No single company should be able to know both who you are and every website you visit - that premise sits at the center of iCloud Private Relay, the privacy feature Apple built into iOS 15. Rather than funneling traffic through one trusted intermediary, as conventional privacy tools do, Private Relay divides the job between two independent relays, each holding only half the picture. The result is a browsing system where identity and destination are deliberately kept apart.
The approach marks a departure from how privacy tools have traditionally worked. A standard Virtual Private Network, for instance, still requires users to place total trust in one operator, who can see the originating IP address and the sites being visited. Private Relay avoids that concentration of trust by design, though it only covers Safari traffic on compatible Apple devices, which means people doing more than web browsing - including frequent video calls - often still rely on dedicated software. Many users looking for broader coverage turn to a VPN that handles video calls well, since conferencing traffic and other app-level data fall outside what Private Relay was built to protect. a VPN that handles video calls well
Two Relays, Two Views, No Complete Picture
The architecture relies on an ingress proxy, run directly by Apple, and an egress proxy, operated by independent content delivery networks such as Cloudflare, Fastly, and Akamai. The ingress proxy authenticates the user's iCloud+ subscription and sees the originating IP address, but it cannot read the destination because that information is encrypted with a separate key belonging to the egress proxy. The egress proxy, in turn, decrypts the destination address and forwards the request, but it never learns the user's actual IP address - only a generalized one tied to a broad geographic area. Neither party holds enough information to connect a person to their browsing history on its own.
Encryption Layers and Modern Transport Protocols
This separation is enforced through layered public-key encryption reminiscent of onion routing, where each relay can only decrypt the portion of data meant for its specific stage. DNS queries are similarly shielded through Oblivious DNS-over-HTTPS, preventing any single party from linking a device to the domains it looks up. Underlying all of this is QUIC, a transport protocol built on UDP that reduces connection delays and allows a device to shift between Wi-Fi and cellular networks without interruption. Apple also draws on the MASQUE framework to run these proxy connections efficiently at scale.
What This Means - and What It Does Not Cover
Private Relay reflects a broader shift in how companies are responding to growing scrutiny of data collection and third-party tracking, particularly as regulators and users alike push for architectures that minimize what any one entity can observe. Still, it is not a replacement for a full VPN: it applies only to Safari, requires an iCloud+ subscription, and can be restricted or disabled entirely by certain network administrators and some national networks. For comprehensive protection across apps, devices, and use cases beyond web browsing, dedicated VPN services remain the more complete option, even as Apple's dual-hop model sets a notable benchmark for what privacy-conscious engineering can look like at the operating-system level.