Tabs, address bar, search, app catalogue, publishing, identity, and explicit permission prompts.
PearBrowser browse the P2P web. Keep your browser private.
Browse the regular web and open hyper:// sites in one familiar desktop app. Discover verified Pear apps, publish your own P2P site, and connect directly to peers while identity and optional history stay local-first.
No telemetry. No analytics. No ads. No tracking SDKs. No central account. Private by default, open source, and built for macOS, Windows, and Linux.
This website is also served peer-to-peer at
hyper://03f0060a35451cfb6b68ad1dda1b8474ebb43fd9100071ccf7d67679a83ebb4f/.
hyper://
Identity and optional history stay local-first
Verified Pear v3 catalogue and installs
No telemetry, ads, or central account
A familiar browser. A local P2P engine. Peers when you need them.
PearBrowser keeps the interface ordinary and the network model visible: the browser owns tabs and permissions, a local engine verifies content and app identity, and peers or optional relays deliver bytes.
Hyperdrive stores files, Hyperbee indexes local data, and signatures verify content and app targets.
Hyperswarm finds direct peers. Accepted relays can add reach and availability without becoming the source of trust.
Delivery is not trust. Direct peers and accepted relays can carry content, but PearBrowser still checks signed content, catalogue provenance, and app identity locally.
PearBrowser doesn't track you.
That means something specific: the browser has no telemetry collector, no remote analytics, no ad network, and no tracking SDK. Open the browser. Search without a profile. Submitted queries are not added to PearBrowser's optional persistent visit log.
No PearBrowser telemetry.
Telemetry is hard-disabled. There is no collector endpoint, and the browser does not upload history to an analytics, advertising, or profiling service.
Your history starts off.
Browsing history and local page indexing are opt-in. If enabled, they are stored locally rather than sent to PearBrowser.
Trackers start blocked.
Content Shield is on by default, alongside HTTPS-only navigation, tracking-parameter stripping, third-party cookie blocking, and fingerprint farbling.
No central account.
Your identity and app permissions are yours. PearBrowser does not require a central profile to browse, search, publish, or run P2P apps.
Use the browser. See the proof when it matters.
Each loop starts with an ordinary action and ends with a visible boundary: where a result came from, what was installed, who can keep a site available, or which capability an app received.
Open the regular web or go direct to hyper://.
Use familiar tabs and an address bar. Search the web from the browser-owned home page, paste a drive key, follow a P2P link, or revisit a bookmark.
Boundary: private search reduces browser tracking; it does not make network requests anonymous.
Find an app, inspect its source, install it locally.
Search the signed catalogue, compare provenance and target identity, then choose whether to install or launch. The remote catalogue supplies metadata; it cannot silently execute an install.
Boundary: catalogue verification proves the accepted metadata and target; it is not public OS-signing trust.
Publish a stable P2P address, then choose who keeps serving it.
Create or update a Hyperdrive locally, share its public key, and optionally ask an accepted relay to pin it. The address stays stable while the content can evolve.
hyper://public-key/
Boundary: a site remains reachable only while at least one peer or accepted relay carrying it is online.
Use an app normally, then open the trust details.
Review catalogue source, signatures, release history, relay availability, identity scope, and granted capabilities. Revoke app permissions from the browser when they are no longer needed.
Boundary: local verification explains what PearBrowser proved; independent public trust remains separate.
Trust the evidence PearBrowser can show—not a bigger promise.
The browser keeps verification calm and available on demand. Stable product paths, local identity controls, and experimental features are labelled separately so package proof, runtime trust, and network availability are not blurred together.
Verified release + catalogue
Desktop v0.8.0 has checksum-verified package-proof builds for macOS, Windows, and Linux. Catalogue v11 contains 14 accepted entries, with source and target provenance shown before local installation.
Local identity + capability control
A 12-word backup phrase restores your identity. Each site receives a different appPubkey, and Settings groups sign-in, profile, contact, and swarm-topic grants by app for review and revocation.
Experimental stays labelled Experimental
P2P names and petnames, encrypted device sync, trusted-contact feeds, and advanced network diagnostics remain opt-in or development-line surfaces. Their UI keeps provenance and recovery boundaries visible.
- Availability: a bookmarked or published
hyper://site remains reachable only while a peer or accepted relay carrying its bytes is online. - Distribution: checksum and package proof are verified for v0.8.0; macOS notarization and Windows public-trust signing remain pending.
- Privacy: PearBrowser adds no telemetry profile, but websites, search providers, peers, and relay operators can receive network metadata needed to answer a request.
Part of a P2P stack, not a silo.
PearBrowser sits alongside the HiveRelay backbone, a mobile sibling that speaks the same catalog and gateway contract, and a growing set of real companion apps.
hyper://.hyper:// drives from any browser via the HiveRelay HTTP gateway. Drop it into a blog, a PWA, or a link previewer.hyper:// pages with three trust tiers, per-app rate limits, a 1 MB/s/peer cap, and persistent grants.Get PearBrowser.
v0.8.0 moves native apps behind an explicit Pear v3 install boundary: catalogue submissions bind canonical production identity, product, version and targets to one signed receipt; optional icons are byte-validated and bounded; the host verifies identity before OS launch. Signed catalogue v11 is live, and the download page lists checksum-verified package-proof builds for macOS, Windows and Linux.
macOS: PearBrowser-0.8.0-macos-arm64.app.zip · -x64.app.zip
Windows: PearBrowser-0.8.0-windows-x64.msix
Linux: PearBrowser-0.8.0-linux-x64.AppImage
# Legacy migration identifier — not a v3 launch command
Legacy migration identifier: tco5k7h38uoxatedp1wongdbhjxow1x7jiwm3t1i9cujbebhsbty
PearRuntime.run(), and cannot install or update this browser. Use the native package for your platform.
- Pick your platform on the download page — it auto-detects your OS and shows a verifiable SHA-256 for each build.
- Package proof, not public trust — macOS is ad-hoc signed but not notarized, Windows is unsigned, and Linux is checksum-verified.
- First-launch onboarding generates a BIP-39-backed identity and helps you pick a first site to visit.
- Local runtime boundary — the native shell starts only its bundled local worker; a legacy remote record is never a runtime entrypoint.
The grown-up table.
For the people who scroll to the bottom first.
| Desktop version | v0.8.0 · signed catalogue v11 · package-proof release |
|---|---|
| Distribution | Checksum-verified package-proof builds attached to v0.8.0: macOS .app.zip (arm64 + x64), Windows .msix, Linux .AppImage; public-trust signing/notarization remains pending; the legacy migration identifier is migration-only |
| Runtime | Native desktop shell with a local bundled worker; remote deployment links are never runtime entrypoints |
| Core libraries | hyperswarm, hyperdrive, hyperbee, corestore, hypercore, autobase, p2p-hiverelay |
| Search | Lighthouse — local Hyperbee full-text index, signed by a per-app search subkey; opt-in federation over Hyperswarm (smoke-validated) |
| Identity | BIP-39 → Ed25519 root with per-app sub-keys; opt-in Nostr (secp256k1/BIP-340) — Phase 3: attested binding, post notes, federated feed over your trust graph (no public relays yet) |
| Bridge surface | window.pear.swarm.v1 — three trust tiers, per-app rate limits, 1 MB/s/peer cap (SWARM-V1.md) |
| Sync | Experimental, opt-in: sync:// Autobase device pairing for bookmarks, tabs, settings, profile, history, contacts, and app grants |
| Platforms | macOS, Windows, Linux — package-proof builds on the download page; Android and iOS source is merged and store delivery remains pending |
| License | Apache-2.0 |
| Legacy migration identifier | tco5k7h38uoxatedp1wongdbhjxow1x7jiwm3t1i9cujbebhsbty |
| This site (P2P) | hyper://03f0060a35451cfb6b68ad1dda1b8474ebb43fd9100071ccf7d67679a83ebb4f/ — the same page, currently pinned on an accepted HiveRelay route |
Honest answers.
Does PearBrowser collect or sell my browsing data?
No. PearBrowser ships without telemetry, remote analytics, an ad network, or tracking SDKs. It does not upload your browsing history to PearBrowser or sell it to advertisers. History and local page indexing are off by default; if you enable them, the data stays local unless you explicitly choose device sync.
Is PearBrowser anonymous?
No. PearBrowser is private by default, but it is not an anonymity network. Websites, relay operators, and P2P peers may receive the network information required to serve your request, including your IP address and requested content. Some HiveRelay operators can expose Tor endpoints, but PearBrowser Desktop does not yet route browser traffic through Tor automatically.
What privacy protections are on by default?
Content Shield, HTTPS-only navigation, common tracking-parameter stripping, third-party cookie blocking, and fingerprint farbling are enabled by default. Browsing history and local full-text search indexing are disabled until you opt in. Telemetry stays off and cannot be enabled.
Does PearBrowser include private web search?
Yes. The first tab and every blank new tab include DuckDuckGo search. PearBrowser sends no search analytics and does not add submitted queries to its optional persistent visit log. DuckDuckGo still receives the query and your network address to return results; its policy says it does not save or share search history. This is private search, not anonymity.
Is Lighthouse search a global crawler?
No — that's the whole point. Lighthouse is a local-first personal index: pages you browse are tokenized, signed by a per-app search subkey, and stored in a local Hyperbee. Library search returns in under 5ms with zero network. If you opt in to “include trusted peers,” the query also fans out to your trust graph over Hyperswarm — never to a central crawler.
How can I trust results coming from other people?
Every federated row is re-verified client-side against the contact's identity binding and dropped on failure before it can affect ranking. Contacts only enter your trust graph through signed invite URLs that are verified at import and rejected if forged. The ranker is deterministic and clock-free, so the same inputs produce identical ordering on every device. The room is an index, not an authority.
How production-ready is federated search?
The local index is live and wired. Federation is smoke-validated by a two-node federation test — meaning the path works end-to-end, not that it's been run at production scale. Treat the opt-in toggle as the early-access feature it is.
Does the Nostr support mean I can post to relays from PearBrowser?
Not to public wss:// relays — not yet. What works today (Phase 3): Settings displays your npub and a one-click “Link (attested)” / Revoke control that cross-curve-binds your Nostr (secp256k1/BIP-340) key to your Pear Ed25519 root. You can post NIP-01 notes signed with that key, and read notes your verified contacts authored with their attested keys — all replicated peer-to-peer over your trust graph, with no relay servers in the middle. Public relay transport is a later, opt-in phase.
What exactly does device sync cover?
Device sync is still experimental and opt-in, but it now covers more than bookmarks: open-tab snapshots, allowlisted settings, profile fields, bounded browsing history, trusted contacts, and app grants. You pair devices with a sync://<key>:<encKey> invite, and rotate or forget the sync group when a device should stop receiving future state.
What happens to my site when I close my laptop?
Nothing — that's the point. When you publish, the block editor signs a seed-request and HiveRelay pins the drive; PearBrowser only reports “published” after a relay confirms replication. The publisher can then be offline indefinitely while the relays serve the bytes to anyone with the key.
Can I read hyper:// from a regular browser?
Yes, via hyper-fetch — a small drop-in JS library that talks to the HiveRelay HTTP gateway. The full peer experience (publishing, identity, Lighthouse search, signed grants) still requires PearBrowser.
How do I install it?
Desktop builds are attached to the v0.8.0 release and listed on the download page: macOS .app.zip, Windows .msix, and Linux .AppImage. They are package-proof artifacts, not public-trust installers; verify the published checksum before opening them. The old migration identifier is for local support only, not an install command.
What if I lose my device?
If you backed up your 12-word BIP-39 phrase, you restore your identity on a new machine and your grants and per-app sub-keys come back with it. If you didn't back up, drives you published stay alive on the relays — but you can never update or unseed them. Write the phrase down.
Browse without becoming the product.
Get a browser with no telemetry, no ad profile, and local-first data—plus hyper:// browsing and explicit local review before a compatible signed native app is installed.