Skip to main content
Toggle table of contents. Current section: Controller and contact details

Privacy Policy

Every network connection Waterfox makes on its own, who receives it, why, and how to switch it off.


Version 2.0 - 19 August 2026

Controller and contact details

BrowserWorks Ltd (Suite 140, 372 Old Street, London, EC1V 9AU, United Kingdom; hereafter “BrowserWorks”, “Waterfox”, “we”, “our”) acts as a controller under the United Kingdom General Data Protection Regulation (UK GDPR) and other applicable data protection law.

Companies House14843353
ICO registrationZC079925
Emailprivacy@browser.works

The short version

Waterfox has no telemetry. It does not build a profile of you, send us a record of your browsing activity or have an analytics pipeline to send it to. The telemetry modules are disabled when the browser is built and the switches that would enable them are locked off.

However, Waterfox does fetch things, such as updates, filter lists, certificate revocations and DNS answers. Each of these is an outbound request, revealing your IP address to the entity that responds. This policy lists all the requests, specifies who receives them and explains how to stop each one.

We compiled this information by running a clean Waterfox profile with full network logging and documenting every host that was contacted. If you would like to verify our findings, you can access the same log by setting MOZ_LOG=nsHttp:3 before launching.

What Waterfox does not do

None of the following are present and none can be activated remotely by us:

  • Telemetry, health reports and crash reports, which are disabled and locked at build time.
  • Studies, experiments and rollouts (Normandy, Shield and Nimbus) are off and locked. We cannot deliver a configuration change to your browser.
  • Safe Browsing: Waterfox does not check the sites you visit or the files you download against Google’s Safe Browsing service. The feature, its provider URLs and the download reputation service have all been removed.
  • Sponsored content: no sponsored top sites, no sponsored new tab stories, no Pocket, no Contile and no suggested-search advertising.
  • LLM and chatbot features: see the LLM Usage Memorandum.
  • Breach alerts: No password or account data is sent to a breach-monitoring service.
  • Terms-of-use acceptance prompts: There is no data collection to consent to, so there is no consent flow.

Search suggestions

This is the only connection that Waterfox receives itself. Every built-in search engine - including Google, Bing, DuckDuckGo, Ecosia, Mojeek, Qwant and 1.org - routes its search suggestions through search.waterfox.com/autocomplete, a service that we operate. When suggestions are enabled, the characters you type into the address or search bar are sent to us, along with your IP address, as you type them. Since this is a privacy proxy, IPs are dropped immediately and never stored.

We run the suggestion endpoint ourselves specifically so that your keystrokes do not go to the search engine until you have decided to perform a search. We do not log suggestion queries against an identifier, nor do we retain them to build a profile. See Waterfox Private Search for the service’s own terms.

To switch off search suggestions, go to Settings → Search and uncheck “Provide search suggestions”. This stops suggestions entirely and nothing is sent until you press Enter.

Searches themselves

When you perform a search, your query is sent to the selected search engine, not to us. Waterfox adds a partner attribution parameter for engines with which we have a revenue agreement, enabling the engine to attribute the search to Waterfox. This identifies the browser, not you.

EngineParameter
DuckDuckGot=waterfox
Ecosiatt=57226k1p
Qwantclient=brz-waterfox
1.orgsegment=1org.waterfox

Your search is then subject to that engine’s privacy policy. See our Revenue Model for details of how these agreements fund the browser.

Region detection

When you first run Waterfox, it performs a single country lookup to pick a sensible default search engine for your region. This request is sent to Mozilla’s location.services.mozilla.com and only includes your IP address - no query and no identifier. This is inherited from the Firefox default rather than being something we added, and we intend to remove the dependency.

To switch this off, set browser.region.network.url to an empty string in about:config before the first run, or set browser.region.update.enabled to false.

However, doing so may leave Qwant as the default search engine, which may be unavailable in your region.


Ultra Protection: DNS

By default, Waterfox resolves DNS over Oblivious HTTP on new profiles. This is designed so that no single party can see both your identity and your search results:

  • dooh.waterfox.com - the relay, which is operated by Fastly. It sees your IP address and an encrypted blob. It cannot read the query.
  • dooh.cloudflare-dns.com: the resolver, operated by Cloudflare. It can read the query, but it only sees the relay’s IP address, not yours.

We cannot see your DNS queries. Cloudflare cannot see who is making them.

One caveat worth noting: Cloudflare’s endpoint sets a network error logging policy, so if you are unable to connect to it, your browser may send a connection failure report to a.nel.cloudflare.com. These reports describe the failed connection, not your browsing activity.

To change or switch this feature off, go to Settings → Privacy & Security → DNS over HTTPS. You can select a different provider, revert to your system resolver or disable the feature.


Content blocking

Waterfox has a built-in ad and tracker blocker. It ships with filter lists already bundled, so it works offline from the first launch. However, the lists can become outdated and are updated by the people who publish them.

These are: easylist.to, raw.githubusercontent.com (uBlock Origin and AdGuard lists), secure.fanboy.co.nz, pgl.yoyo.org, easylist-downloads.adblockplus.org, filters.adtidy.org, cdn.jsdelivr.net, stanev.org and ubo-et.lepik.io.

Each of these sites sees your IP address when a list is downloaded. However, they receive no information about the pages you visit - filtering happens entirely on your machine, and no site you visit is ever sent anywhere for a blocking decision.

Waterfox also fetches the blocker’s scriptlet and resource bundles from aus.waterfox.com. Copies are bundled in the build, and the fetch keeps them current.

To switch off remote updates, set waterfox.blocker.remoteResourcesEnabled to false in about:config. The blocker will then only use what shipped in the build. To disable blocking entirely: Go to Settings → Privacy & Security → Content Blocking.


Updates

Application updates

Waterfox checks our update servers every 12 hours. This request includes information such as your Waterfox version and build ID, platform and architecture, locale, update channel, operating system version, CPU and memory capability string, and distribution identifiers. It contains no information about you or your browsing activity. This information cannot be reduced; without it, we cannot provide you with the correct update file. However, you can turn it off in Settings > General > Waterfox Updates. Please note that you will no longer receive security fixes if you do so.

System add-on updates: a separate check to aus.waterfox.com/update/SystemAddons/, carrying the same class of information.

Extension updates: Waterfox contacts the site that hosts an extension you have installed to check for a new version. It also queries services.addons.mozilla.org for metadata about the built-in themes.

Media plugins: if you play DRM-protected video, Waterfox downloads Google’s Widevine module (checked via aus5.mozilla.org, downloaded from update.googleapis.com and google.com). For H.264 video, it downloads Cisco’s OpenH264 codec from ciscobinary.openh264.org. Both of these processes can be opted out of by going to Settings > General and unchecking “Play DRM-controlled content”, as well as setting media.gmp-gmpopenh264.enabled to false.


Security data

By default, Waterfox keeps Mozilla’s Remote Settings service offline. Almost every collection reads from a copy that is bundled with the build, rather than from the network. Only stale data that matters for security is allowed to sync:

  • certificate revocations (CRLite) and intermediate certificates, so that Waterfox knows which certificates have been revoked.
  • The add-on blocklist, so known malicious extensions are disabled.
  • Anti-tracking lists, including tracking protection lists, query stripping, cookie-blocking exemptions and related breakage fixes.

These items originate from firefox.settings.services.mozilla.com, with attachments from firefox-settings-attachments.cdn.mozilla.net and signature chains from content-signature-2.cdn.mozilla.net. Mozilla receives your IP address, but the requests do not reveal what you browse. New tab wallpapers are also served from the same attachment CDN.

Certificate checking: because revocation is handled by the bundled CRLite data, OCSP is off by default – Waterfox does not contact a Certificate Authority to ask about the sites you visit. This is a meaningful improvement on the upstream default, where each new HTTPS site could trigger a call to its CA.


Other automatic connections

(Temporary: will be removed in version 6.7.1): Connectivity check: Waterfox probes detectportal.firefox.com to determine whether you have an internet connection. Although the captive portal login flow is disabled, the connectivity probe remains. To stop it, set network.connectivity-service.enabled to false in about:config.

Web push: Waterfox opens a connection to push.services.mozilla.com so that sites to which you have granted permission to send notifications can reach you. The service relays messages using your IP address, and neither we nor the service can read the contents of the messages. If you never allow a site to send notifications, nothing is delivered. Set dom.push.enabled to false to disable it completely.


Features you choose to enable

Location: Waterfox will always ask before sharing your location with a website. If you allow this, your location is determined by the geolocation feature of your operating system. The network geolocation provider is blanked out, meaning that no location lookup is sent to Mozilla or Google. To disable location services completely, set geo.enabled to false in about:config.

Sync: Sync is disabled unless you sign in. If you use it with a Mozilla account, your data is shared with Mozilla in an end-to-end encrypted form. This may include tabs, add-ons, passwords, payment autofill, bookmarks, history and preferences. Deleting the account deletes the synced content. The privacy notice for that service can be found here: https://www.mozilla.org/privacy/firefox/#optional-features.

Extensions: Waterfox does not require extensions to be signed, so you can install them from anywhere. Anything an extension does with your data is governed by that extension’s own policy, not ours – an extension can see far more than the browser reports to us, which is nothing.

Translation models are downloaded on demand from the Remote Settings attachment CDN. The translation process itself runs locally on your machine and the text you translate is never sent anywhere.


Your rights

Under the UK GDPR, you have the right to access, rectify, erase or restrict the processing of your personal data, as well as the right to data portability. In practice, however, we hold almost no information that would enable us to act on these rights, as we do not maintain user accounts for the browser and cannot identify you from any of the above connections.

If you use Waterfox Private Search, the service provider holds the minimum information required to operate the service, and its own terms describe what information is held and for how long.

If you believe we have handled your data improperly, you may complain to the Information Commissioner’s Office (ico.org.uk). However, we would prefer you to email us first: privacy@browser.works.

Changes to this policy

We will update this policy when the behaviour of the browser changes, and we will update the version and date above accordingly. Any material changes will be noted in the release notes for the version in which they are introduced.