Reviewed Jun 2026 · some cells re-verified Aug 2026 · policies are checked weekly for changes · stated — every cell is read from Mozilla (Firefox)'s published policy; none has been tested (run by us) yet.
2Accessstated
A dedicated Data Subject Access Request portal covers “a copy of the data we have about you”, portability and deletion, alongside a self-serve account view at accounts.firefox.com — the clearly-documented-request shape, no fee.
Firefox Privacy Notice — your rights · accessed Aug 2026 ↗
1Frictionstated
Deletion, telemetry and sponsored-content controls are all self-serve toggles, and one no-fee portal covers the rest — but the copy-of-your-data path is a form with no stated response window (“in accordance with applicable data protection laws”), the shape that scores moderate across the board.
Firefox Privacy Notice — exercising your rights · accessed Aug 2026 ↗
2Deletionstated
Self-serve permanent account deletion, and stated timelines throughout: Firefox data “will be deleted within 30 days of the request”, interaction data auto-deletes at 90 days, general retention is capped (“we do not retain personal data for more than 25 months”), and inactive accounts are deleted after two years.
Firefox Privacy Notice — retention / account deletion · accessed Aug 2026 ↗
2Sells / sharesstated
“We don’t know that much about you. What little we do know, we never sell.” Sponsored content shares only stated non-identifying data (“device type, IP-derived location information, and category of content viewed … We don’t share any information that identifies you”) with a self-serve opt-out — the plain no-sell shape.
Firefox Privacy Notice — advertising and sponsored content · accessed Aug 2026 ↗
2Trains AIstated
On-device AI by design: “web page content, PDFs, images and tab URLs stay on your device and are not sent to Mozilla’s servers or used for training purposes without your explicit consent”; third-party chatbot conversations are inaccessible to Mozilla. No clause trains Mozilla models on user data.
Firefox Privacy Notice — AI features · accessed Aug 2026 ↗
0API access — feeds Agent Readiness, not the /12stated
Mozilla accounts OAuth “only services clients internal to Mozilla” — third parties cannot register to fetch a user’s account data — and Sync is end-to-end encrypted so Mozilla itself cannot read it; no consumer-grantable data API exists.
Mozilla Ecosystem Platform docs · accessed Aug 2026 ↗
Graded 2026-08-31 against the Firefox Privacy Notice (effective May 4, 2026), the Mozilla Accounts Privacy Notice (last updated Aug 10, 2026) and Mozilla's support articles. Consumer surface = the Firefox browser plus a Mozilla account, operated by Mozilla Corporation. Rights run through a dedicated OneTrust DSAR portal; account deletion is self-serve; Sync is end-to-end encrypted (“Mozilla cannot decrypt this information”). Sponsored content shares only stated non-identifying data with advertising providers, with a self-serve opt-out; the Privacy-Preserving Attribution experiment “was never activated and was later removed”. Firefox removed the Do Not Track setting in version 135 in favor of GPC. No regulator has published a final data-practices action; noyb's 2024 Austrian complaint over PPA remains unresolved and the feature is gone. All cells stated, not tested.
Events
Breaches, policy changes, and export-format changes we’ve recorded at Mozilla (Firefox) — other parties’ actions, alongside the enforcement record above. An event never changes a grade by itself. All events →
No events on record for Mozilla (Firefox).
Grade history
Every change to this company’s grade since it was first published, and why. All grade changes →
No changes since this grade was first published in Jun 2026.