PrivacyPick
Vivaldi logo

Vivaldi

Chromium

5.9
out of 10

Published September 2, 2026By Juan Martinez

Vivaldi
◐ Partly open source
Visit Vivaldi →

This link earns us nothing — it points to the vendor's own site with no tracking. It's here for the review, not a commission.

Engine
Chromium
Open Source
partial
Telemetry
always-on
Established
2016
Privacy Features
Ad/Tracker Block Built-In
End-to-End Encrypted Sync
Built-In VPN/Proxy
Anti-fingerprinting: basicDefault search: Varies by locale (Bing on mobile)
Platforms
WindowsmacOSLinuxAndroidiOS
In This Article

Best for: people who want a highly customisable Chromium browser from an independent company with a clean business model — and who will spend a few minutes turning on the blocking and locking down the settings it doesn’t enable for them.

Pros

  • Made by an independent company in Norway and Iceland with no outside investors, no advertising platform, and no data-brokering line of business — revenue comes from search and bookmark partner deals
  • The privacy policy is specific and readable: browsing history never leaves the device, there is no behavioural profiling, and sync data is end-to-end encrypted
  • Sync uses a separate encryption passphrase (minimum 12 characters) that never reaches Vivaldi’s servers, so the company cannot read your bookmarks, passwords, history, or tabs even though an account is involved
  • A built-in tracker and ad blocker (EasyList plus DuckDuckGo Tracker Radar) with no extension to install, once you switch it on
  • The most customisable browser in this section by a wide margin — tab tiling and stacking, side panels, and a built-in mail client, calendar, and feed reader, all optional
  • Chromium underneath, so Chrome extensions, DRM video, and site compatibility work the way people expect
  • Official builds for all five major platforms plus Raspberry Pi and Android Automotive, with fast security patching on Chromium’s Extended Stable track

Cons

  • Every installation is assigned a persistent unique ID that is sent to Vivaldi’s servers every 24 hours along with version, CPU architecture, and screen resolution — and there is no setting to turn this off. Vivaldi truncates the IP address and says the ID is only used to count active users, but for a browser marketed as not tracking you, an unremovable identifier is a real caveat
  • The ad and tracker blocker is off by default; a fresh install does very little until you pick a blocking level in settings
  • No meaningful anti-fingerprinting: there is no resist-fingerprinting mode, and independent tests report a near-unique fingerprint out of the box
  • Not fully open source — the Chromium modifications are published under a BSD license and the interface code ships readable, but Vivaldi also contains proprietary code and there are no reproducible builds
  • No published independent security audit of the browser, and no paid bug-bounty program — only coordinated disclosure with a Hall of Fame credit
  • The built-in “VPN” is Proton VPN wired into the desktop browser: it protects the browser’s connection only, not the whole device, and it is desktop-only
  • The default mobile search engine is Microsoft Bing
  • The sheer number of features and settings can overwhelm someone who just wants a browser that is private out of the box

Privacy Defaults

Vivaldi’s slogan is “privacy is a default,” and parts of that hold up: your browsing history stays on your machine, Vivaldi has no access to it, there is no usage or feature telemetry, and the company doesn’t run an ad network or sell data. That is a genuinely better starting position than a mainstream Chromium browser.

The gap is that the protective features are opt-in. The tracker and ad blocker is off until you choose a level — during first-run setup you can pick “Block trackers” or “Block Trackers and Ads,” but if you skip past that, a fresh Vivaldi blocks nothing. Google Safe Browsing and Google’s form autofill are on by default (both can be turned off on desktop). And every install sends a daily ping containing a persistent unique identifier, version, CPU architecture, and screen resolution, with no opt-out. Vivaldi removes the last octet of the IP address and says the ID is used only to size its user base for partner negotiations, and the ping carries no browsing data — but an identifier that can’t be disabled sits awkwardly next to the marketing. Out of the box, Vivaldi is a privacy-conscious browser that isn’t yet in its private configuration.

Anti-Fingerprinting

This is Vivaldi’s weakest area. There is no resist-fingerprinting mode, no canvas or WebGL randomisation, and no shared-profile approach. What Vivaldi does is narrow: it limits the Battery Status API and keeps its user-agent string sparse, reporting as Chrome so sites don’t break — which incidentally blends its users into the larger Chrome pool, but only for that one signal.

On EFF’s Cover Your Tracks, a stock Vivaldi typically comes back with a near-unique fingerprint. Canvas, WebGL, font enumeration, screen metrics, and audio-stack characteristics are all readable. Users who want fingerprinting resistance have to stack extensions, and the community has repeatedly asked for a built-in defense. If cross-site fingerprinting is part of your threat model, Vivaldi as shipped does not address it.

Transparency & Audits

The company side of this is strong. Vivaldi Technologies is independent, based in Norway and Iceland, has no venture capital or outside investors, and makes money from search and bookmark partner deals rather than advertising or data. The privacy policies are detailed and name where data is stored (Iceland). There is no history of a privacy scandal on the scale seen at some competitors.

Two things hold the score down. First, the code: Vivaldi is only partly open. The Chromium modifications are published under a BSD license and the interface is readable JavaScript, so “available for audit” is a fair description — but Vivaldi also ships proprietary code, there is no single open-source license, and there are no reproducible builds, so you cannot verify that the binary matches the published source. Second, external review is thin. There is no published independent security audit of the browser, and no paid bug-bounty — vulnerability handling is coordinated disclosure with a credit in a Hall of Fame. Add the unremovable daily identifier, which cuts against the “we don’t track you” framing, and this lands as a browser from a trustworthy-looking company that hasn’t fully shown its work. A browser whose full source is public and reproducibly buildable earns more trust here even if its corporate history is messier — you can check what it does; with Vivaldi you are partly taking the company’s word for it.

Usability & Compatibility

This is where Vivaldi is clearly ahead. Because it is Chromium, Chrome extensions install and run, sites render as they do in Chrome, and DRM video plays normally. On top of that Vivaldi layers more built-in functionality than any other browser here: two-level tab bars, tab stacking and tiling, side panels for web pages, a full email client, a calendar, a feed reader, notes, and page capture — all optional, all off unless you turn them on.

The trade-off is the opposite of a stripped-down privacy browser: nothing breaks, but there is a lot to take in. The settings run deep, the interface has many moving parts, and a non-technical user who just wants “a private browser” faces a lot of surface area. There is no site breakage penalty the way an always-on aggressive blocker would cause — partly because the blocker isn’t always-on — so day-to-day compatibility is excellent.

Cross-Platform & Sync

Vivaldi covers Windows, macOS, Linux, Android, and iOS with official builds, and also ships for Raspberry Pi and Android Automotive. On iOS it is bound to WebKit like every other browser there, so the iOS version is the Vivaldi interface and blocking over Apple’s engine rather than Vivaldi’s own.

Sync is the highlight. It runs through a Vivaldi account, but the synced data — bookmarks, passwords, history, tabs, notes, autofill, extensions — is end-to-end encrypted with a separate passphrase of at least 12 characters that never leaves your device. Vivaldi’s servers, hosted in Iceland, hold only ciphertext plus structural metadata (entry types, timestamps, tree relationships) and cannot decrypt the contents even with your login password. A downloadable backup key is offered so a forgotten passphrase doesn’t mean lost data. It is a solid, genuinely private sync design.

Our Rating

Category Score
Privacy Defaults 5.5/10
Anti-Fingerprinting 3.5/10
Transparency 6/10
Usability & Compatibility 8.5/10
Cross-Platform & Sync 9/10
Overall 5.9/10

Weighted: Privacy Defaults 30% · Anti-Fingerprinting 25% · Transparency 20% · Usability & Compatibility 15% · Cross-Platform & Sync 10%.

Vivaldi is the most feature-rich browser in this section and comes from one of the cleaner companies in it — independent, no investors, no ad platform, a specific privacy policy, and a genuinely private sync. But the rating is about privacy out of the box, and there Vivaldi underperforms the dedicated options: the blocker ships off, there is essentially no fingerprinting defense, the code is only partly open with no reproducible builds or independent audit, and every install carries an identifier you can’t switch off. If you want deep customisation and a browser from a company whose incentives you trust, and you’re willing to configure it, Vivaldi rewards the effort. If you want the defaults to already be the private choice, this isn’t the browser for that.

Affiliate Disclosure

Vivaldi has no affiliate program for websites like ours, and this review carries no tracked link — the “Visit Site” button points to Vivaldi’s plain download page and earns us nothing. Our rating and what we write are unaffected either way.

Rating: 5.9/10

Ready to try Vivaldi?

Visit Vivaldi →

Last updated: September 2, 2026By Juan Martinez