Dazr Browser trust centre
Last updated 6 October 2026
If a translation of this page differs from the English version, the English version applies.
Where your data is stored
Your history, bookmarks, cookies, settings, downloads and the blocklists the browser uses are stored on your computer only. We have no copy and cannot see them. You can clear them in the browser’s settings.
We store personal data in the European Union. Vercel, Upstash and Resend are companies based in the United States. Where one of our providers can access personal data from outside the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses or by an adequacy decision of the European Commission.
For companies in the United States, that adequacy decision is the EU-US Data Privacy Framework, which covers the companies certified under it.
Sub-processors
These companies process personal data for us, only on our instructions and under written contracts that oblige them to protect it:
| Provider | Location | Purpose | Data |
|---|---|---|---|
| Vercel | United States; data stored in the EU | Hosting of browser.dazr.eu, the update server and the downloads, and page statistics | Server logs, kept for up to 30 days |
| Upstash | United States; data stored in the EU | Information about the latest version | Version information only |
| Resend | United States | Sending contact form messages and the copy to you | Name, email address and message |
| GitHub | United States | Storage of the installers, which our server fetches | Installers only |
The browser also connects to services run by others, such as encrypted DNS and blocklists. The privacy notice lists each of them.
How we protect your data
The browser sends no telemetry, usage statistics or crash reports, and it has no Dazr account.
- Updates. Every few hours the browser asks our server (dazr.eu) whether there is a new version. The request contains no identifier. By default a new version downloads in the background and installs when you quit the browser; you can turn this off in settings.
- Encrypted DNS. To find websites, the browser looks up their addresses over DNS-over-HTTPS at dns0.eu, with Quad9 as a fallback. These services see the names of the websites you open, not what you do on them. We do not run them and do not receive their logs.
- Blocklists. The browser downloads ad, tracker and phishing lists (from Ghostery’s ad-blocking project, EasyList, OpenPhish, PhishTank, URLhaus and lists published on GitHub) and checks pages against them on your device. The addresses you visit are not sent anywhere to be checked.
- Inside the browser, cookies are set by the websites you visit and stay on your device. Third-party cookies are blocked by default; you can clear cookies or block them per website in settings.
- Encryption in transit. All traffic is encrypted with HTTPS. Browsers are told to use only HTTPS for dazr.eu and all its subdomains (HSTS, with the preload directive).
- Content Security Policy. Browsers run only the scripts we list: our own files, inline scripts identified by their hash and one pinned library file. Plugins are blocked, and other websites cannot show our pages in a frame.
Privacy
The privacy notice explains what we keep, why and for how long, and the terms of use set out the rules for using the service.
You can ask us for access to your personal data, a copy in a portable format, correction, deletion or restriction, and you can object to processing based on our legitimate interests. Where we rely on your consent, you can withdraw it at any time.
Because the browser keeps your data on your device, we usually hold nothing about you beyond server logs and any email you sent us.
Write to privacy@dazr.eu for anything you cannot do yourself. We reply within 30 days.
You can also complain to a data protection authority: in Italy the Garante per la protezione dei dati personali (garanteprivacy.it), or the authority where you live or work.
Compliance and assessments
- GDPR. Dazr, Viale Cesare Poggi 1, 15061 Arquata Scrivia (AL), Italy, VAT IT 02801250065, is the controller for the personal data described in the privacy notice, under the General Data Protection Regulation (GDPR).
- CSA STAR Level 1: self-assessment in preparation. Dazr is completing the Cloud Security Alliance’s Consensus Assessments Initiative Questionnaire (CAIQ) for the CSA STAR Registry. This page will link to the published entry.
Reporting a vulnerability
If you find a security vulnerability in one of our services, please report it to security@dazr.eu. Describe what you found and the steps to reproduce it, and name the address or app version concerned.
- Scope. The Dazr websites and services on dazr.eu and its subdomains, their APIs, Dazr Browser and the Dazr Suite apps.
- Testing with care. Use your own accounts and test data, access other people’s data only as far as needed to show the problem, and keep the service running for everyone: no denial-of-service tests, spam or social engineering.
- Safe harbour. If you act in good faith and follow this policy, we consider your research authorised and will not take legal action against you. Please give us reasonable time to fix the problem before you share details publicly.
- Our response. We acknowledge your report within 5 working days and keep you informed until the problem is fixed.
Our security contact is also published in security.txt (RFC 9116).
The full policy, including what is out of scope and how we publish fixes, is our vulnerability disclosure policy.
Contact
- Privacy and data requests: privacy@dazr.eu
- Security: security@dazr.eu
- General: hello@dazr.eu
- Post: Dazr, Viale Cesare Poggi 1, 15061 Arquata Scrivia (AL), Italy