NetCage is a per-app firewall: you pick an installed app and its internet access stops, in the foreground and the background, on Wi-Fi and on mobile data. Everything below is built on that one switch. Nothing here needs an account, and nothing here needs root.
Open the list, find the app, turn it off. There is no rule to write, no domain to enter and no allow-list to maintain: the unit of control is the whole app, and it is either connected or it is not. Turning it back on takes the same tap, and the change applies immediately without restarting anything.
A profile is a named group of apps you cage together β Work, Evenings, Everything Loud. Applying one is a single action instead of eleven, and editing the profile changes what it does everywhere it is used. Profiles are the answer to the realisation that you keep caging the same six apps at the same times.
A schedule cages an app or a profile between two times on chosen days, and it survives a reboot and a daylight-saving change. A day pass is the opposite: it lifts a cage for a set period and then puts it back, so a deliberate exception does not quietly become permanent because you forgot to re-enable it.
A home-screen widget shows the apps you pin and toggles them where you already are, and a Quick Settings tile sits beside Wi-Fi and Bluetooth for the everything-off case. Both matter more than they sound: a control you have to go and find is a control you stop using by the second week.
Real app icons, categories, search and sorting, and one action that cages every app in a category at once β with an undo, because a bulk action you cannot reverse is one nobody dares use. Apps you never think about can be hidden, and rules left behind by an app you uninstalled are shown so you can clear them.
Signing in with Google copies your whole configuration β rules, profiles, schedules, preferences, hidden apps, custom icons β to your other phones, and the first sync asks which side to keep rather than guessing. It is genuinely optional: every feature above works without an account, and deleting the account removes what was stored for it.
An event log records what NetCage did and when: a cage applied, a schedule firing, a day pass starting and expiring, the tunnel going down and coming back, a rule pruned because its app was uninstalled. It is there so a block you did not expect has an explanation you can read, rather than being something you have to take on trust. The whole configuration can also be exported to a file and imported again, which is the answer to changing phones without signing in.
On first launch NetCage shows what it is about to do, then asks Android for the VPN permission β the system dialogue, which no app can bypass or pre-answer. Grant it and you land on the app list; nothing is caged until you cage it. Android will show a key icon in the status bar for as long as the tunnel is up, because that is what it does for every VPN, and NetCage explains that rather than hoping you do not notice.
NetCage is not an ad blocker and not a content blocker. It does no domain filtering, no hosts file, no DNS interception and no traffic inspection, so it cannot block ads inside an app you want online. It blocks whole apps, which is a different job β and the one it does completely.