← Browsers
F

Microsoft Edge

Fail
Microsoft · 🇺🇸 United States
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
App: com.microsoft.emmx
Manufacturer: Microsoft

⚠️ The bottom line

Academic research proved Edge is the least private browser you can use — worse than Chrome. It sends a permanent hardware ID to Microsoft that you can't disable, even if you reinstall. It starts tracking before you've agreed to anything. Every letter you type in Edge's address bar goes straight to Microsoft. They were also caught sending every URL you visit to Bing through a 'Follow Creator' feature most people didn't know existed. Microsoft called it a bug. It was the design.

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
Spying
3/4 HIGH
Is someone spying on me?
Data Sharing
2/4 MODERATE
Who gets my data?
Security
3/4 HIGH
Is it actually secure?
Honesty
4/4 EXTREME
Can I trust what they say?
REPLACE Extreme risk. Look for alternatives or lock down hard.
Use LibreWolf or Vivaldi instead
Firefox fork with zero telemetry, or Vivaldi from Norway
See report →
7Contradictions
3Critical
3High
1Medium
3Sources
Findings by concern
Spying 3/4 HIGH 3 findings
⚠️ criticalfirmware analysis vs app permissions
Every letter you type in Edge's address bar goes straight to Microsoft. They were also caught sending every URL you visit to Bing through a 'Follow Creator' feature most people didn't know existed. Microsoft called it a bug. It was the design.

What they claim: Edge's address bar helps you 'search and navigate the web quickly'

What we found: Every keystroke typed in Edge's address bar is sent to Bing in real time by default. The Follow Creator feature was caught sending the FULL URL of almost every website visited to bingapis.com without consent. Microsoft acknowledged this as a 'bug' in a 'poorly implemented' feature — but the feature was designed to send URLs to Bing by default.

⚡ highpolicy claims vs firmware analysis
Edge's Shopping feature tracks everything you buy online — and Microsoft's own docs admit it. It's on by default. Your browser is watching what you shop for and reporting it to Microsoft.

What they claim: Edge's Shopping feature helps you 'save money with built-in coupons and price comparisons'

What we found: Microsoft's own documentation states 'when you use Shopping in Microsoft Edge, you agree to let Microsoft track your activities online.' The feature — enabled by default — tracks product views, price comparisons, coupon usage, and cashback transactions. Your browser has been turned from a neutral tool into a commercial surveillance platform.

⚫ mediumpolicy claims vs regulatory findings
Microsoft was the first company to join PRISM in 2007. Nearly a third of government demands for your data come with gag orders — Microsoft legally can't tell you they handed it over.

What they claim: Microsoft positions Edge as a secure choice backed by enterprise-grade security

What we found: Microsoft was the first PRISM participant (2007). Edge's telemetry data flows through Microsoft's infrastructure, subject to the same surveillance access. 31% of US legal demands to Microsoft in H1 2025 came with secrecy orders — 1,974 gag orders meaning users were never told their data was demanded.

Security 3/4 HIGH 1 finding
⚠️ criticalpolicy claims vs firmware analysis
Edge's AI reads everything you browse, takes screenshots of pages you visit, and builds a profile across all your Microsoft products. This is on by default. Security researchers showed attackers can hijack the AI using the pages you visit.

What they claim: Edge's Copilot AI integration is presented as a helpful browsing assistant

What we found: Copilot ingests your browsing history, search queries, frequently visited sites, reading patterns, and page content. It takes screenshots of pages, retained for 30 days. Cross-product data sharing is enabled by default — your browsing feeds into Copilot's profile of you across Edge, Bing, MSN, Outlook, and Teams. Prompt injection attacks can trick Copilot into performing unintended actions using your browsing context.

Honesty 4/4 EXTREME 3 findings
⚠️ criticalpolicy claims vs firmware analysis
Academic research proved Edge is the least private browser you can use — worse than Chrome. It sends a permanent hardware ID to Microsoft that you can't disable, even if you reinstall. It starts tracking before you've agreed to anything.

What they claim: Microsoft Edge claims to be 'the best browser for Windows' with 'built-in privacy features'

What we found: Trinity College Dublin research ranked Edge as the LEAST PRIVATE major browser — worse than Chrome, Firefox, Safari, and Brave. Edge sends a persistent hardware UUID to Microsoft that cannot be disabled or reset. It phones home on first launch before any user consent. It was ranked alongside Yandex (Russian) in the worst privacy tier.

⚡ highfirmware analysis vs regulatory findings
You can't uninstall Edge from Windows. The button is grayed out. If you force-remove it, Windows puts it back. Links in Outlook and Start Menu open Edge even if Chrome is your default. Microsoft took 15 months to partially comply with EU law requiring them to let you remove it.

What they claim: Edge is described as 'an essential component of Windows' that 'can't be uninstalled'

What we found: The Uninstall button is grayed out on Windows 10/11. Edge reinstalls itself after forced command-line removal. Windows updates re-enable Edge and reset default browser associations. Clicking links in Windows widgets, Outlook, MSN, and Start Menu ALWAYS opens Edge regardless of your default browser setting. EU DMA required allowing uninstallation but Microsoft only partially complied 15 months after the deadline.

⚡ highfirmware analysis vs regulatory findings
Edge's private browsing mode still sends data to Microsoft. The permanent hardware ID Microsoft assigned your machine is sent even in InPrivate mode. Private from your family, not from Microsoft.

What they claim: Edge offers InPrivate browsing for 'private' web sessions

What we found: Microsoft's own privacy whitepaper confirms that diagnostic data is STILL collected during InPrivate browsing sessions. The hardware UUID that Edge sends to Microsoft persists across InPrivate sessions. 'Private' browsing in Edge is private from other users of your device — not from Microsoft.

What happened to real people
Documented incidents involving Microsoft products and user data.
First PRISM participant (2007). 31% of US legal demands come with secrecy orders — 1,974 gag orders in H1 2025 alone. Users never told their data was demanded. [source]
Storm-0558: Chinese hackers used a stolen Microsoft signing key to access US government officials' email accounts. Microsoft's own infrastructure was the attack vector. [source]
What your data is worth to governments
Microsoft complied with 6,288 government data requests in H1 2025. That's 31% of demands include secrecy orders. Microsoft has been a confirmed PRISM participant since 2007. Under this programme, the NSA collects stored communications. The company is legally prohibited from telling you. Jurisdiction: US (CLOUD Act, FISA Section 702, Patriot Act).
Documented: First PRISM participant (2007). 31% of US legal demands come with secrecy orders — 1,974 gag orders in H1 2025 alone. Users never told their data was demanded.
Documented: Storm-0558: Chinese hackers used a stolen Microsoft signing key to access US government officials' email accounts. Microsoft's own infrastructure was the attack vector.
What is PRISM? · What is the CLOUD Act? · Transparency report
Sources