Guides ·

iCloud Private Relay and AI sites: which IP they see, and when to turn it off

iCloud Private Relay is a privacy feature included with iCloud+. With it on, Safari’s requests first go to a relay run by Apple, then to a second relay run by a third party, which connects to the website from a temporary IP address. So when you open ChatGPT, Claude or Gemini in Safari, the platform sees an Apple relay exit: still in your country, but possibly shared with other users nearby, and listed in a file Apple publishes, so it is easy to recognise. That’s fine for everyday browsing. Apple itself notes that without your IP address some websites may ask for extra steps to sign in, so for sign-up and login you can switch it off for a single site or a single network.

At a glance: the IP sites see with Private Relay onSafari page requests pass through Apple’s two relays, so sites see a temporary relay IP in your own country that may be shared with nearby users. Other browsers’ and apps’ HTTPS connections skip the relay, so platforms see your network’s usual exit. At a glance: the IP sites see Safari, Private Relay on Relay exit Your device Two relays Relay IP Same country; the IP may be shared nearby Other browsers, apps (HTTPS) No relay Your device Network Usual exit Platforms see your network’s own exit IP Plain-HTTP app traffic is relayed; VPN traffic isn’t.
On one device, Safari and your other browsers or apps can reach a platform from two different IPs.

How the two relays work

Apple’s support article describes it this way: your network provider and the first relay, operated by Apple, can see your IP address, but your DNS records are encrypted, so neither can see which site you’re visiting. The second relay, operated by a third-party content provider, generates a temporary IP address, decrypts the site name and connects you.

Apple’s technical overview (December 2021) adds details that matter for AI sites:

  • The second relay is run by large content delivery networks. It never learns your original IP, only enough location data to pick an address for your area.
  • Relay IP addresses rotate over time and between sessions, but stay stable within a browsing session, so a site sees a consistent address while you use it.
  • Private Relay offers no way to spoof your location. The relay IP always maps to the country or region you are actually connecting from.

The two “IP Address Location” settings

On iPhone or iPad, go to Settings > [your name] > iCloud > Private Relay > IP Address Location. On a Mac, go to System Settings, click your name, then iCloud > Private Relay and use the IP Address Location pop-up menu (see the iPhone User Guide and Mac User Guide). There are two choices:

  • Maintain general location (the default): the relay IP maps to a rough, city-level area, so sites can still show you local content.
  • Use country and time zone: the relay IP is picked from a wider area, making your location more obscure, but it stays in your original country and time zone.

According to the overview, the first option passes a coarse location (a geohash covering roughly 800 km²) to the second relay; the second does not. Apple’s developer page also says one relay IP may be shared by more than one user in the same area.

Two location settings, two rangesThe default, Maintain general location, gives a relay IP that maps to a rough city-level area. Use country and time zone picks from a wider area. Either way the relay IP stays in your own country or region and time zone. Two location settings, two ranges Your country or region (same time zone) Use country and time zone Picks from a wider area: more obscure Maintain general location (default) Relay IP maps to a rough city-level area Sites can still show local content Other countries Neither setting exits here Source: Apple’s Private Relay overview (Dec 2021)
Private Relay changes how precise your location looks, not which country you’re in. If a platform doesn’t support your region, it won’t help.

It only covers Safari and some other traffic

Apple’s developer page lists three things Private Relay protects: web browsing in Safari, DNS queries, and insecure http traffic from apps. That leads to a few common cases:

  • HTTPS pages opened in Chrome, Firefox or other browsers don’t go through the relay.
  • Apps that reach their servers over encrypted connections (HTTPS) aren’t covered either. On the same iPhone, the web version in Safari and the app can reach a platform from two different IPs.
  • Per the overview, traffic that goes through a VPN doesn’t use Private Relay, and a proxy configuration such as a global proxy takes precedence too.
  • If your Mac says “Some of your system settings prevent Private Relay from working”, Apple’s article points to a VPN or internet filtering app that installed incompatible settings or extensions.

Where it isn’t offered

Apple lists the countries and regions where Private Relay is available on its iOS and iPadOS Feature Availability page. When we checked on October 1, 2026, mainland China was not on the list; Hong Kong, Macao and Taiwan were. Apple’s management article says that when you travel somewhere Private Relay isn’t available, it turns off automatically, turns back on when you return to a supported country or region, and notifies you both times.

Private Relay changes how precise your location looks, not which country you’re in. If a platform doesn’t support your region, turning it on won’t change that; see the ChatGPT, Claude and Gemini checks for each platform’s region verdict.

Apple’s public egress list

Apple publishes every relay exit range at https://mask-api.icloud.com/egress-ip-ranges.csv, linked from both the developer page and the overview. Each line is an address range followed by a country code, a region code and a city, for example 172.224.226.0/27,GB,GB-EN,London,. The copy we downloaded on October 1, 2026 had about 285,000 lines, most of them IPv6 ranges. The overview says the list is also shared with the major geo-IP databases.

The developer page suggests that sites treat these addresses like large carrier-grade NAT or enterprise IP addresses, since many users can share one, and notes that most geo-IP providers label them “iCloud Private Relay” in the organization field. In other words, any site can recognise them easily. How ChatGPT, Claude and Gemini treat them isn’t public. What is public: in its suspicious activity alert article, OpenAI lists disabling any VPN, proxy or Private Relay among the self-serve troubleshooting steps.

How IP Judge flags it

  1. Our server downloads Apple’s list from that address once a week and keeps a local copy.
  2. When you open the home page or a platform check, the exit IP that opened our site is checked against the list, range by range. Only membership counts; the city in the list isn’t used.
  3. On a match, “How to fix” shows “Your exit is iCloud Private Relay” and suggests turning it off for sign-up and login; the separate “Your exit is a datacenter IP” note is not shown in that case. In the report for a single IP, the evidence list gains an entry sourced to “Apple’s public list”.
  4. In scoring, Exit type in the Claude score is capped at 18 of 30 (a home line gets 30), and in the Muse sign-up score at 15 of 40 (home: 40). These weights are IP Judge’s, based on common risk signals, not rules the platforms publish; see Method.

Turning it off for sign-up and login

These steps come from Apple’s official article and user guides, from narrowest to broadest:

  1. One website: on iPhone or iPad, tap the Page Menu button in Safari, then tap Show IP Address. On a Mac, choose View > Reload and Show IP Address in Safari. If the option isn’t there, update to the latest iOS, iPadOS or macOS. Your network provider can then also see which site you’re visiting.
  2. One network: on iPhone or iPad, go to Settings > Wi-Fi, tap the More Info button next to the network and turn off Limit IP Address Tracking. For cellular, go to Settings > Cellular, select your line under SIMs (on iOS 18 or earlier, tap Cellular Data Options) and turn off Limit IP Address Tracking. On a Mac, go to System Settings > Network, click the service you’re using, click Details next to the network name and turn off “Limit IP address tracking”. The setting applies to that network on all your devices that have Private Relay on.
  3. The whole device for a day: Settings > [your name] > iCloud > Private Relay, then Turn Off Until Tomorrow. It turns itself back on within 24 hours.

Then re-run the check on the home page. The first method only applies to the current site: if you chose Show IP Address on chatgpt.com, IP Judge still sees the relay exit until you do the same here. With Private Relay off, platforms see your network’s own exit, so check again which country it is in and whether it is a home or datacenter line. See Which IP do ChatGPT and Claude actually see? and residential vs datacenter IPs.

FAQ

Is Private Relay the same as Hide My Email?

No. An address ending in @privaterelay.appleid.com comes from Hide My Email in Sign in with Apple (Apple). It only concerns your email address, not your exit IP. For a ChatGPT account created that way, OpenAI’s login help says to keep using Continue with Apple with the same Apple account; Claude’s login help says to enter that address, and a secure login link is sent to your Apple ID email.

Why don’t I see this item when I run the check in Chrome?

Private Relay only covers browsing in Safari. HTTPS pages in Chrome don’t go through the relay, so IP Judge sees your network’s own exit. To check what Safari exposes, run the check in Safari.

Which location setting is better for AI sites?

No platform has said. Both use addresses from Apple’s list and both keep your country; IP Judge only checks list membership, so it treats them the same.

My IP changes every time I re-run the check. Is that normal?

Yes. Apple’s overview says relay IPs rotate over time and between sessions and stay stable only within a browsing session.

Which kind of IP do you have?

Check my IP for free