Candy Browser is designed to keep browser data on your device. Candy does not operate an analytics service or a hosted Candy Sync service, and the developer does not receive your browsing history through the app.
Local browser features remain local. Network features connect only when you use or enable them. Candy Sync sends end-to-end encrypted tab data to a server you choose.
1. Scope
This policy covers Candy Browser for Android and iOS where available, and the Candy Sync extension for Chromium-based browsers and Firefox. Websites, search providers, self-hosted server operators, app stores, and other services have their own privacy practices.
2. Data processed by Candy Browser
Depending on the features you use, Candy may process tabs, URLs, page titles, browsing history, favorites, profiles, site permissions, downloads, reading-list content, saved page previews, and local privacy-protection statistics.
This information is stored locally on your device for the browser features you choose. Candy does not send it to the Candy Browser developer. Private tabs, private trails, private permissions, and private reader state are not written into Candy's persistent stores.
Your operating system, browser engine, websites you visit, and installed extensions may process additional data independently of Candy.
3. Candy Sync
Candy Sync is optional and self-hosted. You provide the server endpoint and credentials and decide which supported data types to synchronize.
Information handled during setup
- Server endpoint and username: stored locally as configuration.
- Server password: sent to your selected server during enrollment and not retained by the extension afterward.
- E2EE passphrase: used locally to unlock or create encryption keys. It is not sent to the server and is not persisted.
- Device name and icon: encrypted locally before upload.
Synchronized information
When tab sync is enabled, Candy processes eligible HTTP and HTTPS tab URLs, titles, order, pin state, and supported group metadata. Private tabs, browser-internal pages, and local files are excluded. The payload is encrypted on the device before transmission.
What the selected server can observe
The server stores encrypted payloads plus routing metadata needed to operate sync, such as workspace and device identifiers, revisions, cursors, payload sizes, and timestamps. It does not receive tab URLs, tab titles, device names, profile icons, the E2EE passphrase, the workspace key, or private device keys in plaintext.
The server operator or hosting provider may separately process network metadata, including IP addresses and request logs. Because Candy Sync is self-hosted, those practices are controlled by the operator of the server you select.
Transport security
HTTPS and WSS are the supported production transports. The public browser extension blocks remote HTTP because it does not protect enrollment credentials, device tokens, or connection metadata. HTTP is available only for same-device development through localhost endpoints, while synchronized tab payloads remain end-to-end encrypted.
4. Browser extension permissions
- Storage
- Keeps settings, encrypted local vault data, encrypted pending changes, and redacted status.
- Alarms
- Resumes periodic recovery when realtime delivery is suspended or unavailable.
- Tabs
- Reads and applies eligible tab state only after tab synchronization is selected.
- Tab groups
- Reads supported group assignments only after group synchronization is selected.
- Selected server host
- Connects to the exact server scheme and hostname approved during setup.
The extension does not include content scripts, advertising code, or remotely executed code.
5. Websites and optional external services
Browsing sends requests to the websites you choose. Optional features such as search suggestions, search providers, translation, sharing, external applications, or third-party extensions contact their respective services only when configured, enabled, or invoked. Data sent to those services is governed by their privacy policies.
In the Full app flavor, using Google Cast activates Google's Cast Sender SDK. The SDK processes interactions with Cast devices and may send diagnostic or usage information to Google's logging services to operate and improve Cast. Media URLs and metadata are sent to the Cast device you explicitly select; Candy does not persist or log them. Google's processing is governed by the Google Privacy Policy.
Candy does not sell personal information and does not use browser data for advertising, credit decisions, or profiling unrelated to user-facing browser features.
Candy Sync's use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.
6. Retention and your control
Local data remains until you clear it, remove the relevant profile, reset the feature, or uninstall the app or extension, subject to platform backup behavior. Candy Sync ciphertext remains on your selected server until it is removed according to that server's operation and backup policy.
You can disable sync scopes, revoke extension permissions, clear browser data, remove the extension, or delete the self-hosted server data. Losing the Candy Sync E2EE passphrase makes encrypted workspace data unrecoverable.
7. Security
Candy Sync uses Argon2id for passphrase-based key derivation, AES-256-GCM for authenticated encryption, HKDF-SHA-256 for key separation, and independently generated P-256 device identities. Secrets stored by the extension are kept inside an encrypted local vault.
No system can guarantee absolute security. An unlocked browser profile, device malware, browser debugging, a compromised extension update, or an untrusted server transport may expose information outside Candy's encryption boundary.
8. Children's privacy
Candy Browser is a general-purpose browser and is not directed to children. The project does not knowingly collect personal information from children through a Candy-operated service.
9. Changes to this policy
Material changes will be published on this page and reflected by the “Last updated” date. Repository history provides a public record of policy revisions.
10. Contact
For privacy questions or support, open an issue through the Candy Browser issue tracker. For a security-sensitive report, do not post secrets or exploit details publicly; open a minimal issue requesting a private contact channel.