← Measured in the wild

ocsp2.apple.com

classified as first-party · 2

This page aggregates measured, corroborated evidence: donors' iPhones recorded apps contacting this domain, every claim below was reported by separate accepted donations and published under a human verdict (later rows for an approved app inherit its verdict). A contact is a measurement, not an accusation — it does not show what data was sent.

What our research panel found AI-drafted · human-reviewed

We ask several independent AI models the same question and publish their answers separately — cross-vendor agreement is evidence against fabrication, and disagreement is worth seeing. 3 of 3 models answered, overall confidence high. A human reviewed this domain's claims before anything here published.

Anthropic Claude — first-party

ocsp2.apple.com is an Apple-operated OCSP responder used for X.509 certificate revocation checking, and the app (com.apple.TestFlight) is itself an Apple app, so this is first-party platform security infrastructure rather than a tracking, analytics, or ad endpoint. Certificate-validation traffic is generally not a data-collection flow that store privacy labels are expected to declare, so nothing here indicates an undisclosed flow.

OpenAI — first-party

The domain is under apple.com and is most likely an Apple OCSP certificate-status service used for network security. The provided label has no declarations, but this contact alone does not establish an app data flow that the label would need to cover.

Google Gemini — first-party

ocsp2.apple.com is operated by Apple for Online Certificate Status Protocol (OCSP) certificate validation, making it first-party infrastructure. Essential security checks like certificate revocation checks do not imply undisclosed data collection.

Apps measured contacting this domain

AppLabel gapDonationsContactsSeen
com.apple.TestFlight7302026-07-28 → 2026-07-30
com.apple.Maps4262026-07-28 → 2026-07-29
Zoom Earth - Weather Forecast4182026-07-28 → 2026-07-29
ChatGPT4132026-07-28 → 2026-07-29
The Weather Channel4132026-07-28 → 2026-07-29
com.apple.podcasts4122026-07-28 → 2026-07-29
AccuWeather4122026-07-28 → 2026-07-29
com.apple.Passbook492026-07-28 → 2026-07-29
com.apple.news482026-07-28 → 2026-07-29
com.apple.mobilemail442026-07-28 → 2026-07-29
Google Gemini442026-07-28 → 2026-07-29
com.ilbsoft.irelax442026-07-28 → 2026-07-29
Messages3182026-07-30
com.apple.mobilenotes3122026-07-30
com.lemon.lvoverseas392026-07-30
Grok AI362026-07-30

The corpus grows one report at a time: donate your App Privacy Report — anonymous by design.

Think something here is wrong?

Evidence and research improve when people push back. Tell us what to re-check — a misattributed domain, an outdated classification, a claim about your own app — and a human will review it. Responses can take up to 30 days.

If you leave an email it is encrypted at rest and opened only to answer you — never shared, never used for anything else. It is erased 30 days after we resolve this (or 180 days if it is still open) without you asking, and you can erase it sooner at any time; either way your correction stays, anonymously. Leave it blank and your request is fully anonymous from the start (we store no IP address either way).