Skip to content

Privacy & Security

Vast is local-first and does not collect browsing telemetry.

Core browsing data remains on your device unless you explicitly use a feature that sends data elsewhere, such as visiting a website, using a network service, or exporting data yourself.

Vast Browser, Vast Relay, the Extensions Hub, and independently published extensions do not have the same data practices:

  • Vast Browser does not send browsing history, URLs, searches, tabs, bookmarks, page content, passwords, or account identity to Vast as product analytics.
  • Vast Relay, when enabled, receives a random installation UUID, the running Vast version, cumulative launch count, and instance_kind (packaged, development, test, or unknown). Relay derives first-seen and last-seen timestamps. It does not receive browsing activity. Test cleanup is permitted only for records explicitly tagged test.
  • Extensions Hub processes a publisher’s GitHub identity/profile, session and CSRF records, keyed IP hashes for rate limiting, D1/R2 listings and artifacts, automated and human review records, audit events, versioned Publisher Terms acceptances, and extension reports. Artifacts and evidence may be retained for distribution, security response, disputes, and legal compliance.
  • Publisher extensions are independent software. Their listings must state requested permissions, data practices, and remote services. A publisher privacy-policy URL is required whenever an extension transmits data or uses external processing.

Vast review and package signing reduce risk but do not replace a publisher’s privacy obligations. See Publishing & policies.

Vast supports:

  • common tracker blocking;
  • ad blocking;
  • Standard, Strict, and Custom modes;
  • EasyList;
  • EasyPrivacy;
  • Peter Lowe’s list;
  • a malware-oriented URL list;
  • optional Polish annoyance filters;
  • automatic filter updates;
  • custom block rules;
  • domain allowlists.

Vast can remove common tracking parameters from links while opening them. Affiliate parameter removal is a separate option because it can change referral attribution.

Vast can block third-party cookies, define cookie/login exceptions, clear selected site data on close, and clear broader cookies/site data on exit.

Modes include Standard, Strict, and Maximum. Exceptions can be defined per domain.

Fingerprinting resistance is best-effort. No browser can promise that all websites see an identical fingerprint in every context.

Policies include:

  • Public interface only
  • Default compatibility
  • Disabled

Exceptions can be created for sites that need full WebRTC behavior.

Privacy controls can disable:

  • browsing history;
  • recently closed tabs;
  • page text capture;
  • favicons.

Vast can also use a temporary workspace by default for newly created workspaces.

HTTPS-only mode prefers or requires secure connections where supported. Some legacy or local sites may need exceptions or may not work with strict HTTPS behavior.

Vast can ask before opening links that hand off to other applications.

Potentially dangerous downloads can trigger additional warnings.

Password autofill can be configured to always require user confirmation.

Web content is isolated from Vast’s privileged application APIs. Vast also restricts unsafe navigation and privileged browser behaviors. Implementation details that would meaningfully expose the attack surface are intentionally omitted from public documentation.