Privacy Sandbox APIs

Privacy Sandbox was Google's plan to retire third-party cookies and hand advertisers browser APIs that could pick audiences and count conversions without a cross-site identifier. Neither half happened. On April 22, 2025 Google dropped the promised cookie prompt and kept Chrome 1 's current behavior, so third-party cookies still work in Chrome; users switch them off under Privacy and security, and Incognito blocks them by default. On October 17, 2025 Google retired the advertising APIs too, citing low adoption, and Chrome's feature-status page now files them under "deprecate and remove".

Privacy Sandbox APIs and their status in September 2026
API What it did Status
Topics Interest labels from history Deprecate and remove
Protected Audience On-device ad auctions Deprecate and remove
Attribution Reporting Aggregated conversions Deprecate and remove
Shared Storage, selectURL Cross-site writes Deprecate and remove
Fenced Frames Embedder-proof frame Scheduled for phaseout
Private State Tokens Anti-fraud signals Continue to support

What survives was never about advertising: partitioned cookies (CHIPS, Cookies), the Storage Access API (Embedded Storage Access), FedCM (Credential Management), Private State Tokens, and storage and network partitioning. Related Website Sets went with the ad APIs, so document.requestStorageAccessFor() is going too. Your instruction is short: write nothing new against the retired APIs, and delete inherited <fencedframe>, joinAdInterestGroup() or attributionsrc code. All of them outlive the announcement, so an in check proves nothing.

Probing the Privacy Sandbox surfaceJavaScript
const live = ['browsingTopics' in document, 'runAdAuction' in navigator,
  'sharedStorage' in window, 'HTMLFencedFrameElement' in window];
console.log('Topics, Protected Audience, Shared Storage, Fenced Frames:', live.join(' '));
try { await document.browsingTopics(); } catch (err) { console.log('call:', err.name); }
Output
Topics, Protected Audience, Shared Storage, Fenced Frames: true true true true
call: NotSupportedError

Headless Chrome 152 exposes every one of them, yet browsingTopics() refuses to run outside an ad context allowed by the browsing-topics permission policy. No engine outside Chromium 4,389 shipped these APIs; Firefox 555 and Safari 10 partition or block third-party cookies instead (Total Cookie Protection and ITP). Build for that world: first-party data, partitioned storage, and passkeys or FedCM for identity.