How the browser privacy score works
Privacyassay measures selected information a website can read from your browser. Measurements run in the browser; your fingerprint is not uploaded. This page describes 0.9.2.
The score summarizes an experiment. It is not a probability of being tracked, a uniqueness estimate, or a complete browser privacy grade.
What the test covers
The catalog contains 32 readings across 13 categories, including canvas, WebGL, WebGPU, audio, fonts, layout, screen and device details. The raw report includes additional capability checks. WebRTC public-IP and cross-site storage tests are optional and off by default.
Reading states
| State | Meaning |
|---|---|
| Shown | An observable value was returned. |
| Blended | Output was masked or changed in repeated measurements. |
| Refused | An API is unsupported, access was explicitly denied, or a completed optional test returned no exposed value. |
| Unknown | The measurement was missing, invalid, failed or did not finish. It receives no protection credit. |
Score and completeness
Readings have weights of 3, 2 or 1. Each category is worth its heaviest reading, and earns the share of reading weight classified as blended or refused. Unknowns remain in the denominator.
category earned = category weight × hidden reading weight / total reading weight score = round(100 × sum(category earned) / sum(category weight))
For complete measurements, the bands are A at 90+, B at 75–89, C at 60–74, D at 40–59 and F below 40. These weights and bands are judgments, not measured tracking probabilities.
Grade I means incomplete. The displayed score is then a lower bound, accompanied by coverage and an upper bound that includes unknown readings. Incomplete results do not satisfy CLI score thresholds. They should not be compared with complete results as equivalent.
Repeated and cross-site measurements
Canvas, GPU rendering, audio, font and layout measurements run again with the same stimuli. Failed repeats are unknown. Browser names, common values or missing local fonts do not establish protection.
The cross-site test opens a second origin as a top-level window for every browser. If the window is blocked, fails to respond or serves a different methodology version, the comparison is unmeasured. Results report the number of comparable readings that changed, without claiming a tracker can or cannot recognize you.
Changing a reading does not prove resistance to averaging or linking through other attributes. Localhost comparisons are not equivalent to two registered domains. Compare the same browser/OS versions, settings, opt-ins and context.
Optional checks and privacy
The WebRTC opt-in contacts a public STUN service and reports observed candidates, completion and failures. It is not a VPN-bypass certification. The storage opt-in tests selected persistent stores with confirmed writes and readbacks; failed controls remain unknown.
The hosted comparison loads a companion page, which receives a normal web request. Measured values return between windows inside your browser. Redaction is on by default for display and saved reports; it does not affect scoring.
AI and other limits
The AI section checks web API availability. It cannot establish Firefox AI Controls, sidebar-assistant settings, cloud processing or retention. See Mozilla's AI Controls documentation for those settings.
Browser telemetry, network-layer fingerprinting, comprehensive tracker blocking, bounce tracking and behavioral tracking are outside this score. No population of fingerprints is collected for uniqueness estimates. Compatibility requires testing on each browser and platform.
Reproduce and contribute
Saved reports identify methodology version and completion state. Historical 0.9.1-beta captures are not comparable with current scores. See the technical methodology for every weight and the benchmark instructions for reproductions.
Contribute minimal examples with browser version, operating system and settings. Keep raw fingerprints out of public issues and use the security reporting process for sensitive findings.