{
  "slug": "session",
  "category": "messengers",
  "name": "Session",
  "description": "End-to-end encrypted messenger that uses a random Account ID instead of a phone number and sends messages through onion routing over a decentralized network of community-operated nodes. Stewarded by the Session Technology Foundation in Switzerland.",
  "website": "https://getsession.org",
  "source": "https://github.com/session-foundation",
  "license": null,
  "platforms": [
    "android",
    "ios",
    "windows",
    "macos",
    "linux"
  ],
  "jurisdiction": {
    "code": "CH",
    "name": "Switzerland",
    "eyes": null,
    "eu": false,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "A",
  "score": 94,
  "coverage": 100,
  "summary": "Session scores 94 out of 100 (grade A) on the messengers criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted by default, no phone number needed, metadata protection and decentralized. It partly meets independent audit. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law.",
  "url": "https://privacyratings.com/messengers/session/",
  "markdown": "https://privacyratings.com/messengers/session/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/session-foundation/session-android/blob/dev/LICENSE",
      "note": "The apps are GPL-3.0, and the storage server run by network nodes is MIT."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://reports.exodus-privacy.eu.org/en/reports/network.loki.messenger/latest/",
      "note": "Exodus finds no trackers in the Android app, and the privacy policy states Session stores no information that could be used to track users."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://getsession.org/donate",
      "note": "Funded by donations to the Session Technology Foundation, with no ads."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://blog.quarkslab.com/resources/2021-05-04_audit-of-session-secure-messaging-application/20-08-Oxen-REP-v1.4.pdf",
      "note": "Quarkslab published a full audit report, but it is older than three years."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "e2ee_default": {
      "title": "End-to-end encrypted by default",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://getsession.org/faq",
      "note": "One-to-one chats and groups are end-to-end encrypted by default; large public communities are only encrypted in transit to their server."
    },
    "no_phone_number": {
      "title": "No phone number needed",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://getsession.org/faq",
      "note": "No phone number or email is needed; accounts use a randomly generated Account ID."
    },
    "metadata_protection": {
      "title": "Metadata protection",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://getsession.org/whitepaper",
      "note": "Onion requests hide the sender's IP address and no single node knows both origin and destination of a message."
    },
    "decentralized": {
      "title": "Decentralized",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://getsession.org/faq",
      "note": "Messages are stored and relayed by a network of more than a thousand community-operated Session Nodes rather than central servers."
    }
  },
  "tests": {
    "ssllabs": null,
    "observatory": null,
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "Cloudflare Web Analytics",
        "host": "static.cloudflareinsights.com",
        "effect": "partial"
      }
    ],
    "tested_at": "2026-10-01T10:59:36.112Z"
  },
  "last_modified": "2026-10-01T11:14:42Z"
}