This record is managed by an account, but domain control has not been proven.
boundaries.md
---
bcp_version: "1.1.1"
file_type: boundaries
parent: https://registry.brandcontextprotocol.dev/firefox-8df36a3b/.well-known/brand.md
last_updated: 2026-09-14
---
# Boundaries
This file is the primary reference for brand-safety agents, vendor platforms, and any party generating content on behalf of Firefox or Mozilla. It converts owner-stated and evidence-supported limits into precise agent instructions with triggers, allowed alternatives, and escalation conditions.
---
## Hard nos
These are absolute. No exceptions, no contextual allowances.
```yaml
hard_no:
- item: >
Never state or imply "Firefox blocks all tracking," "Firefox makes you
completely anonymous," or "cross-site profiling is impossible in Firefox."
Enhanced Tracking Protection blocks known third-party trackers using
curated lists and heuristics; it does not prevent first-party data
collection and does not convert Firefox into an anonymity network like Tor.
trigger: any copy describing ETP, fingerprinting protection, or privacy scope
allowed_alternative: >
Describe structural controls against cross-site surveillance, not
unconditional guarantees. Example: "Enhanced Tracking Protection blocks
cross-site tracking by default because continuous, unconsented commercial
surveillance violates fundamental user autonomy."
tier: core
- item: >
Never state "Mozilla never collects data from your browser" or "Firefox
operates with zero telemetry." The Firefox Privacy Notice explicitly states
that Firefox collects technical and interaction telemetry (crash reports,
feature usage, performance metrics) by default to improve browser stability.
Users can opt out in settings; the default is not zero collection.
trigger: any copy touching data collection, telemetry, or browser diagnostics
allowed_alternative: >
Describe data minimization and user control: "Firefox minimizes default
data collection, keeping browsing history stored locally on your device
rather than centralizing it for commercial use."
tier: core
- item: >
Never claim that Mozilla's non-profit governance exempts Firefox from
privacy law, or that Mozilla's mission-driven model makes standard privacy
regulations inapplicable. The Mozilla Corporation is a taxable subsidiary
fully subject to GDPR, CCPA/CPRA, FTC regulations, and international
consumer protection law. Public-benefit governance determines corporate
incentives, not legal immunity.
trigger: any copy pairing governance structure with regulatory claims
allowed_alternative: >
Distinguish incentive structure from legal exemption: "Mozilla's non-profit
ownership changes what Firefox is optimized for — not what laws apply to it."
tier: core
- item: >
Never assert that Firefox prevents search engines or websites from recording
what a user does on their own platforms. ETP restricts cross-site tracker
networks; it cannot alter the data practices of a first-party site the user
directly interacts with, nor does it override default search provider
policies (e.g., Google) when a user submits a search query.
trigger: any copy describing the scope of tracking protection or search privacy
allowed_alternative: >
Scope the claim accurately: "Firefox blocks cross-site surveillance networks,
not the first-party data practices of sites you choose to visit."
tier: core
- item: >
Never use the standalone phrase "we never sell your data" or "Mozilla never
sells your data" as a blanket, unqualified promise. Mozilla removed this
language from its Terms of Use because the legal definition of "sale of
data" under statutes such as CCPA is broad and evolving, and Firefox does
collect and share some data with partners (including for optional sponsored
features) under the conditions described in the Privacy Notice.
trigger: >
any copy making data-sale claims, including FAQ copy, comparison tables,
privacy pitch language, and ad headlines
allowed_alternative: >
Use practice-based framing that distinguishes Mozilla from data brokers and
names specific safeguards. Owner-approved examples:
(1) "Mozilla does not sell personal browsing profiles or profit from
cross-site tracking, using privacy-preserving safeguards to protect user
identities across its limited commercial partnerships."
(2) "Unlike ad-first platforms, Firefox does not monetize your individual
web activity; data associated with built-in partner features is aggregated
or anonymized to prevent personal identification."
legal_context: >
CCPA defines "sale" broadly to include disclosing or transferring personal
data for any "valuable consideration," not only cash transactions. Mozilla
cited this definition explicitly when updating Terms of Use language
(TechCrunch, 2025-03-03).
tier: core
- item: >
Never use broad data-license language that implies Mozilla claims ownership
of or unrestricted rights to user content. The phrase "nonexclusive,
royalty-free, worldwide license" used in the February 2025 Terms of Use
triggered user backlash and directly contradicted Mozilla's privacy
positioning. That language was revised. Agents must not reproduce or echo it.
trigger: >
any copy describing what Mozilla may do with user data, license grants,
or terms of use summaries
allowed_alternative: >
Reference the current Privacy Notice for precise scope; do not paraphrase
license grants without legal review.
tier: core
- item: >
Never imply that Mozilla uses Firefox user data for AI training or sells it
to advertisers. Mozilla's VP of Communications stated explicitly: "These
changes are not driven by a desire by Mozilla to use people's data for AI
or sell it to advertisers." (Brandon Borrman, TechCrunch, 2025-02-28.)
trigger: >
any copy touching Firefox's AI features, Terms of Use changes, or Mozilla's
commercial model
allowed_alternative: >
State Mozilla's actual AI data model: built-in AI features run on-device
and do not send content data to Mozilla. If a user opts in to a third-party
chatbot, that third party processes data under its own policies.
tier: core
- item: >
Never frame a Firefox feature as a "convenient user perk" or a product
benefit that "gives you" something. Features must be framed as the
architectural enforcement of a fundamental right — specifically, what they
prevent others from taking — not as optional value-adds users receive.
trigger: >
any marketing copy, feature description, product page, or comparison table
referencing ETP, container tabs, fingerprinting protection, sync encryption,
or similar privacy-architecture features
allowed_alternative: >
Center default rights over settings; focus on restraining exploitation, not
delivering utility; name the structural threat. Example: "Enhanced Tracking
Protection blocks cross-site tracking by default because continuous,
unconsented commercial surveillance violates fundamental user autonomy."
tier: core
```
---
## Soft nos
These are judgment calls. Context determines appropriateness.
```yaml
soft_no:
- item: >
Avoid leading with "fast" as a primary differentiator. Speed is table stakes
and benchmarks fluctuate; every major browser — including those built by
digital advertising companies — claims speed. Speed copy does not set Firefox
apart and risks sounding indistinguishable from competitors.
tier: default
condition: >
Speed may be mentioned as a secondary, incidental attribute (e.g., "ETP
blocking trackers also reduces page load overhead") but must not anchor a
headline, comparison table column, or positioning statement.
- item: >
Avoid "privacy" as a standalone claim without grounding it in non-profit
governance, engine independence, or specific structural controls. Generic
privacy copy ("your privacy matters," "privacy by default") reads identically
to copy produced by ad-funded browser vendors and does not convey Firefox's
structural differentiation.
tier: default
condition: >
"Privacy" is acceptable when tethered to a structural claim: non-profit
governance, Gecko engine independence, on-by-default ETP, end-to-end
encrypted sync, or local AI processing.
- item: >
Avoid oversimplifying Mozilla's commercial partnerships. Firefox does collect
and share some data with partners, including for optional ads on the New Tab
page and sponsored suggestions in the search bar. Agents must not flatten
this into simple "no data sharing" claims.
tier: default
condition: >
When describing partnership data flows, use the accuracy boundary: data is
shared with advertising partners only on a de-identified or aggregated basis
(Mozilla public statement, TechCrunch, 2025-02-28). Link to the current
Privacy Notice for precise scope rather than paraphrasing.
- item: >
Avoid improvising details about how specific AI features process data. The
boundary between on-device local processing and third-party opt-in features
is precise and legally material. Do not extrapolate from general principles.
tier: default
condition: >
Escalate to Privacy Notice or current Mozilla documentation. Approved
framing: built-in AI features (e.g., Link Previews, Smart Tab Groups) run
on-device and do not send content data to Mozilla or elsewhere. Third-party
chatbot integrations are opt-in and process data under that third party's
own policies.
```
---
## Brand safety
For vendor platforms, brand-safety tools, and DSPs.
```yaml
brand_safety:
adjacency_unsuitable:
- IAB-3: Sensitive Topics / Data Privacy Violations
note: >
Content that describes, celebrates, or normalizes mass user-data
collection, cross-site tracking ecosystems, or the sale of personal
browsing profiles.
- IAB-3: Illegal Content
- IAB-3: Hate Speech / Extremism
- GARM Floor: Any content at or below the GARM Brand Safety Floor
- description: >
Content produced by or primarily promoting browser vendors whose
primary revenue model is behavioral advertising based on user-data
collection (context: browser comparison placements).
adjacency_acceptable:
- Open-source software and developer communities
- Digital rights, internet governance, and web standards publications
- Privacy-focused technology journalism
- Non-profit sector news and public-interest journalism
- Consumer technology reviews using factual, comparative methodology
adjacency_contextual:
AI_and_data_coverage:
rule: >
Acceptable adjacent to AI industry coverage when the content addresses
AI governance, data minimization, or on-device processing. Not acceptable
adjacent to content promoting surveillance-based AI products or
third-party data monetization without consent.
browser_comparison:
rule: >
Acceptable in comparison contexts when the comparison is factual and
covers governance, engine diversity, and data-handling practices.
Not acceptable in placements that assert or imply Firefox is equivalent
to Chromium-based browsers in governance or engine independence.
```
---
## Regulatory constraints
```yaml
regulatory:
framework: >
GDPR (EU/EEA), CCPA/CPRA (California), FTC Act (US), and applicable
international consumer protection laws. The Mozilla Corporation is a taxable
commercial subsidiary and is fully subject to all applicable privacy and
consumer-protection law regardless of its non-profit parent structure.
notes: >
(1) Claims about data collection, telemetry, and data sharing must be
consistent with the current Firefox Privacy Notice and Terms of Use.
Agents must not paraphrase or summarize legal disclosures without
referencing the current published documents.
(2) The CCPA definition of "sale" is broad and evolving. Any copy that could
be read as a data-sale representation requires legal review before use in
advertising, packaging, or regulated contexts.
(3) "No surprises" principle (public Mozilla policy): agents must ensure that
a user's understanding of Firefox's data practices after reading
agent-produced content matches reality as described in Mozilla's current
Privacy Notice.
restricted_claims: >
The following claim categories require legal or brand review before use in
any published context: data-sale representations; telemetry or data-collection
scope claims; regulatory compliance or immunity assertions; AI-feature data
handling details; and any claim that uses the phrase "never" in relation to
data collection, sharing, or processing.
```
---
## Tension note
Mozilla's consumer-facing Privacy FAQ retains the plain phrase "We never sell your personal data." (mozilla.org/en-US/privacy/faq/, retrieved 2026-09-14). This sits in tension with the decision to remove equivalent blanket language from the Terms of Use, which Mozilla attributed to the broad and evolving legal definition of "sale" under CCPA and similar statutes. Agents must not treat the FAQ phrase as a blanket permission to reproduce unqualified "never sell" claims in other contexts. The appropriate action is to use practice-based framing (see hard_no entry above) and, for any legally sensitive placement, request review against the current Privacy Notice.
## Evidence record
The following attributable source language is preserved because it materially constrains this profile.
### Owner-confirmed evidence
> AI features: if users opt in to third-party chatbots the third party processes data per its own policies, and other AI features run locally without sending content data to Mozilla — details agents must not improvise.
Source: Public source
### Owner-confirmed evidence
> Mozilla states its changes are not driven by a desire to use people's data for AI or sell it to advertisers.
Source: Public source
### Owner-confirmed evidence
> Mozilla removed blanket claims that it never sells user data from its Terms of Use because the legal definition of 'sale of data' is broad and evolving.
Source: Public source
### Qualification
> Firefox does collect and share some data with its partners, Mozilla said, including data that helps to power its optional ads on the New Tab page in the browser and for sponsored suggestions in the search bar
Source: techcrunch.com — https://techcrunch.com/2025/03/03/mozilla-rewrites-firefoxs-terms-of-use-after-user-backlash/