{
  "slug": "plunk",
  "category": "email-sending",
  "name": "Plunk",
  "description": "Open-source email platform for transactional email, campaigns and automations, hosted in the EU or self-hosted with Docker.",
  "website": "https://www.useplunk.com",
  "source": "https://github.com/useplunk/plunk",
  "license": "AGPL-3.0",
  "platforms": [],
  "jurisdiction": null,
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": null,
  "score": 42,
  "coverage": 50,
  "summary": "Plunk is not graded yet: 50% of its criteria have evidence, and 60% is needed. It meets 4 of 12 criteria: open source, no trackers or telemetry, no ads or data sales and EU data location. It partly meets TLS configuration. It does not meet security headers. Still needing evidence: independent audit, transparency report, tells users about requests, message content deleted after delivery, open and click tracking off by default and encrypted delivery can be enforced. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade D.",
  "url": "https://privacyratings.com/email-sending/plunk/",
  "markdown": "https://privacyratings.com/email-sending/plunk/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/useplunk/plunk/blob/main/LICENSE",
      "note": "AGPL-3.0."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://www.useplunk.com/privacy",
      "note": "The privacy policy states no Google Analytics, Meta pixel or other third-party tracking scripts are used, with only a login cookie."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.useplunk.com/privacy",
      "note": "Funded by per-email pricing. The privacy policy states data is never sold."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "unknown",
      "evidence": null,
      "note": null
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "unknown",
      "evidence": null,
      "note": null
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "unknown",
      "evidence": null,
      "note": null
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=useplunk.com&hideResults=on",
      "note": "Grade B"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "no",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=useplunk.com",
      "note": "Grade D (30/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "content_retention": {
      "title": "Message content deleted after delivery",
      "weight": 3,
      "answer": "unknown",
      "evidence": null,
      "note": null
    },
    "tracking_off_by_default": {
      "title": "Open and click tracking off by default",
      "weight": 2,
      "answer": "unknown",
      "evidence": null,
      "note": null
    },
    "enforced_tls": {
      "title": "Encrypted delivery can be enforced",
      "weight": 2,
      "answer": "unknown",
      "evidence": null,
      "note": null
    },
    "eu_data_location": {
      "title": "EU data location",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://www.useplunk.com/privacy",
      "note": "The hosted service stores data with Hetzner in Germany and sends mail through Amazon SES. Self-hosting is also supported."
    }
  },
  "tests": {
    "ssllabs": "B",
    "observatory": "D",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T11:03:44.536Z"
  },
  "last_modified": "2026-10-01T11:14:42Z"
}