screen before Android asks for permission.