Ombuntu

Privacy

Ubuntu and the browsers phone home by default. Ombuntu turns that off, and tells you exactly what it changed.

Every change is a config file or a service state, listed here with its location so you can reverse any of them. Running the installer again re-applies the set.

Canonical and Ubuntu

Firefox

A policy file at /etc/firefox/policies/policies.json, which the snap reads too: telemetry, Firefox Studies, Pocket, sponsored tiles and suggestions, and recommendation nags are off; tracking protection is strict with cryptomining and fingerprinting blocked.

Chrome, Chromium, Brave, Edge, Vivaldi

A policy file in each browser's managed-policy directory (for example /etc/vivaldi/policies/managed/): metrics reporting, URL-keyed data collection, extended Safe Browsing reporting, cloud spell-check, address-bar search suggestions, alternate error pages, link prefetching, promotions, surveys, shopping features and the Privacy Sandbox ad APIs are off. Field-trial fetching is limited to critical fixes. Edge additionally has diagnostic data and personalisation reporting off.

Saved passwords are stored with the GNOME keyring rather than a plain-text fallback, because Ombuntu launches browsers with the keyring backend selected.

Developer tools

DO_NOT_TRACK=1 and the opt-out variables for .NET, Next.js, Nuxt, Astro, Gatsby, Homebrew, PowerShell, Azure CLI, AWS SAM, Stripe CLI and Hugging Face are set in the session and shell. VS Code and Zed installed from the menu get telemetry off in their settings.

Left alone, and why

Security choices