Help Center

Privogrid Documentation

Everything you need to install Privogrid, create isolated browser profiles, configure proxies and keep your data safe. Can't find an answer? Email [email protected].

Installation

1. Download the app

Windows: download the installer (Privogrid Browser Setup v2.1.176, about 244 MB):

⬇ Download for Windows

macOS: download the disk image for your Mac — Apple Silicon .dmg (M1/M2/M3/M4) or Intel .dmg, both v2.4.3. Open the .dmg and drag Privogrid into your Applications folder.

Where to find it: privogrid.com → Download

2. About the Windows SmartScreen prompt

Windows SmartScreen may show a warning such as "Windows protected your PC" when you run the installer. Our publisher verification (code-signing certificate) is currently in progress, so Windows does not yet recognise us as an established publisher. Until it completes, verify the SHA-256 checksum published below before installing. If you want to be certain the file is genuine, verify its checksum below before running it.

Official SHA-256 checksum of the installer:

7fd77b958850e6f1ddedb36b063157d426606283bfd9f543b099ddb8bdc26b45

You can verify it in PowerShell with:

Get-FileHash .\Privogrid-Browser-Setup-2.1.176.exe -Algorithm SHA256

The full checksums file is published at SHA256SUMS.txt.

3. macOS: the first launch

Apple notarization for the macOS build is in progress. Until it completes, macOS may show a security prompt on first launch — this is expected for apps that are not yet notarized. Verify the SHA-256 checksum published on this page before installing, and contact support if you need help with the first launch.

macOS will also ask for your Keychain password. On the first launch a system dialog asks whether Privogrid may use the macOS Keychain. Type your Mac login password and click Always Allow. Privogrid uses the Keychain to encrypt the things that must never sit in a plain file — proxy passwords, your webhook secret, saved website logins and automatic cookie backups. If you click Deny, the app still works, but those items fall back to unencrypted files on your Mac.

Where to find it: System Settings → Privacy & Security (and the Keychain dialog on first launch)

4. Install and sign in

  1. Windows: run the installer and follow the setup wizard (the default options are fine). macOS: open the .dmg and drag the app into Applications.
  2. Launch Privogrid — from the Start menu or desktop shortcut on Windows, from Applications or Spotlight on a Mac.
  3. Create a free account (or sign in) and verify your email address. Privogrid asks you to sign in before the app opens.
  4. You're ready — create your first profile.

System requirements

ComponentRequirement
Operating systemWindows 10 or Windows 11, 64-bit (current build v2.1.176) · macOS 13 Ventura or newer (current build v2.4.3)
Mac processorApple Silicon (M1/M2/M3/M4) is the main build. An Intel .dmg is still published, but it is updated less often than the Apple Silicon one.
Memory8 GB RAM recommended (more if you run many profiles at once)
Disk spaceAround 2 GB free
NetworkActive internet connection required (cloud account and licensing)
DisplayLight and dark themes are both supported, and the app can follow your system setting

Linux is not supported. On a Mac, see the first-launch notes about the security and Keychain prompts.

Where to find it: Settings → About (app version) · Settings → Appearance (Light / Dark / System)

Creating your first profile

Each Privogrid profile is a fully isolated browser environment with its own fingerprint (canvas, WebGL, audio, fonts, screen), its own cookies and storage, and optionally its own proxy. A profile can be a desktop browser or an Android phone.

  1. Open Privogrid and sign in to your account.
  2. Open the Profiles page and click New profile.
  3. The editor walks you through five short steps. You can save at any point — the defaults are safe.
1 · Identity — name, tag and colour. Use a name you'll recognise (the store or client it belongs to).
2 · Network — paste a proxy and test it; timezone, language and geolocation follow the proxy's location. See Proxy setup. Optional — leave it empty to use your own connection.
3 · Fingerprint — choose Desktop or Android phone. Auto (recommended) builds a consistent device from a unique seed. Custom lets you pick the OS, screen, GPU, cores and memory yourself. Below that, pick the profile mode: Static keeps the same fingerprint every launch (best for accounts you log into), Dynamic (Pro and up) gives a fresh fingerprint on every launch.
4 · Behaviour — Ad block, Anti-popup (popups, popunders and forced redirects), Start pages (sites that open automatically on launch), Clear data on close, and the video & file downloader.
5 · Advanced — IP Guard (refuses to launch if the proxy's exit IP was already used by another profile) and Kill-switch (if the proxy drops while the profile is running, the profile closes at once so your real IP never leaks). Both are off by default; turn both on when you use rotating proxies.

Click Start on the profile row. A separate browser window opens with the profile's own settings.

Everything else a single profile can do sits behind the More ••• button on its row: Launch & schedule (Auto Launch, Daily Schedule, Task Scheduler), Website automation (Auto-Login, Form Auto-Fill, Session preloader), Network & data (Proxy Automation, Data Automation), Advanced (Team Assignment) and Profile data (import/export cookies, export the profile, Duplicate it — a clone with its own fresh fingerprint — or share it with a teammate). Webhooks are one app-wide setting — see Webhooks.

To create many profiles at once, use Bulk create or CSV on the Profiles page (both are Pro and up), or Other browser to import from other browser-profile managers.

Where to find it: Profiles → New profile · Profiles → a profile row → More •••

Profiles never share cookies, sessions or fingerprints with each other, which keeps each account's environment consistent between sessions. Please use multiple accounts only where the platform's terms permit it.

Android (mobile) profiles

A profile can present itself as a real Android phone instead of a desktop computer. Sites then see a mobile browser: touch input, a phone-sized screen, the phone's GPU and fonts, and the matching Chrome-on-Android user agent — all consistent with each other.

  1. In the Fingerprint step choose Android phone.
  2. Pick a device. There are 34 phones to choose from — Samsung Galaxy (A, S and FE series), Google Pixel, OnePlus, Xiaomi and more. Each is built from real measured or manufacturer-published values, so screen, pixel ratio, cores, memory and GPU always agree.
  3. Leave Auto for all on (recommended). If you need a specific spec, switch to Custom and set the Android version, screen, GPU, cores and memory yourself.
  4. On a Dynamic profile you can also pick Random: a different phone on every launch, cycling through all devices before any repeats.

Network controls — WebRTC, timezone, geolocation and Do-Not-Track — work exactly as on desktop and are available in both Auto and Custom.

Where to find it: New profile → Fingerprint → Android phone

Ad block, anti-popup, start pages, kill-switch, IP Guard, recording and the timeline all work on Android profiles too. A phone profile is still launched from your Windows or Mac — it is the site that sees a phone, not you.

Proxy setup

Privogrid supports HTTP, HTTPS and SOCKS5 proxies, configured per profile. Each profile can route through its own IP address.

Format

On the profile's Proxy tab you can type the address into the separate fields, or paste a whole proxy string into the IP field. All of these are understood:

ip:port
user:pass@ip:port
ip:port:user:pass

Then select the proxy type (HTTP, HTTPS or SOCKS5) that matches what your provider gave you.

SOCKS5 with a username and password is not supported. The browser engine cannot do SOCKS authentication, so Privogrid refuses those before launch instead of leaking your real IP. Use a SOCKS5 proxy with IP-whitelist authentication, or an HTTP/HTTPS proxy if you need username/password.

Testing your proxy

Use Test proxy & check consistency on the Proxy tab before launching. It checks that the proxy is reachable, that authentication works, shows the external IP the profile will use, and then compares the IP's location against the profile's language and timezone. You get either "All consistent — profile is safe, no mismatches" or a list of mismatches with the fix for each one.

The proxy pool Paid plans

On Solo and up, the Proxies page keeps a saved pool: add proxies one at a time or paste a list, test one or test all, see the exit country for each, and assign a proxy to a profile without opening the editor. Your pool is stored encrypted on the machine and backed up to your account.

Tips

  • If your provider uses IP-whitelist authentication instead of username/password, make sure your current IP is whitelisted in the provider's dashboard.
  • Pick a proxy located in the region that matches how you use the profile — leave "Match this profile to the exit IP" on and the timezone, language and geolocation follow the proxy automatically.
  • One proxy per profile is the recommended setup for clean separation.
  • Proxy passwords are stored encrypted (macOS Keychain / Windows DPAPI) and are never written to a plain file.

Where to find it: Profiles → Edit → Proxy tab · Proxies (sidebar) for the saved pool

Cookie import & export Paid plans

On paid plans (Solo and up) you can move logged-in sessions between profiles and devices using JSON cookie files.

  • Export: open the profile's More ••• menu and choose Export cookies under Profile data. You are asked to type EXPORT to confirm, then Privogrid saves the profile's cookies as a JSON file.
  • Import: in the target profile, choose Import cookies and select the JSON file.
  • On a schedule: Data Automation in the same menu can export cookies and take backups on a timer.

Where to find it: Profiles → a profile row → More ••• → Profile data

Cookie import/export is not available on the Free plan. Only import cookies from accounts and sessions you own — importing stolen or purchased sessions violates our Acceptable Use Policy.

Backup & restore

Encrypted profile export / import

You can export a full profile (settings, fingerprint, cookies, storage) as an encrypted backup file, and import it later on the same or another machine. Keep backup files somewhere safe — they contain your logged-in sessions.

Cloud sync Paid plans

On paid plans (Solo and up), profiles are synced to the cloud with AES-256 encryption. Sign in on any computer and your profiles are exactly where you left them.

On the Free plan, cloud sync is not included — your account is locked to one PC and your 3 profiles cannot be synced or shared to another computer, so we recommend making regular encrypted exports as backups.

Automatic per-profile backups

Privogrid keeps a recent automatic backup of each profile on the machine. Restore backup in the profile's More ••• menu rebuilds the latest one as a new profile, so nothing you still have is overwritten. This is available on every plan.

Backing up the app itself Pro and up

Back up settings & automations saves your app preferences, schedules, RPA processes and automation rules to one file. Creating that backup needs Pro or Agency — but Restore is never locked, on any plan. Getting your own backup back must never depend on what you are paying.

Where to find it: Settings → Storage & diagnostics → Back up / Restore · Profiles → More ••• → Restore backup

Webhooks Pro and up

A webhook tells another service the moment something happens in Privogrid — a profile starts, a task finishes, a proxy goes down — without you having the app open. Privogrid sends a small JSON message to a URL you own. Slack, Zapier, Make, n8n and your own server all accept this.

Webhooks are one app-wide setting. They used to be set per profile under More ••• → Advanced; that entry now only points here. On Free and Solo the panel is visible but switched off, with a See plans button.

Where to find it: Settings → Integrations

Setting one up

  1. Webhook URL — where the message goes. It must start with http:// or https://.
  2. Secret (optional) — used to sign every message so your server can prove it really came from Privogrid. It is stored in the macOS Keychain (Windows: DPAPI), never in a plain file, and it is never sent in the message body or the URL.
  3. Events to send — eight checkboxes. Untick anything you do not need.
  4. Apply to — All profiles (including ones you create later) or Selected profiles.
  5. Test webhook — sends one test message right now and answers in place: Delivered (200) or Failed: with the reason. The test is a single attempt; it is never retried.

The eight events

EventSent when
profile_startedA profile was launched
profile_stoppedA profile was closed
task_startedA scheduled task began
task_completedA scheduled task finished
task_failedA task failed after every retry
captcha_handoffAutomation paused for a CAPTCHA
task_assignedA profile was assigned to a teammate
proxy_failedA health check could not reach the proxy

What the message looks like

{
  "event": "profile_started",
  "at": "2026-09-04T09:20:11.482Z",
  "profile": { "id": "p_8f3c21", "name": "Store US 01" },
  "assignee": "[email protected]"
}

Every message has those four fields. Two events add one more:

  • task_failed also carries error — the reason the task gave up.
  • proxy_failed also carries proxy and error. The proxy value is only host:port — your proxy username and password are never put in a webhook.

Checking the signature

If you set a secret, every request carries the header X-Privogrid-Signature. It is an HMAC-SHA256 of the raw request body, using your secret as the key, written as lowercase hex. In Node:

const crypto = require('crypto');
const expected = crypto.createHmac('sha256', process.env.PRIVOGRID_SECRET)
  .update(rawBody).digest('hex');
const okSig = crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(req.headers['x-privogrid-signature'] || ''));

Sign the raw bytes your server received, before any JSON parsing and re-stringifying — re-serialising the object changes the body and the signature will not match.

Delivery, retries and failures

  • Requests are POST with Content-Type: application/json and a 10-second timeout. Redirects are not followed — give Privogrid the final URL.
  • Anything outside HTTP 2xx counts as a failure. Privogrid then retries three times: after 10 seconds, 30 seconds and 60 seconds.
  • Every attempt and its result is written to the Activity log. A webhook entry there has a Copy payload button that puts the last JSON body and its signature on your clipboard — useful when your server rejects a message and you want to see exactly what arrived.
  • After three failures in a row you get a desktop notification and a red banner in Settings → Integrations, so a broken webhook cannot fail silently. (If desktop notifications are off for Privogrid, the panel warns you about that too.)

Which URLs are allowed

Public internet URLs only. Privogrid refuses localhost, 127.x.x.x, and private or reserved ranges — 10.x, 192.168.x, 172.16–172.31.x, 169.254.x, IPv6 loopback and unique-local addresses — as well as anything that is not http or https. The host name is resolved and every IP it resolves to is checked, on every single attempt. This stops a webhook from being turned into a way of reaching machines inside your network.

Example: send events to Slack through Zapier

  1. In Zapier, create a Zap and choose Webhooks by Zapier as the trigger, then Catch Hook.
  2. Zapier shows you a custom webhook URL. Copy it.
  3. Paste it into Privogrid under Settings → Integrations, tick the events you care about, and click Test webhook.
  4. Back in Zapier, click "Test trigger" — it picks up the test message and reads the JSON fields on its own, so event, profile name and assignee are all available.
  5. Add whatever action you want: post to Slack, add a row to Google Sheets, send an email.

Make and n8n work the same way — take their catch/webhook URL and paste it in.

Automation & capture

Beyond profiles, the sidebar has a set of tools that most people find later. Short version of what each one is and what plan it needs:

  • Synchronizer Solo and up — pick one running profile as the master; your clicks, typing, keyboard, scrolling and navigation are mirrored into the followers you choose.
  • RPA Plus — Process (a saved workflow), Task (run or schedule a process across profiles), Task Log (every run and its result) and Marketplace (ready-made templates). Running and scheduling is Solo and up; building or importing your own workflow is Pro and up — below Pro the builder is visible but read-only.
  • Capture — screenshots with an annotation editor (Solo and up), screen recording and Clip/GIF (Pro and up), automatic session recording on launch (Pro and up), and a per-profile proof-of-work timeline with day-ZIP export (Agency). Recordings older than 30 days are cleaned up below Agency; Agency keeps them for as long as you want.
  • Fingerprints — shows what each profile actually reveals, so you can check it yourself.
  • Extensions — import a .crx, .zip or an unpacked folder and have it load into your profiles. Old Manifest V2 extensions do not load in the current engine.
  • Downloads — a built-in video and audio downloader.
  • API & MCP Solo and up — a local gateway on 127.0.0.1:47800 that never listens on the network. Create API keys with their own permissions, profile scope, rate limit and expiry, drive profiles over REST, or connect an AI assistant over MCP. Permissions do not overlap: read lists, control creates and launches/stops profiles, automation drives a running profile and speaks MCP, admin deletes — a script that launches a profile and drives it needs control and automation on the same key. MCP exposes 15 tools, 14 of them on by default (delete_profile ships off). The request allowance is 300/minute on Solo, 600 on Pro and 900 on Agency; on Free the gateway answers 403.

Where to find it: the app sidebar — Workspace (Profiles, Proxies, Extensions, Fingerprints, Downloads, Capture) and Automation (Synchronizer, RPA Plus, API & MCP)

Team & seats Pro and up

A seat is one teammate signed in to your account's workspace. Free and Solo are single-seat. Pro includes 3 seats (you + 2 teammates) and Agency includes 10 (you + 9). Need more, contact [email protected].

  • Invite a teammate by email from the Team page and give them a role. Roles decide who may launch, edit, delete, bulk-create, export data and manage proxies.
  • Roles are enforced on our server, not just hidden in the interface, so a teammate cannot get around them by editing the app.
  • Assign a profile to a teammate from that profile's More ••• → Advanced → Team Assignment. That assignment also fires the task_assigned webhook.
  • The Activity log on the Team page records who did what. You choose how long it is kept — everything, 30, 90, 180 days or a year.
  • Profiles shared with a teammate are end-to-end encrypted; the key never reaches our servers.

Where to find it: Team (sidebar, under System) · Profiles → More ••• → Advanced → Team Assignment

Billing & subscriptions

PlanPriceProfilesSeatsDevicesFeatures
Free$0 — 7-day trial, no card needed311 PCThe full privacy engine; no cloud sync, no cookie import/export, no webhooks
Solo$9/month · $5/week · $23 every 3 months · $54/year201Any PCFree + cloud sync, cookie sync/import/export, encrypted profile sharing, proxy pool, session preloader, screenshots, Synchronizer, RPA robot, Local API & MCP
Pro$29/month · $13/week · $74 every 3 months · $174/year753 (you + 2 teammates)Any PCSolo + team roles, webhooks, session recording, rotating profile, custom RPA workflows, bulk create, app-settings backup · most popular
Agency$79/month · $30/week · $201 every 3 months · $474/year25010 (you + 9 teammates)Any PCPro + proof-of-work timeline, ZIP export, unlimited retention, priority support & onboarding
ScaleContact [email protected]1,000+CustomAny PCAgency + custom limits, personal onboarding, SLA

Paying every 3 months saves 15%; yearly billing is half the monthly price. Full details on the pricing section.

Where to find it: Settings → Subscription in the app (plan, days left, Upgrade) · dashboard → Billing on the web

  • Upgrading: sign in to your dashboard and choose a plan under Billing. Your new limits apply immediately.
  • Payment methods: pay by card via Stripe — Visa, Mastercard, American Express, and Apple Pay / Google Pay where available.
  • Refunds: every first purchase is covered by our 7-day money-back guarantee — see the Refund Policy.
  • Cancelling: cancel anytime from the dashboard (Subscription → Manage billing); your plan stays active until the end of the paid period.

Updates

To update, download the latest build from the website and install it over your existing one. On Windows run the new installer; on a Mac open the new .dmg and replace the app in Applications. Your account, profiles and settings are preserved.

The app checks for a newer version by itself shortly after it starts, and shows the result as one line under Settings → About → Updates: "Up to date", "Version X is available — download it from privogrid.com", or "Could not check for updates". When an update is available, a Download page button appears next to it. There is no manual "check now" button yet — reopen Settings to refresh the line.

See what's new in each version on the changelog.

Where to find it: Settings → About → Updates

Uninstall

Windows

  1. Close Privogrid completely.
  2. Open Windows Settings → Apps → Installed apps.
  3. Find Privogrid Browser, click it and choose Uninstall.

macOS

  1. Quit Privogrid completely (Privogrid → Quit, not just closing the window).
  2. Open Applications and drag Privogrid to the Trash.
  3. To remove the local data too, delete the folder ~/Library/Application Support/PrivogridBrowser. The app shows you this exact path under Settings → Storage & diagnostics, with a Show button.
About your profile data: local profile data may remain on the PC after uninstalling; you can remove it manually from your user's application data folder if you want a clean removal. Profiles synced to the cloud (paid plans) stay safely in your account and reappear when you reinstall and sign in.

Troubleshooting

"I can't sign in on a second computer" (Free plan)

The Free plan is locked to one PC. To use Privogrid on a different computer, either keep using your original PC, or upgrade to any paid plan (usable on any PC). If you replaced your computer, you can deactivate the old device from your dashboard using device deactivation.

Proxy errors

  • Run the built-in proxy test in the profile editor — it tells you whether the proxy is reachable and whether authentication succeeded.
  • Double-check the format: user:pass@ip:port, and make sure the proxy type (HTTP/HTTPS/SOCKS5) matches your provider's specification.
  • If your provider uses IP-whitelist authentication, confirm your current IP is whitelisted.
  • Some proxies expire or have bandwidth limits — verify the proxy is still active in your provider's dashboard.

"Privogrid can't be opened" on a Mac

Apple notarization for the macOS build is in progress, so macOS may show a security prompt on first launch. Verify the SHA-256 checksum before installing; contact support if the first launch needs help. If you dismissed the Keychain dialog the first time, quit and reopen the app and click Always Allow — without it, proxy passwords and your webhook secret cannot be stored encrypted.

Webhooks are not arriving

  • Click Test webhook in Settings → Integrations. It answers in place with "Delivered (200)" or the exact reason it failed.
  • "Internal/loopback address blocked" means the URL points at localhost or a private/reserved IP range. Only public http/https URLs are accepted.
  • "Webhook timeout" means your server took longer than 10 seconds. Answer with a 2xx first and do the slow work afterwards.
  • If your endpoint redirects, use the final URL — redirects are not followed.
  • Signature mismatch is almost always caused by verifying a re-serialised body. Sign the raw bytes exactly as received.
  • Webhooks need Pro or Agency. On Free and Solo the panel is visible but switched off.

Antivirus false positives

While our code-signing certificate is pending, some antivirus products may flag the installer as unknown software. This is a reputation-based warning, not a detection of anything harmful. Verify the installer against the official SHA-256 checksum before running it. Publisher verification is in progress and these warnings will disappear once it completes.

Still stuck?

Email [email protected] with a description of the problem, your Windows or macOS version, the app version from Settings → About, and (if relevant) a screenshot. We reply within 24–48 hours. Or use the contact form. See the Support page for all contact channels.