Skip Navigation

Firefox deletes promise to never sell personal data, asks users not to panic

Firefox maker Mozilla deleted a promise to never sell its users' personal data and is trying to assure worried users that its approach to privacy hasn't fundamentally changed. Until recently, a Firefox FAQ promised that the browser maker never has and never will sell its users' personal data. An archived version from January 30 says:

Does Firefox sell your personal data?

Nope. Never have, never will. And we protect you from many of the advertisers who do. Firefox products are designed to protect your privacy. That's a promise.

That promise is removed from the current version. There's also a notable change in a data privacy FAQ that used to say, "Mozilla doesn't sell data about you, and we don't buy data about you."

The data privacy FAQ now explains that Mozilla is no longer making blanket promises about not selling data because some legal jurisdictions define "sale" in a very broad way:

Mozilla doesn't sell data about you (in the way that most people think about "selling data"), and we don't buy data about you. Since we strive for transparency, and the LEGAL definition of "sale of data" is extremely broad in some places, we've had to step back from making the definitive statements you know and love. We still put a lot of work into making sure that the data that we share with our partners (which we need to do to make Firefox commercially viable) is stripped of any identifying information, or shared only in the aggregate, or is put through our privacy preserving technologies (like OHTTP).

Mozilla didn't say which legal jurisdictions have these broad definitions.

93 comments
  • also

    Update at 10:20 pm ET: Mozilla has since announced a change to the license language to address user complaints. It now says, "You give Mozilla the rights necessary to operate Firefox. This includes processing your data as we describe in the Firefox Privacy Notice. It also includes a nonexclusive, royalty-free, worldwide license for the purpose of doing as you request with the content you input in Firefox. This does not give Mozilla any ownership in that content."

    Mozilla may also receive location-related keywords from your search (such as when you search for "Boston") and share this with our partners to provide recommended and sponsored content. Where this occurs, Mozilla cannot associate the keyword search with an individual user once the search suggestion has been served and partners are never able to associate search suggestions with an individual user. You can remove this functionality at any time by turning off Sponsored Suggestions—more information on how to do this is available in the relevant Firefox Support page.

    So, turn off Sponsored Suggestions and you're (probably) good to go.

  • Made the switch to Fennec and IceRaven on Android, and Zen on my Linux desktop, which also has Windows and Mac versions. Sure, they're forks of Firefox, but they are not subject to the same TOS. I used to use LibreWolf on my desktop but ended up having too many issues with it. Lots of crashing and instablility that regular Firefox just didn't have.

    Another great tool for unGoogled Android users is FFUpdater. It will handle updating of many open source (not just Firefox-based) browsers. You could also use something like Obtanium for something less browser-specific.

  • Some obvious jurisdictions that come to mind, are US vs. EU:

    • US: protects "Personally Identifiable Information" (PII)
    • EU: protects "Personal Information" (PI)

    The color of your hair... is PI in the EU, it isn't PII in the US since it's not enough to pinpoint you as a single person.

    Under US law, a data broker can gather a bunch of "not-PII, just PI", and refine it into profiles that can end up pinpointing single individuals.

    Under EU law, that's illegal; no selling PI, period.

    • This is completely accurate, and people don't know how non anonymous it is.

      Your hair one for example. Who cares, say you even have brunette hair, something generic. Okay, then let's add on that you're using an iPhone. How narrow is the search now? What state you're in? Who owns a specific model of TV?

      I would argue that with only just a few data points you could be identified.

      And now they are taking everything you put into your browser and everything you take out. Add some AI pizazz and they'll be able to build a pretty accurate profile about you.

  • Maybe they should replace it with Google's former pledge "Don't be evil": it's free for the taking, nobody's using it at the moment.

  • Have any of you FUD shoveling geniuses considered that this is because Firefox uses encrypted DNS by default?

93 comments