Privacy defaults
Vimma keeps Firefox's protections and turns off what phones home for Mozilla's business. Every default is a preference you can change back in about:config.
Turned off
- Studies and experiments (Normandy and Nimbus).
- Sponsored stories, shortcuts and address-bar suggestions.
- Feature and add-on recommendations, and Mozilla's promos (VPN, Relay, mobile).
- Telemetry upload and the crash reporter: neither is built in. A crash leaves only a local core dump (
coredumpctl list vimma).
Kept as in Firefox
- Safe Browsing: Vimma downloads Google's lists of dangerous sites and warns you before you open one. Your browsing stays local; only an address that matches the list sends Google a short hash of it to confirm.
- Certificate revocation checks, the add-on blocklist, Firefox Sync and add-ons from addons.mozilla.org.
Still contacts Mozilla
Very little. Firefox's updater is not built into Vimma, and system add-on updates are off, so Vimma never asks Mozilla's update server for a Firefox build. The one request left there is for the OpenH264 and Widevine plugins, which video calls and DRM video need.
Sites see Firefox
Vimma sends Firefox's user agent, byte for byte, and add-ons see Firefox's version, so nothing treats it as a different browser.
Change any of it back
Open about:config, search for the preference and toggle it. The table under Details names the preference for each default.
Details
Everything below is Vimma's own user guide for this topic, in full: every edge case and exception. You do not need it to get started.
Vimma starts quieter than Firefox: no studies, no sponsored content and no telemetry uploads. None of this is locked; each default can be changed back in about:config (search for the name, then toggle or edit it).
| Off in Vimma | Turn it back on |
|---|---|
| Normandy studies and rollouts | app.normandy.enabled = true, app.normandy.api_url = https://normandy.cdn.mozilla.net/api/v1 |
| Nimbus studies and rollouts | app.shield.optoutstudies.enabled, nimbus.rollouts.enabled = true (studies also need datareporting.healthreport.uploadEnabled) |
| Sponsored new-tab stories and shortcuts | browser.newtabpage.activity-stream.showSponsored, …system.showSponsored, …showSponsoredTopSites, browser.topsites.contile.enabled; stories: …feeds.section.topstories (or New Tab settings) |
| Sponsored address-bar suggestions | Settings: search for "sponsors" and tick "Suggestions from sponsors" |
| Feature and add-on recommendations | browser.newtabpage.activity-stream.asrouter.providers.cfr: change "enabled":false to true in its JSON value; then …asrouter.userprefs.cfr.addons, …cfr.features = true |
| Mozilla promos (VPN, Relay, Pin, mobile) | browser.vpn_promo.enabled, browser.promo.relay.enabled, browser.promo.pin.enabled, browser.preferences.moreFromMozilla |
| Crash reporter | Not built in. A crash leaves a local core dump (coredumpctl list vimma). Opt-in reporting to Vimma's own server is planned. |
| Telemetry upload | Not built in (no official telemetry). The data-collection switches in Settings are off to match. |
Kept as in Firefox: Remote Settings (CRLite certificate revocation, intermediate certificates), the add-on blocklist, Firefox Sync, add-ons from addons.mozilla.org and their updates, and Google Safe Browsing (see below). Firefox's app updater is not built into Vimma, and system add-on updates are off, so neither asks Mozilla's update server. The one remaining request there is for the OpenH264 and Widevine plugins, which video calls and DRM video need.
Sites see Firefox 157's user agent, with no Vimma token, and add-ons see Firefox's version (runtime.getBrowserInfo()), so Vimma is treated like Firefox. vimma --version and the About dialog show Vimma's own version (0.1.0).
Safe Browsing
Google Safe Browsing is on by default, as in Firefox: Vimma downloads Google's lists of phishing, malware and unwanted-software sites and warns before you open one. Your browsing stays local: only when an address matches the local list does Vimma send Google a short hash prefix of it to confirm.
Firefox's extra download checks (Google's lists of bad and known-good downloads, and its file reputation service) are open only to Mozilla's own key, so Vimma does not use them: the "Block dangerous downloads" box adds nothing beyond the site lists (limits.md).
To turn Safe Browsing off: Settings → Privacy & Security → untick "Block dangerous and deceptive content". In about:config that is browser.safebrowsing.phishing.enabled and browser.safebrowsing.malware.enabled = false.
A Vimma you build yourself has Safe Browsing only if you build it with a Google API key (runbook). Without one it fetches no lists, and Settings shows the protection off.
Whether or not you use Safe Browsing, we recommend uBlock Origin from addons.mozilla.org as a second line: in its dashboard → Filter lists, keep "uBlock filters – Badware risks" on and tick the lists under "Malware protection, security" (Online Malicious URL Blocklist, Phishing URL Blocklist). They block known malware and phishing sites without asking any server about the pages you visit.
Firefox behaviour Vimma changes
For workspaces; each is a default you can change in about:config:
- Closing the last tab keeps the window and opens a new tab in the workspace, so a window never closes with other workspaces' tabs in it (
browser.tabs.closeWindowWithLastTab=false). - No preloaded new-tab page (
browser.newtab.preload=false): Firefox only uses it for tabs without a container, and every Vimma tab is in one. - Restart restores your session: tabs, workspaces, pane layouts and scroll positions come back (
browser.startup.page=3; Firefox's default1opens the home page). - Firefox Sync leaves two settings alone:
browser.startup.pageandprivacy.userContext.enabled(turning containers off deletes every workspace's data).
Known limits
Vimma is pre-alpha. What does not work yet, or works with a catch, is listed on the known limits page:
The guide at the top is written for this site; the details are built from Vimma's docs/guide.md and bindings.md at 1050bcc (2026-10-10).