Android · phone and Android TV
Block ads on Android
The app filters ad and tracking domains on the phone itself, for every app, on Wi-Fi and on mobile data. Install the certificate it makes on the device and it also cleans the pages your browsers open: ad slots hidden, cookie banners refused, YouTube’s video ads gone in the browser. It never looks inside an app that isn’t a browser.
- Free
- No account
- No ads
- Windows, Linux, Android
- Removed Ad and tracking domains, in every app
- Removed Ad slots, cookie banners and YouTube ads in your browsers, once you install the certificate
- Partly Game ads: banners go, rewarded ads go with their reward
- Stays Ads inside the YouTube app, and inside every other app
- Stays Videos with ads stitched into the stream
On the phone
Two filters, both on the phone.
Names first. Before reaching any server, your phone asks for an address. The app answers those questions on the device: a name on its lists gets “nowhere”, and the app that asked gives up. Every other name goes to an encrypted resolver, Cloudflare by default, with Quad9 behind it, and Cloudflare in the clear as a last resort. An app that ignores the system and talks to a resolver of its own comes back to the filter too, because every request leaving for port 53 is answered by it. An app that encrypts its own DNS questions can still escape it.
Then pages. In the browsers you leave switched on, the app reads the page before the browser draws it: it hides ad slots, neutralises ad scripts, refuses cookie banners for you when the site offers to reject everything, and takes the ads out of YouTube videos. Same engine as the computer version, with lists chosen for the phone. It needs a root certificate, made on the phone, that you install yourself — the steps are further down.
To do either, the app declares itself to Android as a local VPN. Android shows its own permission prompt. All of the phone’s traffic goes through the app, on the device: the tunnel still leads nowhere outside the phone, there is no server of ours behind it, your IP address is not hidden, and nothing of your browsing reaches the publisher. A connection that doesn’t come from a browser is passed on as it is, byte for byte.
AdHole routes your traffic through no server and hides no address. What the app itself sends out comes down to the resolvers it asks, encrypted ones first; the filter lists, when you update them, and the page-cleaning lists each time filtering starts, if page cleaning is on; and the version check, when you ask for it: it carries the version and the system and, unless you turn off “Anonymous statistics”, a random number replaced every month and the number of requests blocked since the previous check. One more is added whenever none of your resolvers answers a request: the resolver of whichever network you are on, asked in the clear for that request and for as long as the outage lasts — your router over Wi-Fi, your operator on mobile data, whoever runs a public Wi-Fi. That one sees those names again; filtering does not stop, and the app goes back to encrypted the moment a resolver answers. No browsing history is written on the device: only the request totals, plain numbers, are kept there so the counter does not start again from zero at every stop.
It reads the same three lists as the computer version, shipped with the app and updated when you ask. To fit a phone’s memory they are turned into a compact index, compared with the computer’s engine on 5,000 names from the lists: each gets the same answer. It works over Wi-Fi and over mobile data, with no computer left on at home.
Good to know: a notification stays up while the app is filtering — Android requires it of an app that holds the tunnel all the time. Turn filtering off from the app’s home screen or from the notification, or withdraw the permission in Android’s settings, and your traffic goes back to normal at once.
Measured
What we measured, on 14 September 2026.
With the default lists, on a phone running the app: 49 of the 52 mobile ad networks we tried were turned away. That was measured on domain names alone, without the certificate. The lists change every day, so this is what one day looked like, not a promise.
Turned away: Google AdMob, Unity Ads, AppLovin, ironSource, Vungle, Chartboost, AdColony, InMobi, Mintegral, Pangle, Tapjoy, Fyber, Amazon Ads, Yandex Ads, Start.io, PubMatic and Apple Search Ads.
The three that get through, and why
- Facebook Audience Network is served by the same host as Facebook login. Blocking that name would lock you out of your account, so the lists leave it alone.
- Adjust and AppsFlyer count installs; they display no advertising. Blocking them breaks links that are supposed to open an app, for no gain on screen.
- Answered graph.facebook.com Facebook Audience Network and Facebook login share this host
Games
Rewarded ads: blocked, so no reward.
A mobile game shows two kinds of advertising. The banner at the bottom of the screen and the full-screen page between two levels come from an ad network the app has to reach: their names are on the lists, so they don’t load.
The rewarded video is the same request, with a reward attached. The app blocks it like the rest, so the ad doesn’t play — and the game, having played nothing, hands out nothing. Some games then show “no ad available”, and the free lives, coins or hints stay out of reach.
That is the honest trade on Android: fewer interruptions, and a game that stops paying you for watching. If you want the reward, turn filtering off for the time it takes, from the app’s home screen.
What stays
Where the phone stops.
-
What is inside apps that aren’t browsers
Android doesn’t let one app read another app’s encrypted traffic, and AdHole doesn’t try: a connection that doesn’t come from a browser is passed on as it is. In a game, a news app or the YouTube app, only the name filter reaches the ads — and the blank rectangle a blocked banner leaves behind stays there, because nothing redraws that screen.
-
The ads inside the YouTube app
They come from the same servers as the videos. There is no ad server to refuse: blocking those names would stop the videos too. In a browser on the phone, with the certificate installed, those ads do go.
-
Videos with ads stitched into the stream
Catch-up TV and the ad-supported plans of video services build one single stream, ads included, on their own servers. Nothing on the device can take them out.
-
The sites left encrypted
Banking, payment, health, government, game stores, encrypted messaging, YouTube’s video streams: the app never opens them, not even in a browser. It starts from the same list as the computer version, which you can read and change — and which is not complete. Add your own sensitive sites before your next login there.
-
Firefox asks for one setting of its own
Firefox doesn’t trust the certificates you install in Android by default. Its “use third-party CA certificates” setting has to be turned on in the browser itself. Until then, Firefox shows a certificate error on the sites the app tries to clean, and the app then lets each of those sites through untouched for ten minutes. Make the setting, or switch Firefox off in the app.
-
Uninstalling leaves the certificate behind
Removing the app doesn’t take the certificate out of Android’s store: you remove it yourself, in Android’s security settings, under Encryption & credentials → User credentials (labels vary by manufacturer). On a computer, uninstalling removes it.
-
HTTP/3 is switched off for browsers
While pages are being cleaned, the app keeps browsers on TLS over TCP: over HTTP/3 nothing could be read, so nothing would be filtered. Every other app keeps QUIC as usual. A page may load a little differently.
-
Page cleaning needs Android 10
To clean a page, the app has to know which app a connection belongs to, and Android only says so from version 10. Below that, every connection is passed on as it is. The name filter itself works from Android 8.0.
-
Every last ad
Some will get through, and a site or an app may occasionally misbehave. One custom rule, from the app’s activity screen, lets that name through again.
Phone and computer
What the computer does that the phone doesn’t.
Both filter names, and both clean pages. The reach isn’t the same, and it’s worth knowing which one you are choosing.
- On the phone
- Names for every app, wherever you are, and pages for the browsers you leave on, once you have installed the certificate yourself. Nothing to set up on the network, no computer to leave on. Nothing inside any other app.
- On the computer
- The same two filters, reaching further: the computer opens pages for every program that goes through it, not for browsers alone. And its certificate is put in place by the installer and taken out when you uninstall, with nothing to do by hand.
- Both at once
- They don’t depend on each other. A phone with the app installed is filtered away from home; at home, pointing its DNS at the computer filters it too, and that is another way to do it.
Install it
Four steps, then the certificate.
The app isn’t distributed through Google Play. You download the file from this site, with its SHA-256 checksum published beside it, as for Windows and Linux. The last three steps are there to clean pages: stop at step four and the app filters names, and nothing else.
-
Download the APK.
From the download page, on the phone itself. Your browser will warn you about the file type: keep it.
-
Allow your browser to install apps.
Android asks once, for that browser only. Put the setting back afterwards if you prefer.
-
Open the file and install it.
Android shows its own warnings for an app that doesn’t come from a store. The published checksum is what tells you the file is the one we publish.
-
Accept the terms, then the prompt.
The app shows its terms of use the first time it opens, and only then asks Android for the connection it needs. Name filtering starts there.
-
Export the certificate from the app.
In the app’s settings, tap “Install the certificate”: it makes a root certificate on the phone, named
adhole Root CA, writesadhole-racine.crtinto your Downloads and opens Android’s security settings. Its private key is created on the device and never leaves it: the publisher has no copy and can’t obtain one. Never copy the app’s data folder. -
Install it in Android’s settings.
In Android’s security settings: Encryption & credentials → Install a certificate → CA certificate (labels vary by manufacturer), then pick
adhole-racine.crtin your Downloads. You go through those screens once, and it is done. From Android 11 on there is no automatic install: these screens are the only way in. -
Turn cleaning on, then choose the browsers.
Turn on “Remove ads and cookie banners in browsers”, off to start with. The app lists the browsers it finds on the phone, all on, each with its own switch: turn off the ones you don’t want cleaned. YouTube and cookie-banner refusal are on to start with; removing “accept or pay” windows is off until you turn it on.
Android 8.0 or later, and Android 10 or later for page cleaning. One file for every phone with an ARM processor, and for 64-bit x86 devices. Until the certificate is installed, or with page cleaning switched off, nothing is opened: the app filters names exactly as before, and no browser ever shows a certificate error. An update never installs itself: in About, “Check for updates” tells you whether a newer version exists; you download it, and Android installs it.
The same file installs on an Android TV box that accepts manual installs — a set-top box from a French internet provider, for instance. The app is built for the remote control as well as for touch, and page cleaning there covers the box’s browsers, if it has any.
Questions
The usual questions.
Does it block ads in mobile games?
The banner at the bottom and the full-screen page between two levels come from ad networks whose names are on the lists, so they don’t load. A rewarded video is blocked in the same way — and a game that has shown no ad hands out no reward. Some then say “no ad available”. If the reward matters to you, turn filtering off for the time it takes.
Why do Facebook’s ads get through?
Facebook Audience Network is served by graph.facebook.com, the same host as Facebook login. Blocking that name would lock you out of your account, so the filter lists leave it alone. It was one of the three networks that got through our measurement of 14 September 2026.
Does the Android app work on mobile data?
Yes. The filtering happens on the phone, so it follows you: Wi-Fi, mobile data, someone else’s network. No computer needs to be on at home.
Does the Android app drain the battery?
We have no measurement to publish, so we won’t give you a figure. What the app does is modest: it answers the phone’s domain-name questions and keeps the answers in memory. All the phone’s traffic now goes through it, on the device: what doesn’t come from a browser is relayed as it is, without being opened. Android counts it among the apps running in the background, so its usage shows in the battery settings.
Why isn’t the Android app on Google Play?
AdHole publishes its files itself, from its own site, with their SHA-256 checksums, as it does for Windows and Linux. What that changes for you: you allow the install by hand once, Android shows its warnings, and updates arrive when you fetch them, not on their own.
Do I need to root my phone?
No. The app uses the connection Android offers any app for this, and asks your permission for it. Nothing else on the phone is modified.
Does it block ads in my browser on the phone?
Yes. Ad servers are turned away, and once you install the certificate the app cleans the page itself, in the browsers you leave on: ad slots hidden, YouTube’s video ads removed, cookie banners refused when the site offers to reject everything. Without the certificate it only stops what the browser loads from ad servers, and the empty slot stays. Firefox asks for one setting of its own, and pages are cleaned from Android 10.
Why does it ask me to install a certificate?
A browser page travels encrypted. To hide an ad slot or refuse a banner, the app has to read that page, and a certificate your browser trusts is what lets it. This one is made on your phone, its private key never leaves the device, and the publisher has no copy. You install it yourself in Android’s settings, and you take it out yourself: uninstalling the app doesn’t. Banking, payment and health sites are never opened, and you can add your own.
What it doesn’t do
- Look inside an app that isn’t a browser: Android forbids it, and that traffic is passed on as it is.
- Remove the ads inside the YouTube app, or those of ad-supported video services.
- Clean a single page before you install its certificate yourself — and it never takes that certificate out when you uninstall.
- Give you the reward of a game’s rewarded ad: the ad is blocked, so the reward never arrives.
- Tidy an app’s screen: an ad that doesn’t load can leave an empty space.
Free, for Windows, Linux and Android.
One program on your computer, one app on your phone. No account, no ads, nothing to pay.
- Free
- No account
- No ads
- Windows, Linux, Android