{
  "slug": "bruno",
  "category": "developer-tools",
  "name": "Bruno",
  "description": "Local-first API client that stores collections as plain text files in the filesystem, so they can be versioned with Git. Supports REST, GraphQL, gRPC and WebSocket requests.",
  "website": "https://www.usebruno.com",
  "source": "https://github.com/usebruno/bruno",
  "license": "MIT",
  "platforms": [],
  "jurisdiction": null,
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "F",
  "score": 25,
  "coverage": 100,
  "summary": "Bruno scores 25 out of 100 (grade F) on the developer tools criteria. It partly meets open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
  "url": "https://privacyratings.com/developer-tools/bruno/",
  "markdown": "https://privacyratings.com/developer-tools/bruno/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://github.com/usebruno/bruno/blob/main/license.md",
      "note": "Open core. The main app is MIT licensed, but features in the paid Pro and Ultimate editions are proprietary."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "The home page loads Google Analytics, Google Tag Manager, HubSpot, LinkedIn Insight, Reddit Pixel and X (Twitter) Pixel (automated test)."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://www.usebruno.com/privacy-policy",
      "note": "Funded by paid licenses, but the privacy policy lists Google AdWords and other tracking for interest-based advertising."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    }
  },
  "tests": {
    "ssllabs": null,
    "observatory": null,
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "Google Analytics",
        "host": "inline code",
        "effect": "no"
      },
      {
        "name": "Google Fonts",
        "host": "fonts.googleapis.com",
        "effect": "none"
      },
      {
        "name": "Google Tag Manager",
        "host": "www.googletagmanager.com",
        "effect": "no"
      },
      {
        "name": "HubSpot",
        "host": "js.hsforms.net",
        "effect": "no"
      },
      {
        "name": "LinkedIn Insight",
        "host": "snap.licdn.com",
        "effect": "no"
      },
      {
        "name": "Reddit Pixel",
        "host": "www.redditstatic.com",
        "effect": "no"
      },
      {
        "name": "X (Twitter) Pixel",
        "host": "static.ads-twitter.com",
        "effect": "no"
      }
    ],
    "tested_at": "2026-10-01T07:01:09.064Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}