Websites load jQuery, React and Bootstrap from a handful of giant delivery networks, and every page tells those networks who you are. Sidestep serves the same files from your own device instead.
Requires macOS 13 or iOS 17 or later · one purchase, every deviceSidestep replaces the requests, it does not block them. Pages behave exactly as before, the networks just never hear from you.
jQuery, React, Vue, AngularJS, Bootstrap, Font Awesome, D3, Lodash, Moment.js, MathJax and hundreds more, kept on your device.
Google Hosted Libraries, cdnjs, jsDelivr, jQuery CDN, Microsoft Ajax, the Bootstrap CDNs and every other major host.
No request leaves your device, so there is no IP address to log and no record of which page you were reading.
For the rare library we do not carry, the referring page and cookies are stripped so the network still cannot tell where you came from.
An optional switch that stops font requests reaching Google at all. Off by default, because it changes how some sites look.
If a page really needs the original file, switch Sidestep off just for that site from the toolbar. Everywhere else stays protected.
A live test page asks twelve well-known libraries from four networks and tells you, one by one, whether each came from your device.
One purchase covers every device on your Apple Account, with the same settings and the same protection.
No account, no rules to write, no maintenance. Install it, switch it on in Safari, and it works from the first page you open.
Sidestep has one job and does it in the background. The interface exists so you can check on it and switch it off when you need to.


One purchase covers Mac, iPhone and iPad.
Safari Settings, then Extensions, then switch Sidestep on and allow it on every website.
That is it. Open the test page any time you want to confirm it is doing its job.
Blocking a page's jQuery would break the page, so blockers let the request through. The delivery network answers it, and in doing so learns your IP address and which site you were on. It happens on an enormous share of the web, and no list will stop it without collateral damage.
Sidestep takes the other route. It answers the request itself, from a copy already on your device, so the page gets exactly the file it asked for and the network gets nothing. Nothing breaks, and nothing leaks.
It runs alongside your blocker, not instead of it.
It should not. Sidestep hands the page exactly the file it asked for, byte for byte, so even sites that verify a library's contents keep working. If a page ever misbehaves, switch Sidestep off for that one site from the toolbar and carry on.
Yes. They solve different problems and work well together. Blockers stop adverts and trackers; they deliberately leave shared code libraries alone because blocking those breaks pages. Sidestep is what handles that remaining category.
No. It makes no network requests of its own and has no server to send anything to. The only thing it stores is your own settings, on your device.
The request goes through to the network as normal, so the page still works. Sidestep strips the referring page and cookies from it first, so the network learns as little as possible.
Open the protection test. It requests twelve well-known libraries from four different networks and reports, for each one, whether it came from your device or from the network.