The Google Incognito Lawsuit:
What the $5 Billion Figure
Actually Means

Date Published: 2nd August 2026 Author: Baizaar Lee Last Updated: 2nd August 2026
TL;DR:
The Google Incognito lawsuit ended in April 2024 with Google agreeing to delete billions of browsing records and rewrite its privacy disclosures, not with a payout. Nobody got a cheque. The $5 billion figure everyone quotes is a lawyers’ valuation of the data destroyed, not money that landed in anyone’s account. What the Google Incognito lawsuit actually proved, in Google’s own internal emails, is that Incognito mode was never built to stop Google, or anyone else’s tracking scripts, from watching what you did online. If you want browsing that’s genuinely hidden from the sites you visit, that’s a VPN’s job, not a browser mode’s.
If you used Incognito between 2016 and 2024 assuming Google couldn’t see your activity, the Google Incognito lawsuit settled that question. It could. It did.
This matters even if you’ve never opened Chrome. The case exposed how “private browsing” interacts with tracking code running on most of the web, and that code doesn’t check which browser logo is in the corner.
BAIZAAR may earn a commission if you buy through links on this page, at no extra cost to you.
- What the Google Incognito lawsuit actually proved
- The tracking Incognito never blocked
- Why the splash screen became evidence
- What the Google Incognito lawsuit changed, and what it didn't
- Firefox's private browsing is different, but not immune
- What actually works if you want to browse privately
- Limitations worth knowing
- Google Incognito Lawsuit (FAQ)
What the Google Incognito lawsuit actually proved
The Google Incognito lawsuit, formally Chasom Brown et al. v. Google LLC, was filed in California, June 2020, on behalf of anyone who’d browsed Chrome in “private” mode since June 2016. The claim was simple: Google kept collecting their data anyway, through Chrome itself, Google Analytics, and Google Ad Manager, no matter what the Incognito splash screen implied. Plaintiffs asked for at least $5 billion.
Here’s the part most coverage skips. In December 2022, more than a year before any settlement existed, the court had already ruled on something crucial. This case could only proceed as a demand for Google to change its behaviour. Not as a claim for money. Individual circumstances varied too much to lump everyone into one payout. Lawyers call this “injunctive relief only” certification. Plain version: a group cheque was never actually on the table, whatever headlines about the settlement figure implied later.
Google agreed to settle the day before a February 2024 trial was due to start. Cutting it close, even by Big Tech legal standards. When the terms went public on 1 April 2024, they showed the scale of what had been collected: court filings put the affected user base at roughly 136 million people. Google had also been using undisclosed “private browsing detection bits” to identify the exact moment someone switched to Incognito, according to Proton’s own coverage of the settlement filing.
Under the deal, Google agreed to:
- Delete or remediate billions of data records tied to Incognito sessions collected since 2016
- Rewrite Chrome’s Incognito disclosures so they describe what actually gets tracked
- Keep third-party cookies blocked by default in Incognito for five years
- Pay the class nothing, while leaving the door open for individuals to sue separately
Around 50 people had already filed individual claims in state court by the time the terms became public, according to NPR’s reporting. Google didn’t admit wrongdoing. Its defence, then and now, is that Incognito was only ever honest about one narrow thing: your history wouldn’t be saved locally. Everything downstream of that, the websites, their embedded analytics, was always fair game.
What actually forced Google’s hand wasn’t the marketing dispute alone. It was an email. Back in 2019, Chief Marketing Officer Lorraine Twohill wrote to CEO Sundar Pichai. Her argument: Google should “make Incognito Mode truly private.” The alternative, she said, was marketing copy built on “fuzzy, hedging language.” Google’s own top marketer thought the branding oversold the product. Juries tend to notice things like that.
The tracking Incognito never blocked
Incognito does three things, and only three. It doesn’t save your history, cookies, or site data once you close the window. It doesn’t keep form entries or site permissions. It doesn’t let someone else on the same device see what you searched for.
What it was never built to do: stop the sites you visit from logging your activity. Run the numbers and it’s obvious why that matters. Per W3Techs’ live tracking data, roughly 83% of websites running any known analytics tool are running Google’s. Same story for Google Ad Manager, DoubleClick, or any other Google service sitting quietly in the page’s code.
Those services don’t need a cookie to identify you, either. IP address, device fingerprint, user agent string, screen resolution, installed fonts, timezone, all of it persists whether or not Incognito just wiped your cookie jar. Clearing cookies is decent local housekeeping. It does nothing to the request your browser already sent to a server on the other side of the planet.
That’s the mechanism the Google Incognito lawsuit put on the record. Google wasn’t breaking into anyone’s private session. It was collecting data the ordinary way, through analytics tags most site owners installed years ago and haven’t thought about since.
Why the splash screen became evidence
For years, Incognito’s splash screen opened with:
“Now you can browse privately, and other people who use this device won’t see your activity.”
Smaller print below noted downloads and bookmarks would still be saved, and that websites could still see your activity. But the bold promise up top, “browse privately”, is the bit that stuck.
Judge Yvonne Gonzalez Rogers rejected Google’s bid to get the case thrown out on summary judgment in August 2023. Her finding: Google never explicitly told users that data collection continued while they browsed in Incognito. Internal filings reported by The Hacker News quoted Google employees describing Incognito as a “confusing mess” in one internal review, with blunter language elsewhere about basic professional ethics. That’s not a marketing team being modest about their own product. That’s a marketing team on record disagreeing with it.
The splash screen got rewritten as a direct result. The version that shipped from early 2024 reads:
“Others who use this device won’t see your activity, so you can browse more privately. This won’t change how data is collected by websites you visit and the services they use, including Google.”
Put the two side by side. The first promised privacy. The second admits, in the same breath, that nothing about your visibility to Google actually changes. That gap, between what was promised and what was true, is the entire Google Incognito lawsuit, condensed into two sentences of splash-screen copy.
What the Google Incognito lawsuit changed, and what it didn’t
Chrome’s Incognito mode now blocks third-party cookies by default. That’s a direct settlement term, one Google has to maintain for five years, confirmed on Google’s own Chrome support pages. You don’t need to hunt through a settings menu for it. It’s already switched on. Genuine improvement over the old default, and it stops advertisers linking your activity across sites using cookie-based IDs.
It doesn’t stop first-party tracking, though. The site you’re actually on still sees everything you do there. It doesn’t touch fingerprinting. It doesn’t touch IP-based tracking. Blocking third-party cookies closes one door in a house that still has several others wide open.
Google also committed to deleting the Incognito data it collected since 2016. Worth being precise about what “deleting” means here: the settlement requires removing records that identify individuals. It doesn’t require Google to un-learn the aggregate patterns, which sites, how long, in what order, it already pulled from that data before the records were destroyed. The raw dataset goes. What Google learned by studying it doesn’t necessarily go with it.
No cheque, for the reason covered above. The court ruled out class-wide damages back in 2022. Individuals can still sue Google directly in state court, and dozens already have.
Where the Google Incognito lawsuit stands in 2026. The story didn’t stop at the settlement. A group of roughly 185 Chrome users, unhappy the case never produced a damages class, tried to intervene in mid-2024 to preserve their right to appeal that earlier ruling. On 20 April 2026, the Ninth Circuit shut that door. Too late, the court said. Class-wide damages in this case are now about as close to definitively dead as these things get. If you’re wondering whether you’re still owed money: no, and that question now has an answer.
Separately, Google’s much bigger plan, phasing out third-party cookies across all of Chrome, not just Incognito, collapsed in mid-2024 after years of delay. The Incognito-specific default block from this settlement survived that reversal. It’s one of the few durable wins to come out of the whole affair.
Firefox’s private browsing is different, but not immune
Firefox’s Private Browsing windows switch on Enhanced Tracking Protection automatically: known trackers, cross-site cookies, and cryptomining scripts, all blocked by default. Chrome’s Incognito has never done that as a baseline. As of Firefox 145 in November 2025, Mozilla added new fingerprinting defences too, shipping first in Private Browsing windows and Strict mode. Mozilla’s own claim is that this roughly halves how many users end up with a trackable, unique fingerprint. Real engineering, not a slide from a marketing deck.
It’s still not a VPN, though. Every site you visit sees your actual IP address. Firefox Private Browsing still routes DNS queries through your ISP’s servers unless you manually switch on DNS over HTTPS, and almost nobody does that. “Roughly halves trackability” is a meaningful improvement. It isn’t a guarantee of anonymity. A determined tracker with enough other signals can often still narrow you down.
Firefox’s real advantage isn’t any single feature. It’s the business model underneath it. Mozilla doesn’t run an ad network. Google does. But Firefox can’t block what it structurally can’t see, and if a site logs your IP server-side and correlates your visits over months, no browser mode from any vendor interrupts that.
The Google Incognito lawsuit was about Chrome specifically. The tracking architecture it exposed doesn’t care which browser you happen to be running.
What actually works if you want to browse privately
Everything the Google Incognito lawsuit exposed happens at the network and analytics layer, not the local one. So the fix lives there too: a VPN with a genuinely audited no-logs policy. Ideally one based somewhere that can’t legally compel it to hand over records it doesn’t keep.
Proton VPN has been independently audited by Securitum every year since 2022. The most recent was August 2025, its fourth consecutive audit. A separate SOC 2 Type II operational security review followed in July 2025. Securitum’s published findings state they found no evidence of user activity logging, connection metadata storage, or traffic inspection contradicting Proton’s no-logs claims. Proton states it operates under Swiss law, which requires a Swiss court order before it can be compelled to hand over data it holds. Its own transparency report lists 29 legal requests for user information up to mid-2025. All 29 were refused, largely because the logs being asked for simply don’t exist to hand over.
That’s the difference between a company saying “trust us” and one that lets a stranger with a clipboard check the server room every year. Read the audits yourself at proton.me rather than taking our word for it.
The current offer: 70% off Proton VPN Plus, down to £2.39/month on the 2-year plan (from £7.99), backed by a 30-day money-back guarantee if it turns out not to be for you. Get Proton VPN Plus HERE.
Currently rated 4.7 out of 5 from more than 900,000 reviews on Google Play, for what a crowd-sourced number is worth.
We’ve also covered the setup and day-to-day performance of Proton VPN Plus in detail in our full 2026 privacy playbook, including the bits that don’t make it into most marketing pages.
When you connect, every site you visit sees Proton’s IP, not yours. Your ISP sees an encrypted tunnel and nothing else. DNS queries route through Proton’s own resolvers instead of your provider’s. NetShield, bundled with paid plans, blocks known ad and tracking domains at the network level before they even load. That covers a meaningful slice of the exact Google Analytics and Ad Manager traffic this whole article has been about.
If you’re already juggling separate subscriptions for a VPN, encrypted email, and a password manager, it’s worth doing the maths on Proton Unlimited instead. It folds the VPN in with Proton Mail, Proton Drive, Proton Pass, and Proton Calendar under one Swiss-jurisdiction subscription, and for anyone already paying for two or more of those separately, it tends to work out cheaper than keeping them apart.
The bundle offer: 30% off Proton Unlimited, down to $9.09 (£7.27/€9.09) per month for a full year from $12.99 (£10.39/€12.99), covering VPN, Mail, Drive, Pass, Calendar, Meet + Lumo AI – under the same 30-day guarantee. Claim this BAIZAAR exclusive Proton Unlimited discount HERE.
That solves network-layer tracking. It does not solve account-based tracking. Log into Gmail, Facebook, or any Google service while the VPN’s running, and those companies can still stitch your activity together across every site running their embedded code. You told them who you are the second you signed in. The VPN hid your IP. You handed over your identity yourself, no help needed. For real separation, Firefox’s Multi-Account Containers extension keeps logged-in Google sessions isolated from the rest of your browsing. Chromium browsers can approximate this with separate profiles, though the isolation is looser.
Incognito mode sweeps the floor after you’ve already left the room. A VPN locks the door while you’re still inside it.
| Feature | Chrome Incognito | Firefox Private Browsing | Proton VPN Plus |
|---|---|---|---|
| Clears local history | Yes | Yes | N/A (network-layer tool) |
| Blocks third-party cookies | Yes, by default | Yes | Yes (via NetShield) |
| Fingerprinting protection | None | Partial, improved since Firefox 145 | Not applicable, browser-level issue |
| Hides real IP from sites | No | No | Yes |
| Hides browsing from your ISP | No | No, unless DoH is enabled manually | Yes |
| Blocks Google Analytics requests | No | Partial | Yes (via NetShield) |
| Legal jurisdiction | United States (Google LLC) | United States (Mozilla Corp) | Switzerland (Proton AG) |
| Independent no-logs audit | No | No | Yes, Securitum, four consecutive years |
| Starting price | Free | Free | From £2.39/month on the 2-year Plus plan |
Pairing Firefox Private Browsing with Proton VPN is roughly where we’d land, unless you’re specifically going for nation-state-grade anonymity, which, statistically, you’re probably not. Firefox handles the browser-level tracking. Proton handles the network-level tracking. Between the two, they close most of the gap this lawsuit put on public record.
Limitations worth knowing
Even running a VPN and Firefox Private Browsing together, you’re not anonymous the moment you log into an account. Google, Facebook, anyone you’ve authenticated with, can still connect the dots across sites running their code, because a login is a far stronger signal than an IP address ever was.
Logged into Gmail in one tab while browsing privately with the VPN active in another? Google can plausibly correlate the two sessions through fingerprinting and timing, even with your real IP hidden. Multi-Account Containers genuinely helps here. It isolates logged-in Google services from everything else. It’s a mitigation, though, not a fix.
Proton VPN isn’t flawless, either. Our UK-specific testing turned up quirks Proton doesn’t put in its own marketing. The mobile app can get twitchy switching between networks quickly. The split-tunnelling settings aren’t especially intuitive unless you’re already comfortable with network configuration. Nothing that breaks the tool. Just the kind of thing a review claiming 100% perfection would quietly leave out.
Secure Core routing, in our own testing, adds roughly 30 to 40ms of latency versus a direct connection: noticeable on video calls, invisible for ordinary browsing. Standard servers add closer to 8 to 12ms, fine for nearly everything. Secure Core is arguably overkill unless your threat model includes a well-resourced adversary specifically interested in you. Most people’s doesn’t.
NetShield’s blocking has, on occasion, broken sites using aggressive anti-adblock detection. Three sites needed whitelisting over six months of regular use. The failure is obvious (the page just won’t load) and takes seconds to fix in settings.
None of this makes anyone immune to malware, phishing, or reused passwords. A VPN solves a tracking problem. It’s never claimed to solve a human-error problem, and neither do we.
What the Google Incognito lawsuit really exposed was tracking that survives after your request has already left your device. A browser mode was never going to touch that. An audited VPN, used with a bit of care about staying logged out, can.
The Proton VPN Plus offer further up this page already links straight to Securitum’s published audit reports, going back to 2022, if you want to check the claims yourself before signing up for anything.
Last updated: August 2026
Google Incognito Lawsuit (FAQ)
Does the Google Incognito lawsuit affect me if I use Firefox?
No, Brown v. Google dealt specifically with Chrome’s Incognito mode and the data Google collected through its own advertising and analytics services during those sessions. Firefox wasn’t a party to it. The underlying issue it exposed, that browser “private” modes don’t stop server-side tracking or IP logging, applies to any browser, though. Firefox Private Browsing blocks considerably more than Chrome Incognito ever did by default. It still exposes your IP address, though, and doesn’t stop sites from logging your activity on their own servers.
Can I still claim money from the Google Incognito lawsuit settlement?
No. The court declined to certify a damages class back in December 2022, well before the April 2024 settlement was even filed, so a group payout was never part of the deal on the table. Google agreed to delete data and rewrite its disclosures instead. If you used Chrome Incognito between June 2016 and the settlement, you were technically part of the class covered by that injunctive relief, but it doesn’t come with a cheque.
You can still file an individual claim against Google in state court, as roughly 50 people had already done by April 2024. That’s a separate legal process, though, not an automatic payout. A group of users who tried to revive class-wide damages through a late appeal had that door closed by the Ninth Circuit in April 2026.
Is Incognito mode safe to use now, after the settlement?
Incognito does exactly what it’s always done: stops Chrome from saving your local browsing history, cookies, and form data once you close the window. It still doesn’t stop websites, your ISP, or Google’s own embedded services from seeing your activity while the session is open. What’s genuinely new since the settlement is that third-party cookies are now blocked by default, and the splash screen is honest about what it can’t do. The mode itself hasn’t been rebuilt. If you want actual privacy from tracking, that’s a VPN’s job, not a browser setting’s.
What’s the real difference between Chrome Incognito and Firefox Private Browsing after the Google Incognito lawsuit?
Firefox enables Enhanced Tracking Protection automatically in Private Browsing, blocking third-party tracking cookies and cryptominers, and since Firefox 145 in November 2025 it adds fingerprinting defences too. Chrome’s Incognito, post-settlement, now blocks third-party cookies by default as well, a direct result of the case, but has no dedicated fingerprinting protection. Both clear local history when the window closes. Neither hides your IP address or stops the site you’re visiting from logging your activity server-side. Firefox simply does more by default. It doesn’t do everything.
Should I switch from Google Drive to Proton Drive because of the Google Incognito lawsuit?
If the scale of data collection the Google Incognito lawsuit revealed bothers you, migrating storage is a reasonable next step, though it’s a separate decision from anything about Incognito specifically. Google Drive uses server-side encryption, meaning Google holds the decryption keys and can scan file contents for policy enforcement or ad-related profiling.
Proton Drive uses zero-knowledge encryption instead: files are encrypted on your device before upload, and Proton states it cannot read them even if legally compelled to try. Proton operates under Swiss data protection law, materially stricter than US law on compelled disclosure. We wrote up our own move away from Google Drive if you want to see what the switch actually involves in practice, rather than the theory of it.
Does a VPN stop Google from tracking me across websites?
It stops IP-based tracking and cross-site behavioural correlation, because the sites you visit and your ISP only ever see the VPN’s IP address, not yours. It does not stop account-based tracking. If you’re signed into a Google account while the VPN is active, Google can still connect your activity across any site running its embedded services. Your login, not your IP, is doing the identifying. A VPN handles network-layer privacy. Staying logged out, or using a separate browser profile for logged-in sessions, handles the rest.


