{
  "slug": "password-pusher",
  "category": "secret-sharing",
  "name": "Password Pusher",
  "description": "Service for sharing passwords, text and files through links that expire after a set number of views or days, with audit logs. Hosted in EU and US regions with paid team plans, and the open source edition can be self-hosted.",
  "website": "https://pwpush.com",
  "source": "https://github.com/pglombardo/PasswordPusher",
  "license": "Apache-2.0",
  "platforms": [
    "web"
  ],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 59,
  "coverage": 100,
  "summary": "Password Pusher scores 59 out of 100 (grade D) on the secret sharing criteria. It meets 4 of 8 criteria: no trackers or telemetry, no ads or data sales, TLS configuration and security headers. It partly meets open source. It does not meet independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
  "url": "https://privacyratings.com/secret-sharing/password-pusher/",
  "markdown": "https://privacyratings.com/secret-sharing/password-pusher/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://eu.pwpush.com/security_compliance",
      "note": "The core, including encryption and data handling, is Apache-2.0, but the hosted Solo and Organization editions add closed-source features."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://eu.pwpush.com/privacy",
      "note": "No third-party trackers. The website's Plausible analytics are cookieless and aggregate-only."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://eu.pwpush.com/privacy",
      "note": "Funded by paid plans. The privacy policy states personal information is not sold to unrelated third parties."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published. The security page states no penetration test summary is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No transparency report or government request policy is published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=eu.pwpush.com&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=eu.pwpush.com",
      "note": "Grade A+ (110/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "A+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "Plausible",
        "host": "plausible.io",
        "effect": "partial"
      }
    ],
    "tested_at": "2026-10-01T07:14:29.360Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}