{
  "slug": "matrix",
  "category": "messengers",
  "name": "Matrix",
  "description": "Open standard and federated network for real-time chat and calls, with end-to-end encryption through the Olm and Megolm protocols. Anyone can run a homeserver, and many clients such as Element support it.",
  "website": "https://matrix.org",
  "source": "https://github.com/matrix-org/matrix-spec",
  "license": "Apache-2.0",
  "platforms": [],
  "jurisdiction": {
    "code": "GB",
    "name": "United Kingdom",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": true,
    "cloud_act": "agreement"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 58,
  "coverage": 100,
  "summary": "Matrix scores 58 out of 100 (grade D) on the messengers criteria. It meets 4 of 8 criteria: open source, no ads or data sales, no phone number needed and decentralized. It partly meets independent audit and end-to-end encrypted by default. It does not meet no trackers or telemetry and metadata protection. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
  "url": "https://privacyratings.com/messengers/matrix/",
  "markdown": "https://privacyratings.com/messengers/matrix/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/matrix-org/matrix-spec/blob/main/LICENSE",
      "note": "Apache-2.0."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://matrix.org/legal/privacy-notice/",
      "note": "The matrix.org homeserver sends account usage analytics to PostHog, and the website uses hosted Plausible analytics."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://matrix.org/support/",
      "note": "The non-profit Matrix.org Foundation is funded by donations and organisational memberships, with no ads."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://matrix.org/media/Least%20Authority%20-%20Matrix%20vodozemac%20Final%20Audit%20Report.pdf",
      "note": "A full Least Authority audit of the vodozemac encryption library is public but is older than three years."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "e2ee_default": {
      "title": "End-to-end encrypted by default",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://spec.matrix.org/latest/client-server-api/#end-to-end-encryption",
      "note": "Encryption is an optional room setting in the protocol; major clients enable it for private chats, but public rooms are unencrypted."
    },
    "no_phone_number": {
      "title": "No phone number needed",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://matrix.org/legal/privacy-notice/",
      "note": "No phone number is needed; on the matrix.org homeserver a verified phone number is optional."
    },
    "metadata_protection": {
      "title": "Metadata protection",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "Homeservers see room membership, senders and timestamps, and share them with every server in a room."
    },
    "decentralized": {
      "title": "Decentralized",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://spec.matrix.org/latest/",
      "note": "Federated protocol; anyone can run a homeserver."
    }
  },
  "tests": {
    "ssllabs": null,
    "observatory": null,
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "Plausible",
        "host": "plausible.io",
        "effect": "partial"
      }
    ],
    "tested_at": "2026-10-01T07:00:47.568Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}