Privacy, security, and permissions
See what stays on the device, what reaches the account service, how site permissions work, and what the blocker can and cannot do.
Trust10 minUpdated July 16, 2026
Local by default
- Saved links, themes, browser state, website sessions, permission choices, voice settings, recordings, and transcripts stay on the device.
- Account services receive limited identity, consent, entitlement, device, session, and release metadata.
- Crash dumps remain local unless you choose to share them.
- Diagnostics exports intentionally exclude URLs, titles, emails, tokens, and theme contents.
Site permissions
Remote pages do not receive the privileged Side Whisper bridge. Permission decisions pass through a minimal, validated path and are scoped to supported capabilities.
- Camera, microphone, location, notifications, clipboard read, display capture, and supported MIDI permissions
- Origin-scoped decisions and explicit screen selection
- Unknown or unsupported capabilities fail closed
Ad and tracker blocking
The blocker runs locally with Ghostery’s engine and EasyList/EasyPrivacy-compatible rules. You can disable it per domain and inspect the local blocked-request count.