{
  "slug": "yopass",
  "category": "secret-sharing",
  "name": "Yopass",
  "description": "Open source secret sharing tool that encrypts messages and files in the browser with OpenPGP and deletes them after one view or an expiry time. Can be self-hosted, and a public instance runs at share.yopass.se.",
  "website": "https://yopass.se",
  "source": "https://github.com/jhaals/yopass",
  "license": "Apache-2.0",
  "platforms": [
    "web"
  ],
  "jurisdiction": {
    "code": "SE",
    "name": "Sweden",
    "eyes": "Fourteen Eyes",
    "eu": true,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 50,
  "coverage": 100,
  "summary": "Yopass scores 50 out of 100 (grade D) on the secret sharing criteria. It meets 4 of 8 criteria: open source, no ads or data sales, TLS configuration and security headers. It does not meet no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in Sweden: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
  "url": "https://privacyratings.com/secret-sharing/yopass/",
  "markdown": "https://privacyratings.com/secret-sharing/yopass/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/jhaals/yopass/blob/master/LICENSE",
      "note": "Apache-2.0. Some business features in the same code base require a paid license key."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://yopass.se/privacy",
      "note": "The privacy policy states the project website uses Google Analytics."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://yopass.se/privacy",
      "note": "Funded by paid business licenses. The privacy policy lists no advertising use of data."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No transparency report or government request policy is published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=share.yopass.se&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=share.yopass.se",
      "note": "Grade A+ (110/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "A+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "Google Analytics",
        "host": "www.google-analytics.com",
        "effect": "no"
      },
      {
        "name": "Google Tag Manager",
        "host": "www.googletagmanager.com",
        "effect": "no"
      }
    ],
    "tested_at": "2026-10-01T10:59:44.415Z"
  },
  "last_modified": "2026-10-01T11:14:42Z"
}