When it can send at all
Two independent switches gate every send and both have to be on. The first is your consent, which starts off. The second is the endpoint itself, which is injected when the build is packaged. Every batch says which kind of build sent it, store or developer, so test builds never inflate the numbers people rely on.
No credential ships in the extension, because a published build is a zip anyone can unpack and read. The endpoint is a thin ingest function that holds its own secrets on its own server. The extension only ever POSTs to it, and never reads anything back. A batch that fails is retried once; each event carries a sequence number so a resent batch is never counted twice.
Why this list is short
The format is a closed allowlist rather than a blocklist. Every field is a fixed choice from a list, a range, a yes or no, or a bounded number, and there is no free-form text field anywhere in it. A URL, a cookie or an account name cannot be transmitted even by accident, because the format has nowhere to put one.
There is exactly one value shaped like a domain: which major sign-in provider had trouble. It is chosen from the fixed list further down this page, and anything not on that list is sent as “other”. No other site can be named.
The server enforces all of this a second time. Anything carrying a value not on this page is rejected rather than stored, and the database refuses it again underneath that. Rejections are counted by reason, never kept.
The identifier
One random identifier is generated when you install the extension. It is tied to no account, no email, no device characteristic and nothing that exists outside the extension. It stays the same for that installation so that repeat visits can be counted without counting people, and it is erased when you turn telemetry off.
Every envelope
These fields travel with every event.
- id
- The random install identifier.
- v, mv
- The extension version and manifest version.
- channel
- One of
- store
- dev
- seq
- A number that goes up by one per event, for this install only.
- at
- When the event happened, by your clock.
Events
Each event carries the envelope plus only what is listed beside it.
- install, startup
- Nothing beyond the envelope.
- update
- The major.minor version it updated from, such as 1.0.
- active
- A daily heartbeat. The environment block below, plus ranges for how many sessions, tabs and burner sessions are in use, the busiest session’s tabs and rules, how long ago the extension was installed and how many sites are on the quiet list; and the plan, the posture, and whether “ask on new sites” is on.Plan
- free
- pro
- session_created
- Only the resulting session count, as a range.
- posture_changed
- One of
- mirror
- standardize
- persona
- feature_used
- One of
- bulk_move
- undo_move
- sign_in
- context_move
- key_move
- release
- pause
- error
- One category name and nothing else, at most once per category per day. Either a runtime fault or one of the isolation signals, described below.Runtime faults
- boot_failed
- flush_failed
- apply_failed
- compile_failed
- adopt_failed
Isolation signals- rule_overflow
- signin_loop
- foreign_cookie
- daily_counts
- Yesterday’s counters, each as a range, and only those that are not zero. The full list of counters is below.
- idp_issue
- Which sign-in provider had trouble (from the fixed list below), what kind of trouble, and how often, as a range.Kind of trouble
- loop_stopped
- replay_exhausted
- hold_timeout
- overflow
- perf
- How long saving and starting up took, as the typical and the slow case, each a range of milliseconds, and the peak rule count as a range.Milliseconds
- none
- <10
- 10-49
- 50-99
- 100-249
- 250-499
- 500-999
- 1000-2999
- 3000+
Rule count- 0
- 1-9
- 10-49
- 50-99
- 100-249
- 250-499
- 500+
- exception
- That an unexpected error happened: where, and its type. Never the message or the stack.Where
- uncaught
- rejection
Type- Error
- TypeError
- RangeError
- ReferenceError
- SyntaxError
- URIError
- EvalError
- AggregateError
- DOMException
The environment block
Sent with the daily heartbeat only.
- os
- windows
- macos
- linux
- chromeos
- android
- other
- arch
- x86-64
- arm64
- x86-32
- other
- browser
- chrome
- opera
- edge
- brave
- vivaldi
- arc
- other
- browser_major
- A whole number, such as 141.
- lang
- The language subtag only, such as en. The region is stripped, because a region is closer to a location than a language preference.
- tz
- A whole hour offset from UTC, between -14 and 14. Not a named timezone, which would be far more identifying.
Counts, as ranges
- most counts
- 0
- 1
- 2-3
- 4-6
- 7-12
- 13+
- rules
- 0
- 1-9
- 10-49
- 50-99
- 100-249
- 250-499
- 500+
- since_install
- 0
- 1
- 2-7
- 8-30
- 31-90
- 90+
- days
Exact numbers are never sent. A precise count is a surprisingly good identifier, and nothing here needs one.
The daily counters
Each is how many times something happened yesterday, as a range: pages that needed a sign-in replay, waits for a session to settle, sign-in loops released, how the session picker was used, and similar. None of them says which site, which session or which account.
- worker_boots
- replay_hop
- replay_chain
- hold_redirect
- hold_ready
- hold_committed
- hold_timeout
- settle_wait
- loop_released
- loop_idp_stopped
- loop_suppressed
- overflow_events
- overflow_hosts
- foreign_real
- foreign_transient
- apply_failed
- picker_shown_new
- picker_shown_multi
- pick_chosen
- pick_created
- pick_remember
- pick_quiet
- pick_unmanaged
- burner_created
- adopt_run
- sync_enable
- sync_now
- release_manual
The sign-in provider list
These are the shared sign-in services that sessions most often have to cooperate with. Knowing which one is struggling is what lets a fix be aimed at it. Any other host is sent as “other”.
- alipay.com
- amazon.com
- apple.com
- atlassian.com
- auth0.com
- awsapps.com
- cloudflareaccess.com
- duosecurity.com
- facebook.com
- force.com
- github.com
- google.com
- jumpcloud.com
- kakao.com
- line.me
- live.com
- login.gov
- mail.ru
- microsoft.com
- microsoftonline-p.com
- microsoftonline.com
- msauth.net
- msftauth.net
- naver.com
- okta-emea.com
- okta-gov.com
- okta.com
- oktacdn.com
- oktapreview.com
- onelogin.com
- pingidentity.com
- pingone.com
- qq.com
- salesforce.com
- signin.aws
- taobao.com
- vk.com
- yahoo.co.jp
- yahoo.com
- yandex.com
- yandex.ru
- youtube.com
- other
The three isolation signals
These are values in the error list above. Each is sent at most once per install per day, which is deliberate: it makes a daily count mean “how many installs saw this” rather than how noisy one install happened to be.
- rule_overflow
- A session needed more isolation rules than its budget allows. Nothing about which session, which sites, or how many rules.
- signin_loop
- A sign-in was caught looping and was released to break it. Nothing about which site or which account.
- foreign_cookie
- The browser’s own cookies reached a tab that should have been isolated. This is the failure the product exists to prevent, so we want to see the rate of it across installs. The signal is the bare word: no host, no cookie name, and no cookie value.
What stays on your device
The extension keeps its own bookkeeping in local storage: whether the install signal was sent, today’s peaks and counters before they are rolled up, which once-a-day signals have already gone out, and the sequence number. None of it is sent except as the rolled-up ranges above, and all of it is erased when you turn telemetry off, along with the random install id.
Never collected
Screen size and pixel ratio, canvas or WebGL output, installed fonts, the full user agent string, a named timezone, geolocation of any kind, an exact install date, exact counts, URLs, any site other than the sign-in providers listed above, page contents, cookies, error messages, account names or email addresses.
Those first four are fingerprinting vectors. A product whose purpose is stopping sites from linking your identities has no business collecting the exact material that would let it do so.
What happens at the other end
Batches are sent to an endpoint on this domain and stored in a database only the operator can read. The request body is never written to a log. An IP address is used to rate limit and is hashed for that purpose only; it is never stored alongside the data it accompanied, so rows cannot be traced back to a network location.
There is no third-party analytics service involved, here or on this website. Adding one would contradict the product.