The Mullvad Browser project configures its desktop browser to reduce browser fingerprinting and cross-session tracking. It does not connect to the Tor network. Mullvad Browser also is not a VPN client. Without a trustworthy VPN, websites still see the public IP address of the current connection.
The fingerprinting strategy tries to make many installations expose similar characteristics. Adding unusual extensions or changing many low-level settings can make one installation easier to distinguish. NoScript and uBlock Origin form part of the intended package and cannot leave through the ordinary extension-removal workflow.
The last private window ends the session
Private browsing starts by default. Closing the last private window clears history, form entries, download-list entries, cookies and other temporary site data associated with that session. Mullvad Browser cannot keep selected website sessions signed in across later sessions.
A selected website session cannot remain signed in after the last window closes. The built-in password manager and Firefox Sync also start disabled, so the browser does not replace that lost session with synchronized credentials.
Extensions cannot save settings through Firefox storage.sync because Mullvad Browser leaves Sync unavailable. An extension may install and display normally while its synchronized settings never work.
Security Level can remove page capabilities
The Security Level limits or disables browser capabilities rather than merely hiding a warning. A higher setting can make a site behave differently or stop one of its functions. A failure that appears only after raising the level may come from the removed capability rather than from the network.
Fingerprint defenses can also spoof devicePixelRatio. Some canvas-rendered elements can look blurry under that behavior. The standardized surface can make some canvas-rendered elements look blurry.
Privacy does not mean zero outbound requests
Mullvad Browser makes documented requests for browser and extension updates, Mullvad DNS-over-HTTPS, Mozilla certificate and domain data, and uBlock Origin filter lists. These requests support the browser’s maintenance and protections.
The browser can run without a Mullvad account. Its privacy model still expects a trustworthy VPN to mask the public IP address.
Windows installation type changes portability
The standard Windows installation uses the current user’s folder. The guide warns against changing its destination to C:\Program Files because updates or removal can fail there. Only the supported standard installation can become the default browser through the normal path.
A standalone installation does not become fully portable merely because it occupies one folder. After moving that folder, the user must select the intended profile through about:profiles or ProfileManager. Deleting a standalone folder removes that installation because it has no uninstaller.
Removing a standard installation leaves profile folders that contain bookmarks and preferences. A user who expects removal to erase those records must locate the profiles separately. On Linux, the repository route also supplies the documented AppArmor profile, while another installation route can show a reduced-protection warning.




