---
bcp_version: "0.8"
file_type: boundaries
parent: https://registry.brandcontextprotocol.dev/firefox-8df36a3b/.well-known/brand.md
last_updated: 2026-09-14
---

# Boundaries

This file is the primary reference for brand-safety agents, vendor platforms, and any party generating content on behalf of Firefox or Mozilla. It converts owner-stated and evidence-supported limits into precise agent instructions with triggers, allowed alternatives, and escalation conditions.

---

## Hard nos

These are absolute. No exceptions, no contextual allowances.

```yaml
hard_no:

  - item: >
      Never state or imply "Firefox blocks all tracking," "Firefox makes you
      completely anonymous," or "cross-site profiling is impossible in Firefox."
      Enhanced Tracking Protection blocks known third-party trackers using
      curated lists and heuristics; it does not prevent first-party data
      collection and does not convert Firefox into an anonymity network like Tor.
    trigger: any copy describing ETP, fingerprinting protection, or privacy scope
    allowed_alternative: >
      Describe structural controls against cross-site surveillance, not
      unconditional guarantees. Example: "Enhanced Tracking Protection blocks
      cross-site tracking by default because continuous, unconsented commercial
      surveillance violates fundamental user autonomy."
    tier: core

  - item: >
      Never state "Mozilla never collects data from your browser" or "Firefox
      operates with zero telemetry." The Firefox Privacy Notice explicitly states
      that Firefox collects technical and interaction telemetry (crash reports,
      feature usage, performance metrics) by default to improve browser stability.
      Users can opt out in settings; the default is not zero collection.
    trigger: any copy touching data collection, telemetry, or browser diagnostics
    allowed_alternative: >
      Describe data minimization and user control: "Firefox minimizes default
      data collection, keeping browsing history stored locally on your device
      rather than centralizing it for commercial use."
    tier: core

  - item: >
      Never claim that Mozilla's non-profit governance exempts Firefox from
      privacy law, or that Mozilla's mission-driven model makes standard privacy
      regulations inapplicable. The Mozilla Corporation is a taxable subsidiary
      fully subject to GDPR, CCPA/CPRA, FTC regulations, and international
      consumer protection law. Public-benefit governance determines corporate
      incentives, not legal immunity.
    trigger: any copy pairing governance structure with regulatory claims
    allowed_alternative: >
      Distinguish incentive structure from legal exemption: "Mozilla's non-profit
      ownership changes what Firefox is optimized for — not what laws apply to it."
    tier: core

  - item: >
      Never assert that Firefox prevents search engines or websites from recording
      what a user does on their own platforms. ETP restricts cross-site tracker
      networks; it cannot alter the data practices of a first-party site the user
      directly interacts with, nor does it override default search provider
      policies (e.g., Google) when a user submits a search query.
    trigger: any copy describing the scope of tracking protection or search privacy
    allowed_alternative: >
      Scope the claim accurately: "Firefox blocks cross-site surveillance networks,
      not the first-party data practices of sites you choose to visit."
    tier: core

  - item: >
      Never use the standalone phrase "we never sell your data" or "Mozilla never
      sells your data" as a blanket, unqualified promise. Mozilla removed this
      language from its Terms of Use because the legal definition of "sale of
      data" under statutes such as CCPA is broad and evolving, and Firefox does
      collect and share some data with partners (including for optional sponsored
      features) under the conditions described in the Privacy Notice.
    trigger: >
      any copy making data-sale claims, including FAQ copy, comparison tables,
      privacy pitch language, and ad headlines
    allowed_alternative: >
      Use practice-based framing that distinguishes Mozilla from data brokers and
      names specific safeguards. Owner-approved examples:
      (1) "Mozilla does not sell personal browsing profiles or profit from
      cross-site tracking, using privacy-preserving safeguards to protect user
      identities across its limited commercial partnerships."
      (2) "Unlike ad-first platforms, Firefox does not monetize your individual
      web activity; data associated with built-in partner features is aggregated
      or anonymized to prevent personal identification."
    legal_context: >
      CCPA defines "sale" broadly to include disclosing or transferring personal
      data for any "valuable consideration," not only cash transactions. Mozilla
      cited this definition explicitly when updating Terms of Use language
      (TechCrunch, 2025-03-03).
    tier: core

  - item: >
      Never use broad data-license language that implies Mozilla claims ownership
      of or unrestricted rights to user content. The phrase "nonexclusive,
      royalty-free, worldwide license" used in the February 2025 Terms of Use
      triggered user backlash and directly contradicted Mozilla's privacy
      positioning. That language was revised. Agents must not reproduce or echo it.
    trigger: >
      any copy describing what Mozilla may do with user data, license grants,
      or terms of use summaries
    allowed_alternative: >
      Reference the current Privacy Notice for precise scope; do not paraphrase
      license grants without legal review.
    tier: core

  - item: >
      Never imply that Mozilla uses Firefox user data for AI training or sells it
      to advertisers. Mozilla's VP of Communications stated explicitly: "These
      changes are not driven by a desire by Mozilla to use people's data for AI
      or sell it to advertisers." (Brandon Borrman, TechCrunch, 2025-02-28.)
    trigger: >
      any copy touching Firefox's AI features, Terms of Use changes, or Mozilla's
      commercial model
    allowed_alternative: >
      State Mozilla's actual AI data model: built-in AI features run on-device
      and do not send content data to Mozilla. If a user opts in to a third-party
      chatbot, that third party processes data under its own policies.
    tier: core

  - item: >
      Never frame a Firefox feature as a "convenient user perk" or a product
      benefit that "gives you" something. Features must be framed as the
      architectural enforcement of a fundamental right — specifically, what they
      prevent others from taking — not as optional value-adds users receive.
    trigger: >
      any marketing copy, feature description, product page, or comparison table
      referencing ETP, container tabs, fingerprinting protection, sync encryption,
      or similar privacy-architecture features
    allowed_alternative: >
      Center default rights over settings; focus on restraining exploitation, not
      delivering utility; name the structural threat. Example: "Enhanced Tracking
      Protection blocks cross-site tracking by default because continuous,
      unconsented commercial surveillance violates fundamental user autonomy."
    tier: core
```

---

## Soft nos

These are judgment calls. Context determines appropriateness.

```yaml
soft_no:

  - item: >
      Avoid leading with "fast" as a primary differentiator. Speed is table stakes
      and benchmarks fluctuate; every major browser — including those built by
      digital advertising companies — claims speed. Speed copy does not set Firefox
      apart and risks sounding indistinguishable from competitors.
    tier: default
    condition: >
      Speed may be mentioned as a secondary, incidental attribute (e.g., "ETP
      blocking trackers also reduces page load overhead") but must not anchor a
      headline, comparison table column, or positioning statement.

  - item: >
      Avoid "privacy" as a standalone claim without grounding it in non-profit
      governance, engine independence, or specific structural controls. Generic
      privacy copy ("your privacy matters," "privacy by default") reads identically
      to copy produced by ad-funded browser vendors and does not convey Firefox's
      structural differentiation.
    tier: default
    condition: >
      "Privacy" is acceptable when tethered to a structural claim: non-profit
      governance, Gecko engine independence, on-by-default ETP, end-to-end
      encrypted sync, or local AI processing.

  - item: >
      Avoid oversimplifying Mozilla's commercial partnerships. Firefox does collect
      and share some data with partners, including for optional ads on the New Tab
      page and sponsored suggestions in the search bar. Agents must not flatten
      this into simple "no data sharing" claims.
    tier: default
    condition: >
      When describing partnership data flows, use the accuracy boundary: data is
      shared with advertising partners only on a de-identified or aggregated basis
      (Mozilla public statement, TechCrunch, 2025-02-28). Link to the current
      Privacy Notice for precise scope rather than paraphrasing.

  - item: >
      Avoid improvising details about how specific AI features process data. The
      boundary between on-device local processing and third-party opt-in features
      is precise and legally material. Do not extrapolate from general principles.
    tier: default
    condition: >
      Escalate to Privacy Notice or current Mozilla documentation. Approved
      framing: built-in AI features (e.g., Link Previews, Smart Tab Groups) run
      on-device and do not send content data to Mozilla or elsewhere. Third-party
      chatbot integrations are opt-in and process data under that third party's
      own policies.
```

---

## Brand safety

For vendor platforms, brand-safety tools, and DSPs.

```yaml
brand_safety:
  adjacency_unsuitable:
    - IAB-3: Sensitive Topics / Data Privacy Violations
      note: >
        Content that describes, celebrates, or normalizes mass user-data
        collection, cross-site tracking ecosystems, or the sale of personal
        browsing profiles.
    - IAB-3: Illegal Content
    - IAB-3: Hate Speech / Extremism
    - GARM Floor: Any content at or below the GARM Brand Safety Floor
    - description: >
        Content produced by or primarily promoting browser vendors whose
        primary revenue model is behavioral advertising based on user-data
        collection (context: browser comparison placements).

  adjacency_acceptable:
    - Open-source software and developer communities
    - Digital rights, internet governance, and web standards publications
    - Privacy-focused technology journalism
    - Non-profit sector news and public-interest journalism
    - Consumer technology reviews using factual, comparative methodology

  adjacency_contextual:
    AI_and_data_coverage:
      rule: >
        Acceptable adjacent to AI industry coverage when the content addresses
        AI governance, data minimization, or on-device processing. Not acceptable
        adjacent to content promoting surveillance-based AI products or
        third-party data monetization without consent.
    browser_comparison:
      rule: >
        Acceptable in comparison contexts when the comparison is factual and
        covers governance, engine diversity, and data-handling practices.
        Not acceptable in placements that assert or imply Firefox is equivalent
        to Chromium-based browsers in governance or engine independence.
```

---

## Regulatory constraints

```yaml
regulatory:
  framework: >
    GDPR (EU/EEA), CCPA/CPRA (California), FTC Act (US), and applicable
    international consumer protection laws. The Mozilla Corporation is a taxable
    commercial subsidiary and is fully subject to all applicable privacy and
    consumer-protection law regardless of its non-profit parent structure.
  notes: >
    (1) Claims about data collection, telemetry, and data sharing must be
    consistent with the current Firefox Privacy Notice and Terms of Use.
    Agents must not paraphrase or summarize legal disclosures without
    referencing the current published documents.
    (2) The CCPA definition of "sale" is broad and evolving. Any copy that could
    be read as a data-sale representation requires legal review before use in
    advertising, packaging, or regulated contexts.
    (3) "No surprises" principle (public Mozilla policy): agents must ensure that
    a user's understanding of Firefox's data practices after reading
    agent-produced content matches reality as described in Mozilla's current
    Privacy Notice.
  restricted_claims: >
    The following claim categories require legal or brand review before use in
    any published context: data-sale representations; telemetry or data-collection
    scope claims; regulatory compliance or immunity assertions; AI-feature data
    handling details; and any claim that uses the phrase "never" in relation to
    data collection, sharing, or processing.
```

---

## Tension note

Mozilla's consumer-facing Privacy FAQ retains the plain phrase "We never sell your personal data." (mozilla.org/en-US/privacy/faq/, retrieved 2026-09-14). This sits in tension with the decision to remove equivalent blanket language from the Terms of Use, which Mozilla attributed to the broad and evolving legal definition of "sale" under CCPA and similar statutes. Agents must not treat the FAQ phrase as a blanket permission to reproduce unqualified "never sell" claims in other contexts. The appropriate action is to use practice-based framing (see hard_no entry above) and, for any legally sensitive placement, request review against the current Privacy Notice.

## Evidence record

The following attributable source language is preserved because it materially constrains this profile.

### Owner-confirmed evidence

> AI features: if users opt in to third-party chatbots the third party processes data per its own policies, and other AI features run locally without sending content data to Mozilla — details agents must not improvise.

Source: Public source

### Owner-confirmed evidence

> Mozilla states its changes are not driven by a desire to use people's data for AI or sell it to advertisers.

Source: Public source

### Owner-confirmed evidence

> Mozilla removed blanket claims that it never sells user data from its Terms of Use because the legal definition of 'sale of data' is broad and evolving.

Source: Public source

### Qualification

> Firefox does collect and share some data with its partners, Mozilla said, including data that helps to power its optional ads on the New Tab page in the browser and for sponsored suggestions in the search bar

Source: techcrunch.com — https://techcrunch.com/2025/03/03/mozilla-rewrites-firefoxs-terms-of-use-after-user-backlash/
