---
bcp_version: "0.8"
file_type: claims
parent: https://registry.brandcontextprotocol.dev/firefox-8df36a3b/.well-known/brand.md
last_updated: 2026-09-14
---

# Claims

All marketing claims Firefox and Mozilla are authorized to make. Agents generating copy must draw from this file. Do not introduce claims absent from this file.

> **Legal review notice:** Claims below are compiled from available public evidence and owner-confirmed interview statements. `proof_status` records evidence and owner-confirmation state. It is not legal advice and does not replace review by Legal or the accountable brand owner before use in advertising, packaging, sales, regulated, or comparative contexts.

---

## Approved at launch

```yaml
approved_at_launch:

  - claim: >
      Firefox blocks trackers automatically and protects your privacy by
      default, so you can browse confidently without becoming a privacy expert.
    tier: default
    proof_status: approved
    owner: "[gap]"
    validity_window:
      valid_from: 2026-09-14
      valid_until: null
    source_hash: "e919c1473ffe62b180ddd283c6556c8e9b2146eb0c9f589fa92304861bed152b"
    exact_text: true
    approved_language: >
      Firefox blocks trackers automatically and protects your privacy by
      default, so you can browse confidently without becoming a privacy expert.
    evidence: >
      First-party claim published on firefox.com/features (retrieved
      2026-09-14). Owner confirmed in interview that rights-based and
      governance framing is approved for agent use, with caveats on scope
      (see requires_caveat section).

  - claim: >
      Mozilla does not sell personal browsing profiles or profit from
      cross-site tracking; privacy-preserving safeguards protect user
      identities across its limited commercial partnerships.
    tier: default
    proof_status: approved
    owner: "[gap]"
    validity_window:
      valid_from: 2026-09-14
      valid_until: null
    source_hash: "853b536dfe92cfb4b667db77a104a5b23adcad0a6a8dd201ab60b6e510254b4b"
    exact_text: false
    approved_language: null
    evidence: >
      Owner confirmed in interview. Mozilla's public blog post (blog.mozilla.org,
      retrieved 2026-09-14) explicitly states: "Mozilla doesn't sell data about
      you (in the way that most people think about 'selling data'), and we don't
      buy data about you." Approved framing distinguishes traditional data
      brokerage from privacy-preserving product monetization. Blanket
      "we never sell your data" language is forbidden (see forbidden section).

  - claim: >
      Unlike ad-first platforms, Firefox does not monetize individual web
      activity; data associated with built-in partner features is aggregated
      or anonymized to prevent personal identification.
    tier: default
    proof_status: approved
    owner: "[gap]"
    validity_window:
      valid_from: 2026-09-14
      valid_until: null
    source_hash: "853b536dfe92cfb4b667db77a104a5b23adcad0a6a8dd201ab60b6e510254b4b"
    exact_text: false
    approved_language: null
    evidence: >
      Owner-confirmed approved example in interview. Grounds commercial
      integrations in specific privacy-preserving safeguards (aggregation,
      anonymized proxies) rather than absolute legal promises.

  - claim: >
      Firefox minimizes default data collection, keeping browsing history
      stored locally on your device rather than centralizing it for
      commercial use.
    tier: default
    proof_status: approved
    owner: "[gap]"
    validity_window:
      valid_from: 2026-09-14
      valid_until: null
    source_hash: "853b536dfe92cfb4b667db77a104a5b23adcad0a6a8dd201ab60b6e510254b4b"
    exact_text: false
    approved_language: null
    evidence: >
      Owner-confirmed approved framing in interview. Focuses on default data
      collection policies rather than absolute legal promises, consistent with
      Mozilla's public privacy disclosures.

  - claim: >
      The Firefox terms of use grant Mozilla a nonexclusive, royalty-free,
      worldwide license only to do as the user requests with content input in
      Firefox, and give Mozilla no ownership of that content.
    tier: core
    proof_status: "requires_caveat"
    owner: Legal
    validity_window:
      valid_from: 2026-09-14
      valid_until: null
    source_hash: "853b536dfe92cfb4b667db77a104a5b23adcad0a6a8dd201ab60b6e510254b4b"
    exact_text: true
    approved_language: >
      a nonexclusive, royalty-free, worldwide license for the purpose of doing
      as you request with the content you input in Firefox. This does not give
      Mozilla any ownership in that content.
    evidence: >
      Sourced verbatim from blog.mozilla.org (update on terms of use, retrieved
      2026-09-14). Legal claim; must be reproduced exactly as approved_language
      above when cited.

  - claim: >
      Enhanced Tracking Protection blocks cross-site tracking by default
      because continuous, unconsented commercial surveillance violates
      fundamental user autonomy.
    tier: default
    proof_status: "requires_caveat"
    owner: "[gap]"
    validity_window:
      valid_from: 2026-09-14
      valid_until: null
    source_hash: "[gap]"
    exact_text: false
    approved_language: null
    evidence: >
      Owner-confirmed framing in interview. This is the approved rights-based
      framing for product features: center default rights, focus on restraining
      exploitation, name the structural threat. Source document for ETP
      mechanics is Mozilla technical documentation (not directly retrieved).
```

---

## Requires caveat

```yaml
requires_caveat:

  - claim: >
      Firefox rolled out Total Cookie Protection by default to all Firefox
      users worldwide, making Firefox the most private and secure major browser
      available across Windows, Mac, Linux and Android.
    tier: default
    proof_status: requires_caveat
    owner: "[gap]"
    validity_window:
      valid_from: 2026-09-14
      valid_until: null
    source_hash: "26b762e05a490b12d060018fa9ab0158dd69d5d7b549208aee34480020f93141"
    exact_text: false
    approved_language: null
    caveat: >
      "Most private and secure major browser" is Mozilla's own self-assessment
      (blog.mozilla.org, retrieved 2026-09-14), not an independently verified
      superlative. Agents must not reproduce this as a verified third-party
      finding. When using this claim, attribute it explicitly to Mozilla's
      characterization or scope it to Total Cookie Protection's specific
      protections rather than treating it as an unqualified absolute.
    evidence: >
      Source: blog.mozilla.org Total Cookie Protection rollout post (retrieved
      2026-09-14). Owner confirmed Total Cookie Protection default rollout as
      an approved fact; however, the "most private and secure" superlative
      is Mozilla self-assessment and carries independent-source confidence
      of 0.6 only.

  - claim: >
      Mozilla does not sell data about you in the way that most people think
      about selling data, and does not buy data about you.
    tier: default
    proof_status: requires_caveat
    owner: "[gap]"
    validity_window:
      valid_from: 2026-09-14
      valid_until: null
    source_hash: "853b536dfe92cfb4b667db77a104a5b23adcad0a6a8dd201ab60b6e510254b4b"
    exact_text: false
    approved_language: null
    caveat: >
      This claim requires the qualifier "in the way that most people think about
      selling data." Mozilla's public blog explicitly explains it changed its
      language because some jurisdictions define "sell" more broadly than most
      people understand. Do not use a standalone, unqualified "we never sell
      your data" claim. Always pair with the approved framing that distinguishes
      traditional data brokerage from privacy-preserving product monetization,
      and note that commercial partnerships (search engine agreements, sponsored
      new-tab features) exist.
    evidence: >
      Source: blog.mozilla.org update on terms of use (retrieved 2026-09-14).
      Owner confirmed in interview that the blanket standalone claim is retired;
      caveated practice-based descriptions are approved.

  - claim: >
      Firefox uses privacy-preserving architectures — such as data aggregation
      and anonymized proxies — to run optional sponsored features without
      exposing individual identities.
    tier: default
    proof_status: requires_caveat
    owner: "[gap]"
    validity_window:
      valid_from: 2026-09-14
      valid_until: null
    source_hash: "[gap]"
    exact_text: false
    approved_language: null
    caveat: >
      This claim describes technical architecture Mozilla has publicly
      referenced. Before use in advertising or regulated contexts, confirm
      current implementation details against Mozilla's technical documentation
      and privacy notices. Do not extend this claim to assert zero data
      transmission to commercial partners.
    evidence: >
      Owner-confirmed framing in interview. Specific technical documentation
      (Oblivious HTTP, aggregation methodology) not independently retrieved
      in this package; source_hash is [gap] pending primary source retrieval.
```

---

## Forbidden

```yaml
forbidden:

  - claim: "Firefox blocks all tracking."
    tier: core
    proof_status: forbidden
    owner: Legal
    validity_window:
      valid_from: 2026-09-14
      valid_until: null
    source_hash: "[gap]"
    exact_text: false
    approved_language: null
    reason: >
      Owner explicitly prohibited in interview. Mozilla's own technical
      documentation states Enhanced Tracking Protection blocks known
      third-party trackers using curated lists and heuristics — not all
      tracking. ETP does not prevent first-party data collection. Claiming
      total protection contradicts Mozilla's legal disclosures.

  - claim: "Firefox makes you completely anonymous."
    tier: core
    proof_status: forbidden
    owner: Legal
    validity_window:
      valid_from: 2026-09-14
      valid_until: null
    source_hash: "[gap]"
    exact_text: false
    approved_language: null
    reason: >
      Owner explicitly prohibited in interview. Firefox is not an anonymity
      network. Standard mode deliberately balances tracking protections against
      site compatibility. Claiming complete anonymity directly contradicts
      Mozilla's technical documentation.

  - claim: "Cross-site profiling is impossible in Firefox."
    tier: core
    proof_status: forbidden
    owner: Legal
    validity_window:
      valid_from: 2026-09-14
      valid_until: null
    source_hash: "[gap]"
    exact_text: false
    approved_language: null
    reason: >
      Owner explicitly prohibited in interview. Firefox's protections reduce
      cross-site profiling risk; they do not make it technically impossible.
      This claim overstates the technical guarantee.

  - claim: "Mozilla never collects data from your browser."
    tier: core
    proof_status: forbidden
    owner: Legal
    validity_window:
      valid_from: 2026-09-14
      valid_until: null
    source_hash: "[gap]"
    exact_text: false
    approved_language: null
    reason: >
      Owner explicitly prohibited in interview. Firefox Privacy Notice
      explicitly details that Firefox collects technical and interaction
      telemetry (crash reports, feature usage, performance metrics) by default.
      This claim directly contradicts Mozilla's legal disclosures.

  - claim: "Firefox operates with zero telemetry."
    tier: core
    proof_status: forbidden
    owner: Legal
    validity_window:
      valid_from: 2026-09-14
      valid_until: null
    source_hash: "[gap]"
    exact_text: false
    approved_language: null
    reason: >
      Owner explicitly prohibited in interview. Contradicts Mozilla's Firefox
      Privacy Notice, which discloses default telemetry collection. Users may
      opt out in settings, but the default state includes telemetry.

  - claim: >
      Mozilla's non-profit governance exempts it from privacy laws, or
      Firefox's mission-driven model makes standard privacy regulations
      inapplicable.
    tier: core
    proof_status: forbidden
    owner: Legal
    validity_window:
      valid_from: 2026-09-14
      valid_until: null
    source_hash: "[gap]"
    exact_text: false
    approved_language: null
    reason: >
      Owner explicitly prohibited in interview. Firefox is operated by the
      Mozilla Corporation — a taxable subsidiary owned by the non-profit Mozilla
      Foundation — and is fully subject to GDPR, CCPA/CPRA, FTC regulations,
      and international consumer protection laws. Non-profit governance
      determines corporate incentives, not legal immunity.

  - claim: >
      Firefox prevents search engines or websites from recording what you
      do on their platforms.
    tier: core
    proof_status: forbidden
    owner: Legal
    validity_window:
      valid_from: 2026-09-14
      valid_until: null
    source_hash: "[gap]"
    exact_text: false
    approved_language: null
    reason: >
      Owner explicitly prohibited in interview. Enhanced Tracking Protection
      restricts cross-site surveillance and third-party tracker networks. It
      cannot alter the data practices of a first-party site a user directly
      interacts with, nor does it override the privacy policies of default
      search providers (such as Google) when a user submits a search query.

  - claim: "We never sell your data."
    tier: core
    proof_status: forbidden
    owner: Legal
    validity_window:
      valid_from: 2026-09-14
      valid_until: null
    source_hash: "853b536dfe92cfb4b667db77a104a5b23adcad0a6a8dd201ab60b6e510254b4b"
    exact_text: false
    approved_language: null
    reason: >
      Owner confirmed in interview and Mozilla's public blog confirms: Mozilla
      stepped away from this blanket standalone claim because the CCPA and other
      jurisdictions define "sale of data" broadly — potentially encompassing
      disclosing, transferring, or making personal data available for any
      "valuable consideration." Firefox has commercial partnerships (search
      engine agreements, sponsored new-tab features) that could intersect with
      broad statutory definitions. The standalone claim is legally unsafe.
      Use approved caveated alternatives in the approved_at_launch section.
```

---

## Agent framing rules (non-claim, operational guidance)

These rules govern how agents use approved claims. They are not claims themselves.

1. **Rights over features.** Frame every feature as the non-negotiable architectural enforcement of a fundamental right, never as a convenient user perk. Describe what the product prevents others from taking, not what the product gives the user.

2. **Structural controls, never unconditional guarantees.** The guiding boundary confirmed by the owner: describe structural controls against cross-site surveillance, never unconditional guarantees against all data collection.

3. **Governance before specs.** The real differentiator is governance (non-profit foundation, independent engine, no shareholder profit motive), not benchmark performance. Do not lead with speed claims.

4. **No absolute protection or anonymity language.** Any claim that implies total, complete, impossible, zero, or never in the context of tracking, anonymity, or data collection is forbidden unless that exact word is present in an approved_at_launch entry with `exact_text: true`.

5. **Attribute superlatives to Mozilla.** "Most private and secure major browser" is Mozilla's self-characterization. When used, attribute it to Mozilla explicitly; do not present it as independently verified.

## Evidence record

The following attributable source language is preserved because it materially constrains this profile.

### Owner-confirmed evidence

> Caveated: rights-based and governance framing is approved, but absolute protection claims ('blocks all tracking', 'zero telemetry', 'complete anonymity'), regulatory immunity claims, and first-party/partner scope claims are forbidden because they contradict Mozilla's own legal disclosures and technical documentation.

Source: Public source

### Counterevidence

> The reason we’ve stepped away from making blanket claims that “We never sell your data” is because, in some places, the LEGAL definition of “sale of data” is broad and evolving.

Source: blog.mozilla.org — https://blog.mozilla.org/en/firefox/update-on-terms-of-use/

### Owner-confirmed evidence

> Mozilla's own technical documentation and privacy notices confirm that Enhanced Tracking Protection blocks known third-party trackers using curated lists and heuristics, not all tracking; Firefox Privacy Notice explicitly details telemetry collection by default; Mozilla Corporation is subject to GDPR, CCPA/CPRA, and FTC regulations; ETP cannot alter first-party site data practices or override default search provider policies.

Source: Public source

### Qualification

> the California Consumer Privacy Act (CCPA) defines “sale” as the “selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer’s personal information by [a] business to another business or a third party” in exchange for “monetary” or “other valuable consideration.”

Source: blog.mozilla.org — https://blog.mozilla.org/en/firefox/update-on-terms-of-use/

### Owner-confirmed evidence

> Firefox rolled out Total Cookie Protection by default to all Firefox users worldwide, which Mozilla describes as making Firefox the most private and secure major browser across Windows, Mac, Linux and Android.

Source: Public source

### Qualification

> Mozilla doesn’t sell data about you (in the way that most people think about “selling data”), and we don’t buy data about you. We changed our language because some jurisdictions define “sell” more broadly than most people would usually understand that word.

Source: blog.mozilla.org — https://blog.mozilla.org/en/firefox/update-on-terms-of-use/
