# Loupe: See What iOS APIs Expose About Your Device Before Apps Do

> Loupe is a free, open-source iOS and iPadOS app by Mysk that reads real device fingerprinting values from public APIs and displays them on screen, sending nothing off-device.

**mysk-research/loupe** — A privacy-focused iOS app that raises awareness about what native apps can see

- Repository: https://github.com/mysk-research/loupe
- Stars: 1,542 · Forks: 59
- Language: Swift
- License: NOASSERTION
- Published: 2026-09-17 · Updated: 2026-09-17 · Language: en
- Canonical page: https://hysenlabs.com/projects/mysk-research-loupe

## Fingerprinting Signals That Require No Permission at All

iOS apps can read a surprisingly wide range of device attributes without triggering any system permission dialog. Locale settings, time zone, screen dimensions, battery level, and similar readings are available to any app simply by calling the relevant public APIs. Taken individually, none of these values is necessarily unique to a single device. Taken together, they form a fingerprint: a stable identifier that can follow a device across apps, websites, and reinstalls.

Loupe is built by Mysk, the team behind Psylo, a privacy browser for iPhone and iPad. The app targets two audiences. The first is iOS developers who want to understand what their own apps inadvertently expose to embedded analytics SDKs. The second is privacy researchers and curious users who want to see raw fingerprinting data exactly as a third-party app would see it, without any processing, hashing, or aggregation standing between the API call and the display.

The project is free and open source. The source code is released under the MIT License. The app is also available on the App Store under ID 6766152470, which means non-technical users can install it without building from Xcode. The App Store version and the source-built version come from the same codebase.

## Three-Tier Signal Taxonomy: Passive, Permission-Gated, and Advanced

Loupe groups every API reading into one of three tiers based on how much access iOS grants by default, and these tiers determine how visible the data collection is to the user.

The passive tier holds signals that any app can read without prompting the user at all. These include locale, time zone, screen brightness, screen resolution, and battery state. Because no system dialog appears, the user has no indication that these readings are being collected by any app on the device.

The permission-gated tier covers readings that trigger a standard iOS prompt. Contacts, photos, location, and calendar access all fall here. When a user declines the prompt, the app cannot read those values. Loupe reflects this faithfully by showing the absence of data when permission is denied.

The advanced tier is the most technically interesting. It covers side-channel uses of public APIs. The README specifically names two techniques: URL-scheme probing via `canOpenURL` and Keychain persistence across reinstalls. The Keychain example deserves attention because it allows an app to recognize a device even after the user has deleted and reinstalled it. Most users expect a reinstall to reset any stored identity, which is why this technique is classified as advanced rather than passive despite using only public APIs.

This taxonomy matters for developers auditing their own apps. A third-party analytics SDK embedded in a host app can call every passive API automatically, on first launch, with no user action required.

## Building Loupe from Source with Xcode 26

The build process requires Xcode 26 or newer. Older versions are not supported by the project.

Start by cloning the repository:

```bash
git clone https://github.com/mysk-research/loupe.git
```

Open the Xcode project at `code/Loupe.xcodeproj`. Before building, copy the signing configuration template to create the live file:

```bash
cp code/Config/Signing.local.xcconfig.example code/Config/Signing.local.xcconfig
```

Edit `code/Config/Signing.local.xcconfig` and fill in your own `DEVELOPMENT_TEAM` and bundle identifiers. The README notes that this file is added to `.gitignore` and is never published, which prevents signing credentials from entering the repository. Once the signing file is in place, build and run from Xcode on a physical device or a simulator.

On a simulator, hardware-specific signals such as battery readings will return simulator-generated values rather than real device data. The README does not document which signals behave differently on a simulator versus a device, so testing on physical hardware gives the most accurate picture of actual exposure.

The project uses Xcode's buildable folders feature, which means adding new Swift files to the `code/` directory is automatically picked up by the build system without editing the project file manually. A macOS build target also exists. The README describes it as mostly complete but notes that a few areas still need work before it is polished.

## What Loupe Reads Stays on the Device

The README is explicit on data handling: nothing Loupe reads leaves the device unless the user explicitly exports it. Values are shown as raw readings, with no aggregation, no hashing, and no synchronization to any server. The project does not include a backend and makes no network calls to transmit collected data.

This constraint is worth naming clearly for developers who use Loupe to audit their own code. The readings visible in Loupe represent what the device makes available through public APIs. Any third-party app on the same device, including analytics SDKs embedded in otherwise unrelated apps, can call the same APIs and collect the same values. Loupe is a mirror, not a collector.

The export feature mentioned in the README is not described in detail there. The README does not specify the export file format, what fields are included, or where the file is saved. For teams building compliance documentation around what their iOS apps expose, this gap means Loupe shows the data but does not currently provide a structured audit trail in a documented format.

## What Loupe Cannot Do: No Blocking, No Guidance, No Cross-App View

Loupe is a read-only diagnostic tool. It shows fingerprinting data but takes no action to block, randomize, or rotate any of the values it displays. An iOS developer who wants to reduce the fingerprinting surface of their app will not find active remediation in Loupe's interface. The app answers the question of what is exposed; it does not answer what to do about it.

Loupe can only show what its own process can read. It cannot inspect what other apps on the device are collecting or transmitting. A user who installs Loupe alongside a tracker-heavy social media app will see the same raw API values in Loupe that the social app can access, but Loupe cannot confirm whether the social app is actually using those values or sending them anywhere.

The advanced-tier readings rely on behaviors that Apple has not explicitly documented as permanent. Keychain persistence across reinstalls and URL-scheme probing via `canOpenURL` represent uses of public APIs that Apple can restrict in future iOS releases without advance notice. The materials do not indicate that Loupe versions its readings against specific iOS releases, so a reading that works on one version may behave differently after a system update.

## Loupe and Psylo: Reading Fingerprints versus Blocking Them

The README positions Psylo, the team's privacy browser for iPhone and iPad, as the complementary product to Loupe. Where Loupe reads and displays fingerprinting signals, Psylo provides proxy-backed browsing, isolated tabs, and anti-fingerprinting protections designed to block or alter the same signals.

The practical difference is the direction of action. Loupe is a transparency tool that answers "what can be read?" Psylo is a protection tool that attempts to answer "how do I prevent it from being read?" They are not interchangeable and serve different users.

Privacy browsers on Android and desktop platforms, such as Firefox's fingerprinting resistance mode, take a similar protective approach to Psylo: they randomize or block certain API outputs rather than displaying them. Loupe has no equivalent on Android or desktop. Its utility is limited to the iOS and iPadOS ecosystem, which means it cannot help a developer compare fingerprinting exposure between platforms.

## MIT Source, Proprietary Assets, and the September 2026 Push Date

The source code is released under the MIT License. The project also makes clear that the Loupe name, logo, app icon, all other images and icons, and the design source files are proprietary and are not covered by the MIT license. A contributor building a fork or a derivative app would need to replace all visual assets before distributing their version.

The last push to the repository was on 2026-09-10. The project has no published GitHub releases as of September 2026. Building requires cloning the main branch directly rather than checking out a tagged version.

The README notes that Loupe was written almost entirely by AI coding tools. The top-level repository entries include a `fastlane/` directory and a `Gemfile`, which suggests that App Store distribution is automated through Fastlane. The materials do not include a test directory in the top-level listing, which leaves open the question of what test coverage exists for the signal-reading code.

## Conclusion

Loupe is the right choice for iOS developers and privacy researchers who want to understand what fingerprinting data their apps expose. It is a diagnostic tool, not a protective one: it reads and displays, it does not block or randomize. Before recommending it to non-technical users, verify that Xcode 26 or newer is available and that the signing configuration file has been filled in correctly.

## FAQ

### What is the Loupe app?

Loupe is a free, open-source iOS and iPadOS app by Mysk that reads real device fingerprinting values from public iOS APIs and displays them on screen. Nothing it reads is uploaded, synced, or shared unless the user explicitly exports it.

### Does Loupe send my device data to any server?

No. The README states that nothing Loupe reads leaves the device unless the user explicitly exports it. No data is aggregated, hashed, or uploaded to any backend.

### Does Loupe require special iOS permissions to show fingerprinting data?

For passive-tier readings such as locale, time zone, battery level, and screen dimensions, no permissions are needed. For contacts, photos, location, and calendars, Loupe triggers the standard iOS permission dialog just as any other app would, and shows no data if permission is denied.

## Sources

- [Issues](https://github.com/mysk-research/loupe/issues)
- [mysk-research/loupe on GitHub](https://github.com/mysk-research/loupe)
- [README](https://github.com/mysk-research/loupe/blob/main/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/mysk-research-loupe
