data report card

Data Report Card · Mozilla (Firefox)

Mozilla (Firefox) Data Report Card

Browser + Mozilla account · Mozilla Corporation
Data
Practices
2Access1Portability1Friction2Deletion2Sells2Trains AI
=
B
10/12
Agent
Readiness
2Access 1Portability 0API access
=
C
3/6

Agent Readiness is a derived signal — a synthesis of two existing cells (Access, Portability) plus one sourced factor (API access), not an independently measured grade. API access scale: Best (2) consumer-grantable API · Moderate (1) partial / encumbered · Restrictive (0) manual export only. What is Agent Readiness?

Help me make a request →
Reviewed Jun 2026  ·  some cells re-verified Aug 2026 · policies are checked weekly for changes  ·  stated — every cell is read from Mozilla (Firefox)'s published policy; none has been tested (run by us) yet.
2Accessstated
A dedicated Data Subject Access Request portal covers “a copy of the data we have about you”, portability and deletion, alongside a self-serve account view at accounts.firefox.com — the clearly-documented-request shape, no fee.
Firefox Privacy Notice — your rights · accessed Aug 2026 ↗
1Portabilitystated
No self-serve download of Mozilla-held data exists — portability is request-only through the DSAR portal. Local browser data exports (bookmarks to HTML, passwords to CSV) are self-serve but live on your device, not on Mozilla’s servers.
Firefox Privacy Notice — your rights / SUMO export articles · accessed Aug 2026 ↗
1Frictionstated
Deletion, telemetry and sponsored-content controls are all self-serve toggles, and one no-fee portal covers the rest — but the copy-of-your-data path is a form with no stated response window (“in accordance with applicable data protection laws”), the shape that scores moderate across the board.
Firefox Privacy Notice — exercising your rights · accessed Aug 2026 ↗
2Deletionstated
Self-serve permanent account deletion, and stated timelines throughout: Firefox data “will be deleted within 30 days of the request”, interaction data auto-deletes at 90 days, general retention is capped (“we do not retain personal data for more than 25 months”), and inactive accounts are deleted after two years.
Firefox Privacy Notice — retention / account deletion · accessed Aug 2026 ↗
2Sells / sharesstated
“We don’t know that much about you. What little we do know, we never sell.” Sponsored content shares only stated non-identifying data (“device type, IP-derived location information, and category of content viewed … We don’t share any information that identifies you”) with a self-serve opt-out — the plain no-sell shape.
Firefox Privacy Notice — advertising and sponsored content · accessed Aug 2026 ↗
2Trains AIstated
On-device AI by design: “web page content, PDFs, images and tab URLs stay on your device and are not sent to Mozilla’s servers or used for training purposes without your explicit consent”; third-party chatbot conversations are inaccessible to Mozilla. No clause trains Mozilla models on user data.
Firefox Privacy Notice — AI features · accessed Aug 2026 ↗
0API access — feeds Agent Readiness, not the /12stated
Mozilla accounts OAuth “only services clients internal to Mozilla” — third parties cannot register to fetch a user’s account data — and Sync is end-to-end encrypted so Mozilla itself cannot read it; no consumer-grantable data API exists.
Mozilla Ecosystem Platform docs · accessed Aug 2026 ↗
Graded 2026-08-31 against the Firefox Privacy Notice (effective May 4, 2026), the Mozilla Accounts Privacy Notice (last updated Aug 10, 2026) and Mozilla's support articles. Consumer surface = the Firefox browser plus a Mozilla account, operated by Mozilla Corporation. Rights run through a dedicated OneTrust DSAR portal; account deletion is self-serve; Sync is end-to-end encrypted (“Mozilla cannot decrypt this information”). Sponsored content shares only stated non-identifying data with advertising providers, with a self-serve opt-out; the Privacy-Preserving Attribution experiment “was never activated and was later removed”. Firefox removed the Do Not Track setting in version 135 in favor of GPC. No regulator has published a final data-practices action; noyb's 2024 Austrian complaint over PPA remains unresolved and the feature is gone. All cells stated, not tested.

Events

Breaches, policy changes, and export-format changes we’ve recorded at Mozilla (Firefox) — other parties’ actions, alongside the enforcement record above. An event never changes a grade by itself. All events →

No events on record for Mozilla (Firefox).

Grade history

Every change to this company’s grade since it was first published, and why. All grade changes →

No changes since this grade was first published in Jun 2026.

How to request your data from Mozilla (Firefox)

  1. Go to https://privacyportal.onetrust.com/webform/1350748f-7139-405c-8188-22740b3b5587/4ba08202-2ede-4934-a89e-f0b0870f95f0 — Mozilla (Firefox)'s data-request entry point.
  2. DSAR portal for access/portability/deletion of Mozilla-held data; account deletion self-serve at accounts.firefox.com.
  3. Expected wait: no numeric window stated (“in accordance with applicable data protection laws”); Firefox data deleted within 30 days of a deletion request — Mozilla (Firefox)'s stated turnaround (we haven't independently timed a request yet).
  4. No self-serve option, or want a formal request? Contact Mozilla — DSAR (OneTrust portal): mailto:compliance@mozilla.com.

These steps reflect Mozilla (Firefox)'s documented process as of Jun 2026. The wait time is the company's stated figure, not yet independently measured by us.