Noise is added for what is called plausible deniability. Note that messages themselves do not contain any user-identifier. We take extra measures to strip request headers not needed by the server to avoid extra information that could be used for implicitly linking messages[1]. Possibility of linking messages based on network fingerprinting (ex: IP - which we do not log) still exists and is an open concern which we will solve in the next version. This at most makes it possible for us to learn that these 3 domains are visited by the same person, again - given that the list of domains are from shortlisted top-news domains, it is safe to assume that they do not contain any PII.
That said, it is not the strongest model we apply -- due to resource-constrains we have not updated to strongest models like we do on more sensitive data - via HumanWeb[2]. We will soon do the changes on a couple of dimensions: a) each domain as separate message, right now this introduces un-wanted spatial correlations, and b) send the domain through the proxy network HPN[3].
Ref: [1]: https://github.com/cliqz-oss/browser-core/blob/7679c40aec9fe... [2]: https://www.0x65.dev/blog/2019-12-03/human-web-collecting-da... [3]: https://www.0x65.dev/blog/2019-12-04/human-web-proxy-network...
Disclaimer: I work for Cliqz.