Skip to main content
All documentation

Privacy, security, and permissions

See what stays on the device, what reaches the account service, how site permissions work, and what the blocker can and cannot do.

Local by default

  • Saved links, themes, browser state, website sessions, permission choices, voice settings, recordings, and transcripts stay on the device.
  • Account services receive limited identity, consent, entitlement, device, session, and release metadata.
  • Crash dumps remain local unless you choose to share them.
  • Diagnostics exports intentionally exclude URLs, titles, emails, tokens, and theme contents.

Site permissions

Remote pages do not receive the privileged Side Whisper bridge. Permission decisions pass through a minimal, validated path and are scoped to supported capabilities.

  • Camera, microphone, location, notifications, clipboard read, display capture, and supported MIDI permissions
  • Origin-scoped decisions and explicit screen selection
  • Unknown or unsupported capabilities fail closed

Ad and tracker blocking

The blocker runs locally with Ghostery’s engine and EasyList/EasyPrivacy-compatible rules. You can disable it per domain and inspect the local blocked-request count.