Why is privatecloudcomputed using my network?

Last updated: 2026-07-31

privatecloudcomputed is Apple’s Private Cloud Compute offload daemon. It validates cloud nodes, encrypts requests, and sends them when Apple Intelligence needs PCC. There is no supported switch for this process alone.

What it is

privatecloudcomputed is an Apple-supplied client daemon for Private Cloud Compute. Apple’s documentation describes it as the “private cloud compute offload daemon.” When a system feature decides that a task should be handled by Private Cloud Compute, this process verifies the remote compute node, encrypts the request, and sends it.

The verified executable belongs to the system-protected PrivateCloudCompute.framework and uses the identifier com.apple.privatecloudcomputed. It is therefore part of macOS rather than an application silently installed by a third party.

privatecloudcomputed is not designed to remain active at all times. Its launchd definition has RunAtLoad set to false, so launchd starts it when the system needs it. An Apple Intelligence request is one possible trigger, but it is not the only one. Background work that maintains attestation material or service configuration can also wake the process even when you are not visibly using an Apple Intelligence feature.

Why it talks to the network

The most obvious trigger is an Apple Intelligence feature deciding that a request requires a cloud model. At that point, privatecloudcomputed handles the Private Cloud Compute side of the request: it verifies an eligible node, encrypts the request, and sends it for processing.

Some connections are preparatory or administrative rather than a direct response to something you just asked the Mac to do. The process can fetch, prefetch, and verify PCC node attestation material. It can also contact services involved in transparency, routing, and server-provided configuration. System-scheduled maintenance may use it for node-distribution and feature-use analysis tasks.

The possible destination categories include third-party anonymizing relays, the PCC Gateway, verified PCC proxies or compute nodes, and Apple services for PCC configuration, attestation, and transparency. Apple has not published a complete, user-facing list of exact hostnames. A firewall log may therefore show connections that fit these categories, but an undocumented hostname should not be presented as a confirmed PCC endpoint without separate verification.

Traffic can appear without a visible prompt because launchd may wake privatecloudcomputed for background attestation or configuration work. Conversely, merely seeing the process connect does not establish that a large Apple Intelligence request was sent. The connection has to be considered together with its timing and actual byte count.

How much traffic is normal

Apple has not published a reliable normal traffic range for privatecloudcomputed. There is no well-supported fixed number of megabytes per request, per hour, or per day. Any universal allowance presented that way would be guesswork.

When no task is being offloaded, the expected pattern is mainly intermittent control traffic for attestation material and configuration. That describes the type and frequency of the traffic, not a guaranteed byte limit. The available evidence does not support turning that description into a precise numerical threshold.

When a PCC request is processed, usage varies with the input, output, and type of feature involved. It will typically be higher than background maintenance traffic. Workloads involving images or video may be substantially larger than lighter requests, but reliable sources do not provide a fixed size for them either.

This means that “normal” is best judged from context. A brief background connection and a feature-driven offload are different events and should not be compared against one invented daily average. If you need an exact figure for your Mac, it has to come from measuring the process rather than from a generic estimate.

Can you turn it off

There is no Apple-supported setting that disables only privatecloudcomputed. The supported way to stop using the upper-level feature is:

Apple menu > System Settings > Apple Intelligence & Siri > Apple Intelligence, then turn Apple Intelligence off.

That control appears only where Apple Intelligence is supported for the Mac’s hardware, language, and region. Turning it off disables the entire Apple Intelligence feature set, not just Private Cloud Compute. It also removes related capabilities that would otherwise have been performed on the device without a PCC request.

Ending privatecloudcomputed in a process manager or blocking it in a firewall is not equivalent to using that setting. Launchd can start the daemon again. Features that require PCC may fail, time out, or repeatedly retry, and Apple does not guarantee that a blocked request will fall back to local processing.

It is therefore optional only in the sense that you may choose to turn off Apple Intelligence as a whole. There is no supported process-specific off switch. Reliable public information also does not establish that every background maintenance connection stops immediately after the upper-level feature is disabled.

What people get wrong

1. “It is third-party malware.” The verified executable is inside Apple’s protected PrivateCloudCompute.framework and is identified and registered as com.apple.privatecloudcomputed. Its presence is expected on macOS.

2. “It is syncing iCloud Drive, making cloud backups, or running iCloud Private Relay.” Those are different services. privatecloudcomputed is responsible for verifying Private Cloud Compute nodes and encrypting and sending PCC requests.

3. “Any connection means macOS is uploading all my files or continuously monitoring me.” A PCC request is constructed by the feature that called it and contains data needed to complete that task. That does not support the claim that all files are being uploaded or that the process is continuously monitoring activity. The relevant request data does, however, need to be decrypted and processed by a verified PCC node inside its protected boundary.

4. “It must run permanently in the background.” It does not have to remain resident. Its launchd configuration uses RunAtLoad=false, and the process is primarily started on demand. Attestation, configuration, and analysis maintenance can still wake it in the background.

5. “Killing or blocking it is a harmless system optimization.” Launchd can relaunch it, while Apple Intelligence features that require PCC may fail or generate retries. Apple provides no supported promise that blocking the daemon has no side effects.

6. “Turning off Siri also turns off Apple Intelligence.” Siri and Apple Intelligence have separate settings on supported macOS systems. Disabling Siri alone is not the same as switching off Apple Intelligence through its own control.

Seeing what it actually used

Because there is no reliable universal traffic allowance, the practical next step is to measure privatecloudcomputed on your own Mac. Use Bytetally’s per-process statistics to check how much network traffic it recorded during the period you care about. Compare quiet periods with times when you used an Apple Intelligence feature so that maintenance traffic and task-driven traffic are not mistaken for the same pattern.

Related processes

Common questions

Is privatecloudcomputed malware?

No. The verified program is part of Apple’s protected PrivateCloudCompute framework and is identified as com.apple.privatecloudcomputed.

Why is privatecloudcomputed connecting to the internet?

It connects when Apple Intelligence sends a task to Private Cloud Compute, and for background work involving node attestation, configuration, routing, transparency, distribution, and feature-use analysis.

Can I disable privatecloudcomputed?

Apple provides no supported switch for this process alone. You can turn off Apple Intelligence in System Settings, but that also disables related features that could otherwise run locally.

How much data should privatecloudcomputed use?

Apple has not published a reliable normal range. Maintenance traffic should be intermittent, while actual requests vary with their input, output, and workload type.

See exactly how much it used

Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.

Download Free on the Mac App Store

macOS 14 Sonoma or later · 100% on-device · No account