AdHole General Terms of Use

This is a translation. The French version is the reference; in case of discrepancy, the French
version prevails. French version: CGU.txt, shipped with the program.

Version 2.9 — 17 September 2026

1. The publisher, and what this document commits to

AdHole is published by Antoine MOURY, sole trader (entrepreneur individuel), 26 rue Charles de
Mouchy, 06210 Mandelieu-la-Napoule, France, registered under SIREN number 913 844 619. Full contact
details are in MENTIONS-LEGALES.txt (English: MENTIONS-LEGALES.en.txt), shipped with the program.

This document is the contract between the publisher and you. It states what the software does, what
it does not do, what you accept by installing it, and what the publisher is answerable for.

1.1 — Acceptance. Before changing anything on your computer, the installation displays these
terms and requires you to accept them: the installer's licence screen on Windows; on
Linux, the adhole setup command, which asks you to type "yes" (« oui » in the French interface).
On Android, the app displays these terms the first time it opens and only turns filtering on once
you have accepted them. Accepting
constitutes full and complete acceptance, and
the installation records the moment it happened. Refusing stops the installation: nothing is put in
place, nothing is changed.

1.2 — Capacity. You must be of legal age, or have the permission of the holder of parental
authority. AdHole changes system settings and decrypts traffic: this is not something a minor does
alone.

1.3 — Free of charge. AdHole is free of charge and remains so. It is not sold. There is no
account, no financial consideration, and no data requested in exchange. No clause of this document
describes a transaction, because there is none.

2. What AdHole does, exactly

AdHole is software for Windows, Linux and Android that filters advertising. It runs on your
machine: nothing it filters passes through the publisher.

On a Windows or Linux computer, once installed:

- a DNS filter answers "nowhere" for advertising domains. It listens on port 53 of your
  computer and answers every device on your local network that designates it as its resolver
  (television, console, phones), and those alone: it refuses any request coming from an address
  outside private networks. When a firewall is active, the installation opens ports 53 (TCP and
  UDP) and 67 (UDP) in it: on Windows, for the local network only; on Linux, port 53 for the
  local subnet and port 67 with no restriction of origin, because a device asking for an address
  does not have one yet;
- a decrypting proxy filters pages in detail and removes YouTube ads, on this computer
  only. It listens on 127.0.0.1, and can only be reached from this machine;
- a service (Windows service, systemd on Linux) starts with the computer,
  before anyone logs in;
- on Windows, an icon near the clock appears at each login. It is used for alerts and to stop
  the program. On Linux, there is no icon: alerts are shown in the dashboard;
- a DHCP server can hand out the network's addresses instead of your router. This function is
  disabled by default and can only be enabled from the command line, deliberately;
- a dashboard opens in an application window. It is served locally, on 127.0.0.1, without a
  password: anyone who uses this computer can read it and change its settings.

2.1 — What AdHole does not do. It does not circumvent any technical protection, does not give
access to any restricted content, does not modify any file of your other software, and sends the
publisher no data about your browsing: only the anonymous statistic described in article 11, which
you can turn off.

2.2 — What is not promised. Filtering depends on public lists maintained by third parties and on
websites that change without notice. No blocking rate is guaranteed. Some ads will get through;
some sites will display incorrectly because of the filtering. This is inherent to this type of
software, and it is not a defect in the contractual sense.

2.3 — The Android app. AdHole also exists as an app for Android 8.0 or later. It filters
domain names on the device, with the same lists as on a computer, over Wi-Fi as over mobile
data, for every app on the device. Since version 1.5.0 it also cleans up the pages you open in
your browsers, provided you install the root certificate described in article 5 yourself.

To receive the system's traffic, the app declares itself to Android as a local virtual private
network — a local VPN. Android then shows its own permission prompt, which you accept or refuse.
That tunnel leads nowhere outside the device: what enters it is handled on the phone, then
leaves the phone for its real destination. AdHole is not an encrypted tunnelling service: it does
not hide your IP address, routes your traffic through no server, and routes none of your data
through the publisher.

What it filters, on two levels.

- Domain names, for every app on the device. A name on its lists is answered "nowhere". Since
  version 1.5.0, every domain-name request the device makes goes through that filter, including
  when an app addresses a resolver of its own choosing.
- The content of pages, in browsers only. Ad slots hidden, ad scripts neutralised, cookie
  banners refused when the site offers to reject everything, ads taken off YouTube videos. This
  filtering requires that you have installed the root certificate (article 5); it applies only
  to the browsers you leave ticked in the settings, and never to the sites left encrypted (5.4).

What is never opened. The traffic of apps other than browsers. Android does not let one app read
another's encrypted traffic, and AdHole does not try: a connection that does not belong to a ticked
browser is relayed as it is, byte for byte. The same goes for the sites left encrypted, in a browser
as anywhere else.

As long as the certificate is not installed, or if you turn off the "Remove ads and cookie
banners in browsers" setting, no page is opened: the app filters domain names, and nothing more.
No browser shows a certificate error in that state.

Two technical effects, said here rather than discovered. While pages are being cleaned, the app
turns off the HTTP/3 protocol for the ticked browsers, so that they fall back to the connection it
can read; the rest of the device goes on using it. And recognising which app a connection belongs to
requires Android 10 or later: below that, no page is opened and only domain-name filtering
applies.

What leaves the device: the encrypted DNS resolvers you have chosen, the download of the filter
lists, and the version check together with the anonymous statistic of article 11 — the same outgoing
connections as on a computer (11.3), with the same guarantees and the same switch. One more is
added, and only when all your encrypted resolvers have failed three times in a row: the resolver
of the network the phone is attached to — your router over Wi-Fi, your mobile operator's relay on
mobile data, the operator's own on a public Wi-Fi. The app then puts your questions to it in plain
text, for as long as the outage lasts, and it is the one that sees those names (11.3). No data
about your browsing reaches the publisher, and no browsing history is written on the device.

2.4 — What the Android app does not remove. Outside browsers, filtering is done by domain name,
and it has the limits of that:

- the ads shown inside other apps, whose traffic AdHole never opens (2.3): only the ad network's
  domain name is reached, and the slot may be left empty;
- the ads inside the YouTube app, which come from the same servers as the videos;
- videos whose ads are stitched into the stream by the server that sends it: catch-up TV, the
  ad-supported plans of video services;
- rewarded ads in games: they are blocked, so the reward they pay for does not arrive, and some
  games then show "no ad available";
- Facebook Audience Network, served by the same host as Facebook login
  (graph.facebook.com): blocking it would stop you signing in to your account;
- install attribution tools such as Adjust and AppsFlyer, which display no advertising but whose
  blocking breaks some links that open an app.

In browsers, where pages are opened (2.3), three limits remain:

- Firefox keeps its own list of certificates and ignores Android's until its "Use third-party CA
  certificates" setting is turned on: its pages are then left as they are. The publisher describes
  that setting; it does not promise its result, which is up to Firefox;
- the sites left encrypted (5.4) are never opened, so never cleaned;
- windows that demand your consent without offering a free way to refuse stay in place unless
  you turn on their removal (9.2 and 9.3), and a subscriber-only wall is never removed (9.4).

No blocking rate is guaranteed (2.2). A measurement of the mobile ad networks turned away by the
default lists, dated 14 September 2026, is published on the publisher's website: it describes
what was observed that day, not an undertaking, and it covers domain-name filtering only.

2.5 — Installing on Android is done by hand, and it is on you. The app is distributed neither
through Google Play nor through any other store. It is downloaded from the publisher's website as
an APK file, whose SHA-256 checksum is published next to it: that checksum, and nothing else, proves
that the file you received is the one that was published.

Installing an app this way means allowing your browser to install apps from unknown sources. That
is a security setting of your device, which you change yourself and under your sole
responsibility; the publisher advises you to put it back as it was once the installation is
finished. Android shows its own warnings: they are normal for an app that does not come from a
store, and they say nothing about the quality of the file.

2.6 — What does not change. The Android app changes nothing on your computers, and installing on
a computer changes nothing on your phone. Article 5 (interception of HTTPS traffic) now applies
to the Android app as well, with the device's particulars set out in 5.6. Article 6 (changes
to your computer's network settings) still concerns the Windows and Linux versions only: on Android
the app changes no system setting itself, and it is you who install the root certificate in
Android's settings. Everything else in this document — licence (3), where you may install (4), updates (7), acceptable
use (10), privacy (11), warranty (12), liability (13), termination and uninstallation (14) — applies
to the Android app as it does to the computer program.

3. Licence to use

AdHole is proprietary software. Its source code is not provided.

The publisher grants you a free, personal, non-exclusive, non-transferable and revocable right to
install and use AdHole on the computers that you own or that you administer. This right does not
transfer any intellectual property right to you.

You may not: resell it, rent it, lend it for payment, redistribute it under your name or that of a
third party, publish a modified copy of it, remove or hide the proprietary notices, or decompile it
outside the cases where the law permits it.

Decompilation and analysis remain permitted in the cases and within the limits of article L122-6-1
of the French Intellectual Property Code, in particular for interoperability. This right is a
matter of public policy: no clause of this document claims to exclude it.

Libraries written by others and used in the program keep their own licences, all of which permit
this use. Their list and the full text of
each licence are shipped with the program in LICENCES-TIERCES.txt. Do not delete this file: it is
the consideration for these licences.

4. Where you are allowed to install AdHole

4.1 — Your machine, or one you administer. You may only install AdHole on a computer that you
own, or of which you are the legitimate administrator and for which you have the owner's consent.

4.2 — Never on someone else's machine. Installing AdHole on someone else's computer without
their consent is not a blunder, it is a criminal offence. The software installs a root certificate
and decrypts traffic: anyone who installs it on another person's machine without their knowledge is
liable to the penalties of article 323-1 of the French Criminal Code (fraudulently accessing or
remaining in an automated data processing system: three years' imprisonment and a fine of
100,000 euros) and of article 226-15 of the French Criminal Code (intercepting correspondence
sent electronically, or installing a device enabling such interceptions: one year's imprisonment and
a fine of 45,000 euros).

4.3 — The home network. If you designate this computer as the DNS resolver for other devices,
the requests of those devices pass through it and appear in the dashboard, with their local IP
address. Tell the people who live with you. Doing so without the knowledge of an adult in the
household falls under the same provisions as in 4.2.

4.4 — In a company or a public administration. Installation on a work computer requires the
formal consent of the person who administers the IT equipment. An employee cannot decide alone to
decrypt the traffic of a workstation: the security of their employer's information system is at
stake, and often their employment contract too. In such a case, it is the organisation that must
decide, and it is the organisation that is answerable for the use it makes of it.

4.5 — Prohibited places. Do not install AdHole on a shared computer in open access, nor on a
system where a failure would endanger people's safety.

4.6 — On Android. Only install the app on a device that belongs to you, or whose owner has
agreed. It sees the domain names the device asks for and, once its root certificate is installed,
the content of the pages opened in browsers (2.3, 5.6): putting it on someone else's phone
without their knowledge falls under the same provisions as 4.2, and installing the certificate on
someone else's phone adds the circumstance 4.2 describes about interception devices.

5. Interception of HTTPS traffic: what you expressly accept

This is the most important point of this document. Read it in full. It concerns the Windows and
Linux versions and — since version 1.5.0 — the Android app, whose particulars are set out in 5.6.
It does not concern the iPhone and iPad app, which decrypts nothing.

5.1 — What is done. To filter HTTPS sites, AdHole installs in the system's certificate store
(and, on Linux, in those of Chrome and Firefox when their tool is present) a root certificate it
has generated itself, and declares itself as the proxy for your session through an automatic
configuration script that provides for a direct connection when AdHole
does not respond. Your browser then opens its connections to AdHole, which reopens them to the
site. AdHole therefore sees in clear the content of the pages you visit, including what you
type into them, except for the sites excluded from decryption (5.4).

5.2 — The private key. The certificate and its private key are generated on your machine
during installation — on your phone, the first time you ask for the certificate. They are unique to
that device. They are never transmitted, neither to the publisher nor to anyone: the publisher
has no copy of them and cannot obtain one.

The private key is the file adhole-ca.key, in the ca subfolder of the data folder:
C:\ProgramData\adhole on Windows, /var/lib/adhole on Linux. Access to it is restricted to the
machine's administrators (root on Linux). On Android it sits in the ca subfolder of the app's
private data folder, which Android keeps apart from other apps.

What a third party who obtained this file could do: they could create, for any site, a
certificate that your device would believe to be authentic. They could then decrypt and modify
your traffic without your browser displaying the slightest warning, for as long as this root
certificate remains installed. Do not copy this file anywhere, do not put it on a USB stick, do not
back it up to online storage, do not attach it to a message. If you think it may have been copied,
uninstall AdHole: on a computer the root certificate is then removed from the system store and the
key loses all value. On Android, uninstalling does not remove the certificate from Android's
store: remove it yourself (5.6).

5.3 — The scope of consent. By installing AdHole on a computer, and by installing its root
certificate on an Android phone, you expressly consent to this decryption, for your own traffic, on
your own device. This consent applies only to you. It does not cover another person's traffic (see
article 4).

5.4 — The sites left encrypted, and what is up to you. Some sites are never decrypted: AdHole
then opens a plain tunnel and sees nothing of their content. A default list is shipped with the
program; it covers in particular system updates, game stores, storage services, encrypted
messaging services, payment services and video streams.

This list cannot be exhaustive, and the publisher does not claim that it is. No publisher can
list every bank, every mutual health insurer, every health or government service in the world. The
list actually applied on your machine can be viewed and edited in the dashboard settings, in
the section on sites left encrypted (no_decrypt in the configuration file); on Android, in the
app's settings, under "Sites left encrypted". The starting list is the same as on a computer.

It is therefore up to you to add the sites you do not want to see decrypted. Take that minute
before your next sensitive login — bank, health, taxes, employer. Whatever you do not remove from
decryption remains subject to it, knowingly.

5.5 — How to refuse this function. Decryption is not mandatory. Installing with the option
adhole setup -no-proxy sets up the DNS filter without a root certificate and without a proxy:
nothing is decrypted, and the filtering of pages and of YouTube does not work. This is a legitimate
choice, and the program works that way. On Android, refusal is the starting state: the app ships
with no certificate installed, and until you install one it filters domain names and nothing else.

5.6 — On Android: what differs, point by point. The principle is the one in 5.1, but four things
are specific to the device.

- You install the certificate, by hand. The app creates it on the phone, exports it to your
  downloads as adhole-racine.crt and opens Android's security settings; the rest is in your hands:
  Encryption & credentials, Install a certificate, CA certificate, then pick the file. Since
  Android 11 there is no one-tap install. Android shows its own warning at that point about what a
  certificate authority allows: it is accurate, read it. The app cannot install the certificate
  for you, and does not try.
- Browsers, and nothing else. Only the connections of the browsers you leave ticked in the
  settings are opened, towards the web's ports, and only for sites that are not on the 5.4 list. All
  the rest of the device's traffic — other apps, messaging, banking, games — is relayed as it is,
  byte for byte. AdHole therefore sees in clear the content of the pages you open in those
  browsers, including what you type into them, and nothing else.
- What uninstalling does not remove. Uninstalling the app takes its data folder with it, and so
  the private key. It does not remove the root certificate from Android's store: Android does
  not allow an app to do that. Remove it yourself under Settings, Security, User credentials, then
  adhole Root CA. For as long as it stays there — even though the matching key went with the app —
  a useless certificate remains trusted on your phone, and there is no reason to leave it.
- Firefox decides for itself. Firefox keeps its own list of certificates and ignores Android's
  until its "Use third-party CA certificates" setting is turned on. The publisher describes that
  setting; it does not guarantee its effect, which is up to Firefox and may change without notice.

6. Changes to your computer's network settings

AdHole changes your machine's network configuration. This is the most concrete risk of this
software, and it is described here plainly. This article concerns the Windows and Linux versions
only: on Android, the app changes no system setting itself — the root certificate is one you
install (5.6) — and filtering stops as soon as you turn it off or withdraw its permission
(2.3, 14.7).

6.1 — What is changed. The installation designates AdHole as this computer's first DNS
resolver — on Windows, 127.0.0.1 and ::1 on the active network adapter; on Linux, in
systemd-resolved, whose local listener on 127.0.0.53 is turned off to
free port 53, or failing that in NetworkManager. It enables the system proxy, opens the firewall
ports as described in article 2, installs a service that starts automatically and, on Windows, adds
the launch of the notification icon at login and AdHole's folder to the system's command path.

6.2 — The risk, stated frankly. When your computer asks itself to resolve domain names and
AdHole no longer answers, no website opens any more, in any software.
This is not a textbook hypothesis: on 13 September 2026, the publisher's machine was left without
any name resolution, and therefore without internet, because the service had stopped while the
network adapter was still pointing to it.

6.3 — What has been put in place since. A fallback resolver — your router — is now added after
AdHole in the computer's DNS configuration: if AdHole stops, name resolution continues, only
filtering is lost. The service is configured to restart automatically after an incident (on Windows
after 1 s, 15 s, then 60 s; on Linux after 5 s, with no limit on attempts). Before
stopping, AdHole checks that nothing is listening any more and then hands DNS back to the router by
itself. Finally, since version 1.1, the proxy is declared through an automatic configuration script
that provides for a direct connection: if AdHole no longer responds, pages keep opening, without
filtering, instead of no longer opening at all.
And when it is the encrypted resolvers that go down rather than AdHole itself, AdHole puts your
questions to the router in plain text for as long as the outage lasts, instead of answering with
a failure — which amounted to cutting your internet (11.3).
Connections in progress at the time of an abrupt stop, however, are cut and must be restarted.

These safeguards reduce the risk. They do not eliminate it.

6.4 — How to regain control — remember this before you need it. If your connection no longer
works, open a command prompt as administrator — on Linux, a terminal, prefixing each command
with sudo — and run one of these commands (on Windows, the installer makes the adhole command
available in any command prompt opened after installation):

- adhole dns off — immediately hands DNS back to your router. This is the step that fixes the case
  described in 6.2;
- adhole arreter — really stops AdHole: DNS handed back to the router, proxy turned off, service
  stopped;
- adhole status — shows the state and explicitly reports the failure when it is present;
- adhole teardown — removes everything the installation put in place, including the root
  certificate;
- failing that, on Windows, uninstall AdHole from "Installed apps": uninstalling performs the
  restoration.

On Windows, the same stop is available without the command line: right-click the icon near the
clock, then "Stop AdHole" ("Arrêter AdHole" in the French interface).

6.5 — The computer must stay on. The devices you point at this PC lose name resolution when it
is off or asleep. That is the cost of this method, and you accept it by choosing it.

6.6 — The DHCP server. The function that makes this computer hand out the network's addresses,
instead of your router, is disabled by default. It disrupts the whole network if it is enabled
without turning off the router's. Only enable it if you know what you are doing.
Address assignments are then kept in a file on your disk, with the hardware address and the name of
each device in the household.

7. Automatic updates

7.1 — They are on by default, and you accept this by installing. When a newer version is
published, AdHole downloads it, checks its fingerprint, then installs it by itself, without asking
you anything, unless it comes with new terms of use: it then waits for your agreement (article
15).

7.2 — When. Installation takes place at night, between 3 am and 5 am. If the machine is off at
those times, an update that has been pending for more than seven days is installed at the first
possible moment, whatever the time.

7.3 — What it costs. The installation interrupts filtering for about thirty seconds.
During that time, the devices that depend on this PC for their DNS have no name resolution. Your
downloads and your video calls may suffer.

7.4 — What protects this update. The file is only accepted over HTTPS, and only if its SHA-256
fingerprint exactly matches the one announced. Without a fingerprint, or with a fingerprint that
does not match, nothing is installed. The address where AdHole looks for versions can only be
set in the configuration file, never from the dashboard: whoever chooses this address chooses what
will be installed on the machine.

7.5 — How to refuse. The setting that installs updates automatically ("Installer les mises à
jour toute seule" in the French interface) can be turned off in the dashboard. AdHole then only
notifies you, and you decide. Emptying the update address in the configuration file disables even
the check.

7.6 — What the publisher does not guarantee. No release frequency, no period of maintenance, no
future compatibility. The publisher may stop publishing versions at any time, without notice and
without compensation. The software already installed continues to work.

7.7 — On Android, nothing installs by itself. The app reads the version file and, if a newer
version exists, offers to download it. You start the download, and Android installs it, with its own
warnings. The SHA-256 checksum published next to the file lets you check what you are installing.
Filtering is never interrupted by an update you did not start.

8. Blocking advertising is lawful

Filtering what your own computer — or your own phone — displays falls within your freedom to use
your machine. You are under no obligation to display the advertising a site sends you, and no
provision requires it.

Nothing more follows from this: AdHole does not authorise you to access paid content without being
entitled to it, nor to circumvent a technical protection measure.

9. Refusing trackers, and consent walls

9.1 — Refusing trackers is a right. Article 82 of French law no. 78-17 of 6 January 1978
makes reading and writing information on your device subject to your prior consent.
The CNIL (the French data protection authority) concluded from it, in its guidelines
(deliberation no. 2020-091 of 17 September 2020) and its recommendation (deliberation
no. 2020-092 of the same day), that refusing must be as simple as accepting.

AdHole clicks "reject all" when the button exists. And it refuses by design to record a positive
consent: it never accepts on your behalf, even when a public filter list would ask it to do so.

9.2 — "Consent or pay" walls are a different matter. The Conseil d'État (France's highest
administrative court), in its decision no. 434684 of 19 June 2020, annulled the general and
absolute ban that the CNIL had laid down in its guidelines, holding that such a ban could not appear
in a soft-law instrument. These walls are therefore not unlawful in principle in France; their
validity is assessed case by case.

Removing such a wall to reach the content without consenting goes beyond simply refusing trackers.
That is why this function is disabled by default (remove_walls: false).

9.3 — If you enable it, the decision is yours. Enabling it is a deliberate act, which you
perform for your own machine, knowingly. You alone bear the consequences, and you indemnify the
publisher against any claim by a website publisher that results from it.

9.4 — No circumvention of paywalls. AdHole never removes a subscription wall, and is not meant
to. The selectors that targeted such a wall have been explicitly removed from the code.
Providing a means of circumventing a technical protection measure is punishable under article
L335-3-1 of the French Intellectual Property Code: the publisher does not intend to expose himself
to this, and forbids you to misuse the software for that purpose.

10. Acceptable use

You undertake not to use AdHole to:

- access content reserved for subscribers without being entitled to it;
- install it on a machine that does not belong to you and that you do not legitimately administer,
  or without the knowledge of its user;
- intercept another person's traffic or communications;
- disrupt a third party's network, in particular by enabling address distribution on a network
  that is not yours;
- modify, recompile or redistribute the program;
- use it in any way contrary to applicable law.

Failure to comply with this article automatically terminates your licence to use, without prejudice
to any proceedings the injured party may bring.

11. Privacy and personal data

11.1 — What goes to the publisher: an anonymous statistic, and nothing else. Shortly after each
start of the service, then once a day, with the version check, AdHole sends the publisher's server a
number drawn at random on your computer and renewed every month, its version number, the system
(for example "windows-amd64" from a computer, "android" or "android-tv" from an Android device),
and the number of requests it blocked since the previous check.
This number
says nothing about you and changes every month: it makes it possible to count active
installations, not to follow one. The number of blocked requests is a plain number: no domain name,
no address, no browsing date. It is only used to show, on the publisher's website, the total number
of requests blocked across all installations. The publisher receives no data about your browsing —
no sites, no domain names, no content — and has no technical means of receiving any. The statistic
is on by default and can be turned off in the settings ("Anonymous statistics", "Statistiques
anonymes" in the French interface): the identifier is then erased from your disk, that number stops
being sent, and the version check goes out on its own.

11.2 — Only one processing operation on the publisher's side: this statistic. It is described in
detail in CONFIDENTIALITE.txt (English: CONFIDENTIALITE.en.txt): no IP address is recorded in it,
and only totals are kept. For your browsing, on the other hand, there is no data controller on the
publisher's side, within the meaning of article 4 of Regulation (EU) 2016/679: no data about it
reaches the publisher. This is not a commercial promise, it is a consequence of the software's
architecture, verifiable in the program's behaviour.

11.3 — The outgoing connections that actually exist. The program connects to five things, and
to nothing else:

- the DNS resolvers you have chosen, queried in list order: the next one is only asked if the
  previous one has not answered within a second or has failed, and the first answer received is
  used. By default: Cloudflare over DNS-over-HTTPS, then Quad9 over DNS-over-TLS, and as a last
  resort 1.1.1.1 (Cloudflare), in plain, unencrypted DNS. They see your IP address and the names
  you request;
- your network's router, and it alone when all the resolvers above have failed three times in a
  row: AdHole then puts your questions to it, in plain text, rather than leaving you with no
  name resolution. Your internet service provider sees those questions. This fallback lasts as long
  as the outage: AdHole tries the encrypted resolvers again every ten seconds and goes back to them
  as soon as one answers. Filtering is not suspended in the meantime. The Android app does the
  same, with the resolver of whichever network it is on: on a phone that is not always a router —
  it is the home Wi-Fi's, your mobile operator's on mobile data, or the operator's on a public
  Wi-Fi, and that is who then sees your questions. The iPhone and iPad app does not have this
  fallback;
- the filter lists, downloaded once a day from their authors (AdGuard, hagezi) or from GitHub,
  which hosts some of them. These servers see your IP address, as with any download;
- the version file, shortly after each start of the service then once a day, on the
  publisher's server (adhole.io), accompanied by the statistic of article 11.1 unless you have
  turned it off. This server sees your IP address and does not record it (details in
  CONFIDENTIALITE.en.txt);
- the installer of an update, when there is one, from the address that this file
  indicates.

The resolvers, the list authors and GitHub are third parties, independent data controllers for what they
see of you. The choice of resolvers and lists is yours, and each of these connections can be
disabled in the configuration.

11.4 — What remains on your disk. The details are in CONFIDENTIALITE.txt. In short: the
dashboard's latest requests, its rankings, the cache and the latency live in RAM and disappear when
the service stops; only the request totals, seen and blocked, are written to disk, in
compteurs.json, with no domain name and no address;
a technical log is written to disk; the certificate's private key is stored there; and, if you have
enabled address distribution, the network's address assignments are kept there.

On Android, the app's data folder holds your custom rules, your settings, the list of your filter
lists, the downloaded lists, the request totals — seen and blocked — in compteurs.json, with no
domain name and no address, the number used by the anonymous statistic together with the mark of
its last accepted send, and — since version 1.5.0 — the root certificate and its private key, in
the ca subfolder (5.2). No browsing history is written there, and the content of the pages
opened in your browsers is not kept there either: it is handled in memory, for the time of the page.
Uninstalling the app takes that folder with it — but not the certificate installed in Android's
store (5.6, 14.7).

11.5 — You, and the other people in the household. When devices that are not yours use this PC
as their resolver, their requests appear in the dashboard with their local IP address. In a
strictly domestic setting, this processing falls outside the European regulation under its
Article 2(2)(c). Outside that setting — a shop, an association, a work computer —, it is you
who become the controller of this processing, and it is up to you to inform the people concerned.

12. Warranty

12.1 — The software is provided as is. The publisher does not guarantee the absence of defects,
the absence of interruption, fitness for a particular need, that a given site will display
correctly, or that a given ad will be blocked.

12.2 — The real scope of this clause, without pretence. Under French consumer law, an exclusion
of warranty cannot be enforced against a consumer where the law imposes a warranty.

The legal guarantee of conformity for digital content is provided for in articles L224-25-1 et
seq. of the French Consumer Code. Its scope, set by article L224-25-2, covers contracts under
which the consumer « s'acquitte d'un prix ou procure tout autre avantage au lieu ou en complément du
paiement d'un prix » ("pays a price or provides any other benefit instead of, or in addition to, the
payment of a price"). AdHole is provided free of charge. In return it collects only technical
information about the installation — the statistic of article 11.1: a number drawn at random and
renewed every month, the version, the system, the number of blocked requests —, which recital 25 of
Directive (EU) 2019/770, of
which these articles are the transposition, leaves outside its scope.
This characterisation is the publisher's own; it has not been decided by a court, and a court could
decide otherwise.

12.3 — What remains owed whatever happens. Even in the absence of a contractual warranty, the
publisher remains bound not to knowingly deliver dangerous or misleading software, and is liable for
his proven fault. Nothing in this document claims to exclude what cannot be excluded.

13. Liability

13.1 — The principle. AdHole is provided free of charge. The publisher's liability is assessed
in light of this free provision and of the nature of the software.

13.2 — What is excluded, within the limits permitted by law. The publisher is not liable for
indirect damage, in particular: loss of data, operating loss, business interruption, loss of
turnover, damage to reputation, loss of internet connection and its consequences, cost of a repair,
or harm suffered by a third party. In accordance with article 1231-3 of the French Civil Code,
the publisher is in any event liable only for the damage that was foreseeable when the contract was
concluded.

13.3 — What is never excluded, and saying so is more honest than writing it anyway.
No provision of this document excludes the publisher's liability in the event of fraud (dol), gross
negligence (faute lourde), harm to the physical integrity of persons, nor in the cases where the law
prohibits it. In particular:

- towards a consumer, a clause that would remove or reduce their right to compensation in the
  event of a breach by the publisher is deemed unwritten: this is item 6° of article R212-1 of
  the French Consumer Code, whose list is irrebuttable;
- liability for defective products can be neither excluded nor limited by contract, under
  article 1245-14 of the French Civil Code.

13.4 — Towards a professional user. If you use AdHole in the course of your professional
activity, the limitations of article 13.2 apply in full,
and the publisher's total liability, for all causes combined, is limited to compensation for the
proven direct damage, and may not exceed the sum of one hundred euros — the software being provided
without financial consideration, this limit reflects the real economics of the contract.

13.5 — What is your responsibility. You alone are responsible for: the choice to install this
software on a given machine, backing up your data before installation, protecting the certificate's
private key, the content of the list of sites left encrypted, enabling the functions disabled by
default, the custom filtering rules you add, the network configuration you impose on other
devices, and — on Android — the permission to install apps from unknown sources that you grant your
browser (2.5), the installation of the root certificate in the device's settings, and its removal
after an uninstall (5.6).

13.6 — Force majeure. The publisher is not liable for a failure due to an event beyond his
control, within the meaning of article 1218 of the French Civil Code, including the unilateral
modification of a third-party site or the discontinuation of a public filter list.

14. Term, termination, uninstallation

14.1 — Term. The licence runs for as long as you use the software.

14.2 — Termination by you. Uninstall: the licence ends. You have nothing to ask of anyone, and
nothing is owed.

14.3 — Termination by the publisher. The publisher may terminate your licence in the event of a
breach of articles 3, 4, 9 or 10. The licence being free of charge, this termination gives rise to no
compensation.

14.4 — What uninstallation removes. Uninstallation — from "Installed apps" on Windows, with the
command sudo adhole teardown on Linux — performs the
restoration: the root certificate is removed from the system store, the system proxy disabled, DNS
handed back to your router, the firewall rules deleted, the service removed, the launchers removed,
AdHole's folder removed from the system's command path, and the automatic launch of the icon
cancelled.

14.5 — What remains on the machine after uninstallation. On Windows, the installer asks you
whether you also want to delete the data folder C:\ProgramData\adhole; on Linux, the
data folder remains until you delete it. As long as it is not deleted, it stays on your disk:
your configuration, your custom rules, the downloaded lists, the technical log, the address
assignments where applicable, and the private key of the root certificate. This last point
deserves your attention: the key is of no further use once the certificate has been removed from
the system store, but nothing requires you to keep it. Delete this folder if you do not intend to
reinstall.

14.6 — Check afterwards. If you want to make sure nothing remains: on Windows, adhole status
before uninstalling, then check that the "adhole" service is absent from Windows services and that
"adhole Root CA" is absent from the trusted root certification authorities store; on
Linux, what adhole status shows after sudo adhole teardown.

14.7 — On Android. You can turn filtering off at any time from the app's home screen, or
withdraw its permission in Android's settings: the device's traffic goes back to normal at once,
unfiltered. You can also turn off page cleaning alone, with its switch in the settings: domain-name
filtering carries on, and no page is opened any more.

Uninstalling the app like any other takes its data folder with it (11.4), and so the certificate's
private key. One thing survives it: the root certificate you installed in Android's store.
Android does not let an app remove it. Remove it yourself under Settings, Security, User
credentials, then adhole Root CA — that is the one gesture left to make, and there is no reason
not to make it.

15. Changes to these terms

The publisher may change these terms. The applicable version is the one shipped with the version of
the software you are using, and it can be consulted at any time in the installation folder.
A substantial change is presented for acceptance before the version concerned is installed: that
version does not install automatically; the dashboard shows a link to the new terms ("Read the new
terms of use") and the button "Accept the new terms and install". As long as you have not accepted
them, the version you have continues to work.

This hold is provided by the software installed from version 1.2.0 onwards. An older installation
(1.0 or 1.1) does not have it: it moves to version 1.2.0 without asking anything.

On Android the question does not arise in the same terms: no update installs by itself (7.7). The
terms in force can be read at any time from the app's "About" screen, and you read them before
deciding to install a newer version.

16. Applicable law and dispute resolution

16.1 — Applicable law. French law.

16.2 — Prior complaint. Any complaint must first be addressed to the publisher, by email to
contact@antoinemoury.fr. It is the fastest way to get an answer.

16.3 — Jurisdiction, stated honestly. Failing an amicable agreement, the French courts have
jurisdiction. But what this sentence is worth must be made clear: if you are a consumer, no
clause can deprive you of the right to bring the matter before the court of the place where you
lived at the time the contract was concluded, or of the place where the damage occurred (article
R631-3 of the French Consumer Code), and, if you live in another Member State of the European Union,
the protective rules of Regulation (EU) no. 1215/2012 apply. The designation of a specific court is
only enforceable between professionals.

16.4 — Consumer mediation. Article L612-1 of the French Consumer Code gives every consumer
the right to free recourse to a mediator for disputes arising from a contract for the sale of goods
or the provision of services concluded with a professional. AdHole is neither sold nor provided for
remuneration: the publisher considers that this obligation is not triggered, and has therefore not
appointed a mediator. This is a position, not a certainty: it is stated here so that you do not
look for a scheme that does not exist. If a paid offer were ever to come about, a mediator would be
appointed and named in these terms.

17. Final provisions

17.1 — Partial invalidity. If a clause of this document is held to be unwritten or invalid, the
other clauses remain in force.

17.2 — Tolerance. Not relying on a clause does not constitute a waiver of it.

17.3 — Entire agreement. These terms, together with CONFIDENTIALITE.txt, MENTIONS-LEGALES.txt
and LICENCES-TIERCES.txt, form the agreement between the publisher and you regarding AdHole.

18. Contact

Antoine MOURY — 26 rue Charles de Mouchy, 06210 Mandelieu-la-Napoule, France.
Email: contact@antoinemoury.fr — Phone: 07 60 82 76 49 (from abroad: +33 7 60 82 76 49).

Does a site display incorrectly, or no longer open, since the installation? This is the most
frequent case, and it can usually be fixed on your own: add a custom allow rule for this site from
the dashboard, or add its domain to the sites left encrypted (5.4). If the problem persists, write
to contact@antoinemoury.fr giving the exact address of the page and what you see instead. No
obligation of support is undertaken for all that, the software being free of charge (7.6).

Full contact details and identification information: MENTIONS-LEGALES.txt (English:
MENTIONS-LEGALES.en.txt).
