Data and privacy in WebView2

WebView2 collects a set of optional and required diagnostic data to keep WebView2 secure and up to date, diagnose issues, and improve WebView2. By agreeing to the WebView2 Runtime Terms and Conditions License, WebView2 developers acknowledge that WebView2 will collect the data that's described in this article. To view the license, go to Download the WebView2 Runtime, where clicking any of the download buttons, such as Get the Link, Download, or x64, shows the license in a dialog.

Additionally, WebView2 follows the standards that are outlined in Microsoft Edge Privacy Whitepaper. WebView2 has mechanisms to ensure privacy. WebView2 data collection follows the same strict standards as Microsoft Edge. For more information, see Microsoft Privacy Statement – Microsoft privacy.

The main diagnostic data sources are:

  • Chromium and Microsoft Edge telemetry infrastructure.
  • Windows data reporting.
  • Watson (Microsoft Internal) infrastructure to collect crash dumps.

This article is for WebView2 developers.

Optional diagnostic data

WebView2 is a Windows component and thus follows the Windows diagnostic data collection practices. For more information, see Windows diagnostic data. The data collection consent for WebView2 is governed by the Settings > Privacy & security > Diagnostics & feedback > Diagnostic data setting on Windows 10 and Windows 11 as a centralized switch.

Users can control WebView2 data collection through the Windows Diagnostic data setting on Windows 10 and Windows 11, as shown below. As a developer, consider conveying this to your WebView2 app users and inviting them to use the Windows Diagnostic data setting to fit their preference.

Here's an example of diagnostic data settings, for a Windows 11 machine that has some settings managed by an organization:

Settings on Windows 11 for Diagnostic data

When the Windows Diagnostic data setting is on:

  • WebView2-related data is collected, including API usage, SDK usage, and creation failure.
  • Browser diagnostic data is collected. Only browser events that are relevant to WebView2 are collected.

Regardless of the Windows Diagnostic data setting, WebView2 collects required data that's necessary to maintain performance and reliability; see Diagnostics, feedback, and privacy in Windows.

Although you don't have control of overall diagnostic data collection, WebView2 offers APIs to control the behavior of the following features that generate data:

  • SmartScreen.
  • Custom crash reporting.

These features are described below.

SmartScreen

Microsoft Defender SmartScreen ("SmartScreen") is a security feature that is enabled by default to help users safely browse the web. The IsReputationCheckingRequired property controls whether SmartScreen is enabled. Generally, all other services in edge://settings/privacy are turned off, for WebView2.

If you don't disable SmartScreen, you must provide notice to all users that your software includes Microsoft Defender SmartScreen, and collects and sends the user's information to Microsoft as disclosed in Microsoft Privacy Statement and in SmartScreen in Microsoft Edge Privacy Whitepaper.

See also:

Custom crash reporting

If any WebView2 process crashes, one or more minidump files are created and sent to Microsoft for diagnosis. Use this API to customize crash reporting when running diagnostics and doing analysis.

  • When IsCustomCrashReportingEnabled is set to true, Windows won't send crash data to the Microsoft endpoint.
  • To locate crash dumps and do customization with them, use the CrashDumpFolderPath property.

See also:

See also