Privacy & Security
Vast is local-first and does not collect browsing telemetry.
Core browsing data remains on your device unless you explicitly use a feature that sends data elsewhere, such as visiting a website, using a network service, or exporting data yourself.
Separate data contexts
Section titled “Separate data contexts”Vast Browser, Vast Relay, the Extensions Hub, and independently published extensions do not have the same data practices:
- Vast Browser does not send browsing history, URLs, searches, tabs, bookmarks, page content, passwords, or account identity to Vast as product analytics.
- Vast Relay, when enabled, receives a random installation UUID, the running Vast version, cumulative launch count, and
instance_kind(packaged,development,test, orunknown). Relay derives first-seen and last-seen timestamps. It does not receive browsing activity. Test cleanup is permitted only for records explicitly taggedtest. - Extensions Hub processes a publisher’s GitHub identity/profile, session and CSRF records, keyed IP hashes for rate limiting, D1/R2 listings and artifacts, automated and human review records, audit events, versioned Publisher Terms acceptances, and extension reports. Artifacts and evidence may be retained for distribution, security response, disputes, and legal compliance.
- Publisher extensions are independent software. Their listings must state requested permissions, data practices, and remote services. A publisher privacy-policy URL is required whenever an extension transmits data or uses external processing.
Vast review and package signing reduce risk but do not replace a publisher’s privacy obligations. See Publishing & policies.
Tracking and ad blocking
Section titled “Tracking and ad blocking”Vast supports:
- common tracker blocking;
- ad blocking;
- Standard, Strict, and Custom modes;
- EasyList;
- EasyPrivacy;
- Peter Lowe’s list;
- a malware-oriented URL list;
- optional Polish annoyance filters;
- automatic filter updates;
- custom block rules;
- domain allowlists.
Link cleaning
Section titled “Link cleaning”Vast can remove common tracking parameters from links while opening them. Affiliate parameter removal is a separate option because it can change referral attribution.
Cookies
Section titled “Cookies”Vast can block third-party cookies, define cookie/login exceptions, clear selected site data on close, and clear broader cookies/site data on exit.
Fingerprinting protection
Section titled “Fingerprinting protection”Modes include Standard, Strict, and Maximum. Exceptions can be defined per domain.
Fingerprinting resistance is best-effort. No browser can promise that all websites see an identical fingerprint in every context.
WebRTC privacy
Section titled “WebRTC privacy”Policies include:
- Public interface only
- Default compatibility
- Disabled
Exceptions can be created for sites that need full WebRTC behavior.
History and local traces
Section titled “History and local traces”Privacy controls can disable:
- browsing history;
- recently closed tabs;
- page text capture;
- favicons.
Vast can also use a temporary workspace by default for newly created workspaces.
HTTPS-only mode
Section titled “HTTPS-only mode”HTTPS-only mode prefers or requires secure connections where supported. Some legacy or local sites may need exceptions or may not work with strict HTTPS behavior.
External protocol confirmation
Section titled “External protocol confirmation”Vast can ask before opening links that hand off to other applications.
Download warnings
Section titled “Download warnings”Potentially dangerous downloads can trigger additional warnings.
Autofill confirmation
Section titled “Autofill confirmation”Password autofill can be configured to always require user confirmation.
Security boundaries
Section titled “Security boundaries”Web content is isolated from Vast’s privileged application APIs. Vast also restricts unsafe navigation and privileged browser behaviors. Implementation details that would meaningfully expose the attack surface are intentionally omitted from public documentation.