{
  "slug": "openpgp",
  "category": "messengers",
  "name": "OpenPGP",
  "description": "Open standard for public-key encryption and signing of messages and files, defined in RFC 9580. It adds end-to-end encryption to existing channels such as email, through implementations like GnuPG.",
  "website": "https://www.openpgp.org",
  "source": "https://gitlab.com/openpgp-wg/rfc4880bis",
  "license": null,
  "platforms": [],
  "jurisdiction": null,
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "B",
  "score": 78,
  "coverage": 100,
  "summary": "OpenPGP scores 78 out of 100 (grade B) on the messengers criteria. It meets 5 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, no phone number needed and decentralized. It partly meets end-to-end encrypted by default. It does not meet metadata protection.",
  "url": "https://privacyratings.com/messengers/openpgp/",
  "markdown": "https://privacyratings.com/messengers/openpgp/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://www.rfc-editor.org/rfc/rfc9580.html",
      "note": "Open IETF standard with open source implementations such as GnuPG (GPL-3.0)."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://www.gnupg.org/privacy-policy.html",
      "note": "The standard has no telemetry, and the GnuPG reference project states it does not track users or share data."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://gnupg.org/donate/",
      "note": "The reference implementation GnuPG is funded mainly by donations, with no ads."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "A standard is not audited as a product; audits cover individual implementations."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "e2ee_default": {
      "title": "End-to-end encrypted by default",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://www.rfc-editor.org/rfc/rfc9580.html",
      "note": "Messages are end-to-end encrypted only when both parties have keys and the sender chooses to encrypt; email is sent in plaintext by default."
    },
    "no_phone_number": {
      "title": "No phone number needed",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.rfc-editor.org/rfc/rfc9580.html",
      "note": "There are no accounts; keys carry a user ID, usually an email address, and no phone number."
    },
    "metadata_protection": {
      "title": "Metadata protection",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "Encryption covers the message body only; senders, recipients and subject lines of the carrying channel stay visible."
    },
    "decentralized": {
      "title": "Decentralized",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://www.rfc-editor.org/rfc/rfc9580.html",
      "note": "No central service; keys are generated locally and messages travel over any channel."
    }
  },
  "tests": {
    "ssllabs": null,
    "observatory": null,
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:00:47.820Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}