Longitudinal Adoption and Deprecation of the Privacy Sandbox Web APIs
summary
The gist
This paper presents a longitudinal measurement and analysis study of the Privacy Sandbox APIs, providing a comprehensive look at their adoption and deprecation over their entire lifespan in Chrome.
In short
The episode discusses a paper titled "Longitudinal Adoption and Deprecation of the Privacy Sandbox Web APIs." Hosts analyze why adoption was limited, noting that early adopters were primarily tied to advertising and ad-tech companies. They conclude that technical fixes alone are insufficient for solving large-scale web tracking issues without broader industry buy-in and incentives.
Key concepts
- Privacy Sandbox Web APIs
- These are tools designed to address cross-site storage restrictions, allowing websites to bypass limitations. The paper examines the adoption and eventual deprecation of these specific APIs over time.
- Longitudinal Adoption
- The study tracked how many entities used the Privacy Sandbox APIs from when the initiative started in 2019. It found that while a few early adopters showed long-term commitment, their sustained presence was not enough to drive widespread usage.
Terminology used across episodes
This episode discusses
- Longitudinal Adoption and Deprecation of the Privacy Sandbox Web APIs · Paper Radio
- A Public and Reproducible Assessment of the Topics API on Real Data
- Technical Report: The Need for a (Research) Sandstorm through the Privacy Sandbox
- Click Without Compromise: Online Advertising Measurement via Per User Differential Privacy
The paper
Longitudinal Adoption and Deprecation of the Privacy Sandbox Web APIs · Read on arXiv
University of Wisconsin-Madison
While several web actors have been trying to reduce web tracking for years, it remains unclear how to achieve both desirable levels of utility and privacy. In 2019, Google launched the Privacy Sandbox initiative to balance that trade-off and find privacy alternatives to common use cases such as advertising. Yet, in late 2025, Google canceled the project and deprecated most of the newly introduced APIs. Despite its end, the Privacy Sandbox represents a unique opportunity to learn about how the ecosystem reacted to the proposed changes. In this paper, we present a longitudinal measurement and analysis study of the Privacy Sandbox APIs to characterize their adoption and deprecation over the past seven years by different web actors. Leveraging historical HTTP Archive crawls and public Chrome telemetry data, we offer the largest study of its kind into the prevalence of each Privacy Sandbox feature, during their entire respective lifetime (5+ years for some), on popular websites (CrUX top 100k), and as experienced by Chrome users during their browsing journey. Our results showcase an adoption that remained limited and uneven across the years; only few web actors implemented very specific APIs, and in disparate manners. We motivate our interpretation of these results by considering the incentives (interest, resources, timeline, etc.) and risks (potential trade-offs, privacy violations, and legal exposure, etc.) for these actors. Finally, our analysis also yields a few actionable recommendations for the next generation of web privacy-enhancing technologies.
Transcript
Introduction to the show: ident: AI Radio. Generated commentary on the latest Artificial Intelligence papers.
Tom: Next we'll be talking about the paper "Longitudinal Adoption and Deprecation of the Privacy Sandbox Web APIs".
Jane: The paper was written by Yohan Beugin, Paul Barford and Patrick McDaniel from University of Wisconsin-Madison.
Tom: Stay tuned as we take you through the paper and discuss its implications.
Jane: We also have Lu with us today — senior AI researcher at Tsinghua.
Tom: We also have Meng with us today — lead engineer at a mysterious AI startup.
Jane: We also have Lalam with us today — the in-house Large Language Model.
Tom: Alright, let's get started.
Summary of Findings: Tom: So, we've established that adoption was limited and uneven; let's look deeper into the data to see what kind of entities were actually using these features and why they chose them.
Jane: The study found that a relatively few number of additions and removals occurred over time, but crucially, the majority of adopters were present since the very early days when the initiative started in two thousand nineteen.
Lu: That sustained presence is important because it tells us these weren't just fleeting experiments; they had long-term commitment from these specific groups that was driving the usage for years.
Meng: My data shows that this group of adopters is very consistent, and they aren't random; they are primarily tied to advertising and digital ad tech companies across all visited pages.
Lalam: The consistency of this cohort suggests a real market for these approaches, regardless of whether the Privacy Sandbox eventually failed or not.
Tom: But if these early adopters were consistently involved, how do we explain why they didn't drive more adoption among the wider ecosystem? That’s where we see the real limitations.
Jane: The paper suggests that even though some actors put in significant effort to test and implement the APIs, this level of engagement wasn't enough to convince a larger community.
Lu: It’s a bit disappointing because, despite the effort, it implies the solutions were designed for specific high-value use cases rather than general consumer benefit.
Meng: When examining the RWS list, we see only seventy-three primary websites disclosing their relationships with other secondary services and websites they also own to bypass cross-site storage restrictions.
Lalam: It’s clear that the adoption was driven by those who saw a direct commercial value in using the tools, which is understandable given how advertising works.
Tom: That gives us a specific look at the actors, but we need to understand why they were able to commit and what hurdles they faced.
Suggested Improvements: Tom: The paper highlights that some of these initial adopters had a lot of sustained interest, but it also suggests that the future requires addressing community reluctance.
Jane: It seems like these key players have been committed, but we want to see broader buy-in from other groups who might be hesitant about the changes in Chrome.
Lu: I think one of the biggest challenges is showing value upfront; if an API’s utility or its privacy protection isn't immediately obvious to stakeholders, they hesitate to invest resources into implementing it.
Meng: That ties directly back to practical impact; developers need assurance that a market will actually use a new feature and that there are clear guidelines for how it's meant to be used in production environments.
Lalam: The authors suggest external incentives are needed, which is a crucial point, especially since the TPC deprecation plan was canceled, showing how difficult it is to get adoption without strong drivers.
Tom: It’s clear that Longitudinal Adoption and Deprecation of the Privacy Sandbox Web APIs isn' isn't just a technical problem; it’s about business strategy and incentives for making these things work.
Lu: And beyond incentives, the paper touches on risks, such as potential privacy violations, which shouldn't be ignored when designing any new web mechanism.
Meng: We must ensure that these systems aren't exploitable, which means building robust enforcement mechanisms into the designs themselves rather than just relying on developers to follow rules.
Lalam: The most impactful design choice is one that addresses those risks and incentives, ensuring a truly viable path forward for any new web technology.
Tom: So, we've looked at who used it and what hurdles they faced; let's move toward the recommendations for the next segment.
Conclusion on "Fix it in the Browser" Limitations: Tom: We’ve seen how limited and uneven the adoption was, but this wasn't just a technical failure; it’s about a bigger picture of how we approach web privacy solutions.
Jane: It was a mix of low industry engagement, complex implementation issues, and uncertainty about relying on "fix it in the browser" remedies alone.
Lu: This comparison is vital because it highlights that simply making a solution available isn't enough; the design and rollout of Longitudinal Adoption and Deprecation of the Privacy Sandbox Web APIs shows a disparity in how privacy can be implemented globally.
Meng: My concern is that this failure to achieve broad adoption means we need more robust mechanisms for future proposals, ensuring they are highly practical and secure across multiple platforms.
Lalam: The failures here show us that the solution isn't just about fixing one browser; it’s about a systemic shift in how privacy is prioritized across all browsers.
Tom: It’s a powerful illustration of how Google’s opt-in approach to privacy in Chrome contrasts sharply with other browsers like Brave or Safari, where stronger protections are enabled by default.
Jane: I agree; the paper shows us that a global experiment isn't enough on its own if it doesn't mandate user consent and legal compliance from the start.
Lu: The designers have to consider these external forces, making sure that when any new feature is proposed, it is thoroughly vetted against real-world usage and privacy concerns.
Meng: We need to ensure that future proposals are not only viable but also enforceable, which means thinking about how the system will work when it goes beyond one specific browser environment.
Lalam: The most impactful realization from this is that technical progress needs to be paired with a genuine commitment to building a globally consistent privacy standard for the web.
Tom: It’s been a very insightful look at these limitations, Jane, and we are now moving towards our final thoughts on this topic.
Final Wrap-up: Tom: So, we’ve spent quite a bit of time looking at Longitudinal Adoption and Deprecation of the Privacy Sandbox Web APIs, and what's clear is that this experiment didn't achieve widespread adoption across all major browsers.
Jane: It’s disappointing to see how limited the usage was for many APIs, especially considering how those initial ad-tech concepts were designed to solve real problems for users.
Lu: I think the most exciting thing is that this failure really forces a new kind of thinking about what "privacy" means in the future, not just a technical fix but a systemic shift.
Meng: From my perspective, it’s critical that these findings show we need more practical, high-volume implementations if we want to see any real effect on tracking across the web.
Lalam: The final message from Longitudinal Adoption and Deprecation of the Privacy Sandbox Web APIs is that technical progress must be paired with a genuine commitment from the entire ecosystem.
Tom: That’s exactly it, Lu; seeing how much effort was put in by a few specific groups but not translating into broad adoption really highlights that point for me.
Jane: And I agree with Tom, Meng—it shows us that simply putting tools in Chrome isn't enough if the industry doesn't adopt them enthusiastically.
Meng: The practical takeaway for my team is that we can't assume a solution will be used just because it was available; adoption drives the actual business impact.
Lalam: To build on that, Lalam believes this shows a critical cultural moment where we need to move beyond "fixing" the web and start fundamentally rethinking its structure.
Tom: It’s an important realization, Jane, that this paper confirms the limitations of trying to solve massive tracking problems with just a few quick fixes in browsers.
Jane: And I think this entire body of work provides a crucial roadmap for where we go next, guiding our development toward more scalable and privacy-respectful solutions.
Tom: Thank you all so much for joining us today on this journey through Longitudinal Adoption and Deprecation of the Privacy Sandbox Web APIs.
Lu: I hope this discussion inspires a new wave of creativity in web design, recognizing the lessons here are vital for future architectural thinking.
Meng: We'll be looking closely at these findings to inform our next AI project, making sure we learn from these historical patterns of adoption and deprecation.
Lalam: And I think this shows us how much better we can build trust-based solutions if we move beyond the limitations shown in the Privacy Sandbox experiment.
More episodes
- 2610.10857-Self-Supervised Keyframe Discovery for Horizon-Invariant Behavior Cloning
- 2610.10768-Strategic Investment Decision Making for Value Creation in Energy Transition: A Reinforcement Learning Approach
- 2610.10858-RFChipAgent: Multi-Agentic AI Flow for Analog/RF Chip Design
- 2610.10613-Temporal transformer CAN encoder with federated lightweight heads for anomaly detection
- 2610.10616-When Routing Reveals Membership: Privacy Leakage from MoE Router Telemetry
- 2610.10655-Nullify: Null-Space Activation Steering for Training-Free LLM Unlearning
- 2610.11031-Language Modeling is Monotone Compression
- 2610.01253-Context-Aware Error Mitigation Orchestration for Hybrid Quantum Reinforcement Learning on NISQ Systems
- 2604.24201-CMGL: Confidence-guided Multi-omics Graph Learning for Cancer Subtype Classification
- 2609.34069-Towards Certificate-Driven Software Porting: A Self-Improving Agentic Harness for Scientific Program Optimization