This record is managed by an account, but domain control has not been proven.
claims.md
---
bcp_version: "1.1.1"
file_type: claims
parent: https://registry.brandcontextprotocol.dev/firefox-8df36a3b/.well-known/brand.md
last_updated: 2026-09-14
---
# Claims
All marketing claims Firefox and Mozilla are authorized to make. Agents generating copy must draw from this file. Do not introduce claims absent from this file.
> **Legal review notice:** Claims below are compiled from available public evidence and owner-confirmed interview statements. `proof_status` records evidence and owner-confirmation state. It is not legal advice and does not replace review by Legal or the accountable brand owner before use in advertising, packaging, sales, regulated, or comparative contexts.
---
## Approved at launch
```yaml
approved_at_launch:
- claim: >
Firefox blocks trackers automatically and protects your privacy by
default, so you can browse confidently without becoming a privacy expert.
tier: default
proof_status: approved
owner: "[gap]"
validity_window:
valid_from: 2026-09-14
valid_until: null
source_hash: "e919c1473ffe62b180ddd283c6556c8e9b2146eb0c9f589fa92304861bed152b"
exact_text: true
approved_language: >
Firefox blocks trackers automatically and protects your privacy by
default, so you can browse confidently without becoming a privacy expert.
evidence: >
First-party claim published on firefox.com/features (retrieved
2026-09-14). Owner confirmed in interview that rights-based and
governance framing is approved for agent use, with caveats on scope
(see requires_caveat section).
- claim: >
Mozilla does not sell personal browsing profiles or profit from
cross-site tracking; privacy-preserving safeguards protect user
identities across its limited commercial partnerships.
tier: default
proof_status: approved
owner: "[gap]"
validity_window:
valid_from: 2026-09-14
valid_until: null
source_hash: "853b536dfe92cfb4b667db77a104a5b23adcad0a6a8dd201ab60b6e510254b4b"
exact_text: false
approved_language: null
evidence: >
Owner confirmed in interview. Mozilla's public blog post (blog.mozilla.org,
retrieved 2026-09-14) explicitly states: "Mozilla doesn't sell data about
you (in the way that most people think about 'selling data'), and we don't
buy data about you." Approved framing distinguishes traditional data
brokerage from privacy-preserving product monetization. Blanket
"we never sell your data" language is forbidden (see forbidden section).
- claim: >
Unlike ad-first platforms, Firefox does not monetize individual web
activity; data associated with built-in partner features is aggregated
or anonymized to prevent personal identification.
tier: default
proof_status: approved
owner: "[gap]"
validity_window:
valid_from: 2026-09-14
valid_until: null
source_hash: "853b536dfe92cfb4b667db77a104a5b23adcad0a6a8dd201ab60b6e510254b4b"
exact_text: false
approved_language: null
evidence: >
Owner-confirmed approved example in interview. Grounds commercial
integrations in specific privacy-preserving safeguards (aggregation,
anonymized proxies) rather than absolute legal promises.
- claim: >
Firefox minimizes default data collection, keeping browsing history
stored locally on your device rather than centralizing it for
commercial use.
tier: default
proof_status: approved
owner: "[gap]"
validity_window:
valid_from: 2026-09-14
valid_until: null
source_hash: "853b536dfe92cfb4b667db77a104a5b23adcad0a6a8dd201ab60b6e510254b4b"
exact_text: false
approved_language: null
evidence: >
Owner-confirmed approved framing in interview. Focuses on default data
collection policies rather than absolute legal promises, consistent with
Mozilla's public privacy disclosures.
- claim: >
The Firefox terms of use grant Mozilla a nonexclusive, royalty-free,
worldwide license only to do as the user requests with content input in
Firefox, and give Mozilla no ownership of that content.
tier: core
proof_status: "requires_caveat"
owner: Legal
validity_window:
valid_from: 2026-09-14
valid_until: null
source_hash: "853b536dfe92cfb4b667db77a104a5b23adcad0a6a8dd201ab60b6e510254b4b"
exact_text: true
approved_language: >
a nonexclusive, royalty-free, worldwide license for the purpose of doing
as you request with the content you input in Firefox. This does not give
Mozilla any ownership in that content.
evidence: >
Sourced verbatim from blog.mozilla.org (update on terms of use, retrieved
2026-09-14). Legal claim; must be reproduced exactly as approved_language
above when cited.
- claim: >
Enhanced Tracking Protection blocks cross-site tracking by default
because continuous, unconsented commercial surveillance violates
fundamental user autonomy.
tier: default
proof_status: "requires_caveat"
owner: "[gap]"
validity_window:
valid_from: 2026-09-14
valid_until: null
source_hash: "[gap]"
exact_text: false
approved_language: null
evidence: >
Owner-confirmed framing in interview. This is the approved rights-based
framing for product features: center default rights, focus on restraining
exploitation, name the structural threat. Source document for ETP
mechanics is Mozilla technical documentation (not directly retrieved).
```
---
## Requires caveat
```yaml
requires_caveat:
- claim: >
Firefox rolled out Total Cookie Protection by default to all Firefox
users worldwide, making Firefox the most private and secure major browser
available across Windows, Mac, Linux and Android.
tier: default
proof_status: requires_caveat
owner: "[gap]"
validity_window:
valid_from: 2026-09-14
valid_until: null
source_hash: "26b762e05a490b12d060018fa9ab0158dd69d5d7b549208aee34480020f93141"
exact_text: false
approved_language: null
caveat: >
"Most private and secure major browser" is Mozilla's own self-assessment
(blog.mozilla.org, retrieved 2026-09-14), not an independently verified
superlative. Agents must not reproduce this as a verified third-party
finding. When using this claim, attribute it explicitly to Mozilla's
characterization or scope it to Total Cookie Protection's specific
protections rather than treating it as an unqualified absolute.
evidence: >
Source: blog.mozilla.org Total Cookie Protection rollout post (retrieved
2026-09-14). Owner confirmed Total Cookie Protection default rollout as
an approved fact; however, the "most private and secure" superlative
is Mozilla self-assessment and carries independent-source confidence
of 0.6 only.
- claim: >
Mozilla does not sell data about you in the way that most people think
about selling data, and does not buy data about you.
tier: default
proof_status: requires_caveat
owner: "[gap]"
validity_window:
valid_from: 2026-09-14
valid_until: null
source_hash: "853b536dfe92cfb4b667db77a104a5b23adcad0a6a8dd201ab60b6e510254b4b"
exact_text: false
approved_language: null
caveat: >
This claim requires the qualifier "in the way that most people think about
selling data." Mozilla's public blog explicitly explains it changed its
language because some jurisdictions define "sell" more broadly than most
people understand. Do not use a standalone, unqualified "we never sell
your data" claim. Always pair with the approved framing that distinguishes
traditional data brokerage from privacy-preserving product monetization,
and note that commercial partnerships (search engine agreements, sponsored
new-tab features) exist.
evidence: >
Source: blog.mozilla.org update on terms of use (retrieved 2026-09-14).
Owner confirmed in interview that the blanket standalone claim is retired;
caveated practice-based descriptions are approved.
- claim: >
Firefox uses privacy-preserving architectures — such as data aggregation
and anonymized proxies — to run optional sponsored features without
exposing individual identities.
tier: default
proof_status: requires_caveat
owner: "[gap]"
validity_window:
valid_from: 2026-09-14
valid_until: null
source_hash: "[gap]"
exact_text: false
approved_language: null
caveat: >
This claim describes technical architecture Mozilla has publicly
referenced. Before use in advertising or regulated contexts, confirm
current implementation details against Mozilla's technical documentation
and privacy notices. Do not extend this claim to assert zero data
transmission to commercial partners.
evidence: >
Owner-confirmed framing in interview. Specific technical documentation
(Oblivious HTTP, aggregation methodology) not independently retrieved
in this package; source_hash is [gap] pending primary source retrieval.
```
---
## Forbidden
```yaml
forbidden:
- claim: "Firefox blocks all tracking."
tier: core
proof_status: forbidden
owner: Legal
validity_window:
valid_from: 2026-09-14
valid_until: null
source_hash: "[gap]"
exact_text: false
approved_language: null
reason: >
Owner explicitly prohibited in interview. Mozilla's own technical
documentation states Enhanced Tracking Protection blocks known
third-party trackers using curated lists and heuristics — not all
tracking. ETP does not prevent first-party data collection. Claiming
total protection contradicts Mozilla's legal disclosures.
- claim: "Firefox makes you completely anonymous."
tier: core
proof_status: forbidden
owner: Legal
validity_window:
valid_from: 2026-09-14
valid_until: null
source_hash: "[gap]"
exact_text: false
approved_language: null
reason: >
Owner explicitly prohibited in interview. Firefox is not an anonymity
network. Standard mode deliberately balances tracking protections against
site compatibility. Claiming complete anonymity directly contradicts
Mozilla's technical documentation.
- claim: "Cross-site profiling is impossible in Firefox."
tier: core
proof_status: forbidden
owner: Legal
validity_window:
valid_from: 2026-09-14
valid_until: null
source_hash: "[gap]"
exact_text: false
approved_language: null
reason: >
Owner explicitly prohibited in interview. Firefox's protections reduce
cross-site profiling risk; they do not make it technically impossible.
This claim overstates the technical guarantee.
- claim: "Mozilla never collects data from your browser."
tier: core
proof_status: forbidden
owner: Legal
validity_window:
valid_from: 2026-09-14
valid_until: null
source_hash: "[gap]"
exact_text: false
approved_language: null
reason: >
Owner explicitly prohibited in interview. Firefox Privacy Notice
explicitly details that Firefox collects technical and interaction
telemetry (crash reports, feature usage, performance metrics) by default.
This claim directly contradicts Mozilla's legal disclosures.
- claim: "Firefox operates with zero telemetry."
tier: core
proof_status: forbidden
owner: Legal
validity_window:
valid_from: 2026-09-14
valid_until: null
source_hash: "[gap]"
exact_text: false
approved_language: null
reason: >
Owner explicitly prohibited in interview. Contradicts Mozilla's Firefox
Privacy Notice, which discloses default telemetry collection. Users may
opt out in settings, but the default state includes telemetry.
- claim: >
Mozilla's non-profit governance exempts it from privacy laws, or
Firefox's mission-driven model makes standard privacy regulations
inapplicable.
tier: core
proof_status: forbidden
owner: Legal
validity_window:
valid_from: 2026-09-14
valid_until: null
source_hash: "[gap]"
exact_text: false
approved_language: null
reason: >
Owner explicitly prohibited in interview. Firefox is operated by the
Mozilla Corporation — a taxable subsidiary owned by the non-profit Mozilla
Foundation — and is fully subject to GDPR, CCPA/CPRA, FTC regulations,
and international consumer protection laws. Non-profit governance
determines corporate incentives, not legal immunity.
- claim: >
Firefox prevents search engines or websites from recording what you
do on their platforms.
tier: core
proof_status: forbidden
owner: Legal
validity_window:
valid_from: 2026-09-14
valid_until: null
source_hash: "[gap]"
exact_text: false
approved_language: null
reason: >
Owner explicitly prohibited in interview. Enhanced Tracking Protection
restricts cross-site surveillance and third-party tracker networks. It
cannot alter the data practices of a first-party site a user directly
interacts with, nor does it override the privacy policies of default
search providers (such as Google) when a user submits a search query.
- claim: "We never sell your data."
tier: core
proof_status: forbidden
owner: Legal
validity_window:
valid_from: 2026-09-14
valid_until: null
source_hash: "853b536dfe92cfb4b667db77a104a5b23adcad0a6a8dd201ab60b6e510254b4b"
exact_text: false
approved_language: null
reason: >
Owner confirmed in interview and Mozilla's public blog confirms: Mozilla
stepped away from this blanket standalone claim because the CCPA and other
jurisdictions define "sale of data" broadly — potentially encompassing
disclosing, transferring, or making personal data available for any
"valuable consideration." Firefox has commercial partnerships (search
engine agreements, sponsored new-tab features) that could intersect with
broad statutory definitions. The standalone claim is legally unsafe.
Use approved caveated alternatives in the approved_at_launch section.
```
---
## Agent framing rules (non-claim, operational guidance)
These rules govern how agents use approved claims. They are not claims themselves.
1. **Rights over features.** Frame every feature as the non-negotiable architectural enforcement of a fundamental right, never as a convenient user perk. Describe what the product prevents others from taking, not what the product gives the user.
2. **Structural controls, never unconditional guarantees.** The guiding boundary confirmed by the owner: describe structural controls against cross-site surveillance, never unconditional guarantees against all data collection.
3. **Governance before specs.** The real differentiator is governance (non-profit foundation, independent engine, no shareholder profit motive), not benchmark performance. Do not lead with speed claims.
4. **No absolute protection or anonymity language.** Any claim that implies total, complete, impossible, zero, or never in the context of tracking, anonymity, or data collection is forbidden unless that exact word is present in an approved_at_launch entry with `exact_text: true`.
5. **Attribute superlatives to Mozilla.** "Most private and secure major browser" is Mozilla's self-characterization. When used, attribute it to Mozilla explicitly; do not present it as independently verified.
## Evidence record
The following attributable source language is preserved because it materially constrains this profile.
### Owner-confirmed evidence
> Caveated: rights-based and governance framing is approved, but absolute protection claims ('blocks all tracking', 'zero telemetry', 'complete anonymity'), regulatory immunity claims, and first-party/partner scope claims are forbidden because they contradict Mozilla's own legal disclosures and technical documentation.
Source: Public source
### Counterevidence
> The reason we’ve stepped away from making blanket claims that “We never sell your data” is because, in some places, the LEGAL definition of “sale of data” is broad and evolving.
Source: blog.mozilla.org — https://blog.mozilla.org/en/firefox/update-on-terms-of-use/
### Owner-confirmed evidence
> Mozilla's own technical documentation and privacy notices confirm that Enhanced Tracking Protection blocks known third-party trackers using curated lists and heuristics, not all tracking; Firefox Privacy Notice explicitly details telemetry collection by default; Mozilla Corporation is subject to GDPR, CCPA/CPRA, and FTC regulations; ETP cannot alter first-party site data practices or override default search provider policies.
Source: Public source
### Qualification
> the California Consumer Privacy Act (CCPA) defines “sale” as the “selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer’s personal information by [a] business to another business or a third party” in exchange for “monetary” or “other valuable consideration.”
Source: blog.mozilla.org — https://blog.mozilla.org/en/firefox/update-on-terms-of-use/
### Owner-confirmed evidence
> Firefox rolled out Total Cookie Protection by default to all Firefox users worldwide, which Mozilla describes as making Firefox the most private and secure major browser across Windows, Mac, Linux and Android.
Source: Public source
### Qualification
> Mozilla doesn’t sell data about you (in the way that most people think about “selling data”), and we don’t buy data about you. We changed our language because some jurisdictions define “sell” more broadly than most people would usually understand that word.
Source: blog.mozilla.org — https://blog.mozilla.org/en/firefox/update-on-terms-of-use/