This is a translation. The French version is the reference; in case of discrepancy, the French
version prevails. French version: CGU.txt, shipped with the program.
1. The publisher, and what this document commits to
AdHole is published by Antoine MOURY, sole trader (entrepreneur individuel), 26 rue Charles de
Mouchy, 06210 Mandelieu-la-Napoule, France, registered under SIREN number 913 844 619. Full contact
details are in MENTIONS-LEGALES.txt (English: MENTIONS-LEGALES.en.txt), shipped with the desktop
program; the annex of the iPhone and iPad app repeats them.
This document is the contract between the publisher and you. It states what the software does, what it does not do, what you accept by installing it, and what the publisher is answerable for.
1.1 — Acceptance. Before changing anything on your computer, the installation displays these
terms and requires you to accept them: the installer's licence screen on Windows; on
Linux, the adhole setup command, which asks you to type "yes" (« oui » in the French interface).
On Android, the app displays these terms the first time it opens and only turns filtering on once
you have accepted them. On iPhone and iPad, when first opened, the app gives access to these terms
and to the privacy policy, followed by their annexes, just above the button that accepts them; it
registers nothing in iOS settings and sends nothing to its server before you accept. Accepting
constitutes full and complete acceptance, and the installation records the
moment it happened. Refusing stops the installation: nothing is put in place, nothing is changed.
1.2 — Capacity. You must be of legal age, or have the permission of the holder of parental authority. AdHole changes system settings and, on computers and Android, decrypts traffic: this is not something a minor does alone.
1.3 — Free of charge. AdHole is free of charge and remains so. It is not sold. There is no account, no financial consideration, and no data requested in exchange. No clause of this document describes a transaction, because there is none.
2. What AdHole does, exactly
AdHole is software for Windows, Linux and Android that filters advertising. It runs on your machine: nothing it filters passes through the publisher.
The iPhone and iPad app works differently: the domain names the device asks for go, encrypted, through a server run by the publisher, which filters them. The annex shipped with the app, after these terms, describes how it works and prevails, for that app, over any provision of this document that contradicts it.
On a Windows or Linux computer, once installed:
- a DNS filter answers "nowhere" for advertising domains. It listens on port 53 of your computer and answers every device on your local network that designates it as its resolver (television, console, phones), and those alone: it refuses any request coming from an address outside private networks. When a firewall is active, the installation opens ports 53 (TCP and UDP) and 67 (UDP) in it: on Windows, for the local network only; on Linux, port 53 for the local subnet and port 67 with no restriction of origin, because a device asking for an address does not have one yet;
- a decrypting proxy filters pages in detail and removes YouTube ads, on this computer only. It listens on 127.0.0.1, and can only be reached from this machine;
- a service (Windows service, systemd on Linux) starts with the computer, before anyone logs in;
- on Windows, an icon near the clock appears at each login. It is used for alerts and to stop the program. On Linux, there is no icon: alerts are shown in the dashboard;
- a DHCP server can hand out the network's addresses instead of your router. This function is disabled by default and can only be enabled from the command line, deliberately;
- a dashboard opens in an application window. It is served locally, on 127.0.0.1, without a password: anyone who uses this computer can read it and change its settings.
2.1 — What AdHole does not do. It does not circumvent any technical protection, does not give access to any restricted content and does not modify any file of your other software. On computers and Android, it sends the publisher no data about your browsing: only the anonymous statistic described in article 11, which you can turn off. On iPhone and iPad, the domain names the device asks for go through the publisher's server, which does not write them down, and the anonymous statistic is not sent (iPhone and iPad annex).
2.2 — What is not promised. Filtering depends on public lists maintained by third parties and on websites that change without notice. No blocking rate is guaranteed. Some ads will get through; some sites will display incorrectly because of the filtering. This is inherent to this type of software, and it is not a defect in the contractual sense.
2.3 — The Android app. AdHole also exists as an app for Android 8.0 or later. It filters domain names on the device, with the same lists as on a computer, over Wi-Fi as over mobile data, for every app on the device. Since version 1.5.0 it also cleans up the pages you open in your browsers, provided you install the root certificate described in article 5 yourself.
To receive the system's traffic, the app declares itself to Android as a local virtual private network — a local VPN. Android then shows its own permission prompt, which you accept or refuse. That tunnel leads nowhere outside the device: what enters it is handled on the phone, then leaves the phone for its real destination. AdHole is not an encrypted tunnelling service: it does not hide your IP address, routes your traffic through no server, and routes none of your data through the publisher.
What it filters, on two levels.
- Domain names, for every app on the device. A name on its lists is answered "nowhere". Since version 1.5.0, every domain-name request the device makes goes through that filter, including when an app addresses a resolver of its own choosing.
- The content of pages, in browsers only. Ad slots hidden, ad scripts neutralised, cookie banners refused when the site offers to reject everything, ads taken off YouTube videos. This filtering requires that you have installed the root certificate (article 5); it applies only to the browsers you leave ticked in the settings, and never to the sites left encrypted (5.4).
What is never opened. The traffic of apps other than browsers. Android does not let one app read another's encrypted traffic, and AdHole does not try: a connection that does not belong to a ticked browser is relayed as it is, byte for byte. The same goes for the sites left encrypted, in a browser as anywhere else.
As long as the certificate is not installed, or if you turn off the "Remove ads and cookie banners in browsers" setting, no page is opened: the app filters domain names, and nothing more. No browser shows a certificate error in that state.
Two technical effects, said here rather than discovered. While pages are being cleaned, the app turns off the HTTP/3 protocol for the ticked browsers, so that they fall back to the connection it can read; the rest of the device goes on using it. And recognising which app a connection belongs to requires Android 10 or later: below that, no page is opened and only domain-name filtering applies.
What leaves the device: the encrypted DNS resolvers you have chosen, the download of the filter lists, and the version check together with the anonymous statistic of article 11 — the same outgoing connections as on a computer (11.3), with the same guarantees and the same switch. One more is added, and only when all your encrypted resolvers have failed three times in a row: the resolver of the network the phone is attached to — your router over Wi-Fi, your mobile operator's relay on mobile data, the operator's own on a public Wi-Fi. The app then puts your questions to it in plain text, for as long as the outage lasts, and it is the one that sees those names (11.3). No data about your browsing reaches the publisher, and no browsing history is written on the device.
2.4 — What the Android app does not remove. Outside browsers, filtering is done by domain name, and it has the limits of that:
- the ads shown inside other apps, whose traffic AdHole never opens (2.3): only the ad network's domain name is reached, and the slot may be left empty;
- the ads inside the YouTube app, which come from the same servers as the videos;
- videos whose ads are stitched into the stream by the server that sends it: catch-up TV, the ad-supported plans of video services;
- rewarded ads in games: they are blocked, so the reward they pay for does not arrive, and some games then show "no ad available";
- Facebook Audience Network, served by the same host as Facebook login
(
graph.facebook.com): blocking it would stop you signing in to your account; - install attribution tools such as Adjust and AppsFlyer, which display no advertising but whose blocking breaks some links that open an app.
In browsers, where pages are opened (2.3), three limits remain:
- Firefox keeps its own list of certificates and ignores Android's until its "Use third-party CA certificates" setting is turned on: its pages are then left as they are. The publisher describes that setting; it does not promise its result, which is up to Firefox;
- the sites left encrypted (5.4) are never opened, so never cleaned;
- windows that demand your consent without offering a free way to refuse stay in place unless you turn on their removal (9.2 and 9.3), and a subscriber-only wall is never removed (9.4).
No blocking rate is guaranteed (2.2). A measurement of the mobile ad networks turned away by the default lists, dated 14 September 2026, is published on the publisher's website: it describes what was observed that day, not an undertaking, and it covers domain-name filtering only.
2.5 — Installing on Android is done by hand, and it is on you. The app is distributed neither through Google Play nor through any other store. It is downloaded from the publisher's website as an APK file, whose SHA-256 checksum is published next to it: that checksum, and nothing else, proves that the file you received is the one that was published.
Installing an app this way means allowing your browser to install apps from unknown sources. That is a security setting of your device, which you change yourself and under your sole responsibility; the publisher advises you to put it back as it was once the installation is finished. Android shows its own warnings: they are normal for an app that does not come from a store, and they say nothing about the quality of the file.
2.6 — What does not change. The Android app changes nothing on your computers, and installing on a computer changes nothing on your phone. Article 5 (interception of HTTPS traffic) now applies to the Android app as well, with the device's particulars set out in 5.6. Article 6 (changes to your computer's network settings) still concerns the Windows and Linux versions only: on Android the app changes no system setting itself, and it is you who install the root certificate in Android's settings. Everything else in this document — licence (3), where you may install (4), updates (7), acceptable use (10), privacy (11), warranty (12), liability (13), termination and uninstallation (14) — applies to the Android app as it does to the computer program.
3. Licence to use
AdHole is proprietary software. Its source code is not provided.
The publisher grants you a free, personal, non-exclusive, non-transferable and revocable right to install and use AdHole on the computers and devices that you own or that you administer. This right does not transfer any intellectual property right to you.
You may not: resell it, rent it, lend it for payment, redistribute it under your name or that of a third party, publish a modified copy of it, remove or hide the proprietary notices, or decompile it outside the cases where the law permits it.
Decompilation and analysis remain permitted in the cases and within the limits of article L122-6-1 of the French Intellectual Property Code, in particular for interoperability. This right is a matter of public policy: no clause of this document claims to exclude it.
Libraries written by others and used in the program keep their own licences, all of which permit
this use. Their list and the full text of
each licence are shipped with the program in LICENCES-TIERCES.txt. Do not delete this file: it is
the consideration for these licences.
4. Where you are allowed to install AdHole
4.1 — Your machine, or one you administer. You may only install AdHole on a computer that you own, or of which you are the legitimate administrator and for which you have the owner's consent.
4.2 — Never on someone else's machine. Installing AdHole on someone else's computer without their consent is not a blunder, it is a criminal offence. The software installs a root certificate and decrypts traffic: anyone who installs it on another person's machine without their knowledge is liable to the penalties of article 323-1 of the French Criminal Code (fraudulently accessing or remaining in an automated data processing system: three years' imprisonment and a fine of 100,000 euros) and of article 226-15 of the French Criminal Code (intercepting correspondence sent electronically, or installing a device enabling such interceptions: one year's imprisonment and a fine of 45,000 euros).
4.3 — The home network. If you designate this computer as the DNS resolver for other devices, the requests of those devices pass through it and appear in the dashboard, with their local IP address. Tell the people who live with you. Doing so without the knowledge of an adult in the household falls under the same provisions as in 4.2.
4.4 — In a company or a public administration. Installation on a work computer requires the formal consent of the person who administers the IT equipment. An employee cannot decide alone to decrypt the traffic of a workstation: the security of their employer's information system is at stake, and often their employment contract too. In such a case, it is the organisation that must decide, and it is the organisation that is answerable for the use it makes of it.
4.5 — Prohibited places. Do not install AdHole on a shared computer in open access, nor on a system where a failure would endanger people's safety.
4.6 — On Android. Only install the app on a device that belongs to you, or whose owner has agreed. It sees the domain names the device asks for and, once its root certificate is installed, the content of the pages opened in browsers (2.3, 5.6): putting it on someone else's phone without their knowledge falls under the same provisions as 4.2, and installing the certificate on someone else's phone adds the circumstance 4.2 describes about interception devices.
5. Interception of HTTPS traffic: what you expressly accept
This is the most important point of this document. Read it in full. It concerns the Windows and Linux versions and — since version 1.5.0 — the Android app, whose particulars are set out in 5.6. It does not concern the iPhone and iPad app, which decrypts nothing.
5.1 — What is done. To filter HTTPS sites, AdHole installs in the system's certificate store (and, on Linux, in those of Chrome and Firefox when their tool is present) a root certificate it has generated itself, and declares itself as the proxy for your session through an automatic configuration script that provides for a direct connection when AdHole does not respond. Your browser then opens its connections to AdHole, which reopens them to the site. AdHole therefore sees in clear the content of the pages you visit, including what you type into them, except for the sites excluded from decryption (5.4).
5.2 — The private key. The certificate and its private key are generated on your machine during installation — on your phone, the first time you ask for the certificate. They are unique to that device. They are never transmitted, neither to the publisher nor to anyone: the publisher has no copy of them and cannot obtain one.
The private key is the file adhole-ca.key, in the ca subfolder of the data folder:
C:\ProgramData\adhole on Windows, /var/lib/adhole on Linux. Access to it is restricted to the
machine's administrators (root on Linux). On Android it sits in the ca subfolder of the app's
private data folder, which Android keeps apart from other apps.
What a third party who obtained this file could do: they could create, for any site, a certificate that your device would believe to be authentic. They could then decrypt and modify your traffic without your browser displaying the slightest warning, for as long as this root certificate remains installed. Do not copy this file anywhere, do not put it on a USB stick, do not back it up to online storage, do not attach it to a message. If you think it may have been copied, uninstall AdHole: on a computer the root certificate is then removed from the system store and the key loses all value. On Android, uninstalling does not remove the certificate from Android's store: remove it yourself (5.6).
5.3 — The scope of consent. By installing AdHole on a computer, and by installing its root certificate on an Android phone, you expressly consent to this decryption, for your own traffic, on your own device. This consent applies only to you. It does not cover another person's traffic (see article 4).
5.4 — The sites left encrypted, and what is up to you. Some sites are never decrypted: AdHole then opens a plain tunnel and sees nothing of their content. A default list is shipped with the program; it covers in particular system updates, game stores, storage services, encrypted messaging services, payment services and video streams.
This list cannot be exhaustive, and the publisher does not claim that it is. No publisher can
list every bank, every mutual health insurer, every health or government service in the world. The
list actually applied on your machine can be viewed and edited in the dashboard settings, in
the section on sites left encrypted (no_decrypt in the configuration file); on Android, in the
app's settings, under "Sites left encrypted". The starting list is the same as on a computer.
It is therefore up to you to add the sites you do not want to see decrypted. Take that minute before your next sensitive login — bank, health, taxes, employer. Whatever you do not remove from decryption remains subject to it, knowingly.
5.5 — How to refuse this function. Decryption is not mandatory. Installing with the option
adhole setup -no-proxy sets up the DNS filter without a root certificate and without a proxy:
nothing is decrypted, and the filtering of pages and of YouTube does not work. This is a legitimate
choice, and the program works that way. On Android, refusal is the starting state: the app ships
with no certificate installed, and until you install one it filters domain names and nothing else.
5.6 — On Android: what differs, point by point. The principle is the one in 5.1, but four things are specific to the device.
- You install the certificate, by hand. The app creates it on the phone, exports it to your
downloads as
adhole-racine.crtand opens Android's security settings; the rest is in your hands: Encryption & credentials, Install a certificate, CA certificate, then pick the file. Since Android 11 there is no one-tap install. Android shows its own warning at that point about what a certificate authority allows: it is accurate, read it. The app cannot install the certificate for you, and does not try. - Browsers, and nothing else. Only the connections of the browsers you leave ticked in the settings are opened, towards the web's ports, and only for sites that are not on the 5.4 list. All the rest of the device's traffic — other apps, messaging, banking, games — is relayed as it is, byte for byte. AdHole therefore sees in clear the content of the pages you open in those browsers, including what you type into them, and nothing else.
- What uninstalling does not remove. Uninstalling the app takes its data folder with it, and so
the private key. It does not remove the root certificate from Android's store: Android does
not allow an app to do that. Remove it yourself under Settings, Security, User credentials, then
adhole Root CA. For as long as it stays there — even though the matching key went with the app — a useless certificate remains trusted on your phone, and there is no reason to leave it. - Firefox decides for itself. Firefox keeps its own list of certificates and ignores Android's until its "Use third-party CA certificates" setting is turned on. The publisher describes that setting; it does not guarantee its effect, which is up to Firefox and may change without notice.
6. Changes to your computer's network settings
AdHole changes your machine's network configuration. This is the most concrete risk of this software, and it is described here plainly. This article concerns the Windows and Linux versions only: on Android, the app changes no system setting itself — the root certificate is one you install (5.6) — and filtering stops as soon as you turn it off or withdraw its permission (2.3, 14.7). On iPhone and iPad, the app registers a DNS setting in iOS, which you turn on yourself: that setting and its risk of outage are described in the iPhone and iPad annex.
6.1 — What is changed. The installation designates AdHole as this computer's first DNS resolver — on Windows, 127.0.0.1 and ::1 on the active network adapter; on Linux, in systemd-resolved, whose local listener on 127.0.0.53 is turned off to free port 53, or failing that in NetworkManager. It enables the system proxy, opens the firewall ports as described in article 2, installs a service that starts automatically and, on Windows, adds the launch of the notification icon at login and AdHole's folder to the system's command path.
6.2 — The risk, stated frankly. When your computer asks itself to resolve domain names and AdHole no longer answers, no website opens any more, in any software. This is not a textbook hypothesis: on 13 September 2026, the publisher's machine was left without any name resolution, and therefore without internet, because the service had stopped while the network adapter was still pointing to it.
6.3 — What has been put in place since. A fallback resolver — your router — is now added after AdHole in the computer's DNS configuration: if AdHole stops, name resolution continues, only filtering is lost. The service is configured to restart automatically after an incident (on Windows after 1 s, 15 s, then 60 s; on Linux after 5 s, with no limit on attempts). Before stopping, AdHole checks that nothing is listening any more and then hands DNS back to the router by itself. Finally, since version 1.1, the proxy is declared through an automatic configuration script that provides for a direct connection: if AdHole no longer responds, pages keep opening, without filtering, instead of no longer opening at all. And when it is the encrypted resolvers that go down rather than AdHole itself, AdHole puts your questions to the router in plain text for as long as the outage lasts, instead of answering with a failure — which amounted to cutting your internet (11.3). Connections in progress at the time of an abrupt stop, however, are cut and must be restarted.
These safeguards reduce the risk. They do not eliminate it.
6.4 — How to regain control — remember this before you need it. If your connection no longer
works, open a command prompt as administrator — on Linux, a terminal, prefixing each command
with sudo — and run one of these commands (on Windows, the installer makes the adhole command
available in any command prompt opened after installation):
adhole dns off— immediately hands DNS back to your router. This is the step that fixes the case described in 6.2;adhole arreter— really stops AdHole: DNS handed back to the router, proxy turned off, service stopped;adhole status— shows the state and explicitly reports the failure when it is present;adhole teardown— removes everything the installation put in place, including the root certificate;- failing that, on Windows, uninstall AdHole from "Installed apps": uninstalling performs the restoration.
On Windows, the same stop is available without the command line: right-click the icon near the clock, then "Stop AdHole" ("Arrêter AdHole" in the French interface).
6.5 — The computer must stay on. The devices you point at this PC lose name resolution when it is off or asleep. That is the cost of this method, and you accept it by choosing it.
6.6 — The DHCP server. The function that makes this computer hand out the network's addresses, instead of your router, is disabled by default. It disrupts the whole network if it is enabled without turning off the router's. Only enable it if you know what you are doing. Address assignments are then kept in a file on your disk, with the hardware address and the name of each device in the household.
7. Automatic updates
7.1 — They are on by default, and you accept this by installing. When a newer version is published, AdHole downloads it, checks its fingerprint, then installs it by itself, without asking you anything, unless it comes with new terms of use: it then waits for your agreement (article 15).
7.2 — When. Installation takes place at night, between 3 am and 5 am. If the machine is off at those times, an update that has been pending for more than seven days is installed at the first possible moment, whatever the time.
7.3 — What it costs. The installation interrupts filtering for about thirty seconds. During that time, the devices that depend on this PC for their DNS have no name resolution. Your downloads and your video calls may suffer.
7.4 — What protects this update. The file is only accepted over HTTPS, and only if its SHA-256 fingerprint exactly matches the one announced. Without a fingerprint, or with a fingerprint that does not match, nothing is installed. The address where AdHole looks for versions can only be set in the configuration file, never from the dashboard: whoever chooses this address chooses what will be installed on the machine.
7.5 — How to refuse. The setting that installs updates automatically ("Installer les mises à jour toute seule" in the French interface) can be turned off in the dashboard. AdHole then only notifies you, and you decide. Emptying the update address in the configuration file disables even the check.
7.6 — What the publisher does not guarantee. No release frequency, no period of maintenance, no future compatibility. The publisher may stop publishing versions at any time, without notice and without compensation. The software already installed continues to work.
7.7 — On Android, nothing installs by itself. The app reads the version file and, if a newer version exists, offers to download it. You start the download, and Android installs it, with its own warnings. The SHA-256 checksum published next to the file lets you check what you are installing. Filtering is never interrupted by an update you did not start.
8. Blocking advertising is lawful
Filtering what your own computer — or your own phone — displays falls within your freedom to use your machine. You are under no obligation to display the advertising a site sends you, and no provision requires it.
Nothing more follows from this: AdHole does not authorise you to access paid content without being entitled to it, nor to circumvent a technical protection measure.
9. Refusing trackers, and consent walls
9.1 — Refusing trackers is a right. Article 82 of French law no. 78-17 of 6 January 1978 makes reading and writing information on your device subject to your prior consent. The CNIL (the French data protection authority) concluded from it, in its guidelines (deliberation no. 2020-091 of 17 September 2020) and its recommendation (deliberation no. 2020-092 of the same day), that refusing must be as simple as accepting.
AdHole clicks "reject all" when the button exists. And it refuses by design to record a positive consent: it never accepts on your behalf, even when a public filter list would ask it to do so.
9.2 — "Consent or pay" walls are a different matter. The Conseil d'État (France's highest administrative court), in its decision no. 434684 of 19 June 2020, annulled the general and absolute ban that the CNIL had laid down in its guidelines, holding that such a ban could not appear in a soft-law instrument. These walls are therefore not unlawful in principle in France; their validity is assessed case by case.
Removing such a wall to reach the content without consenting goes beyond simply refusing trackers.
That is why this function is disabled by default (remove_walls: false).
9.3 — If you enable it, the decision is yours. Enabling it is a deliberate act, which you perform for your own machine, knowingly. You alone bear the consequences, and you indemnify the publisher against any claim by a website publisher that results from it.
9.4 — No circumvention of paywalls. AdHole never removes a subscription wall, and is not meant to. The selectors that targeted such a wall have been explicitly removed from the code. Providing a means of circumventing a technical protection measure is punishable under article L335-3-1 of the French Intellectual Property Code: the publisher does not intend to expose himself to this, and forbids you to misuse the software for that purpose.
10. Acceptable use
You undertake not to use AdHole to:
- access content reserved for subscribers without being entitled to it;
- install it on a machine that does not belong to you and that you do not legitimately administer, or without the knowledge of its user;
- intercept another person's traffic or communications;
- disrupt a third party's network, in particular by enabling address distribution on a network that is not yours;
- modify, recompile or redistribute the program;
- use it in any way contrary to applicable law.
Failure to comply with this article automatically terminates your licence to use, without prejudice to any proceedings the injured party may bring.
11. Privacy and personal data
11.1 — What goes to the publisher from a computer or an Android device: an anonymous statistic, and nothing else. Shortly after each start of the service, then once a day, with the version check, AdHole sends the publisher's server a number drawn at random on your computer and renewed every month, its version number, the system (for example "windows-amd64" from a computer, "android" or "android-tv" from an Android device), and the number of requests it blocked since the previous check. This number says nothing about you and changes every month: it makes it possible to count active installations, not to follow one. The number of blocked requests is a plain number: no domain name, no address, no browsing date. It is only used to show, on the publisher's website, the total number of requests blocked across all installations. From these installations, the publisher receives no data about your browsing — no sites, no domain names, no content — and has no technical means of receiving any. The statistic is on by default and can be turned off in the settings ("Anonymous statistics", "Statistiques anonymes" in the French interface): the identifier is then erased from your disk, that number stops being sent, and the version check goes out on its own. The iPhone and iPad app does not send this statistic; what it makes reach the publisher's server is described in its annex.
11.2 — On computers and Android, only one processing operation on the publisher's side: this
statistic. It is described in detail in CONFIDENTIALITE.txt (English:
CONFIDENTIALITE.en.txt): no IP address is recorded in it, and only totals are kept. For your
browsing on those devices, on the other hand, there is no data controller on the publisher's side,
within the meaning of article 4 of Regulation (EU) 2016/679: no data about it reaches the
publisher. This is not a commercial promise, it is a consequence of the software's architecture,
verifiable in the program's behaviour.
On iPhone and iPad, the publisher is also the controller of the processing carried out by the filter's server: resolving the names requested, a counter of blocked requests per identifier drawn at random, and rate limiting. The annex to the privacy policy, shipped with the app, describes them with their legal bases and retention periods.
11.3 — The outgoing connections that actually exist. The program connects to five things, and to nothing else:
- the DNS resolvers you have chosen, queried in list order: the next one is only asked if the previous one has not answered within a second or has failed, and the first answer received is used. By default: Cloudflare over DNS-over-HTTPS, then Quad9 over DNS-over-TLS, and as a last resort 1.1.1.1 (Cloudflare), in plain, unencrypted DNS. They see your IP address and the names you request;
- your network's router, and it alone when all the resolvers above have failed three times in a row: AdHole then puts your questions to it, in plain text, rather than leaving you with no name resolution. Your internet service provider sees those questions. This fallback lasts as long as the outage: AdHole tries the encrypted resolvers again every ten seconds and goes back to them as soon as one answers. Filtering is not suspended in the meantime. The Android app does the same, with the resolver of whichever network it is on: on a phone that is not always a router — it is the home Wi-Fi's, your mobile operator's on mobile data, or the operator's on a public Wi-Fi, and that is who then sees your questions. The iPhone and iPad app does not have this fallback of its own: when iOS goes back to the network's DNS — because the publisher's filter was not answering when iOS checked it, or through iOS 26's fallback, which the publisher cannot guarantee —, that resolver sees the names requested (iPhone and iPad annex);
- the filter lists, downloaded once a day from their authors (AdGuard, hagezi) or from GitHub, which hosts some of them. These servers see your IP address, as with any download;
- the version file, shortly after each start of the service then once a day, on the
publisher's server (adhole.io), accompanied by the statistic of article 11.1 unless you have
turned it off. This server sees your IP address and does not record it (details in
CONFIDENTIALITE.en.txt); - the installer of an update, when there is one, from the address that this file indicates.
The resolvers, the list authors and GitHub are third parties, independent data controllers for what they see of you. The choice of resolvers and lists is yours, and each of these connections can be disabled in the configuration.
The connections of the iPhone and iPad app, which are not these, are described in its annex.
11.4 — What remains on your disk. The details are in CONFIDENTIALITE.txt. In short: the
dashboard's latest requests, its rankings, the cache and the latency live in RAM and disappear when
the service stops; only the request totals, seen and blocked, are written to disk, in
compteurs.json, with no domain name and no address;
a technical log is written to disk; the certificate's private key is stored there; and, if you have
enabled address distribution, the network's address assignments are kept there.
On Android, the app's data folder holds your custom rules, your settings, the list of your filter
lists, the downloaded lists, the request totals — seen and blocked — in compteurs.json, with no
domain name and no address, the number used by the anonymous statistic together with the mark of
its last accepted send, and — since version 1.5.0 — the root certificate and its private key, in
the ca subfolder (5.2). No browsing history is written there, and the content of the pages
opened in your browsers is not kept there either: it is handled in memory, for the time of the page.
Uninstalling the app takes that folder with it — but not the certificate installed in Android's
store (5.6, 14.7).
What the iPhone and iPad app writes on the device, and what the publisher's server keeps, is described in its annex.
11.5 — You, and the other people in the household. When devices that are not yours use this PC as their resolver, their requests appear in the dashboard with their local IP address. In a strictly domestic setting, this processing falls outside the European regulation under its Article 2(2)(c). Outside that setting — a shop, an association, a work computer —, it is you who become the controller of this processing, and it is up to you to inform the people concerned.
12. Warranty
12.1 — The software is provided as is. The publisher does not guarantee the absence of defects, the absence of interruption, fitness for a particular need, that a given site will display correctly, or that a given ad will be blocked.
12.2 — The real scope of this clause, without pretence. Under French consumer law, an exclusion of warranty cannot be enforced against a consumer where the law imposes a warranty.
The legal guarantee of conformity for digital content is provided for in articles L224-25-1 et seq. of the French Consumer Code. Its scope, set by article L224-25-2, covers contracts under which the consumer « s'acquitte d'un prix ou procure tout autre avantage au lieu ou en complément du paiement d'un prix » ("pays a price or provides any other benefit instead of, or in addition to, the payment of a price"). AdHole is provided free of charge. In return it collects only technical information about the installation — the statistic of article 11.1: a number drawn at random and renewed every month, the version, the system, the number of blocked requests —, which recital 25 of Directive (EU) 2019/770, of which these articles are the transposition, leaves outside its scope. On iPhone and iPad, this statistic is not sent, and the data processed by the publisher's server are only used to provide the service: Article 3(1) of the same Directive leaves data processed for that sole purpose outside its scope. This characterisation is the publisher's own; it has not been decided by a court, and a court could decide otherwise.
12.3 — What remains owed whatever happens. Even in the absence of a contractual warranty, the publisher remains bound not to knowingly deliver dangerous or misleading software, and is liable for his proven fault. Nothing in this document claims to exclude what cannot be excluded.
13. Liability
13.1 — The principle. AdHole is provided free of charge. The publisher's liability is assessed in light of this free provision and of the nature of the software.
13.2 — What is excluded, within the limits permitted by law. The publisher is not liable for indirect damage, in particular: loss of data, operating loss, business interruption, loss of turnover, damage to reputation, loss of internet connection and its consequences, cost of a repair, or harm suffered by a third party. In accordance with article 1231-3 of the French Civil Code, the publisher is in any event liable only for the damage that was foreseeable when the contract was concluded.
13.3 — What is never excluded, and saying so is more honest than writing it anyway. No provision of this document excludes the publisher's liability in the event of fraud (dol), gross negligence (faute lourde), harm to the physical integrity of persons, nor in the cases where the law prohibits it. In particular:
- towards a consumer, a clause that would remove or reduce their right to compensation in the event of a breach by the publisher is deemed unwritten: this is item 6° of article R212-1 of the French Consumer Code, whose list is irrebuttable;
- liability for defective products can be neither excluded nor limited by contract, under article 1245-14 of the French Civil Code.
13.4 — Towards a professional user. If you use AdHole in the course of your professional activity, the limitations of article 13.2 apply in full, and the publisher's total liability, for all causes combined, is limited to compensation for the proven direct damage, and may not exceed the sum of one hundred euros — the software being provided without financial consideration, this limit reflects the real economics of the contract.
13.5 — What is your responsibility. You alone are responsible for: the choice to install this software on a given machine, backing up your data before installation, protecting the certificate's private key, the content of the list of sites left encrypted, enabling the functions disabled by default, the custom filtering rules you add, the network configuration you impose on other devices, and — on Android — the permission to install apps from unknown sources that you grant your browser (2.5), the installation of the root certificate in the device's settings, and its removal after an uninstall (5.6).
13.6 — Force majeure. The publisher is not liable for a failure due to an event beyond his control, within the meaning of article 1218 of the French Civil Code, including the unilateral modification of a third-party site or the discontinuation of a public filter list.
14. Term, termination, uninstallation
14.1 — Term. The licence runs for as long as you use the software.
14.2 — Termination by you. Uninstall: the licence ends. You have nothing to ask of anyone, and nothing is owed.
14.3 — Termination by the publisher. The publisher may terminate your licence in the event of a breach of articles 3, 4, 9 or 10. The licence being free of charge, this termination gives rise to no compensation.
14.4 — What uninstallation removes. Uninstallation — from "Installed apps" on Windows, with the
command sudo adhole teardown on Linux — performs the
restoration: the root certificate is removed from the system store, the system proxy disabled, DNS
handed back to your router, the firewall rules deleted, the service removed, the launchers removed,
AdHole's folder removed from the system's command path, and the automatic launch of the icon
cancelled.
14.5 — What remains on the machine after uninstallation. On Windows, the installer asks you
whether you also want to delete the data folder C:\ProgramData\adhole; on Linux, the
data folder remains until you delete it. As long as it is not deleted, it stays on your disk:
your configuration, your custom rules, the downloaded lists, the technical log, the address
assignments where applicable, and the private key of the root certificate. This last point
deserves your attention: the key is of no further use once the certificate has been removed from
the system store, but nothing requires you to keep it. Delete this folder if you do not intend to
reinstall.
14.6 — Check afterwards. If you want to make sure nothing remains: on Windows, adhole status
before uninstalling, then check that the "adhole" service is absent from Windows services and that
"adhole Root CA" is absent from the trusted root certification authorities store; on
Linux, what adhole status shows after sudo adhole teardown.
14.7 — On Android. You can turn filtering off at any time from the app's home screen, or withdraw its permission in Android's settings: the device's traffic goes back to normal at once, unfiltered. You can also turn off page cleaning alone, with its switch in the settings: domain-name filtering carries on, and no page is opened any more.
Uninstalling the app like any other takes its data folder with it (11.4), and so the certificate's
private key. One thing survives it: the root certificate you installed in Android's store.
Android does not let an app remove it. Remove it yourself under Settings, Security, User
credentials, then adhole Root CA — that is the one gesture left to make, and there is no reason
not to make it.
15. Changes to these terms
The publisher may change these terms. The applicable version is the one shipped with the version of the software you are using, and it can be consulted at any time in the installation folder. A substantial change is presented for acceptance before the version concerned is installed: that version does not install automatically; the dashboard shows a link to the new terms ("Read the new terms of use") and the button "Accept the new terms and install". As long as you have not accepted them, the version you have continues to work.
This hold is provided by the software installed from version 1.2.0 onwards. An older installation (1.0 or 1.1) does not have it: it moves to version 1.2.0 without asking anything.
On Android the question does not arise in the same terms: no update installs by itself (7.7). The terms in force can be read at any time from the app's "About" screen, and you read them before deciding to install a newer version.
On iPhone and iPad, updates arrive through the App Store, according to your iOS settings, and the app cannot hold them back. The terms in force and their annex can be read at any time in the app's settings, under "About".
16. Applicable law and dispute resolution
16.1 — Applicable law. French law.
16.2 — Prior complaint. Any complaint must first be addressed to the publisher, by email to contact@antoinemoury.fr. It is the fastest way to get an answer.
16.3 — Jurisdiction, stated honestly. Failing an amicable agreement, the French courts have jurisdiction. But what this sentence is worth must be made clear: if you are a consumer, no clause can deprive you of the right to bring the matter before the court of the place where you lived at the time the contract was concluded, or of the place where the damage occurred (article R631-3 of the French Consumer Code), and, if you live in another Member State of the European Union, the protective rules of Regulation (EU) no. 1215/2012 apply. The designation of a specific court is only enforceable between professionals.
16.4 — Consumer mediation. Article L612-1 of the French Consumer Code gives every consumer the right to free recourse to a mediator for disputes arising from a contract for the sale of goods or the provision of services concluded with a professional. AdHole is neither sold nor provided for remuneration: the publisher considers that this obligation is not triggered, and has therefore not appointed a mediator. This is a position, not a certainty: it is stated here so that you do not look for a scheme that does not exist. If a paid offer were ever to come about, a mediator would be appointed and named in these terms.
17. Final provisions
17.1 — Partial invalidity. If a clause of this document is held to be unwritten or invalid, the other clauses remain in force.
17.2 — Tolerance. Not relying on a clause does not constitute a waiver of it.
17.3 — Entire agreement. These terms, together with CONFIDENTIALITE.txt, MENTIONS-LEGALES.txt
and LICENCES-TIERCES.txt, form the agreement between the publisher and you regarding AdHole. For
the iPhone and iPad app, the agreement also includes the annexes shipped with it, which prevail
over these documents where they contradict them.
18. Contact
Antoine MOURY — 26 rue Charles de Mouchy, 06210 Mandelieu-la-Napoule, France. Email: contact@antoinemoury.fr — Phone: 07 60 82 76 49 (from abroad: +33 7 60 82 76 49).
Does a site display incorrectly, or no longer open, since the installation? This is the most frequent case, and it can usually be fixed on your own: add a custom allow rule for this site from the dashboard, or add its domain to the sites left encrypted (5.4); on iPhone and iPad, add it to the allowed sites, in the app's settings. If the problem persists, write to contact@antoinemoury.fr giving the exact address of the page and what you see instead. No obligation of support is undertaken for all that, the software being free of charge (7.6).
Full contact details and identification information: MENTIONS-LEGALES.txt (English:
MENTIONS-LEGALES.en.txt).