NVX Session
Install
Transparency

Everything it can collect

Telemetry is off until you turn it on. When it is on, this is the complete set of things that can be sent, and there is nothing else it is capable of sending.

Last updated
3 October 2026
Sections
13
On this page13 sections

When it can send at all

Two independent switches gate every send and both have to be on. The first is your consent, which starts off. The second is the endpoint itself, which is injected when the build is packaged. Every batch says which kind of build sent it, store or developer, so test builds never inflate the numbers people rely on.

No credential ships in the extension, because a published build is a zip anyone can unpack and read. The endpoint is a thin ingest function that holds its own secrets on its own server. The extension only ever POSTs to it, and never reads anything back. A batch that fails is retried once; each event carries a sequence number so a resent batch is never counted twice.

Why this list is short

The format is a closed allowlist rather than a blocklist. Every field is a fixed choice from a list, a range, a yes or no, or a bounded number, and there is no free-form text field anywhere in it. A URL, a cookie or an account name cannot be transmitted even by accident, because the format has nowhere to put one.

There is exactly one value shaped like a domain: which major sign-in provider had trouble. It is chosen from the fixed list further down this page, and anything not on that list is sent as “other”. No other site can be named.

The server enforces all of this a second time. Anything carrying a value not on this page is rejected rather than stored, and the database refuses it again underneath that. Rejections are counted by reason, never kept.

The identifier

One random identifier is generated when you install the extension. It is tied to no account, no email, no device characteristic and nothing that exists outside the extension. It stays the same for that installation so that repeat visits can be counted without counting people, and it is erased when you turn telemetry off.

Every envelope

These fields travel with every event.

id
The random install identifier.
v, mv
The extension version and manifest version.
channel
One of
  • store
  • dev
seq
A number that goes up by one per event, for this install only.
at
When the event happened, by your clock.

Events

Each event carries the envelope plus only what is listed beside it.

install, startup
Nothing beyond the envelope.
update
The major.minor version it updated from, such as 1.0.
active
A daily heartbeat. The environment block below, plus ranges for how many sessions, tabs and burner sessions are in use, the busiest session’s tabs and rules, how long ago the extension was installed and how many sites are on the quiet list; and the plan, the posture, and whether “ask on new sites” is on.
Plan
  • free
  • pro
session_created
Only the resulting session count, as a range.
posture_changed
One of
  • mirror
  • standardize
  • persona
feature_used
One of
  • bulk_move
  • undo_move
  • sign_in
  • context_move
  • key_move
  • release
  • pause
error
One category name and nothing else, at most once per category per day. Either a runtime fault or one of the isolation signals, described below.
Runtime faults
  • boot_failed
  • flush_failed
  • apply_failed
  • compile_failed
  • adopt_failed
Isolation signals
  • rule_overflow
  • signin_loop
  • foreign_cookie
daily_counts
Yesterday’s counters, each as a range, and only those that are not zero. The full list of counters is below.
idp_issue
Which sign-in provider had trouble (from the fixed list below), what kind of trouble, and how often, as a range.
Kind of trouble
  • loop_stopped
  • replay_exhausted
  • hold_timeout
  • overflow
perf
How long saving and starting up took, as the typical and the slow case, each a range of milliseconds, and the peak rule count as a range.
Milliseconds
  • none
  • <10
  • 10-49
  • 50-99
  • 100-249
  • 250-499
  • 500-999
  • 1000-2999
  • 3000+
Rule count
  • 0
  • 1-9
  • 10-49
  • 50-99
  • 100-249
  • 250-499
  • 500+
exception
That an unexpected error happened: where, and its type. Never the message or the stack.
Where
  • uncaught
  • rejection
Type
  • Error
  • TypeError
  • RangeError
  • ReferenceError
  • SyntaxError
  • URIError
  • EvalError
  • AggregateError
  • DOMException

The environment block

Sent with the daily heartbeat only.

os
  • windows
  • macos
  • linux
  • chromeos
  • android
  • other
arch
  • x86-64
  • arm64
  • x86-32
  • other
browser
  • chrome
  • opera
  • edge
  • brave
  • vivaldi
  • arc
  • other
browser_major
A whole number, such as 141.
lang
The language subtag only, such as en. The region is stripped, because a region is closer to a location than a language preference.
tz
A whole hour offset from UTC, between -14 and 14. Not a named timezone, which would be far more identifying.

Counts, as ranges

most counts
  • 0
  • 1
  • 2-3
  • 4-6
  • 7-12
  • 13+
rules
  • 0
  • 1-9
  • 10-49
  • 50-99
  • 100-249
  • 250-499
  • 500+
since_install
  • 0
  • 1
  • 2-7
  • 8-30
  • 31-90
  • 90+
  • days

Exact numbers are never sent. A precise count is a surprisingly good identifier, and nothing here needs one.

The daily counters

Each is how many times something happened yesterday, as a range: pages that needed a sign-in replay, waits for a session to settle, sign-in loops released, how the session picker was used, and similar. None of them says which site, which session or which account.

28 counters
  • worker_boots
  • replay_hop
  • replay_chain
  • hold_redirect
  • hold_ready
  • hold_committed
  • hold_timeout
  • settle_wait
  • loop_released
  • loop_idp_stopped
  • loop_suppressed
  • overflow_events
  • overflow_hosts
  • foreign_real
  • foreign_transient
  • apply_failed
  • picker_shown_new
  • picker_shown_multi
  • pick_chosen
  • pick_created
  • pick_remember
  • pick_quiet
  • pick_unmanaged
  • burner_created
  • adopt_run
  • sync_enable
  • sync_now
  • release_manual

The sign-in provider list

These are the shared sign-in services that sessions most often have to cooperate with. Knowing which one is struggling is what lets a fix be aimed at it. Any other host is sent as “other”.

43 providers
  • alipay.com
  • amazon.com
  • apple.com
  • atlassian.com
  • auth0.com
  • awsapps.com
  • cloudflareaccess.com
  • duosecurity.com
  • facebook.com
  • force.com
  • github.com
  • google.com
  • jumpcloud.com
  • kakao.com
  • line.me
  • live.com
  • login.gov
  • mail.ru
  • microsoft.com
  • microsoftonline-p.com
  • microsoftonline.com
  • msauth.net
  • msftauth.net
  • naver.com
  • okta-emea.com
  • okta-gov.com
  • okta.com
  • oktacdn.com
  • oktapreview.com
  • onelogin.com
  • pingidentity.com
  • pingone.com
  • qq.com
  • salesforce.com
  • signin.aws
  • taobao.com
  • vk.com
  • yahoo.co.jp
  • yahoo.com
  • yandex.com
  • yandex.ru
  • youtube.com
  • other

The three isolation signals

These are values in the error list above. Each is sent at most once per install per day, which is deliberate: it makes a daily count mean “how many installs saw this” rather than how noisy one install happened to be.

rule_overflow
A session needed more isolation rules than its budget allows. Nothing about which session, which sites, or how many rules.
signin_loop
A sign-in was caught looping and was released to break it. Nothing about which site or which account.
foreign_cookie
The browser’s own cookies reached a tab that should have been isolated. This is the failure the product exists to prevent, so we want to see the rate of it across installs. The signal is the bare word: no host, no cookie name, and no cookie value.

What stays on your device

The extension keeps its own bookkeeping in local storage: whether the install signal was sent, today’s peaks and counters before they are rolled up, which once-a-day signals have already gone out, and the sequence number. None of it is sent except as the rolled-up ranges above, and all of it is erased when you turn telemetry off, along with the random install id.

Never collected

Screen size and pixel ratio, canvas or WebGL output, installed fonts, the full user agent string, a named timezone, geolocation of any kind, an exact install date, exact counts, URLs, any site other than the sign-in providers listed above, page contents, cookies, error messages, account names or email addresses.

Those first four are fingerprinting vectors. A product whose purpose is stopping sites from linking your identities has no business collecting the exact material that would let it do so.

What happens at the other end

Batches are sent to an endpoint on this domain and stored in a database only the operator can read. The request body is never written to a log. An IP address is used to rate limit and is hashed for that purpose only; it is never stored alongside the data it accompanied, so rows cannot be traced back to a network location.

There is no third-party analytics service involved, here or on this website. Adding one would contradict the product.