What Is Chrome’s Privacy Sandbox?
With privacy sandbox Chrome explained simply: it is Google’s multi-year initiative to replace third-party cookies with new browser APIs that keep ad targeting functional while limiting cross-site tracking. Five core components — Topics API, Protected Audiences, Attribution Reporting, Related Website Sets, and Private State Tokens — each handle a different piece of the advertising puzzle. But here is the critical nuance most coverage misses: Privacy Sandbox does not eliminate tracking. It moves tracking from third-party ad networks into Chrome itself, with Google as the new intermediary.

Why Google Built Privacy Sandbox
Third-party cookies have been the backbone of online advertising for over two decades. They let ad networks track users across websites, build behavioral profiles, and serve targeted ads. Safari and Firefox blocked third-party cookies years ago. Chrome, which controls roughly 65% of the global browser market, held out — because Google’s advertising revenue depends on the targeting infrastructure those cookies enable.
Privacy Sandbox is Google’s answer to an impossible-seeming problem: how do you kill third-party cookies (which regulators and users demand) without killing the ad targeting engine (which funds Google’s business)? The solution was to rebuild tracking capabilities directly inside the browser, giving Google control over both the mechanism and the data.
The Timeline
| Date | Milestone |
|---|---|
| January 2020 | Privacy Sandbox initiative announced |
| 2021–2022 | Origin trials for FLoC, then Topics API, FLEDGE, Attribution Reporting |
| July 2023 | Topics API and Protected Audiences reach general availability in Chrome 115 |
| January 2024 | Chrome begins disabling third-party cookies for 1% of users |
| July 2024 | Google reverses full cookie deprecation — third-party cookies stay, Sandbox APIs remain optional |
| April 2025 | Google announces revised approach: user-choice prompt for cookie preferences |
| 2026 | Privacy Sandbox APIs fully available; third-party cookies still active with user controls |
The fact that Google reversed course on cookie deprecation in 2024 is telling. It signals that the advertising industry — including Google’s own ad business — was not ready to operate solely on Privacy Sandbox signals. The APIs are live, but adoption remains uneven.
The Five Core Components Explained
1. Topics API (Replaced FLoC)
The Topics API is Chrome’s replacement for interest-based ad targeting. Instead of third-party cookies tracking you across sites, Chrome itself classifies your browsing history into a set of interest “topics” from a taxonomy of roughly 470 categories (sports, travel, technology, etc.).
How it works:
- Chrome monitors your browsing history locally on your device
- Each week, Chrome assigns your top 5 interest topics based on the sites you visited
- When you visit a site with ads, Chrome shares up to 3 topics (one from each of the past 3 weeks) with the ad network
- A random topic is included 5% of the time to add noise
- Topics expire after 3 weeks and are never sent to Google’s servers
Privacy reality: Topics API is genuinely more private than third-party cookies. Your full browsing history stays on-device, topics are coarse-grained, and they expire quickly. However, Chrome is still classifying your behavior and sharing interest signals with advertisers — it just does so with less granularity. And the browser doing the classifying is Chrome, a Google product.
2. Protected Audiences (Formerly FLEDGE)
Protected Audiences handles remarketing — showing you ads based on sites you have previously visited. Currently, this works through third-party cookies: you visit a shoe store, and the shoe store’s ad network follows you across the web with shoe ads.
How it works:
- When you visit a site, that site can ask Chrome to add you to an “interest group” (e.g., “viewed running shoes”)
- Interest groups are stored locally in Chrome, not on ad network servers
- When you visit a page with ad slots, Chrome runs an on-device auction to determine which interest group’s ad wins the slot
- The winning ad is displayed in a “fenced frame” that prevents the ad from reading page data or vice versa
- Reporting uses aggregate data rather than individual-level tracking
Privacy reality: Protected Audiences genuinely removes third-party servers from the remarketing loop — the auction happens in your browser. But it still enables remarketing, and the sites that add you to interest groups know you visited. The system is complex enough that smaller ad networks struggle to implement it, potentially concentrating more power with Google’s own ad platform. Understanding how your browser fingerprint works alongside these APIs is essential for grasping the full privacy picture.
3. Attribution Reporting API
Attribution Reporting lets advertisers measure whether their ads led to conversions (purchases, sign-ups, etc.) without tracking individual users across sites.
How it works:
- When you click or view an ad, Chrome stores an “attribution source” locally
- If you later convert on the advertiser’s site, Chrome matches the source to the conversion
- Reports are sent to the advertiser with noise added, delays of up to 3 days, and limited data (no user identifiers)
- Two report types: event-level (limited conversion data per click) and aggregate (noisy statistical summaries across many users)
Privacy reality: This is arguably the most privacy-friendly component. The noise addition and delays genuinely prevent individual-level tracking. However, large advertisers with high traffic volumes can still derive meaningful signals from aggregate data, while smaller advertisers may find the noisy reports too imprecise to be useful — creating another asymmetry that favors large players like Google.
4. Related Website Sets (Formerly First-Party Sets)
Related Website Sets let companies declare that multiple domains belong to the same organization (e.g., google.com, youtube.com, and gmail.com are all “Google”). Browsers can then allow limited cross-site data sharing between these declared related sites.
How it works:
- Organizations submit a JSON manifest listing their related domains
- Chrome validates these through a public GitHub repository
- Related sites can share certain cookies and storage using the Storage Access API
- Sets are capped at a maximum number of associated domains to prevent abuse
Privacy reality: On the surface, this is reasonable — a company should be able to keep you logged in across its own properties. In practice, large corporations with dozens of domains benefit disproportionately. Independent sites that use shared services (authentication providers, CDNs) don’t gain the same advantages. The feature is also Chrome-specific, with Firefox and Safari declining to implement it.
5. Private State Tokens (Formerly Trust Tokens)
Private State Tokens help websites distinguish real users from bots without relying on fingerprinting or third-party cookies. They are cryptographic tokens that carry a “trust” signal without identifying the user.
How it works:
- A trusted issuer (e.g., a CAPTCHA provider) issues tokens to users who pass verification
- Users can “spend” these tokens on other sites to prove they are likely human
- Tokens use cryptographic blinding so the issuer cannot correlate issuance to redemption
- Sites can check whether a user has tokens without learning anything about the user’s identity
Privacy reality: This is the strongest privacy component in the Sandbox. It addresses a real problem (bot detection) without tracking individual users. However, the system depends on a limited set of trusted issuers, which again creates centralization pressure — whoever controls the “trust” infrastructure gains significant power over web access.
The Core Criticism: Google as the New Intermediary
Privacy Sandbox replaces distributed tracking (many ad networks with cookies) with centralized processing (Chrome itself handling targeting, auctions, and measurement). This is the fundamental tension that critics highlight.
Anticompetitive Concerns
The UK’s Competition and Markets Authority (CMA) investigated Privacy Sandbox and imposed commitments on Google before allowing the project to proceed. The CMA’s concern was straightforward: by moving ad infrastructure into Chrome, Google gains an unfair advantage over competing ad networks that relied on third-party cookies. Google’s own ad platform has first-party data from Search, YouTube, Gmail, and Android — it doesn’t need third-party cookies the way smaller competitors do.
Cross-Browser Fragmentation
Privacy Sandbox is a Chrome initiative. Firefox has not adopted any Privacy Sandbox APIs, preferring its own Total Cookie Protection system. Safari continues to use Intelligent Tracking Prevention. This means Privacy Sandbox creates a Chrome-specific web where ad targeting works differently depending on the browser — further entrenching Chrome’s market position.
The “Privacy” Framing Problem
Calling it “Privacy Sandbox” implies that it protects user privacy. And in narrow technical terms, some components do improve on the cookie-based status quo. But the overall effect is to preserve behavioral advertising while shifting control to Google. Users who want actual privacy — not just “better than cookies” privacy — need solutions that go beyond what any browser vendor’s ad framework offers. Implementing your own safe browsing practices remains essential regardless of which APIs Chrome deploys.
Privacy Sandbox vs. Real Privacy: A Comparison
| Feature | Privacy Sandbox (Chrome) | Antidetect Browser (e.g., Send.win) | Tor Browser |
|---|---|---|---|
| Third-party cookie blocking | Optional (user choice) | Per-profile isolation | Blocked by default |
| Interest-based targeting | Topics API (on-device) | No ad targeting | No ad targeting |
| Cross-site tracking prevention | Partial (API-based) | Full session isolation | Full (Tor circuit per tab) |
| Fingerprint protection | Minimal | Per-profile spoofing | Uniform fingerprint |
| Multi-account support | None | 150–500 profiles | Not designed for this |
| Automation API | N/A | Selenium/Puppeteer/Playwright | Not recommended |
| Speed | Normal | Normal | Slow (onion routing) |
| Data controller | User | User (decentralized) |
Impact on Advertisers and Marketers
If you run ad campaigns, Privacy Sandbox changes your attribution and targeting capabilities in meaningful ways:
Targeting Gets Coarser
Topics API provides interest categories, not individual user profiles. If you currently rely on precise behavioral targeting through third-party cookies, expect reduced signal quality. Contextual advertising (targeting based on page content rather than user behavior) becomes more important.
Remarketing Changes Mechanics
Protected Audiences moves remarketing into the browser. You can still retarget users, but the auction runs on-device, reporting is delayed and noisy, and fenced frames limit creative flexibility. Campaign optimization loops become slower.
Measurement Loses Precision
Attribution Reporting adds noise and delays. Multi-touch attribution models that require precise per-user journey tracking become impractical. Marketers need to shift toward incrementality testing and media mix modeling — approaches that work with aggregate data.
The Multi-Account Problem
Marketers and agencies managing multiple client accounts, ad accounts, or e-commerce storefronts cannot rely on Privacy Sandbox for anonymous browsing across those accounts. Sandbox APIs don’t provide session isolation — they assume one user with one browser profile. Professionals who need distinct browser environments per account need purpose-built tools.
How Antidetect Browsers Operate Outside Sandbox Constraints
Privacy Sandbox operates within Chrome’s architecture — it reshapes how Chrome handles ads and tracking. Antidetect browsers step outside this architecture entirely by creating isolated browser environments where each profile has its own fingerprint, cookies, storage, and network route.
This means Privacy Sandbox APIs are irrelevant to users who already isolate their sessions. Topics API cannot classify your interests if each profile has a separate browsing history. Protected Audiences cannot retarget you if each profile has its own interest groups. Attribution Reporting cannot link your ad clicks to conversions across profiles because there is no shared identity layer. Proper session isolation is a more complete privacy solution than any API framework that still assumes a single user identity.
Send.win for Privacy Beyond Sandbox
Send.win provides the browser-level isolation that Privacy Sandbox does not. Where Sandbox reshapes tracking within a single browser profile, Send.win eliminates cross-contamination between profiles entirely.
Sendwin Browser, the native desktop application for Windows, macOS, and Linux, lets you create up to 150 (Pro) or 500 (Team) isolated browser profiles. Each profile has unique fingerprint parameters, separate cookie jars, independent local storage, and its own proxy configuration. This is genuine isolation, not an API-mediated compromise.
Cloud browser sessions go further — run profiles on cloud infrastructure without installing anything locally. Each cloud session starts clean, with no data leakage between sessions or to your local machine.
The Automation API supports Selenium, Puppeteer, and Playwright, available on both Pro and Team plans. Automate workflows across isolated profiles without the limitations that Privacy Sandbox imposes on automation tools.
Pricing starts at $9.99/month for Pro ($6.99/month with annual billing) with 150 profiles, 5GB bandwidth, and a 30-day free trial that requires no credit card. The Team plan at $29.99/month ($20.99/month annual) adds 500 profiles, 20GB bandwidth, and 16 seats for agency and team workflows.
🏆 Send.win Verdict
Chrome’s Privacy Sandbox improves on third-party cookies in narrow technical ways, but it does not deliver meaningful privacy. It reshapes ad tracking to run inside Chrome with Google as the new data controller — hardly a win for users who want real autonomy. For genuine privacy, you need browser-level isolation where each profile is a separate, un-linkable environment. Send.win provides exactly that: isolated profiles with unique fingerprints, dedicated proxies, and zero cross-session data sharing. Privacy Sandbox is Google’s compromise with advertisers. Send.win is your tool for actual browser privacy.
Try Send.win free today — 150 isolated profiles, 30-day trial, no credit card required.
Frequently Asked Questions
What is Chrome Privacy Sandbox in simple terms?
Chrome Privacy Sandbox is a collection of browser APIs that replace third-party cookies for advertising purposes. Instead of ad networks tracking you with cookies, Chrome itself handles interest classification (Topics API), ad auctions (Protected Audiences), and conversion measurement (Attribution Reporting) — all on your device. The goal is to maintain targeted advertising while reducing cross-site tracking, but Google controls the entire system.
Does Privacy Sandbox actually protect my privacy?
Partially. It reduces the number of parties that can track you by moving ad processing into the browser. Your full browsing history stays on-device, and individual-level tracking is harder. However, Chrome still classifies your interests and shares them with advertisers, remarketing still works through interest groups, and Google — as both the browser maker and the world’s largest ad company — controls the entire system. It is better than cookies, but far from true privacy.
Will third-party cookies be removed from Chrome?
As of 2026, no. Google originally planned to deprecate third-party cookies entirely but reversed course in July 2024. Instead, Chrome now offers users a choice about cookie preferences. Third-party cookies and Privacy Sandbox APIs coexist, with adoption of the new APIs remaining optional for advertisers.
How does Privacy Sandbox affect advertisers?
Targeting becomes coarser (broad interest categories instead of individual profiles), remarketing moves to on-device auctions with delayed reporting, and attribution measurements include noise to prevent individual tracking. Large advertisers with first-party data adapt more easily; smaller advertisers who relied on third-party cookies for precise targeting are disproportionately affected.
Do Firefox and Safari support Privacy Sandbox?
No. Firefox uses Total Cookie Protection (isolating cookies per site) and Safari uses Intelligent Tracking Prevention (machine learning-based tracker blocking). Both browsers have declined to implement Google’s Privacy Sandbox APIs. This means Privacy Sandbox only affects Chrome users, creating a fragmented web where ad targeting works differently across browsers.
Can Privacy Sandbox prevent browser fingerprinting?
Not effectively. Privacy Sandbox focuses on replacing cookie-based tracking, not on fingerprinting. Chrome has made minor fingerprinting mitigations (reducing User-Agent string detail via User-Agent Client Hints), but canvas fingerprinting, WebGL fingerprinting, audio context fingerprinting, and dozens of other vectors remain available. Fingerprint protection requires dedicated tools that manage each data point per profile.
How do antidetect browsers bypass Privacy Sandbox limitations?
Antidetect browsers create fully isolated browser profiles, each with its own cookies, storage, fingerprint parameters, and network configuration. Privacy Sandbox APIs operate within a single profile — they cannot correlate activity across separate, isolated profiles. This makes session isolation a more complete privacy solution than any API-level framework that assumes a single user identity per browser.
Is Privacy Sandbox the same as Google’s FLoC?
No, but it is related. FLoC (Federated Learning of Cohorts) was an earlier Privacy Sandbox proposal that grouped users into behavioral cohorts for ad targeting. After criticism that cohorts could enable new forms of tracking and discrimination, Google replaced FLoC with the Topics API, which uses broader interest categories and shorter retention periods. Topics API is the current interest-based targeting component within Privacy Sandbox.
Run Privacy Sandbox Chrome Explained in the Cloud With Send.win
Send.win’s cloud browser runs your isolated profiles on remote infrastructure — open a clean, fingerprint-isolated session from any device without installing anything:
- Instant cloud sessions – launch an isolated browser in seconds, no local install
- Isolated profiles – separate fingerprint, cookies, and storage per session
- Cloud sync & profile sharing – pick up the same profiles on the desktop app (Windows, macOS, Linux) or share them with your team
- Built-in residential proxies – with automatic timezone and locale matching
You can try it right now: the Send.win demo browser opens an isolated cloud session directly in this browser tab. The 30-day free trial needs no credit card, and paid plans start at $6.99/month billed annually — see pricing.