{
  "site": {
    "title": "Privacy Ratings",
    "url": "https://privacyratings.com",
    "repository": "https://github.com/privacyratings/privacyratings.com",
    "license": "CC-BY-SA-4.0",
    "generated": "2026-10-01T08:47:08.570Z"
  },
  "categories": [
    {
      "id": "email-providers",
      "name": "Email providers",
      "group": "Email",
      "type": "service",
      "description": "Hosted email services. Where mail is stored, and who can read it.",
      "url": "https://privacyratings.com/email-providers/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "e2ee",
        "encrypted_storage",
        "open_protocols",
        "custom_domains",
        "anonymous_signup",
        "mail_standards",
        "imap_standards",
        "pop3_standards",
        "smtp_standards",
        "transport_security",
        "srs",
        "arc"
      ]
    },
    {
      "id": "email-forwarding",
      "name": "Email forwarding and aliases",
      "group": "Email",
      "type": "service",
      "description": "Services that hide a real address behind aliases or forward mail to another inbox.",
      "url": "https://privacyratings.com/email-forwarding/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "e2ee",
        "no_mail_storage",
        "open_protocols",
        "custom_domains",
        "anonymous_signup",
        "mail_standards",
        "transport_security",
        "srs",
        "arc"
      ]
    },
    {
      "id": "email-clients",
      "name": "Email clients",
      "group": "Email",
      "type": "app",
      "description": "Apps for reading and sending email from any provider.",
      "url": "https://privacyratings.com/email-clients/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "openpgp",
        "no_cloud_relay",
        "remote_content_blocked",
        "any_provider"
      ]
    },
    {
      "id": "webmail",
      "name": "Webmail",
      "group": "Email",
      "type": "service",
      "description": "Email clients that run in the browser, hosted or self-hosted.",
      "url": "https://privacyratings.com/webmail/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "openpgp",
        "no_cloud_relay",
        "remote_content_blocked",
        "any_provider",
        "self_hostable"
      ]
    },
    {
      "id": "email-security-tools",
      "name": "Email security tools",
      "group": "Email",
      "type": "app",
      "description": "Tools that check or improve the privacy of email.",
      "url": "https://privacyratings.com/email-security-tools/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "spam-filters",
      "name": "Spam and virus filtering",
      "group": "Email",
      "type": "service",
      "description": "Spam filters, email virus scanners and email security gateways, self-hosted and hosted.",
      "url": "https://privacyratings.com/spam-filters/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "email-backup",
      "name": "Email backup tools",
      "group": "Email",
      "type": "app",
      "description": "Tools that back up, migrate or sync mailboxes over IMAP.",
      "url": "https://privacyratings.com/email-backup/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "mail-server-software",
      "name": "Mail server software",
      "group": "Email",
      "type": "app",
      "description": "Software for running a mail server on your own hardware.",
      "url": "https://privacyratings.com/mail-server-software/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "email-sending",
      "name": "Email sending services",
      "group": "Email",
      "type": "service",
      "description": "SMTP relays and email APIs for sending transactional and bulk email from apps and websites.",
      "url": "https://privacyratings.com/email-sending/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "content_retention",
        "tracking_off_by_default",
        "enforced_tls",
        "eu_data_location"
      ]
    },
    {
      "id": "browsers",
      "name": "Browsers",
      "group": "Browsing",
      "type": "app",
      "description": "Web browsers for desktop and mobile.",
      "url": "https://privacyratings.com/browsers/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "tracker_blocking",
        "fingerprinting_protection",
        "no_google_services",
        "security_updates"
      ]
    },
    {
      "id": "ad-blockers",
      "name": "Ad and tracker blockers",
      "group": "Browsing",
      "type": "app",
      "description": "Browser extensions, apps and network tools that block ads and trackers.",
      "url": "https://privacyratings.com/ad-blockers/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "blocks_by_default",
        "no_data_collection",
        "custom_filters"
      ]
    },
    {
      "id": "browser-extensions",
      "name": "Browser extensions",
      "group": "Browsing",
      "type": "app",
      "description": "Extensions that add privacy and security features to a browser.",
      "url": "https://privacyratings.com/browser-extensions/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "search-engines",
      "name": "Search engines",
      "group": "Browsing",
      "type": "service",
      "description": "Web search services.",
      "url": "https://privacyratings.com/search-engines/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "no_search_logs",
        "no_personalized_ads",
        "no_account_needed"
      ]
    },
    {
      "id": "browser-sync",
      "name": "Bookmarks and read-later",
      "group": "Browsing",
      "type": "app",
      "description": "Bookmark managers, read-later apps and bookmark sync.",
      "url": "https://privacyratings.com/browser-sync/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "app-stores",
      "name": "App stores",
      "group": "Browsing",
      "type": "app",
      "description": "Stores and installers for mobile apps, including ones that do not need a Google account.",
      "url": "https://privacyratings.com/app-stores/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "no_account_needed",
        "tracker_info"
      ]
    },
    {
      "id": "proxy-frontends",
      "name": "Private front ends",
      "group": "Browsing",
      "type": "service",
      "description": "Alternative front ends for popular sites that strip tracking.",
      "url": "https://privacyratings.com/proxy-frontends/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "password-managers",
      "name": "Password managers",
      "group": "Security",
      "type": "service",
      "description": "Apps and services that store passwords. Hosted ones get automated tests.",
      "url": "https://privacyratings.com/password-managers/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "e2ee_vault",
        "self_host_or_local",
        "export"
      ]
    },
    {
      "id": "two-factor-authentication",
      "name": "Two-factor authentication",
      "group": "Security",
      "type": "app",
      "description": "Authenticator apps for one-time codes.",
      "url": "https://privacyratings.com/two-factor-authentication/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "file-encryption",
      "name": "File encryption",
      "group": "Security",
      "type": "app",
      "description": "Tools that encrypt files and drives.",
      "url": "https://privacyratings.com/file-encryption/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "pgp-tools",
      "name": "PGP tools",
      "group": "Security",
      "type": "app",
      "description": "Apps for managing OpenPGP keys and encrypting messages.",
      "url": "https://privacyratings.com/pgp-tools/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "secret-sharing",
      "name": "Secret sharing",
      "group": "Security",
      "type": "service",
      "description": "Services for sending passwords and secrets that expire.",
      "url": "https://privacyratings.com/secret-sharing/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "online-privacy-tools",
      "name": "Privacy test tools",
      "group": "Security",
      "type": "service",
      "description": "Websites that test for leaks, fingerprinting and breaches.",
      "url": "https://privacyratings.com/online-privacy-tools/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "security-audit-firms",
      "name": "Security audit firms",
      "group": "Security",
      "type": "service",
      "description": "Independent firms that audit software and services for security and privacy. The ratings focus on whether their reports are public.",
      "url": "https://privacyratings.com/security-audit-firms/",
      "criteria": [
        "public_reports",
        "open_source_work",
        "public_research",
        "no_trackers"
      ]
    },
    {
      "id": "compliance-automation",
      "name": "Compliance automation",
      "group": "Security",
      "type": "service",
      "description": "Tools for SOC 2, ISO 27001 and other compliance programs.",
      "url": "https://privacyratings.com/compliance-automation/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "data-broker-removal",
      "name": "Data broker removal",
      "group": "Security",
      "type": "service",
      "description": "Services and guides that remove personal information from people-search sites and data brokers.",
      "url": "https://privacyratings.com/data-broker-removal/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "mobile-security-apps",
      "name": "Mobile security apps",
      "group": "Security",
      "type": "app",
      "description": "Android and iOS apps that improve privacy and security.",
      "url": "https://privacyratings.com/mobile-security-apps/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "metadata-removal",
      "name": "Metadata removal",
      "group": "Security",
      "type": "app",
      "description": "Tools that strip location and device data from files.",
      "url": "https://privacyratings.com/metadata-removal/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "data-erasers",
      "name": "Data erasers",
      "group": "Security",
      "type": "app",
      "description": "Tools that securely delete files and wipe drives.",
      "url": "https://privacyratings.com/data-erasers/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "usb-security",
      "name": "USB kill switches and anti-forensics",
      "group": "Security",
      "type": "app",
      "description": "Tools that lock or shut down a computer when USB devices change, and other anti-forensic protections.",
      "url": "https://privacyratings.com/usb-security/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "anti-malware",
      "name": "Anti-malware",
      "group": "Security",
      "type": "app",
      "description": "Malware scanners.",
      "url": "https://privacyratings.com/anti-malware/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "messengers",
      "name": "Messengers",
      "group": "Communication",
      "type": "app",
      "description": "Chat and calling apps, including peer-to-peer ones.",
      "url": "https://privacyratings.com/messengers/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "e2ee_default",
        "no_phone_number",
        "metadata_protection",
        "decentralized"
      ]
    },
    {
      "id": "team-chat",
      "name": "Team chat",
      "group": "Communication",
      "type": "app",
      "description": "Chat and collaboration tools for teams.",
      "url": "https://privacyratings.com/team-chat/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "video-calls",
      "name": "Video calls",
      "group": "Communication",
      "type": "app",
      "description": "Private video and conference calls.",
      "url": "https://privacyratings.com/video-calls/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "e2ee",
        "no_account_needed",
        "self_hostable"
      ]
    },
    {
      "id": "newsletters",
      "name": "Newsletter platforms",
      "group": "Communication",
      "type": "service",
      "description": "Tools for sending email newsletters and mailing lists.",
      "url": "https://privacyratings.com/newsletters/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "customer-support",
      "name": "Customer support and live chat",
      "group": "Communication",
      "type": "service",
      "description": "Help desks, ticketing and website live chat.",
      "url": "https://privacyratings.com/customer-support/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "voip-clients",
      "name": "Voice calls",
      "group": "Communication",
      "type": "app",
      "description": "Voice-over-IP apps.",
      "url": "https://privacyratings.com/voip-clients/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "virtual-phone-numbers",
      "name": "Virtual phone numbers",
      "group": "Communication",
      "type": "service",
      "description": "Phone numbers for sign-ups without handing over a real number.",
      "url": "https://privacyratings.com/virtual-phone-numbers/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "communications-apis",
      "name": "SMS and voice APIs",
      "group": "Communication",
      "type": "service",
      "description": "APIs for sending and receiving SMS and making phone calls from apps, including one-time codes and notifications.",
      "url": "https://privacyratings.com/communications-apis/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "content_retention",
        "eu_data_location"
      ]
    },
    {
      "id": "vpns",
      "name": "VPN providers",
      "group": "Networking",
      "type": "service",
      "description": "Virtual private network services.",
      "url": "https://privacyratings.com/vpns/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "no_logs_audited",
        "anonymous_payment",
        "open_source_clients",
        "modern_protocols"
      ]
    },
    {
      "id": "dns-resolvers",
      "name": "DNS resolvers",
      "group": "Networking",
      "type": "service",
      "description": "Public DNS resolvers that look up domain names for devices.",
      "url": "https://privacyratings.com/dns-resolvers/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "encrypted_dns",
        "no_query_logs",
        "dnssec_validation"
      ]
    },
    {
      "id": "dns-hosting",
      "name": "DNS hosting",
      "group": "Networking",
      "type": "service",
      "description": "Services that host the DNS records for your own domains.",
      "url": "https://privacyratings.com/dns-hosting/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "dnssec",
        "api_access",
        "two_factor"
      ]
    },
    {
      "id": "domain-registrars",
      "name": "Domain registrars",
      "group": "Networking",
      "type": "service",
      "description": "Where to register and renew domain names.",
      "url": "https://privacyratings.com/domain-registrars/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "free_whois_privacy",
        "at_cost_renewals",
        "two_factor",
        "registry_lock"
      ]
    },
    {
      "id": "server-hosting",
      "name": "Server hosting",
      "group": "Networking",
      "type": "service",
      "description": "VPS, dedicated and cloud servers, including providers that allow mail servers.",
      "url": "https://privacyratings.com/server-hosting/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "port_25",
        "reverse_dns",
        "ipv6",
        "anonymous_payment"
      ]
    },
    {
      "id": "app-hosting",
      "name": "App hosting platforms",
      "group": "Networking",
      "type": "service",
      "description": "Platforms that deploy and run web apps, from hosted services to self-hosted alternatives.",
      "url": "https://privacyratings.com/app-hosting/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "status-pages",
      "name": "Status pages and uptime monitoring",
      "group": "Networking",
      "type": "app",
      "description": "Tools that monitor uptime and publish a status page.",
      "url": "https://privacyratings.com/status-pages/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "self_hosted",
        "no_visitor_tracking",
        "history"
      ]
    },
    {
      "id": "dns-clients",
      "name": "DNS clients",
      "group": "Networking",
      "type": "app",
      "description": "Software that encrypts DNS lookups on a device.",
      "url": "https://privacyratings.com/dns-clients/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "firewalls",
      "name": "Firewalls",
      "group": "Networking",
      "type": "app",
      "description": "Firewalls that control which apps connect to the internet.",
      "url": "https://privacyratings.com/firewalls/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "blocklists",
      "name": "Blocklists",
      "group": "Networking",
      "type": "app",
      "description": "Host and filter lists for blocking ads, trackers and malware.",
      "url": "https://privacyratings.com/blocklists/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "anonymity-networks",
      "name": "Anonymity networks",
      "group": "Networking",
      "type": "app",
      "description": "Networks that hide who is talking to whom.",
      "url": "https://privacyratings.com/anonymity-networks/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "proxies",
      "name": "Proxies",
      "group": "Networking",
      "type": "app",
      "description": "Proxy software for routing traffic.",
      "url": "https://privacyratings.com/proxies/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "self-hosted-network-security",
      "name": "Self-hosted network security",
      "group": "Networking",
      "type": "app",
      "description": "Network-wide blocking, VPN and security tools to run at home or on a server.",
      "url": "https://privacyratings.com/self-hosted-network-security/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "mesh-vpns",
      "name": "Mesh VPNs and private networks",
      "group": "Networking",
      "type": "app",
      "description": "Software that joins devices into an encrypted private network, with a coordination server that is hosted by the vendor or self-hosted.",
      "url": "https://privacyratings.com/mesh-vpns/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "device_keys",
        "self_hosted_control",
        "no_connection_logs"
      ]
    },
    {
      "id": "remote-desktop",
      "name": "Remote desktop",
      "group": "Networking",
      "type": "app",
      "description": "Software for controlling another computer over the network.",
      "url": "https://privacyratings.com/remote-desktop/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "router-firmware",
      "name": "Router firmware",
      "group": "Networking",
      "type": "app",
      "description": "Open firmware for home routers.",
      "url": "https://privacyratings.com/router-firmware/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "network-analysis",
      "name": "Network analysis",
      "group": "Networking",
      "type": "app",
      "description": "Tools for measuring censorship and inspecting traffic.",
      "url": "https://privacyratings.com/network-analysis/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "intrusion-detection",
      "name": "Intrusion detection",
      "group": "Networking",
      "type": "app",
      "description": "Tools that detect attacks on a network or host.",
      "url": "https://privacyratings.com/intrusion-detection/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "mobile-operating-systems",
      "name": "Mobile operating systems",
      "group": "Operating systems",
      "type": "app",
      "description": "Privacy-focused Android-based systems.",
      "url": "https://privacyratings.com/mobile-operating-systems/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "keyboards",
      "name": "Mobile keyboards",
      "group": "Operating systems",
      "type": "app",
      "description": "On-screen keyboards for phones and tablets. A keyboard sees everything you type.",
      "url": "https://privacyratings.com/keyboards/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "offline"
      ]
    },
    {
      "id": "desktop-operating-systems",
      "name": "Desktop operating systems",
      "group": "Operating systems",
      "type": "app",
      "description": "Operating systems built for privacy and security.",
      "url": "https://privacyratings.com/desktop-operating-systems/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "os-installers",
      "name": "OS downloaders and bootable USB tools",
      "group": "Operating systems",
      "type": "app",
      "description": "Tools that download operating system installers and write bootable USB drives.",
      "url": "https://privacyratings.com/os-installers/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "disk-usage-analyzers",
      "name": "Disk usage analyzers",
      "group": "Operating systems",
      "type": "app",
      "description": "Tools that scan drives and show which files and folders use the most space. A scan lists every file name on the computer.",
      "url": "https://privacyratings.com/disk-usage-analyzers/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "offline",
        "no_account_needed"
      ]
    },
    {
      "id": "launchers",
      "name": "App launchers",
      "group": "Operating systems",
      "type": "app",
      "description": "Keyboard launchers and command palettes for opening apps, files and commands.",
      "url": "https://privacyratings.com/launchers/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "clipboard-managers",
      "name": "Clipboard managers",
      "group": "Operating systems",
      "type": "app",
      "description": "Clipboard history apps. They see every password and message you copy.",
      "url": "https://privacyratings.com/clipboard-managers/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "linux-hardening",
      "name": "Linux hardening",
      "group": "Operating systems",
      "type": "app",
      "description": "Tools that harden Linux systems.",
      "url": "https://privacyratings.com/linux-hardening/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "windows-hardening",
      "name": "Windows hardening",
      "group": "Operating systems",
      "type": "app",
      "description": "Tools that reduce Windows telemetry and harden Windows systems.",
      "url": "https://privacyratings.com/windows-hardening/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "macos-hardening",
      "name": "macOS hardening",
      "group": "Operating systems",
      "type": "app",
      "description": "Tools that harden macOS systems.",
      "url": "https://privacyratings.com/macos-hardening/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "virtual-machines",
      "name": "Virtual machines",
      "group": "Operating systems",
      "type": "app",
      "description": "Software for running isolated operating systems.",
      "url": "https://privacyratings.com/virtual-machines/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "emulators",
      "name": "Emulators and compatibility layers",
      "group": "Operating systems",
      "type": "app",
      "description": "Game console and Android emulators, and tools for running Windows apps on other systems.",
      "url": "https://privacyratings.com/emulators/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "notes",
      "name": "Notes",
      "group": "Productivity",
      "type": "app",
      "description": "Note-taking apps.",
      "url": "https://privacyratings.com/notes/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "journaling",
      "name": "Journaling apps",
      "group": "Productivity",
      "type": "app",
      "description": "Diary and journaling apps. Journals hold some of the most personal writing people keep.",
      "url": "https://privacyratings.com/journaling/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "wikis",
      "name": "Wikis and knowledge bases",
      "group": "Productivity",
      "type": "service",
      "description": "Team wikis, documentation and knowledge base software.",
      "url": "https://privacyratings.com/wikis/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "diagrams",
      "name": "Diagrams and whiteboards",
      "group": "Productivity",
      "type": "service",
      "description": "Diagram editors and online whiteboards.",
      "url": "https://privacyratings.com/diagrams/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "calendars",
      "name": "Calendars",
      "group": "Productivity",
      "type": "app",
      "description": "Calendar apps and services.",
      "url": "https://privacyratings.com/calendars/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "scheduling",
      "name": "Scheduling",
      "group": "Productivity",
      "type": "service",
      "description": "Meeting scheduling and polls.",
      "url": "https://privacyratings.com/scheduling/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "task-management",
      "name": "Task management",
      "group": "Productivity",
      "type": "app",
      "description": "To-do and project apps.",
      "url": "https://privacyratings.com/task-management/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "file-sync",
      "name": "File sync and backup",
      "group": "Productivity",
      "type": "app",
      "description": "Tools for syncing and backing up files.",
      "url": "https://privacyratings.com/file-sync/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "archivers",
      "name": "File archivers",
      "group": "Productivity",
      "type": "app",
      "description": "Apps for creating and extracting zip, 7z, rar and other archives.",
      "url": "https://privacyratings.com/archivers/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "office-suites",
      "name": "Office suites",
      "group": "Productivity",
      "type": "service",
      "description": "Documents, spreadsheets and shared editing.",
      "url": "https://privacyratings.com/office-suites/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "pdf-tools",
      "name": "PDF readers and editors",
      "group": "Productivity",
      "type": "app",
      "description": "Apps for reading, editing, merging and signing PDF files.",
      "url": "https://privacyratings.com/pdf-tools/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "screen-recording",
      "name": "Screenshots and screen recording",
      "group": "Productivity",
      "type": "app",
      "description": "Tools for screenshots, screen recordings and screen-recorded video messages.",
      "url": "https://privacyratings.com/screen-recording/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "local_by_default",
        "no_account_needed"
      ]
    },
    {
      "id": "e-signatures",
      "name": "Electronic signatures",
      "group": "Productivity",
      "type": "service",
      "description": "Services for sending documents and collecting legally binding signatures.",
      "url": "https://privacyratings.com/e-signatures/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "forms",
      "name": "Forms and surveys",
      "group": "Productivity",
      "type": "service",
      "description": "Form builders, surveys and polls.",
      "url": "https://privacyratings.com/forms/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "ebook-readers",
      "name": "Ebook readers",
      "group": "Productivity",
      "type": "app",
      "description": "Apps and tools for reading and managing ebooks.",
      "url": "https://privacyratings.com/ebook-readers/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "translation",
      "name": "Translation",
      "group": "Productivity",
      "type": "service",
      "description": "Translation apps and services, including ones that run offline.",
      "url": "https://privacyratings.com/translation/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "offline",
        "no_retention"
      ]
    },
    {
      "id": "speech-to-text",
      "name": "Dictation and transcription",
      "group": "Productivity",
      "type": "service",
      "description": "Speech-to-text, dictation and meeting transcription, on the device or in the cloud.",
      "url": "https://privacyratings.com/speech-to-text/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "runs_locally",
        "no_training"
      ]
    },
    {
      "id": "ai-assistants",
      "name": "AI assistants",
      "group": "Productivity",
      "type": "service",
      "description": "AI chatbots and assistants, hosted and local, rated on how they keep prompts and whether they train models on them.",
      "url": "https://privacyratings.com/ai-assistants/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "no_training",
        "runs_locally",
        "chat_retention",
        "no_account_needed"
      ]
    },
    {
      "id": "cloud-storage",
      "name": "Encrypted cloud storage",
      "group": "Productivity",
      "type": "service",
      "description": "Cloud storage with client-side encryption.",
      "url": "https://privacyratings.com/cloud-storage/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "file-sharing",
      "name": "File sharing",
      "group": "Productivity",
      "type": "service",
      "description": "Tools for sending files privately.",
      "url": "https://privacyratings.com/file-sharing/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "habit-trackers",
      "name": "Habit trackers",
      "group": "Productivity",
      "type": "app",
      "description": "Apps for tracking habits.",
      "url": "https://privacyratings.com/habit-trackers/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "maps",
      "name": "Maps and navigation",
      "group": "Productivity",
      "type": "app",
      "description": "Map and navigation apps.",
      "url": "https://privacyratings.com/maps/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "accessibility",
      "name": "Accessibility",
      "group": "Productivity",
      "type": "app",
      "description": "Accessibility tools that keep data on the device.",
      "url": "https://privacyratings.com/accessibility/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "code-hosting",
      "name": "Code hosting",
      "group": "Development",
      "type": "service",
      "description": "Places to host Git repositories.",
      "url": "https://privacyratings.com/code-hosting/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "code-editors",
      "name": "Code editors",
      "group": "Development",
      "type": "app",
      "description": "Editors and IDEs without telemetry.",
      "url": "https://privacyratings.com/code-editors/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "terminals",
      "name": "Terminals",
      "group": "Development",
      "type": "app",
      "description": "Terminal emulators.",
      "url": "https://privacyratings.com/terminals/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "developer-tools",
      "name": "Developer tools",
      "group": "Development",
      "type": "app",
      "description": "Tools for developers that keep data local.",
      "url": "https://privacyratings.com/developer-tools/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "node-frameworks",
      "name": "Node.js frameworks",
      "group": "Development",
      "type": "app",
      "description": "Web and API frameworks for Node.js. Telemetry and dependencies matter for every app built on them.",
      "url": "https://privacyratings.com/node-frameworks/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "web-frameworks",
      "name": "Front-end and full-stack frameworks",
      "group": "Development",
      "type": "app",
      "description": "JavaScript front-end, single-page and full-stack frameworks. Some collect telemetry from developers by default.",
      "url": "https://privacyratings.com/web-frameworks/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "build-tools",
      "name": "Bundlers and build tools",
      "group": "Development",
      "type": "app",
      "description": "JavaScript bundlers and build tools.",
      "url": "https://privacyratings.com/build-tools/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "static-site-generators",
      "name": "Static site generators",
      "group": "Development",
      "type": "app",
      "description": "Tools that build websites, blogs and documentation into static files. Some collect telemetry from developers.",
      "url": "https://privacyratings.com/static-site-generators/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "app-frameworks",
      "name": "Cross-platform app frameworks",
      "group": "Development",
      "type": "app",
      "description": "Frameworks for building desktop and mobile apps from one codebase. Their tooling and SDKs can add telemetry to every app built with them.",
      "url": "https://privacyratings.com/app-frameworks/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "python-frameworks",
      "name": "Python web frameworks",
      "group": "Development",
      "type": "app",
      "description": "Web and API frameworks for Python.",
      "url": "https://privacyratings.com/python-frameworks/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "ruby-frameworks",
      "name": "Ruby web frameworks",
      "group": "Development",
      "type": "app",
      "description": "Web and API frameworks for Ruby.",
      "url": "https://privacyratings.com/ruby-frameworks/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "php-frameworks",
      "name": "PHP frameworks",
      "group": "Development",
      "type": "app",
      "description": "Web and API frameworks for PHP.",
      "url": "https://privacyratings.com/php-frameworks/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "go-frameworks",
      "name": "Go web frameworks",
      "group": "Development",
      "type": "app",
      "description": "Web and API frameworks and routers for Go.",
      "url": "https://privacyratings.com/go-frameworks/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "rust-frameworks",
      "name": "Rust web frameworks",
      "group": "Development",
      "type": "app",
      "description": "Web, API and full-stack frameworks for Rust.",
      "url": "https://privacyratings.com/rust-frameworks/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "jvm-frameworks",
      "name": "Java and Kotlin frameworks",
      "group": "Development",
      "type": "app",
      "description": "Web and application frameworks for the JVM, written in Java, Kotlin or Scala.",
      "url": "https://privacyratings.com/jvm-frameworks/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "dotnet-frameworks",
      "name": ".NET web frameworks",
      "group": "Development",
      "type": "app",
      "description": "Web and API frameworks for C# and .NET. The .NET SDK itself sends telemetry by default.",
      "url": "https://privacyratings.com/dotnet-frameworks/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "elixir-frameworks",
      "name": "Elixir, Erlang and Gleam frameworks",
      "group": "Development",
      "type": "app",
      "description": "Web frameworks for languages on the BEAM virtual machine.",
      "url": "https://privacyratings.com/elixir-frameworks/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "other-web-frameworks",
      "name": "Web frameworks for other languages",
      "group": "Development",
      "type": "app",
      "description": "Web frameworks for Swift, Dart, Crystal, C++, Haskell, OCaml, Clojure, Nim and Zig.",
      "url": "https://privacyratings.com/other-web-frameworks/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "web-analytics",
      "name": "Website analytics",
      "group": "Development",
      "type": "service",
      "description": "Tools that count website visitors. Some track people across sites, others collect no personal data.",
      "url": "https://privacyratings.com/web-analytics/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "no_cookies",
        "no_personal_data",
        "self_hostable"
      ]
    },
    {
      "id": "url-shorteners",
      "name": "URL shorteners",
      "group": "Development",
      "type": "service",
      "description": "Link shorteners and link management.",
      "url": "https://privacyratings.com/url-shorteners/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "smart-home",
      "name": "Smart home",
      "group": "Home and IoT",
      "type": "app",
      "description": "Home automation that runs locally.",
      "url": "https://privacyratings.com/smart-home/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "home-design",
      "name": "Home and floor plan design",
      "group": "Home and IoT",
      "type": "service",
      "description": "Floor plan, interior design and home 3D modeling apps.",
      "url": "https://privacyratings.com/home-design/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "security-cameras",
      "name": "Security cameras",
      "group": "Home and IoT",
      "type": "app",
      "description": "Camera software that keeps footage private.",
      "url": "https://privacyratings.com/security-cameras/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "wearables",
      "name": "Wearables and health",
      "group": "Home and IoT",
      "type": "app",
      "description": "Apps for wearables that work without a vendor cloud.",
      "url": "https://privacyratings.com/wearables/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "period-trackers",
      "name": "Period trackers",
      "group": "Health",
      "type": "app",
      "description": "Menstrual cycle and fertility tracking apps. Cycle data is sensitive health data.",
      "url": "https://privacyratings.com/period-trackers/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards",
        "local_storage",
        "no_account_needed"
      ]
    },
    {
      "id": "fitness-trackers",
      "name": "Fitness trackers",
      "group": "Health",
      "type": "app",
      "description": "Apps for recording runs, rides and workouts.",
      "url": "https://privacyratings.com/fitness-trackers/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "weather",
      "name": "Weather apps",
      "group": "Health",
      "type": "app",
      "description": "Weather apps. Many sell precise location data; some need none.",
      "url": "https://privacyratings.com/weather/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "cryptocurrencies",
      "name": "Private cryptocurrencies",
      "group": "Finance",
      "type": "app",
      "description": "Cryptocurrencies designed for private payments.",
      "url": "https://privacyratings.com/cryptocurrencies/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "crypto-wallets",
      "name": "Crypto wallets",
      "group": "Finance",
      "type": "app",
      "description": "Wallets for holding cryptocurrency.",
      "url": "https://privacyratings.com/crypto-wallets/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "crypto-exchanges",
      "name": "Crypto exchanges",
      "group": "Finance",
      "type": "app",
      "description": "Peer-to-peer exchanges.",
      "url": "https://privacyratings.com/crypto-exchanges/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "virtual-cards",
      "name": "Virtual cards",
      "group": "Finance",
      "type": "service",
      "description": "Virtual and masked payment cards.",
      "url": "https://privacyratings.com/virtual-cards/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "budgeting",
      "name": "Budgeting",
      "group": "Finance",
      "type": "app",
      "description": "Budgeting and accounting apps that keep data local.",
      "url": "https://privacyratings.com/budgeting/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "social-networks",
      "name": "Social networks",
      "group": "Social and media",
      "type": "app",
      "description": "Decentralized and privacy-respecting social platforms.",
      "url": "https://privacyratings.com/social-networks/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "video-platforms",
      "name": "Video platforms",
      "group": "Social and media",
      "type": "app",
      "description": "Video hosting without tracking.",
      "url": "https://privacyratings.com/video-platforms/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "music-streaming",
      "name": "Music streaming",
      "group": "Social and media",
      "type": "service",
      "description": "Music streaming services and self-hosted music libraries.",
      "url": "https://privacyratings.com/music-streaming/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "blogging",
      "name": "Blogging",
      "group": "Social and media",
      "type": "service",
      "description": "Blogging platforms.",
      "url": "https://privacyratings.com/blogging/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "news-readers",
      "name": "News readers",
      "group": "Social and media",
      "type": "app",
      "description": "RSS and news readers.",
      "url": "https://privacyratings.com/news-readers/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "media-players",
      "name": "Media and podcast players",
      "group": "Social and media",
      "type": "app",
      "description": "Video, music and podcast players.",
      "url": "https://privacyratings.com/media-players/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "media-servers",
      "name": "Media servers",
      "group": "Social and media",
      "type": "app",
      "description": "Self-hosted servers for streaming your own films, music, books and photos.",
      "url": "https://privacyratings.com/media-servers/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "photo-management",
      "name": "Photo management",
      "group": "Social and media",
      "type": "app",
      "description": "Photo libraries and backups.",
      "url": "https://privacyratings.com/photo-management/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "torrent-clients",
      "name": "Torrent clients",
      "group": "Social and media",
      "type": "app",
      "description": "BitTorrent clients.",
      "url": "https://privacyratings.com/torrent-clients/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "games",
      "name": "Games",
      "group": "Social and media",
      "type": "app",
      "description": "Game launchers without tracking.",
      "url": "https://privacyratings.com/games/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "file-converters",
      "name": "File converters",
      "group": "Social and media",
      "type": "app",
      "description": "Converters that run locally.",
      "url": "https://privacyratings.com/file-converters/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    },
    {
      "id": "creative-tools",
      "name": "Creative tools",
      "group": "Social and media",
      "type": "app",
      "description": "Image, video, audio, 3D and streaming software.",
      "url": "https://privacyratings.com/creative-tools/",
      "criteria": [
        "open_source",
        "no_trackers",
        "no_ads",
        "independent_audit",
        "transparency_report",
        "user_notice",
        "tls",
        "security_headers",
        "web_standards"
      ]
    }
  ],
  "criteria": [
    {
      "id": "open_source",
      "title": "Open source",
      "weight": 3,
      "question": "Is all the source code needed to run the product public?",
      "yes": "All code needed to run the product is public, the apps (front end) and, for hosted services, the server (back end), under an open-source (OSI-approved) or source-available license. Source-available entries are labeled and left out of open-source lists.",
      "partial": "Only part of the code is public, for example the apps but not the server, or the product's own paid edition adds unpublished code. Separate paid products and services do not count.",
      "no": "The product is closed source.",
      "why": "Public code lets anyone check what the software does with your data instead of trusting a privacy policy.",
      "verify": "Link the source repository and its license file."
    },
    {
      "id": "no_trackers",
      "title": "No trackers or telemetry",
      "weight": 3,
      "question": "Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?",
      "yes": "No third-party trackers. Any analytics, first-party or from a privacy-focused service such as Plausible, Simple Analytics or GoatCounter, are cookieless and aggregate-only, with no stored IP addresses or persistent identifiers. App telemetry is absent or opt-in.",
      "partial": "No third-party trackers, but analytics use cookies or persistent identifiers, or app telemetry or crash reporting is on by default.",
      "no": "Third-party trackers or analytics are present, or telemetry cannot be turned off.",
      "why": "Trackers and telemetry leak usage data to the vendor and to third parties.",
      "verify": "Link the privacy policy or telemetry documentation, or a network capture or tracker report (for example Exodus Privacy for Android apps)."
    },
    {
      "id": "no_ads",
      "title": "No ads or data sales",
      "weight": 2,
      "question": "Is the product funded without advertising, ad targeting or selling user data?",
      "yes": "Funded by payments, donations or grants. No ads, no data sales, and no sharing of user data with ad networks.",
      "partial": "No ads based on user data and no data sales, but ads are opt-in or contextual, or the vendor shares website or app data with ad networks to advertise its own product (retargeting).",
      "no": "Funded by advertising, shows ads based on user data, or sells or shares user data for other companies' advertising.",
      "why": "An ad-funded product earns more when it collects more data about you.",
      "verify": "Link the pricing page, funding page or privacy policy."
    },
    {
      "id": "independent_audit",
      "title": "Independent audit",
      "weight": 2,
      "question": "Has an independent security or privacy audit been published within the last three years?",
      "yes": "A full report from an independent auditor is public.",
      "partial": "An audit was done but only a summary is public, or the audit is older than three years.",
      "no": "No independent audit is public.",
      "why": "Audits catch problems that the vendor missed or did not disclose.",
      "verify": "Link the published audit report."
    },
    {
      "id": "transparency_report",
      "title": "Transparency report",
      "weight": 2,
      "services": true,
      "question": "Does the provider regularly publish how many government and legal requests it receives and how it responds?",
      "yes": "Publishes a transparency report with request counts and outcomes, updated at least once a year.",
      "partial": "Publishes a policy on requests or a warrant canary, but no counts.",
      "no": "Publishes nothing about government requests.",
      "why": "Jurisdiction alone says little. Request counts and outcomes show how much a provider hands over, and how often, under its local law.",
      "verify": "Link the transparency report or government request policy."
    },
    {
      "id": "user_notice",
      "title": "Tells users about requests",
      "weight": 1,
      "services": true,
      "question": "Does the provider promise to tell users about requests for their data, unless a court forbids it?",
      "yes": "A published policy promises notice when legally allowed.",
      "partial": "Notice is given case by case, with no published policy.",
      "no": "No notice, or a policy of not notifying.",
      "why": "Notice gives people the chance to challenge a request.",
      "verify": "Link the law enforcement or privacy policy."
    },
    {
      "id": "tls",
      "title": "TLS configuration",
      "weight": 2,
      "services": true,
      "auto": "ssllabs",
      "question": "Does the website pass the Qualys SSL Labs test with a grade of A or better?",
      "yes": "Grade A+ or A on every endpoint.",
      "partial": "Grade A- or B on the weakest endpoint.",
      "no": "Grade C or lower, or the test failed.",
      "why": "Weak TLS settings can expose traffic and logins to interception.",
      "verify": "Run https://www.ssllabs.com/ssltest/ on the domain."
    },
    {
      "id": "security_headers",
      "title": "Security headers",
      "weight": 1,
      "services": true,
      "auto": "observatory",
      "question": "Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?",
      "yes": "Grade A+ or A.",
      "partial": "Grade A-, B+ or B.",
      "no": "Grade B- or lower, or the test failed.",
      "why": "Headers such as CSP and HSTS block common attacks against logged-in users.",
      "verify": "Run https://developer.mozilla.org/en-US/observatory on the domain."
    },
    {
      "id": "web_standards",
      "title": "Modern web standards",
      "weight": 1,
      "services": true,
      "auto": "internetnl-web",
      "question": "Does the website score 90% or higher on the Internet.nl website test?",
      "yes": "Score of 90% or higher.",
      "partial": "Score between 70% and 89%.",
      "no": "Score below 70%.",
      "why": "The test checks IPv6, DNSSEC, HTTPS and security options that protect visitors.",
      "verify": "Run https://internet.nl/test-site/ on the domain."
    },
    {
      "id": "e2ee",
      "title": "End-to-end encryption",
      "weight": 3,
      "question": "Can mail be end-to-end encrypted so that the provider cannot read message contents?",
      "yes": "Built in by default between users, and supported for outside recipients (for example OpenPGP or password-protected mail).",
      "partial": "Supported but not by default, or only with a browser extension or separate app.",
      "no": "Not supported.",
      "why": "Without end-to-end encryption, the provider and anyone with access to its servers can read mail.",
      "verify": "Link the documentation that describes the encryption."
    },
    {
      "id": "encrypted_storage",
      "title": "Encrypted mailbox storage",
      "weight": 3,
      "question": "Is stored mail encrypted with a key the provider does not hold?",
      "yes": "Mailboxes are encrypted at rest with a key derived from the user's password or private key.",
      "partial": "Encrypted at rest, but with keys the provider holds.",
      "no": "Stored unencrypted or undocumented.",
      "why": "Encrypted storage protects mail from breaches, rogue staff and bulk data requests.",
      "verify": "Link the security or encryption documentation."
    },
    {
      "id": "open_protocols",
      "title": "Open protocols",
      "weight": 2,
      "question": "Can any standard app connect over IMAP, POP3, SMTP, CalDAV or CardDAV, without extra software?",
      "yes": "IMAP and SMTP work with any client on every paid plan.",
      "partial": "Standard protocols need a bridge app or a higher plan.",
      "no": "Only the provider's own apps work.",
      "why": "Open protocols prevent lock-in and let people choose their own apps.",
      "verify": "Link the IMAP and SMTP setup documentation."
    },
    {
      "id": "custom_domains",
      "title": "Custom domains",
      "weight": 1,
      "question": "Can mail be sent and received with your own domain?",
      "yes": "Supported on affordable plans.",
      "partial": "Only on business plans.",
      "no": "Not supported.",
      "why": "Your own domain makes it possible to switch providers without changing addresses.",
      "verify": "Link the custom domain documentation."
    },
    {
      "id": "anonymous_signup",
      "title": "Sign up without personal data",
      "weight": 2,
      "question": "Can an account be created without a phone number or another email address?",
      "yes": "No phone number or existing email required.",
      "partial": "Required only in some cases, such as flagged sign-ups.",
      "no": "A phone number or other personal data is required.",
      "why": "Requiring a phone number ties the account to a real identity.",
      "verify": "Link the sign-up page or documentation."
    },
    {
      "id": "mail_standards",
      "title": "Email security standards",
      "weight": 2,
      "services": true,
      "auto": "internetnl-mail",
      "question": "Does the mail domain score 90% or higher on the Internet.nl email test?",
      "yes": "Score of 90% or higher.",
      "partial": "Score between 70% and 89%.",
      "no": "Score below 70%.",
      "why": "The test checks DMARC, DKIM, SPF, DNSSEC, DANE and STARTTLS, which protect mail from spoofing and interception.",
      "verify": "Run https://internet.nl/test-mail/ on the mail domain."
    },
    {
      "id": "imap_standards",
      "title": "IMAP support",
      "weight": 2,
      "services": true,
      "auto": "imap",
      "question": "Does the IMAP server accept connections over implicit TLS on port 993 and advertise IMAP4rev1 or IMAP4rev2 with IDLE push?",
      "yes": "Implicit TLS on 993 (RFC 8314), IMAP4rev1 (RFC 3501) or IMAP4rev2 (RFC 9051), and IDLE (RFC 2177) advertised in CAPABILITY.",
      "partial": "IMAP works, but only with STARTTLS on 143, or without IDLE in the advertised capabilities.",
      "no": "No IMAP server. Mail can only be read in the provider's own apps or through a local bridge.",
      "why": "Standard IMAP lets people use any email app and keeps them free to leave. Implicit TLS is the current recommendation for mail access.",
      "verify": "Connect with `openssl s_client -connect imap.example.com:993` and send `a1 CAPABILITY`."
    },
    {
      "id": "pop3_standards",
      "title": "POP3 support",
      "weight": 1,
      "services": true,
      "auto": "pop3",
      "question": "Does the POP3 server accept connections over implicit TLS on port 995 and answer CAPA with UIDL?",
      "yes": "Implicit TLS on 995 (RFC 8314), CAPA (RFC 2449) and UIDL (RFC 1939).",
      "partial": "POP3 works, but only with STLS on 110, or without CAPA or UIDL.",
      "no": "No POP3 server.",
      "why": "POP3 is the simplest way to download and keep a full local copy of every message.",
      "verify": "Connect with `openssl s_client -connect pop3.example.com:995` and send `CAPA`."
    },
    {
      "id": "smtp_standards",
      "title": "SMTP submission",
      "weight": 2,
      "services": true,
      "auto": "smtp",
      "question": "Does mail submission work over implicit TLS on port 465 with SMTPUTF8, 8BITMIME, PIPELINING and AUTH?",
      "yes": "Implicit TLS on 465 (RFC 8314) with SMTPUTF8 (RFC 6531), 8BITMIME (RFC 6152), PIPELINING (RFC 2920) and AUTH (RFC 4954) in EHLO.",
      "partial": "Submission works, but only with STARTTLS on 587, or without one of these extensions.",
      "no": "No SMTP submission. Mail can only be sent from the provider's own apps or through a local bridge.",
      "why": "Standard SMTP submission lets any app send mail, and SMTPUTF8 allows international addresses.",
      "verify": "Connect with `openssl s_client -connect smtp.example.com:465` and send `EHLO example.com`."
    },
    {
      "id": "transport_security",
      "title": "Mail transport security",
      "weight": 3,
      "services": true,
      "auto": "mail-dns",
      "question": "Does the mail domain enforce encrypted, authenticated delivery with MTA-STS, DANE, DNSSEC, TLS-RPT and an enforced DMARC policy?",
      "yes": "SPF, DMARC set to quarantine or reject, MTA-STS in enforce mode (RFC 8461), TLS-RPT (RFC 8460), DNSSEC, and DANE TLSA records on every MX host (RFC 7672).",
      "partial": "DMARC is enforced and either MTA-STS is enforced or DANE is published, but not everything above.",
      "no": "DMARC is not enforced, or neither MTA-STS nor DANE is used.",
      "why": "These records stop attackers from downgrading or intercepting mail in transit, and from spoofing the provider's own domain.",
      "verify": "Check the TXT records for _mta-sts, _smtp._tls and _dmarc, the TLSA records for _25._tcp on each MX host, and DNSSEC validation."
    },
    {
      "id": "srs",
      "title": "Sender Rewriting Scheme",
      "weight": 1,
      "question": "Is the envelope sender rewritten with SRS when mail is forwarded, so forwarded mail keeps passing SPF?",
      "yes": "SRS is applied to all forwarded mail.",
      "partial": "SRS is applied only in some cases or on some plans.",
      "no": "Forwarded mail is not rewritten.",
      "why": "Without SRS, forwarded mail often fails SPF and lands in spam or is rejected.",
      "verify": "Link documentation or source code, or check the Return-Path of a forwarded message."
    },
    {
      "id": "arc",
      "title": "ARC sealing",
      "weight": 1,
      "question": "Does the provider validate and add ARC (RFC 8617) signatures, so authentication results survive forwarding?",
      "yes": "ARC chains are validated on inbound mail and ARC seals are added to forwarded mail.",
      "partial": "Only one of the two.",
      "no": "ARC is not supported.",
      "why": "ARC lets receivers trust authentication results after a message is forwarded or modified by a mailing list.",
      "verify": "Link documentation or source code, or check for ARC-Seal headers on a forwarded message."
    },
    {
      "id": "e2ee",
      "title": "End-to-end encryption",
      "weight": 2,
      "question": "Can mail be end-to-end encrypted so that the provider cannot read message contents?",
      "yes": "Built in by default between users, and supported for outside recipients (for example OpenPGP or password-protected mail).",
      "partial": "Supported but not by default, or only with a browser extension or separate app.",
      "no": "Not supported.",
      "why": "Without end-to-end encryption, the provider and anyone with access to its servers can read mail.",
      "verify": "Link the documentation that describes the encryption."
    },
    {
      "id": "no_mail_storage",
      "title": "No stored mail",
      "weight": 3,
      "question": "Is forwarded mail passed through without being written to disk?",
      "yes": "Mail is forwarded in memory and never stored, except in a documented retry queue.",
      "partial": "Mail is stored briefly for a documented reason.",
      "no": "Mail is stored or logged in full.",
      "why": "Mail that is never stored cannot be breached or handed over later.",
      "verify": "Link the documentation or source code that shows how mail is handled."
    },
    {
      "id": "open_protocols",
      "title": "Open protocols",
      "weight": 2,
      "question": "Can any standard app connect over IMAP, POP3, SMTP, CalDAV or CardDAV, without extra software?",
      "yes": "IMAP and SMTP work with any client on every paid plan.",
      "partial": "Standard protocols need a bridge app or a higher plan.",
      "no": "Only the provider's own apps work.",
      "why": "Open protocols prevent lock-in and let people choose their own apps.",
      "verify": "Link the IMAP and SMTP setup documentation."
    },
    {
      "id": "custom_domains",
      "title": "Custom domains",
      "weight": 1,
      "question": "Can mail be sent and received with your own domain?",
      "yes": "Supported on affordable plans.",
      "partial": "Only on business plans.",
      "no": "Not supported.",
      "why": "Your own domain makes it possible to switch providers without changing addresses.",
      "verify": "Link the custom domain documentation."
    },
    {
      "id": "anonymous_signup",
      "title": "Sign up without personal data",
      "weight": 2,
      "question": "Can an account be created without a phone number or another email address?",
      "yes": "No phone number or existing email required.",
      "partial": "Required only in some cases, such as flagged sign-ups.",
      "no": "A phone number or other personal data is required.",
      "why": "Requiring a phone number ties the account to a real identity.",
      "verify": "Link the sign-up page or documentation."
    },
    {
      "id": "mail_standards",
      "title": "Email security standards",
      "weight": 2,
      "services": true,
      "auto": "internetnl-mail",
      "question": "Does the mail domain score 90% or higher on the Internet.nl email test?",
      "yes": "Score of 90% or higher.",
      "partial": "Score between 70% and 89%.",
      "no": "Score below 70%.",
      "why": "The test checks DMARC, DKIM, SPF, DNSSEC, DANE and STARTTLS, which protect mail from spoofing and interception.",
      "verify": "Run https://internet.nl/test-mail/ on the mail domain."
    },
    {
      "id": "transport_security",
      "title": "Mail transport security",
      "weight": 3,
      "services": true,
      "auto": "mail-dns",
      "question": "Does the mail domain enforce encrypted, authenticated delivery with MTA-STS, DANE, DNSSEC, TLS-RPT and an enforced DMARC policy?",
      "yes": "SPF, DMARC set to quarantine or reject, MTA-STS in enforce mode (RFC 8461), TLS-RPT (RFC 8460), DNSSEC, and DANE TLSA records on every MX host (RFC 7672).",
      "partial": "DMARC is enforced and either MTA-STS is enforced or DANE is published, but not everything above.",
      "no": "DMARC is not enforced, or neither MTA-STS nor DANE is used.",
      "why": "These records stop attackers from downgrading or intercepting mail in transit, and from spoofing the provider's own domain.",
      "verify": "Check the TXT records for _mta-sts, _smtp._tls and _dmarc, the TLSA records for _25._tcp on each MX host, and DNSSEC validation."
    },
    {
      "id": "srs",
      "title": "Sender Rewriting Scheme",
      "weight": 2,
      "question": "Is the envelope sender rewritten with SRS when mail is forwarded, so forwarded mail keeps passing SPF?",
      "yes": "SRS is applied to all forwarded mail.",
      "partial": "SRS is applied only in some cases or on some plans.",
      "no": "Forwarded mail is not rewritten.",
      "why": "Without SRS, forwarded mail often fails SPF and lands in spam or is rejected.",
      "verify": "Link documentation or source code, or check the Return-Path of a forwarded message."
    },
    {
      "id": "arc",
      "title": "ARC sealing",
      "weight": 1,
      "question": "Does the provider validate and add ARC (RFC 8617) signatures, so authentication results survive forwarding?",
      "yes": "ARC chains are validated on inbound mail and ARC seals are added to forwarded mail.",
      "partial": "Only one of the two.",
      "no": "ARC is not supported.",
      "why": "ARC lets receivers trust authentication results after a message is forwarded or modified by a mailing list.",
      "verify": "Link documentation or source code, or check for ARC-Seal headers on a forwarded message."
    },
    {
      "id": "openpgp",
      "title": "OpenPGP support",
      "weight": 2,
      "question": "Can the app encrypt and sign mail with OpenPGP, built in or through an official add-on?",
      "yes": "Built in.",
      "partial": "Through a separate app or add-on.",
      "no": "Not supported.",
      "why": "OpenPGP gives end-to-end encryption with any provider.",
      "verify": "Link the documentation."
    },
    {
      "id": "no_cloud_relay",
      "title": "Connects directly",
      "weight": 3,
      "question": "Does the app connect directly to your mail server, without passing mail or passwords through the vendor's servers?",
      "yes": "Connects directly. Passwords and mail stay on the device.",
      "partial": "Connects directly, but optional features (such as push or sync) use vendor servers.",
      "no": "Mail or credentials pass through vendor servers.",
      "why": "A client that syncs through the vendor's cloud gives the vendor a copy of every mailbox.",
      "verify": "Link the documentation or privacy policy that describes how the app connects."
    },
    {
      "id": "remote_content_blocked",
      "title": "Blocks remote content",
      "weight": 2,
      "question": "Are remote images and tracking pixels blocked by default?",
      "yes": "Blocked by default.",
      "partial": "Can be blocked in settings.",
      "no": "Cannot be blocked.",
      "why": "Remote images tell senders when and where a message was opened.",
      "verify": "Link the documentation or settings screen."
    },
    {
      "id": "any_provider",
      "title": "Works with any provider",
      "weight": 1,
      "question": "Does the app work with any standard IMAP and SMTP provider?",
      "yes": "Any IMAP and SMTP provider.",
      "partial": "A limited list of providers.",
      "no": "Only the vendor's own service.",
      "why": "Apps tied to one provider make switching harder.",
      "verify": "Link the account setup documentation."
    },
    {
      "id": "openpgp",
      "title": "OpenPGP support",
      "weight": 2,
      "question": "Can the app encrypt and sign mail with OpenPGP, built in or through an official add-on?",
      "yes": "Built in.",
      "partial": "Through a separate app or add-on.",
      "no": "Not supported.",
      "why": "OpenPGP gives end-to-end encryption with any provider.",
      "verify": "Link the documentation."
    },
    {
      "id": "no_cloud_relay",
      "title": "Connects directly",
      "weight": 3,
      "question": "Does the app connect directly to your mail server, without passing mail or passwords through the vendor's servers?",
      "yes": "Connects directly. Passwords and mail stay on the device.",
      "partial": "Connects directly, but optional features (such as push or sync) use vendor servers.",
      "no": "Mail or credentials pass through vendor servers.",
      "why": "A client that syncs through the vendor's cloud gives the vendor a copy of every mailbox.",
      "verify": "Link the documentation or privacy policy that describes how the app connects."
    },
    {
      "id": "remote_content_blocked",
      "title": "Blocks remote content",
      "weight": 2,
      "question": "Are remote images and tracking pixels blocked by default?",
      "yes": "Blocked by default.",
      "partial": "Can be blocked in settings.",
      "no": "Cannot be blocked.",
      "why": "Remote images tell senders when and where a message was opened.",
      "verify": "Link the documentation or settings screen."
    },
    {
      "id": "any_provider",
      "title": "Works with any provider",
      "weight": 1,
      "question": "Does the app work with any standard IMAP and SMTP provider?",
      "yes": "Any IMAP and SMTP provider.",
      "partial": "A limited list of providers.",
      "no": "Only the vendor's own service.",
      "why": "Apps tied to one provider make switching harder.",
      "verify": "Link the account setup documentation."
    },
    {
      "id": "self_hostable",
      "title": "Self-hostable",
      "weight": 1,
      "question": "Can the webmail be installed on your own server?",
      "yes": "Officially supported self-hosting.",
      "partial": "Possible but unsupported or limited.",
      "no": "Hosted only.",
      "why": "Self-hosting keeps mail and sessions on servers you control.",
      "verify": "Link the installation guide."
    },
    {
      "id": "content_retention",
      "title": "Message content deleted after delivery",
      "weight": 3,
      "question": "Is the content of sent mail deleted once it has been delivered?",
      "yes": "Message bodies are not kept after delivery, or are kept only when the sender turns this on.",
      "partial": "Message bodies are kept by default for a documented period of 30 days or less, or a longer period can be shortened to 30 days or less or turned off.",
      "no": "Message bodies are kept for more than 30 days or for an undocumented period, with no way to shorten it.",
      "why": "Every stored copy of a password reset, receipt or newsletter can be breached or handed over later.",
      "verify": "Link the documentation on message logs, content storage or data retention."
    },
    {
      "id": "tracking_off_by_default",
      "title": "Open and click tracking off by default",
      "weight": 2,
      "question": "Are open tracking pixels and click tracking links off unless the sender turns them on?",
      "yes": "Open and click tracking are not offered, or are off until the sender turns them on.",
      "partial": "Open or click tracking is on by default, but can be turned off or made anonymous for the account or for each message.",
      "no": "Open or click tracking is always on.",
      "why": "Tracking pixels and rewritten links record when, where and on which device each recipient reads mail.",
      "verify": "Link the tracking settings documentation or API reference."
    },
    {
      "id": "enforced_tls",
      "title": "Encrypted delivery can be enforced",
      "weight": 2,
      "question": "Can outbound mail be kept from being delivered without TLS?",
      "yes": "Outbound delivery honors the recipient domain's MTA-STS or DANE policy, or the sender can require TLS so mail is not sent in plain text.",
      "partial": "TLS is used when the receiving server offers it, with no way to require it.",
      "no": "Outbound mail is sent without TLS.",
      "why": "With opportunistic TLS alone, an attacker on the network can strip encryption and read mail in transit.",
      "verify": "Link the TLS or delivery security documentation."
    },
    {
      "id": "eu_data_location",
      "title": "EU data location",
      "weight": 1,
      "question": "Can message content and delivery logs be processed and stored only in the European Union?",
      "yes": "An EU region, an EU-only service or self-hosting keeps message data in the EU, on every plan.",
      "partial": "An EU region is offered only on some plans, on request or in beta.",
      "no": "Message data is processed or stored outside the EU.",
      "why": "Data kept in the EU stays under the GDPR and out of reach of some foreign surveillance laws.",
      "verify": "Link the data location, region or data residency documentation."
    },
    {
      "id": "tracker_blocking",
      "title": "Blocks trackers by default",
      "weight": 3,
      "question": "Are third-party trackers blocked by default, without installing extensions?",
      "yes": "Blocked by default.",
      "partial": "Limits cross-site tracking (for example cookie isolation) but does not block tracker requests.",
      "no": "Not blocked by default.",
      "why": "Most people never change default settings.",
      "verify": "Link the documentation, or a test such as https://coveryourtracks.eff.org/."
    },
    {
      "id": "fingerprinting_protection",
      "title": "Fingerprinting protection",
      "weight": 2,
      "question": "Does the browser defend against fingerprinting by default?",
      "yes": "Randomizes or standardizes fingerprinting data by default.",
      "partial": "Only in a stricter mode that is off by default.",
      "no": "No protection.",
      "why": "Fingerprinting tracks people even after cookies are cleared.",
      "verify": "Link the documentation, or a test such as https://coveryourtracks.eff.org/."
    },
    {
      "id": "no_google_services",
      "title": "No calls to big-tech services",
      "weight": 2,
      "question": "Does the browser work without background connections to Google, Microsoft or Apple services?",
      "yes": "No background connections to big-tech services by default.",
      "partial": "Some connections remain and can be turned off.",
      "no": "Background connections are built in and cannot be turned off.",
      "why": "Background connections share browsing activity and device data.",
      "verify": "Link documentation or source code that lists removed or disabled services."
    },
    {
      "id": "security_updates",
      "title": "Timely security updates",
      "weight": 3,
      "question": "Are security fixes from the upstream engine shipped quickly and automatically?",
      "yes": "Fixes ship within days and install automatically.",
      "partial": "Fixes ship quickly but must be installed by hand or through a package manager.",
      "no": "Fixes often lag weeks behind upstream.",
      "why": "Browsers are the most attacked software on most devices.",
      "verify": "Link the release notes or update documentation."
    },
    {
      "id": "blocks_by_default",
      "title": "Effective by default",
      "weight": 3,
      "question": "Does it block ads and trackers with its default settings, without paid tiers?",
      "yes": "Blocks ads and trackers by default, for free.",
      "partial": "Needs extra lists or configuration.",
      "no": "Allows \"acceptable ads\" by default, or blocking is paid.",
      "why": "Allowlists paid for by advertisers let their ads and trackers through.",
      "verify": "Link the documentation or filter list settings."
    },
    {
      "id": "no_data_collection",
      "title": "No browsing data collected",
      "weight": 3,
      "question": "Does it work without sending browsing data to the developer?",
      "yes": "All filtering happens on the device, with no data sent.",
      "partial": "Anonymous usage statistics that can be turned off.",
      "no": "Browsing data is collected.",
      "why": "An ad blocker sees every page visited.",
      "verify": "Link the privacy policy or source code."
    },
    {
      "id": "custom_filters",
      "title": "Custom filters",
      "weight": 1,
      "question": "Can users add their own filter lists and rules?",
      "yes": "Yes.",
      "partial": "Limited.",
      "no": "No.",
      "why": "Custom rules handle sites that default lists miss.",
      "verify": "Link the documentation."
    },
    {
      "id": "no_search_logs",
      "title": "No search history logs",
      "weight": 3,
      "question": "Are searches stored without IP addresses or other identifiers?",
      "yes": "Searches are not stored with identifiers.",
      "partial": "Identifiers are removed after a short, documented period.",
      "no": "Searches are tied to identifiers or accounts.",
      "why": "Search history reveals health, money, politics and more.",
      "verify": "Link the privacy policy."
    },
    {
      "id": "no_personalized_ads",
      "title": "No profile-based ads",
      "weight": 2,
      "question": "Are ads (if any) based only on the current search, not a profile?",
      "yes": "No ads, or ads based only on the search terms.",
      "partial": "Profile-based ads can be turned off.",
      "no": "Ads are based on a profile.",
      "why": "Profile-based ads need a stored profile of your searches.",
      "verify": "Link the privacy policy or ad documentation."
    },
    {
      "id": "no_account_needed",
      "title": "No account needed",
      "weight": 1,
      "question": "Can every feature be used without an account?",
      "yes": "No account needed.",
      "partial": "Some features need an account.",
      "no": "An account is needed.",
      "why": "Accounts link searches to an identity.",
      "verify": "Link the help or settings page."
    },
    {
      "id": "no_account_needed",
      "title": "No account needed",
      "weight": 2,
      "question": "Can apps be installed without an account?",
      "yes": "No account needed.",
      "partial": "Only for some apps.",
      "no": "An account is required.",
      "why": "An account links every installed app to an identity.",
      "verify": "Link the documentation."
    },
    {
      "id": "tracker_info",
      "title": "Shows trackers and anti-features",
      "weight": 1,
      "question": "Does the store show which apps contain trackers, ads or other anti-features?",
      "yes": "Shown for every app.",
      "partial": "Partly, for example self-reported privacy labels.",
      "no": "Not shown.",
      "why": "It helps people avoid apps that track them.",
      "verify": "Link an example listing or documentation."
    },
    {
      "id": "e2ee_vault",
      "title": "End-to-end encrypted vault",
      "weight": 3,
      "question": "Is the vault encrypted on the device before it is synced, with a key the provider does not hold?",
      "yes": "End-to-end encrypted, or local-only with no sync service.",
      "partial": "Encrypted, but key handling is not documented.",
      "no": "The provider can decrypt vaults.",
      "why": "A breached password manager exposes every account.",
      "verify": "Link the security whitepaper or encryption documentation."
    },
    {
      "id": "self_host_or_local",
      "title": "Local or self-hosted option",
      "weight": 2,
      "question": "Can the vault be kept locally or on your own server?",
      "yes": "Local files or a supported self-hosted server.",
      "partial": "Export only.",
      "no": "Only the vendor's cloud.",
      "why": "Keeping data under your control removes a third party.",
      "verify": "Link the documentation."
    },
    {
      "id": "export",
      "title": "Full export",
      "weight": 1,
      "question": "Can every item be exported in an open format?",
      "yes": "Full export in an open format.",
      "partial": "Partial export.",
      "no": "No export.",
      "why": "Export prevents lock-in.",
      "verify": "Link the export documentation."
    },
    {
      "id": "public_reports",
      "title": "Publishes full reports",
      "weight": 3,
      "question": "Are full audit reports routinely published, with client consent, rather than only summaries or badges?",
      "yes": "Many full reports are public, listed by the firm or linked from clients.",
      "partial": "Some reports or summaries are public.",
      "no": "Reports stay private.",
      "why": "A public report lets anyone check what was tested, what was found and what was fixed.",
      "verify": "Link the firm's publications page or public reports."
    },
    {
      "id": "open_source_work",
      "title": "Audits open-source projects",
      "weight": 2,
      "question": "Does the firm regularly audit open-source software and non-profit projects?",
      "yes": "Regular public audits of open-source projects, for example through OSTIF or the Open Technology Fund.",
      "partial": "Occasional open-source audits.",
      "no": "Commercial clients only.",
      "why": "Audits of open-source software protect everyone who uses it.",
      "verify": "Link public audits of open-source projects."
    },
    {
      "id": "public_research",
      "title": "Public research",
      "weight": 1,
      "question": "Does the firm publish security research, advisories or tools?",
      "yes": "Regular public research, advisories or open-source tools.",
      "partial": "Occasional publications.",
      "no": "None.",
      "why": "Published research shows expertise and helps defenders.",
      "verify": "Link the research or advisories page."
    },
    {
      "id": "no_trackers",
      "title": "No trackers on website",
      "weight": 1,
      "question": "Is the firm's website free of third-party trackers?",
      "yes": "No third-party trackers. Any analytics are cookieless and aggregate-only.",
      "partial": "Analytics that use cookies or persistent identifiers, without other trackers.",
      "no": "Third-party trackers are present.",
      "why": "A privacy and security firm's own site shows its standards.",
      "verify": "Run the tracker test or check the privacy policy."
    },
    {
      "id": "e2ee_default",
      "title": "End-to-end encrypted by default",
      "weight": 3,
      "question": "Are all chats, including groups, end-to-end encrypted by default?",
      "yes": "All chats and calls by default.",
      "partial": "Only some chats, or only when turned on.",
      "no": "Not end-to-end encrypted.",
      "why": "Without it, the service can read messages.",
      "verify": "Link the encryption documentation."
    },
    {
      "id": "no_phone_number",
      "title": "No phone number needed",
      "weight": 2,
      "question": "Can an account be created without a phone number?",
      "yes": "No phone number needed.",
      "partial": "A phone number is needed but can be hidden from contacts.",
      "no": "A phone number is needed and visible.",
      "why": "Phone numbers are tied to real identities.",
      "verify": "Link the sign-up documentation."
    },
    {
      "id": "metadata_protection",
      "title": "Metadata protection",
      "weight": 2,
      "question": "Does the service minimize who-talks-to-whom metadata (for example sealed sender or no user identifiers)?",
      "yes": "Documented design that hides sender or contact lists from the server.",
      "partial": "Some metadata protection.",
      "no": "The server sees who talks to whom.",
      "why": "Metadata alone can reveal relationships and habits.",
      "verify": "Link the documentation or design paper."
    },
    {
      "id": "decentralized",
      "title": "Decentralized",
      "weight": 1,
      "question": "Can people run their own server or talk peer to peer?",
      "yes": "Federated or peer to peer.",
      "partial": "Self-hosting is possible but not federated.",
      "no": "One central service.",
      "why": "Decentralized networks cannot be shut down or censored at one point.",
      "verify": "Link the self-hosting documentation."
    },
    {
      "id": "e2ee",
      "title": "End-to-end encrypted",
      "weight": 3,
      "question": "Are calls end-to-end encrypted by default?",
      "yes": "All calls, including group calls, by default.",
      "partial": "Optional, or only for some calls.",
      "no": "Not end-to-end encrypted.",
      "why": "Without end-to-end encryption, the provider can access calls.",
      "verify": "Link the security documentation."
    },
    {
      "id": "no_account_needed",
      "title": "Join without an account",
      "weight": 1,
      "question": "Can people join calls without an account?",
      "yes": "Guests join from a link with no account.",
      "partial": "Only the host needs an account.",
      "no": "Everyone needs an account.",
      "why": "Accounts tie calls to identities.",
      "verify": "Link the documentation."
    },
    {
      "id": "self_hostable",
      "title": "Self-hostable",
      "weight": 1,
      "question": "Can the server be self-hosted?",
      "yes": "Officially supported.",
      "partial": "Possible but limited.",
      "no": "Hosted only.",
      "why": "Self-hosting keeps call metadata on your own servers.",
      "verify": "Link the self-hosting guide."
    },
    {
      "id": "content_retention",
      "title": "Message content deleted or redacted",
      "weight": 3,
      "question": "Can the text of messages be kept from being stored after delivery?",
      "yes": "Message bodies are not stored after delivery, or the customer can turn on redaction or deletion for every message without asking.",
      "partial": "Message bodies are kept for a documented period of 30 days or less, or can be deleted through the API, or redaction is available on request or on some plans.",
      "no": "Message bodies are kept for more than 30 days or an undocumented period, with no way to delete them.",
      "why": "Stored texts hold one-time codes, appointments and personal conversations tied to phone numbers.",
      "verify": "Link the data retention, message redaction or deletion documentation."
    },
    {
      "id": "eu_data_location",
      "title": "EU data location",
      "weight": 1,
      "question": "Can messages, call records and logs be processed and stored in the European Union?",
      "yes": "An EU region, an EU-only service or self-hosting keeps message data in the EU, on every plan.",
      "partial": "An EU region is offered only on some plans, on request or in beta.",
      "no": "Message data is processed or stored outside the EU.",
      "why": "Data kept in the EU stays under the GDPR and out of reach of some foreign surveillance laws.",
      "verify": "Link the data location, region or data residency documentation."
    },
    {
      "id": "no_logs_audited",
      "title": "Audited no-logs policy",
      "weight": 3,
      "question": "Has an independent audit confirmed that activity and connection logs are not kept?",
      "yes": "A public audit report confirms it.",
      "partial": "A no-logs policy exists but has not been audited.",
      "no": "Logs are kept, or there is no policy.",
      "why": "A VPN sees all traffic. Only an audit shows the policy is followed.",
      "verify": "Link the audit report and the privacy policy."
    },
    {
      "id": "anonymous_payment",
      "title": "Anonymous payment",
      "weight": 2,
      "question": "Can an account be created and paid for without an email address, name or card?",
      "yes": "Accounts need no email, and cash or Monero is accepted.",
      "partial": "Cryptocurrency is accepted but an email is needed.",
      "no": "Personal data is required.",
      "why": "Payment details tie the account to a real identity.",
      "verify": "Link the payment and sign-up documentation."
    },
    {
      "id": "open_source_clients",
      "title": "Open-source apps",
      "weight": 2,
      "question": "Are the apps for every platform open source?",
      "yes": "All platforms.",
      "partial": "Some platforms.",
      "no": "None.",
      "why": "The VPN app handles all traffic and keys.",
      "verify": "Link the source repositories."
    },
    {
      "id": "modern_protocols",
      "title": "Modern protocols",
      "weight": 1,
      "question": "Is WireGuard (or another modern audited protocol) supported?",
      "yes": "WireGuard supported.",
      "partial": "Only OpenVPN or IKEv2.",
      "no": "Only outdated or proprietary protocols.",
      "why": "Modern protocols are faster and have smaller, audited codebases.",
      "verify": "Link the documentation."
    },
    {
      "id": "encrypted_dns",
      "title": "Encrypted DNS",
      "weight": 3,
      "question": "Are DNS over HTTPS and DNS over TLS supported?",
      "yes": "Both.",
      "partial": "One of them.",
      "no": "Neither.",
      "why": "Unencrypted DNS shows every site visited to anyone on the network.",
      "verify": "Link the setup documentation."
    },
    {
      "id": "no_query_logs",
      "title": "No query logs",
      "weight": 3,
      "question": "Are queries stored without IP addresses, and is this independently audited?",
      "yes": "No identifying logs, confirmed by an audit.",
      "partial": "No identifying logs claimed, but not audited, or logs kept briefly.",
      "no": "Identifying logs are kept.",
      "why": "DNS logs are a full browsing history.",
      "verify": "Link the privacy policy and audit."
    },
    {
      "id": "dnssec_validation",
      "title": "DNSSEC validation",
      "weight": 1,
      "question": "Does the resolver validate DNSSEC?",
      "yes": "Yes.",
      "partial": "Optional.",
      "no": "No.",
      "why": "Validation stops forged DNS answers.",
      "verify": "Link the documentation or a test."
    },
    {
      "id": "dnssec",
      "title": "DNSSEC",
      "weight": 3,
      "question": "Can DNSSEC be turned on for hosted zones?",
      "yes": "One click or automatic.",
      "partial": "Supported with manual steps.",
      "no": "Not supported.",
      "why": "DNSSEC stops attackers from forging a domain's records.",
      "verify": "Link the documentation."
    },
    {
      "id": "api_access",
      "title": "API access",
      "weight": 1,
      "question": "Can records be managed through an API on every plan?",
      "yes": "Yes, on every plan.",
      "partial": "Only on paid plans.",
      "no": "No API.",
      "why": "An API makes automation and migrations possible.",
      "verify": "Link the API documentation."
    },
    {
      "id": "two_factor",
      "title": "Two-factor login",
      "weight": 2,
      "question": "Do accounts support two-factor authentication with an authenticator app or security key?",
      "yes": "TOTP or security keys.",
      "partial": "SMS only.",
      "no": "No two-factor login.",
      "why": "A hijacked DNS account can redirect all mail and web traffic.",
      "verify": "Link the documentation."
    },
    {
      "id": "free_whois_privacy",
      "title": "Free WHOIS privacy",
      "weight": 2,
      "question": "Is registrant data hidden from public WHOIS and RDAP at no extra cost?",
      "yes": "Free for every supported domain extension.",
      "partial": "Free for some extensions only, or paid.",
      "no": "Not offered.",
      "why": "Public registrant data exposes names, addresses and phone numbers.",
      "verify": "Link the pricing or privacy documentation."
    },
    {
      "id": "at_cost_renewals",
      "title": "Honest renewal pricing",
      "weight": 1,
      "question": "Are renewal prices the same as, or close to, the first-year price?",
      "yes": "At-cost or flat renewal pricing.",
      "partial": "Renewals cost somewhat more.",
      "no": "Large renewal increases.",
      "why": "Cheap first years with expensive renewals make it costly to keep a domain.",
      "verify": "Link the pricing page."
    },
    {
      "id": "two_factor",
      "title": "Two-factor login",
      "weight": 2,
      "question": "Do accounts support two-factor authentication with an authenticator app or security key?",
      "yes": "TOTP or security keys.",
      "partial": "SMS only.",
      "no": "No two-factor login.",
      "why": "A hijacked registrar account means a hijacked domain.",
      "verify": "Link the documentation."
    },
    {
      "id": "registry_lock",
      "title": "Transfer and registry lock",
      "weight": 1,
      "question": "Is transfer lock on by default, with registry lock available?",
      "yes": "Both.",
      "partial": "Transfer lock only.",
      "no": "Neither.",
      "why": "Locks prevent domain theft.",
      "verify": "Link the documentation."
    },
    {
      "id": "port_25",
      "title": "Mail-friendly (port 25)",
      "weight": 1,
      "question": "Is outbound port 25 open by default, or opened on request?",
      "yes": "Open by default.",
      "partial": "Blocked by default but opened on request.",
      "no": "Always blocked.",
      "why": "Running a mail server needs outbound port 25.",
      "verify": "Link the documentation or support policy."
    },
    {
      "id": "reverse_dns",
      "title": "Reverse DNS",
      "weight": 1,
      "question": "Can reverse DNS (PTR) records be set for IPv4 and IPv6?",
      "yes": "Both, self-service.",
      "partial": "On request, or IPv4 only.",
      "no": "Not supported.",
      "why": "Mail servers without matching reverse DNS are rejected as spam.",
      "verify": "Link the documentation."
    },
    {
      "id": "ipv6",
      "title": "IPv6",
      "weight": 1,
      "question": "Is native IPv6 included?",
      "yes": "Yes, at no extra cost.",
      "partial": "For an extra fee.",
      "no": "No.",
      "why": "IPv6 is required for modern networking and many mail tests.",
      "verify": "Link the documentation."
    },
    {
      "id": "anonymous_payment",
      "title": "Anonymous payment",
      "weight": 1,
      "question": "Can servers be paid for with cryptocurrency or without identity checks?",
      "yes": "Yes.",
      "partial": "Only after verification.",
      "no": "No.",
      "why": "Payment details tie servers to an identity.",
      "verify": "Link the payment documentation."
    },
    {
      "id": "self_hosted",
      "title": "Runs on your own infrastructure",
      "weight": 3,
      "question": "Can it run entirely on your own infrastructure or repository, without a vendor account?",
      "yes": "Fully self-hosted or runs in your own repository.",
      "partial": "Self-hosted with optional vendor services.",
      "no": "Hosted by the vendor only.",
      "why": "Status data and visitor logs stay under your control.",
      "verify": "Link the installation documentation."
    },
    {
      "id": "no_visitor_tracking",
      "title": "No visitor tracking",
      "weight": 2,
      "question": "Is the public status page free of third-party trackers and analytics?",
      "yes": "No third-party trackers.",
      "partial": "Analytics can be turned off.",
      "no": "Trackers are always included.",
      "why": "Status pages are visited by customers during outages.",
      "verify": "Link the source code or privacy policy."
    },
    {
      "id": "history",
      "title": "Public uptime history",
      "weight": 1,
      "question": "Does it publish response times and incident history?",
      "yes": "Yes.",
      "partial": "Current status only.",
      "no": "No.",
      "why": "History shows how reliable a service has been over time.",
      "verify": "Link a live example."
    },
    {
      "id": "device_keys",
      "title": "Keys stay on devices",
      "weight": 3,
      "question": "Is traffic encrypted between devices with private keys created on each device, so the coordination server and relays cannot read it?",
      "yes": "Private keys are created on each device and never leave it. Relays only forward encrypted packets.",
      "partial": "Traffic is encrypted between devices, but key handling is not documented, or some setups use keys created on the server.",
      "no": "Traffic is decrypted on the vendor's servers.",
      "why": "The coordination server knows every device on the network. Keys that stay on the devices keep it from reading the traffic too.",
      "verify": "Link the security or architecture documentation that describes key generation and relays."
    },
    {
      "id": "self_hosted_control",
      "title": "Self-hosted coordination server",
      "weight": 2,
      "question": "Can the coordination or control server be self-hosted with open-source software?",
      "yes": "The vendor's control server is open source and can be self-hosted, or the network needs no central server.",
      "partial": "Self-hosting needs a proprietary or source-available server, is not officially supported, or works only through a third-party open-source replacement.",
      "no": "Only the vendor's hosted service can be used.",
      "why": "A self-hosted server keeps the list of devices, users and access rules off a third party's servers.",
      "verify": "Link the self-hosting documentation and the server's license."
    },
    {
      "id": "no_connection_logs",
      "title": "No connection logs by default",
      "weight": 2,
      "question": "Are connection logs and client diagnostic logs kept off the vendor's servers unless a user or admin turns them on?",
      "yes": "Nothing is sent to the vendor by default, or there is no vendor service.",
      "partial": "Logs or crash reports are sent to the vendor by default, but can be turned off.",
      "no": "Connection logs are kept by the vendor, with no documented way to turn them off.",
      "why": "Connection logs show which devices talked to each other and when, even when the traffic itself is encrypted.",
      "verify": "Link the logging, telemetry or data collection documentation."
    },
    {
      "id": "offline",
      "title": "Works offline",
      "weight": 3,
      "question": "Does the keyboard work without internet access?",
      "yes": "Has no internet permission, or makes no network requests.",
      "partial": "Network features such as suggestions or sync are optional and off by default.",
      "no": "Sends typing data or requires network access.",
      "why": "A keyboard sees every password, message and search you type.",
      "verify": "Link the app permissions, source code or privacy policy."
    },
    {
      "id": "offline",
      "title": "Works offline",
      "weight": 2,
      "question": "Does the app scan and show disk usage without contacting the internet?",
      "yes": "Makes no network requests, or only checks for updates when you ask or after you opt in.",
      "partial": "Works offline, but checks for updates, loads content or sends usage data by default.",
      "no": "Needs an internet connection to work, or sends file names or scan results to a server.",
      "why": "A disk scan lists every file and folder name on the computer, which can reveal projects, people and habits.",
      "verify": "Link the source code, network documentation or privacy policy."
    },
    {
      "id": "no_account_needed",
      "title": "No account needed",
      "weight": 1,
      "question": "Can the app be used without an account or registering an email address?",
      "yes": "No account or registration needed.",
      "partial": "Only some features, such as cloud storage scanning, need an account.",
      "no": "An account or email registration is required.",
      "why": "An account or registration ties the app and its use to an identity.",
      "verify": "Link the download page, documentation or privacy policy."
    },
    {
      "id": "local_by_default",
      "title": "Saved locally by default",
      "weight": 2,
      "question": "Are screenshots and recordings saved on the device unless you choose to upload them?",
      "yes": "Saved locally; uploading is optional.",
      "partial": "Saved locally, but some features upload automatically.",
      "no": "Recordings are uploaded to the vendor's cloud by default.",
      "why": "Screen recordings often capture passwords, messages and private documents.",
      "verify": "Link the documentation."
    },
    {
      "id": "no_account_needed",
      "title": "No account needed",
      "weight": 1,
      "question": "Can the app be used without an account?",
      "yes": "No account needed.",
      "partial": "Only some features need an account.",
      "no": "An account is required.",
      "why": "An account ties recordings to an identity.",
      "verify": "Link the documentation or sign-up page."
    },
    {
      "id": "offline",
      "title": "Works offline",
      "weight": 3,
      "question": "Can text be translated on the device, without sending it to a server?",
      "yes": "Translation runs on the device or on your own server.",
      "partial": "Offline translation is optional, with online translation by default.",
      "no": "Online only.",
      "why": "Translated text is often private, such as messages, contracts and medical letters.",
      "verify": "Link the documentation."
    },
    {
      "id": "no_retention",
      "title": "Text not kept",
      "weight": 2,
      "question": "Is translated text deleted after translation and kept out of model training?",
      "yes": "Not stored or used for training.",
      "partial": "Stored or used for training unless you opt out or pay.",
      "no": "Stored and used for training.",
      "why": "Stored texts can be read, breached or used to train models.",
      "verify": "Link the privacy policy."
    },
    {
      "id": "runs_locally",
      "title": "Runs on the device",
      "weight": 3,
      "question": "Is speech converted to text on the device, without sending audio to a server?",
      "yes": "Transcription runs fully on the device or on your own server.",
      "partial": "Local transcription is available, but cloud processing is the default or needed for some features.",
      "no": "Audio is sent to the vendor's servers.",
      "why": "Voice recordings and transcripts hold private conversations, names and health or business details.",
      "verify": "Link the documentation or privacy policy."
    },
    {
      "id": "no_training",
      "title": "No training on recordings",
      "weight": 2,
      "question": "Are recordings and transcripts kept out of model training by default?",
      "yes": "Never used for training, or processing is entirely local.",
      "partial": "Used for training by default with an opt-out.",
      "no": "Used for training with no opt-out.",
      "why": "Training on recordings can expose what was said.",
      "verify": "Link the privacy policy."
    },
    {
      "id": "no_training",
      "title": "No training on your data",
      "weight": 3,
      "question": "Are prompts, chats and files kept out of model training by default?",
      "yes": "Never used for training, or the model runs entirely on your device.",
      "partial": "Used for training by default, but you can opt out.",
      "no": "Used for training with no opt-out.",
      "why": "Text sent to an AI often contains private, work or health information. Training on it can expose it later.",
      "verify": "Link the privacy policy or data use documentation."
    },
    {
      "id": "runs_locally",
      "title": "Runs locally",
      "weight": 2,
      "question": "Can the assistant run on your own device or server, so prompts never leave it?",
      "yes": "Runs fully on your own hardware.",
      "partial": "Can use local models, but defaults to a hosted service.",
      "no": "Hosted only.",
      "why": "A local model cannot leak prompts to anyone.",
      "verify": "Link the documentation."
    },
    {
      "id": "chat_retention",
      "title": "Limited chat retention",
      "weight": 2,
      "question": "Are chats deleted by default or on request, with no long-term server copy?",
      "yes": "Chats are not stored on servers, or are deleted within 30 days of deletion or by default.",
      "partial": "Chats are kept until you delete them, then removed.",
      "no": "Chats are kept indefinitely or for review even after deletion.",
      "why": "Stored chats can be breached, subpoenaed or read by staff.",
      "verify": "Link the data retention policy."
    },
    {
      "id": "no_account_needed",
      "title": "No account needed",
      "weight": 1,
      "question": "Can it be used without an account or personal details?",
      "yes": "No account or email needed.",
      "partial": "Limited use without an account.",
      "no": "An account is required.",
      "why": "An account ties every prompt to an identity.",
      "verify": "Link the sign-up page or documentation."
    },
    {
      "id": "no_cookies",
      "title": "No cookies",
      "weight": 2,
      "question": "Does it count visitors without cookies or other identifiers stored on the device?",
      "yes": "No cookies, local storage or fingerprinting.",
      "partial": "Cookieless mode is available but not the default.",
      "no": "Uses cookies or persistent identifiers.",
      "why": "Cookies and identifiers let visitors be followed across visits and sites, and need consent under EU law.",
      "verify": "Link the documentation or privacy policy."
    },
    {
      "id": "no_personal_data",
      "title": "No personal data",
      "weight": 3,
      "question": "Does it avoid storing IP addresses and personal data, and never share data with advertisers?",
      "yes": "No IP addresses or personal data stored, and no data shared for ads.",
      "partial": "Personal data is anonymized by default, or stored only in self-hosted setups.",
      "no": "Stores personal data or shares it for advertising.",
      "why": "Counting visits needs no profile of each visitor.",
      "verify": "Link the data policy."
    },
    {
      "id": "self_hostable",
      "title": "Self-hostable",
      "weight": 1,
      "question": "Can the analytics be self-hosted?",
      "yes": "Officially supported self-hosting.",
      "partial": "Possible but unsupported or limited.",
      "no": "Hosted only.",
      "why": "Self-hosting keeps visitor data on your own servers.",
      "verify": "Link the self-hosting guide."
    },
    {
      "id": "local_storage",
      "title": "Data stays on device",
      "weight": 3,
      "question": "Is cycle data stored only on the device by default?",
      "yes": "Stored only on the device unless you choose to back it up.",
      "partial": "Synced to a server but end-to-end encrypted.",
      "no": "Stored on the vendor's servers in readable form.",
      "why": "Cycle and pregnancy data can be requested by courts and police in some jurisdictions.",
      "verify": "Link the privacy policy or documentation."
    },
    {
      "id": "no_account_needed",
      "title": "No account needed",
      "weight": 2,
      "question": "Can the app be used without an account?",
      "yes": "No account needed.",
      "partial": "Account optional.",
      "no": "An account is required.",
      "why": "An account links health data to an identity.",
      "verify": "Link the app listing or documentation."
    }
  ],
  "jurisdictions": [
    {
      "code": "US",
      "name": "United States",
      "eyes": "Five Eyes",
      "eu": false,
      "gdpr": false,
      "cloud_act": "provider",
      "notes": [
        {
          "text": "The CLOUD Act requires US providers to hand over data they control in response to valid US legal process, wherever in the world the data is stored.",
          "source": "https://www.justice.gov/criminal/cloud-act-resources"
        },
        {
          "text": "Section 702 of FISA allows intelligence collection targeting non-US persons abroad through US providers, without an individual warrant.",
          "source": "https://www.eff.org/702-spying"
        },
        {
          "text": "National Security Letters can demand subscriber records and usually come with gag orders that stop the provider from telling the user.",
          "source": "https://www.eff.org/issues/national-security-letters"
        },
        {
          "text": "The Fourth Amendment and the Stored Communications Act generally require a warrant for the content of communications, and code has been recognized as protected speech.",
          "source": "https://www.eff.org/cases/bernstein-v-us-dept-justice"
        }
      ],
      "url": "https://privacyratings.com/jurisdictions/united-states/"
    },
    {
      "code": "DE",
      "name": "Germany",
      "eyes": "Fourteen Eyes",
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [
        {
          "text": "German judges can order a mailbox to be seized or monitored in real time. Unencrypted mail is then handed over in plain text. End-to-end encrypted mail stays encrypted.",
          "source": "https://tuta.com/blog/transparency-report"
        },
        {
          "text": "A regional court ordered Tutanota (now Tuta) to build a function to monitor a single account under investigation.",
          "source": "https://techcrunch.com/2020/12/08/german-secure-email-provider-tutanota-forced-to-monitor-an-account-after-regional-court-ruling/"
        }
      ],
      "url": "https://privacyratings.com/jurisdictions/germany/"
    },
    {
      "code": "FR",
      "name": "France",
      "eyes": "Nine Eyes",
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/france/"
    },
    {
      "code": "GB",
      "name": "United Kingdom",
      "eyes": "Five Eyes",
      "eu": false,
      "gdpr": true,
      "cloud_act": "agreement",
      "notes": [
        {
          "text": "The Investigatory Powers Act allows Technical Capability Notices that can require providers to change their systems to enable access, with secrecy obligations.",
          "source": "https://www.legislation.gov.uk/ukpga/2016/25/contents"
        },
        {
          "text": "A CLOUD Act data access agreement with the US is in force, so UK authorities can request data directly from US providers for serious crimes.",
          "source": "https://www.justice.gov/archives/opa/pr/landmark-us-uk-data-access-agreement-enters-force"
        }
      ],
      "url": "https://privacyratings.com/jurisdictions/united-kingdom/"
    },
    {
      "code": "CH",
      "name": "Switzerland",
      "eyes": null,
      "eu": false,
      "gdpr": true,
      "cloud_act": null,
      "notes": [
        {
          "text": "Outside all Eyes arrangements and outside the EU. Foreign requests must go through Swiss courts, but Swiss orders are still enforced. Proton complied with most of the thousands of Swiss legal orders it received.",
          "source": "https://proton.me/legal/transparency"
        },
        {
          "text": "A proposed revision of the surveillance ordinance (VÜPF/OSCPT) would expand user identification and require six months of metadata retention. It was paused for a second consultation after strong opposition, and Proton began moving some infrastructure out of Switzerland.",
          "source": "https://www.isoc.ch/swiss-surveillance-ordinance-encryption-threat-vupf-oscpt/"
        }
      ],
      "url": "https://privacyratings.com/jurisdictions/switzerland/"
    },
    {
      "code": "CA",
      "name": "Canada",
      "eyes": "Five Eyes",
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/canada/"
    },
    {
      "code": "NL",
      "name": "Netherlands",
      "eyes": "Nine Eyes",
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/netherlands/"
    },
    {
      "code": "SE",
      "name": "Sweden",
      "eyes": "Fourteen Eyes",
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [
        {
          "text": "VPN services are not covered by the data retention rules in the Electronic Communications Act, according to Mullvad's legal review.",
          "source": "https://mullvad.net/en/help/swedish-legislation"
        }
      ],
      "url": "https://privacyratings.com/jurisdictions/sweden/"
    },
    {
      "code": "AU",
      "name": "Australia",
      "eyes": "Five Eyes",
      "eu": false,
      "gdpr": false,
      "cloud_act": "agreement",
      "notes": [
        {
          "text": "The Assistance and Access Act allows authorities to issue technical assistance and capability notices to communications providers.",
          "source": "https://www.legislation.gov.au/C2018A00148/latest/text"
        },
        {
          "text": "A CLOUD Act data access agreement with the US is in force.",
          "source": "https://www.justice.gov/criminal/cloud-act-resources"
        }
      ],
      "url": "https://privacyratings.com/jurisdictions/australia/"
    },
    {
      "code": "CZ",
      "name": "Czechia",
      "eyes": null,
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/czechia/"
    },
    {
      "code": "AT",
      "name": "Austria",
      "eyes": null,
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/austria/"
    },
    {
      "code": "SG",
      "name": "Singapore",
      "eyes": null,
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/singapore/"
    },
    {
      "code": "IE",
      "name": "Ireland",
      "eyes": null,
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/ireland/"
    },
    {
      "code": "IT",
      "name": "Italy",
      "eyes": "Fourteen Eyes",
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/italy/"
    },
    {
      "code": "EE",
      "name": "Estonia",
      "eyes": null,
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/estonia/"
    },
    {
      "code": "FI",
      "name": "Finland",
      "eyes": null,
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/finland/"
    },
    {
      "code": "IN",
      "name": "India",
      "eyes": null,
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/india/"
    },
    {
      "code": "NO",
      "name": "Norway",
      "eyes": "Nine Eyes",
      "eu": false,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/norway/"
    },
    {
      "code": "PL",
      "name": "Poland",
      "eyes": null,
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/poland/"
    },
    {
      "code": "CY",
      "name": "Cyprus",
      "eyes": null,
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/cyprus/"
    },
    {
      "code": "ES",
      "name": "Spain",
      "eyes": "Fourteen Eyes",
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/spain/"
    },
    {
      "code": "BE",
      "name": "Belgium",
      "eyes": "Fourteen Eyes",
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/belgium/"
    },
    {
      "code": "CN",
      "name": "China",
      "eyes": null,
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [
        {
          "text": "The National Intelligence Law requires organizations and citizens to support, assist and cooperate with state intelligence work, and to keep that cooperation secret.",
          "source": "https://www.chinalawtranslate.com/en/national-intelligence-law-of-the-p-r-c-2017/"
        }
      ],
      "url": "https://privacyratings.com/jurisdictions/china/"
    },
    {
      "code": "DK",
      "name": "Denmark",
      "eyes": "Nine Eyes",
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/denmark/"
    },
    {
      "code": "IL",
      "name": "Israel",
      "eyes": null,
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/israel/"
    },
    {
      "code": "JP",
      "name": "Japan",
      "eyes": null,
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/japan/"
    },
    {
      "code": "RO",
      "name": "Romania",
      "eyes": null,
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/romania/"
    },
    {
      "code": "KR",
      "name": "South Korea",
      "eyes": null,
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/south-korea/"
    },
    {
      "code": "BG",
      "name": "Bulgaria",
      "eyes": null,
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/bulgaria/"
    },
    {
      "code": "LU",
      "name": "Luxembourg",
      "eyes": null,
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/luxembourg/"
    },
    {
      "code": "MH",
      "name": "Marshall Islands",
      "eyes": null,
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/marshall-islands/"
    },
    {
      "code": "NZ",
      "name": "New Zealand",
      "eyes": "Five Eyes",
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/new-zealand/"
    },
    {
      "code": "RU",
      "name": "Russia",
      "eyes": null,
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/russia/"
    },
    {
      "code": "SK",
      "name": "Slovakia",
      "eyes": null,
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/slovakia/"
    },
    {
      "code": "VG",
      "name": "British Virgin Islands",
      "eyes": null,
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/british-virgin-islands/"
    },
    {
      "code": "KY",
      "name": "Cayman Islands",
      "eyes": null,
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/cayman-islands/"
    },
    {
      "code": "CR",
      "name": "Costa Rica",
      "eyes": null,
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/costa-rica/"
    },
    {
      "code": "GI",
      "name": "Gibraltar",
      "eyes": null,
      "eu": false,
      "gdpr": true,
      "cloud_act": null,
      "notes": [
        {
          "text": "British Overseas Territory with its own courts and data protection law. The UK is responsible for its defense and foreign relations.",
          "source": "https://en.wikipedia.org/wiki/Gibraltar"
        }
      ],
      "url": "https://privacyratings.com/jurisdictions/gibraltar/"
    },
    {
      "code": "HU",
      "name": "Hungary",
      "eyes": null,
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/hungary/"
    },
    {
      "code": "IS",
      "name": "Iceland",
      "eyes": null,
      "eu": false,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/iceland/"
    },
    {
      "code": "LV",
      "name": "Latvia",
      "eyes": null,
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/latvia/"
    },
    {
      "code": "LT",
      "name": "Lithuania",
      "eyes": null,
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/lithuania/"
    },
    {
      "code": "PA",
      "name": "Panama",
      "eyes": null,
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/panama/"
    },
    {
      "code": "SI",
      "name": "Slovenia",
      "eyes": null,
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/slovenia/"
    },
    {
      "code": "UA",
      "name": "Ukraine",
      "eyes": null,
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/ukraine/"
    },
    {
      "code": "AE",
      "name": "United Arab Emirates",
      "eyes": null,
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/united-arab-emirates/"
    },
    {
      "code": "AR",
      "name": "Argentina",
      "eyes": null,
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/argentina/"
    },
    {
      "code": "BM",
      "name": "Bermuda",
      "eyes": null,
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/bermuda/"
    },
    {
      "code": "GR",
      "name": "Greece",
      "eyes": null,
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/greece/"
    },
    {
      "code": "HK",
      "name": "Hong Kong",
      "eyes": null,
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/hong-kong/"
    },
    {
      "code": "MY",
      "name": "Malaysia",
      "eyes": null,
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/malaysia/"
    },
    {
      "code": "MT",
      "name": "Malta",
      "eyes": null,
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/malta/"
    },
    {
      "code": "PK",
      "name": "Pakistan",
      "eyes": null,
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/pakistan/"
    },
    {
      "code": "PT",
      "name": "Portugal",
      "eyes": null,
      "eu": true,
      "gdpr": true,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/portugal/"
    },
    {
      "code": "TR",
      "name": "Türkiye",
      "eyes": null,
      "eu": false,
      "gdpr": false,
      "cloud_act": null,
      "notes": [],
      "url": "https://privacyratings.com/jurisdictions/turkiye/"
    }
  ],
  "entries": [
    {
      "slug": "123-reg-email",
      "category": "email-providers",
      "name": "123 Reg Email Hosting",
      "description": "Business email hosting for custom domains from 123 Reg, a UK domain and hosting company owned by GoDaddy. Mailboxes run on GoDaddy mail servers, with webmail and mobile apps.",
      "website": "https://www.123-reg.co.uk/email-hosting/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 27,
      "coverage": 100,
      "summary": "123 Reg Email Hosting scores 27 out of 100 (grade F) on the email providers criteria. It meets 5 of 19 criteria: TLS configuration, open protocols, custom domains, IMAP support and POP3 support. It partly meets no ads or data sales and SMTP submission. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests, security headers, end-to-end encryption, encrypted mailbox storage, sign up without personal data, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/email-providers/123-reg-email/",
      "markdown": "https://privacyratings.com/email-providers/123-reg-email/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.123-reg.co.uk/terms/privacy/",
          "note": "The privacy notice lists Google Analytics and third-party identifiers used for measurement and personalized advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.123-reg.co.uk/terms/privacy/",
          "note": "Funded by paid plans and personal data is not sold, but it is disclosed to marketers and advertisers for personalized advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.123-reg.co.uk&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.123-reg.co.uk",
          "note": "Grade F (0/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Not supported."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Encryption at rest for stored mail is not documented."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.123-reg.co.uk/support/email/how-do-i-set-up-an-email-client-with-123-mail/",
          "note": "IMAP, POP3 and SMTP work with other apps."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.123-reg.co.uk/email-hosting/",
          "note": "Every plan uses your own domain."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://sso.123-reg.co.uk/account/create",
          "note": "Creating an account requires an existing email address, and purchases require contact and payment details."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "imap.secureserver.net:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "pop.secureserver.net:995 (implicit TLS). CAPA: CAPA, TOP, UIDL, RESP-CODES, PIPELINING, AUTH-RESP-CODE, USER, SASL."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "smtpout.secureserver.net:465 (implicit TLS). Missing: SMTPUTF8."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF, DMARC reject. Missing: MTA-STS missing, TLS-RPT, DNSSEC, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Trustpilot",
            "host": "www.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:46:29.492Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "aol-mail",
      "category": "email-providers",
      "name": "AOL Mail",
      "description": "Free, ad-supported email service from AOL, owned by Bending Spoons, with webmail and mobile apps. A paid subscription removes ads.",
      "website": "https://mail.aol.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 22,
      "coverage": 100,
      "summary": "AOL Mail scores 22 out of 100 (grade F) on the email providers criteria. It meets 3 of 19 criteria: TLS configuration, open protocols and IMAP support. It partly meets security headers, POP3 support and SMTP submission. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests, end-to-end encryption, encrypted mailbox storage, custom domains, sign up without personal data, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/email-providers/aol-mail/",
      "markdown": "https://privacyratings.com/email-providers/aol-mail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://legal.aol.com/privacy/index.html",
          "note": "The AOL website loads New Relic, Heap and Google tags, and the privacy policy allows third-party tracking technologies for advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://help.aol.com/articles/ad-free-aol-mail",
          "note": "The free service is funded by ads, and the privacy policy allows sharing data with advertising networks. A paid subscription removes ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mail.aol.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mail.aol.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Not supported."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Encryption at rest for stored mail is not documented."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://help.aol.com/articles/how-do-i-use-other-email-applications-to-send-and-receive-my-aol-mail",
          "note": "IMAP, POP3 and SMTP work with other apps."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Not supported. Addresses use AOL domains."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://help.aol.com/articles/use-whatsapp-to-verify-your-aol-account",
          "note": "Registration requires a mobile phone number to receive a verification code."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "imap.aol.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "partial",
          "evidence": null,
          "note": "pop.aol.com:995 (implicit TLS). CAPA: IMPLEMENTATION, TOP, USER, SASL."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "smtp.aol.com:465 (implicit TLS). Missing: SMTPUTF8."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF, DMARC reject. Missing: MTA-STS missing, TLS-RPT, DNSSEC, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:28.550Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "countermail",
      "category": "email-providers",
      "name": "CounterMail",
      "description": "Paid email service in Sweden that encrypts mail with OpenPGP and stores it encrypted. New registrations are closed.",
      "website": "https://countermail.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "SE",
        "name": "Sweden",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 62,
      "coverage": 100,
      "summary": "CounterMail scores 62 out of 100 (grade C) on the email providers criteria. It meets 9 of 19 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, end-to-end encryption, encrypted mailbox storage, open protocols, custom domains, sign up without personal data and IMAP support. It partly meets security headers, SMTP submission and mail transport security. It does not meet open source, independent audit, transparency report, tells users about requests, POP3 support, Sender Rewriting Scheme and ARC sealing. It is based in Sweden: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/email-providers/countermail/",
      "markdown": "https://privacyratings.com/email-providers/countermail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://countermail.com/?p=privacy",
          "note": "No cookies and no IP logging, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://countermail.com/?p=privacy",
          "note": "Funded by paid accounts. Account data is never shared or sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=countermail.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=countermail.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://countermail.com/?p=services",
          "note": "OpenPGP encryption is built in and automatic between users, and works with any OpenPGP user outside CounterMail."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://countermail.com/?p=server",
          "note": "Mail is stored encrypted with the user's OpenPGP key, and incoming unencrypted mail is encrypted on arrival."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.countermail.com/kb/faq.php?id=14",
          "note": "IMAP and SMTP work with any client on premium accounts, with a PGP plugin needed to read mail."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://countermail.com/?p=services",
          "note": "Available for a one-time setup fee."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://webmail.countermail.com/register/index.php",
          "note": "Registration asks only for a username, password and invitation code, but it is closed to new users."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "imap1.countermail.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Not offered."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "imap1.countermail.com:465 (implicit TLS). Missing: SMTPUTF8."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "partial",
          "evidence": null,
          "note": "Passes: SPF, DMARC quarantine, DNSSEC, DANE all. Missing: MTA-STS missing, TLS-RPT."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:02.187Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "disroot",
      "category": "email-providers",
      "name": "Disroot",
      "description": "Volunteer-run platform from the Netherlands offering email and other open services.",
      "website": "https://disroot.org",
      "source": "https://git.disroot.org/Disroot-Ansible",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 59,
      "coverage": 100,
      "summary": "Disroot scores 59 out of 100 (grade D) on the email providers criteria. It meets 9 of 19 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, open protocols, custom domains, IMAP support, POP3 support and mail transport security. It partly meets security headers, end-to-end encryption and SMTP submission. It does not meet independent audit, transparency report, tells users about requests, encrypted mailbox storage, sign up without personal data, Sender Rewriting Scheme and ARC sealing. It is based in the Netherlands: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/email-providers/disroot/",
      "markdown": "https://privacyratings.com/email-providers/disroot/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://disroot.org/about",
          "note": "Runs only free and open-source software such as Postfix, Dovecot and Roundcube. Deployment roles are published at git.disroot.org."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://disroot.org/privacy_policy",
          "note": "The privacy policy states that user behavior is not analyzed or profiled and that there are no advertisers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://disroot.org/privacy_policy",
          "note": "Funded by donations. No ads and no data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=disroot.org&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=disroot.org",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://disroot.org/services/email",
          "note": "OpenPGP is possible with the Mailvelope browser extension or a desktop client. Not on by default."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "no",
          "evidence": "https://disroot.org/privacy_policy",
          "note": "Mail is stored unencrypted unless the user encrypts it. An opt-in Lacre beta encrypts incoming mail with the user's own PGP key for a limited group of users."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://disroot.org/services/email",
          "note": "IMAP, POP3 and SMTP work with any client."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://disroot.org/perks",
          "note": "Available as a lifetime feature after a donation of the suggested amount."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://user.disroot.org/pwm/public/newuser",
          "note": "An existing email address is required for verification during sign-up."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "disroot.org:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "disroot.org:995 (implicit TLS). CAPA: CAPA, TOP, UIDL, RESP-CODES, PIPELINING, AUTH-RESP-CODE, USER, SASL."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "disroot.org:465 (implicit TLS). Missing: SMTPUTF8."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "yes",
          "evidence": null,
          "note": "Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:20.833Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "fastmail",
      "category": "email-providers",
      "name": "Fastmail",
      "description": "Paid email service from Australia with custom domains and standard protocols.",
      "website": "https://www.fastmail.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "AU",
        "name": "Australia",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Fastmail scores 50 out of 100 (grade D) on the email providers criteria. It meets 9 of 19 criteria: no ads or data sales, transparency report, tells users about requests, TLS configuration, open protocols, custom domains, IMAP support, POP3 support and ARC sealing. It partly meets security headers, encrypted mailbox storage, sign up without personal data, SMTP submission and Sender Rewriting Scheme. It does not meet open source, no trackers or telemetry, independent audit, end-to-end encryption and mail transport security. It is based in Australia: Five Eyes member; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/email-providers/fastmail/",
      "markdown": "https://privacyratings.com/email-providers/fastmail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.fastmail.com/policies/cookies-policy/",
          "note": "The marketing website uses third-party marketing cookies, including PartnerStack, to measure paid ads. Logged-in pages have no third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.fastmail.com/policies/privacy/",
          "note": "Funded by paid plans. The privacy policy states that personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.fastmail.com/policies/transparency-report/",
          "note": "Publishes yearly counts of valid and actioned law enforcement requests by origin and data type."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.fastmail.help/hc/en-us/articles/1500000277902-Information-for-law-enforcement",
          "note": "Users are notified of legal requests for their data unless prohibited by law or notice would cause harm."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.fastmail.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.fastmail.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.fastmail.com/features/security/",
          "note": "No end-to-end encryption in Fastmail's own apps. PGP or S/MIME only works in third-party apps."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.fastmail.com/features/security/",
          "note": "Mail is stored on encrypted disks with keys Fastmail holds."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.fastmail.help/hc/en-us/articles/1500000278342-Server-names-and-ports",
          "note": "IMAP, POP3, SMTP, CalDAV and CardDAV work with any client."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.fastmail.help/hc/en-us/articles/360058753394-Custom-domains-with-Fastmail",
          "note": "Available on every plan above Basic."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.fastmail.help/hc/en-us/articles/1500000277442-Trial-accounts",
          "note": "No phone number is needed by default, but some trial accounts are asked to verify a mobile number by SMS."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "imap.fastmail.com:993 (implicit TLS). IMAP4rev2 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "pop.fastmail.com:995 (implicit TLS). CAPA: EXPIRE, LOGIN-DELAY, TOP, UIDL, PIPELINING, RESP-CODES, AUTH-RESP-CODE, USER, SASL."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "smtp.fastmail.com:465 (implicit TLS). Missing: SMTPUTF8."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF, TLS-RPT. Missing: DMARC none, MTA-STS testing, DNSSEC, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.fastmail.help/hc/en-us/articles/360058753434-Set-up-mail-forwarding",
          "note": "SRS is available as an option for forwarding, but regular forwarding does not rewrite the sender."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.fastmail.com/blog/what-is-arc/",
          "note": "Validates ARC chains on inbound mail and adds ARC headers."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:19.429Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "forward-email",
      "category": "email-providers",
      "name": "Forward Email",
      "description": "Open-source email service with encrypted mailboxes, custom domains, and IMAP, POP3, SMTP, CalDAV and CardDAV on every paid plan.",
      "website": "https://forwardemail.net",
      "source": "https://github.com/forwardemail/forwardemail.net",
      "license": "BUSL-1.1 AND MPL-2.0",
      "platforms": [
        "web",
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": true,
      "pick_reason": "The whole service is published on GitHub, server code included. Each mailbox is a separately encrypted SQLite file, IMAP, POP3, SMTP, CalDAV and CardDAV work with any app, and custom domains are included on low-cost plans.",
      "disclosure": "Privacy Ratings is maintained by the team behind Forward Email. This entry is scored by the same criteria as every other email provider, and changes to it are reviewed under the published conflict-of-interest rules.",
      "grade": "A",
      "score": 93,
      "coverage": 100,
      "summary": "Forward Email scores 93 out of 100 (grade A) on the email providers criteria. It meets 17 of 19 criteria: open source, no ads or data sales, independent audit, tells users about requests, TLS configuration, security headers, end-to-end encryption, encrypted mailbox storage, open protocols, custom domains, sign up without personal data, IMAP support, POP3 support, SMTP submission, mail transport security, Sender Rewriting Scheme and ARC sealing. It partly meets no trackers or telemetry and transparency report. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/email-providers/forward-email/",
      "markdown": "https://privacyratings.com/email-providers/forward-email/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/forwardemail/forwardemail.net/blob/master/LICENSE.md",
          "note": "All code is public, including the web, API, IMAP, POP3, SMTP, MX, CalDAV and CardDAV servers that run the service. Core mail storage and protocol code is MPL-2.0 and the rest is under the source-available Business Source License 1.1 (BUSL-1.1), which becomes MPL-2.0 four years after each release."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://forwardemail.net/en/privacy#analytics",
          "note": "No third-party analytics or telemetry. First-party page statistics keep no IP addresses, cookies or identifiers and are deleted after 30 days. Cloudflare Turnstile loads only on sign-in and sign-up forms to stop bots."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/private-business-email",
          "note": "Funded by paid plans. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cure53.de/pentest-report_forward-email.pdf",
          "note": "Two independent Cure53 audits of the code and infrastructure, published by Cure53 and on forwardemail.net."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://forwardemail.net/technical-whitepaper.pdf",
          "note": "The technical whitepaper (section 9.3) publishes the government request policy and commits to regular transparency reports with request counts. A report with counts is not published yet."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://forwardemail.net/technical-whitepaper.pdf",
          "note": "Users are notified of requests when legally allowed, with notice after disclosure when advance notice is prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=forwardemail.net&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=forwardemail.net",
          "note": "Grade A+ (125/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/faq#do-you-support-openpgpmime-end-to-end-encryption-e2ee-and-web-key-directory-wkd",
          "note": "Mail is automatically encrypted with OpenPGP when the recipient publishes a key through Web Key Directory. OpenPGP/MIME and S/MIME work with any app."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://forwardemail.net/technical-whitepaper.pdf",
          "note": "Each mailbox is a separately encrypted SQLite file (ChaCha20-Poly1305). The technical whitepaper states Forward Email cannot access mailbox contents."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/faq#do-you-support-receiving-email-with-imap",
          "note": "IMAP, POP3, SMTP, CalDAV and CardDAV on every paid plan, with no bridge app."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/private-business-email",
          "note": "Unlimited domains on every plan."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/faq#how-do-i-get-started-and-set-up-email-forwarding",
          "note": "Free forwarding is set up entirely with DNS records, with no account at all. Paid mailboxes need only an email address and password, never a phone number."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "imap.forwardemail.net:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "pop3.forwardemail.net:995 (implicit TLS). CAPA: TOP, UIDL, USER, RESP-CODES, SASL, PIPELINING."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "smtp.forwardemail.net:465 (implicit TLS). SMTPUTF8, 8BITMIME, PIPELINING and AUTH advertised."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "yes",
          "evidence": null,
          "note": "Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/faq#how-do-i-set-up-srs-for-forward-email",
          "note": "Applied automatically to all forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/faq#do-you-support-email-best-practices",
          "note": "ARC chains are validated (RFC 8617) and forwarded mail is ARC-sealed."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:47.512Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "gandi-mail",
      "category": "email-providers",
      "name": "GandiMail",
      "description": "Paid email hosting for custom domains from Gandi, a French domain registrar, with SOGo and Roundcube webmail and standard protocol access.",
      "website": "https://www.gandi.net/en/domain/email",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 34,
      "coverage": 100,
      "summary": "GandiMail scores 34 out of 100 (grade F) on the email providers criteria. It meets 6 of 19 criteria: no ads or data sales, transparency report, open protocols, custom domains, IMAP support and POP3 support. It partly meets TLS configuration, security headers and SMTP submission. It does not meet open source, no trackers or telemetry, independent audit, tells users about requests, end-to-end encryption, encrypted mailbox storage, sign up without personal data, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/email-providers/gandi-mail/",
      "markdown": "https://privacyratings.com/email-providers/gandi-mail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.gandi.net/en/contracts/privacy-policy",
          "note": "The privacy policy lists AT Internet audience-measurement cookies, which can be opted out of."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.gandi.net/en/domain/email",
          "note": "Funded by paid mailbox plans. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published. Gandi states ISO 27001 certification, but no report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.gandi.net/en/digital-service-act-transparency-report",
          "note": "Yearly reports with counts of information requests from authorities and content notices."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=webmail.gandi.net&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=webmail.gandi.net",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Not supported."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Encryption at rest for stored mail is not documented."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.gandi.net/en/gandimail/standard_email_settings/index.html",
          "note": "IMAP, POP3 and SMTP work with any client on every plan."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.gandi.net/en/domain/email",
          "note": "Every mailbox uses your own domain, registered with Gandi or elsewhere."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://account.gandi.net/en/create_account",
          "note": "Creating a Gandi account requires an existing email address, and purchases require contact and payment details."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "mail.gandi.net:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "mail.gandi.net:995 (implicit TLS). CAPA: CAPA, TOP, UIDL, RESP-CODES, PIPELINING, AUTH-RESP-CODE, USER, SASL."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "mail.gandi.net:465 (implicit TLS). Missing: SMTPUTF8."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF. Missing: DMARC none, MTA-STS missing, TLS-RPT, DNSSEC, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": "https://docs.gandi.net/en/gandimail/forwarding_and_aliases/index.html",
          "note": "The forwarding documentation warns that forwarded mail may fail SPF checks, and no SRS is documented."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Trustpilot",
            "host": "www.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:46:34.090Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "gmail",
      "category": "email-providers",
      "name": "Gmail",
      "description": "Google's free email service. Mail is stored and processed on Google's servers, and Google Workspace offers it for business domains.",
      "website": "https://mail.google.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 41,
      "coverage": 100,
      "summary": "Gmail scores 41 out of 100 (grade D) on the email providers criteria. It meets 7 of 19 criteria: transparency report, tells users about requests, security headers, open protocols, IMAP support, POP3 support and SMTP submission. It partly meets independent audit, TLS configuration, encrypted mailbox storage and custom domains. It does not meet open source, no trackers or telemetry, no ads or data sales, end-to-end encryption, sign up without personal data, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/email-providers/gmail/",
      "markdown": "https://privacyratings.com/email-providers/gmail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Google collects activity data across its services and uses it for analytics and personalized ads."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "The free service shows ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cloud.google.com/security/compliance/soc-3",
          "note": "Google Workspace, which includes Gmail, has third-party SOC 2 audits. Only the SOC 3 summary report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://transparencyreport.google.com/user-data/overview",
          "note": "Publishes counts of government requests for user data and how often data is disclosed, updated twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://policies.google.com/terms/information-requests",
          "note": "Google emails the user before disclosing information unless legally prohibited or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mail.google.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mail.google.com",
          "note": "Grade A+ (110/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Personal Gmail accounts have no end-to-end encryption. Client-side encryption and S/MIME are limited to some Google Workspace business plans."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://docs.cloud.google.com/docs/security/encryption/default-encryption",
          "note": "Data is encrypted at rest with keys Google holds."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.google.com/mail/answer/7126229",
          "note": "IMAP and SMTP work with other apps."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://workspace.google.com/pricing",
          "note": "Custom domains require a paid Google Workspace business plan."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://support.google.com/accounts/answer/27441",
          "note": "Sign-up requires a birthday and gender. Adding a phone number is optional in the documented flow."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "imap.gmail.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "pop.gmail.com:995 (implicit TLS). CAPA: USER, RESP-CODES, EXPIRE, LOGIN-DELAY, TOP, UIDL, X-GOOGLE-RICO, SASL."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "smtp.gmail.com:465 (implicit TLS). SMTPUTF8, 8BITMIME, PIPELINING and AUTH advertised."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF, MTA-STS enforce, TLS-RPT. Missing: DMARC none, DNSSEC, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": "https://knowledge.workspace.google.com/admin/security/arc-email-authentication",
          "note": "Google's documentation explains ARC but does not state that Gmail validates or adds ARC seals."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:48.547Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "gmx",
      "category": "email-providers",
      "name": "GMX",
      "description": "Free, ad-supported email service from 1&1 Mail & Media in Germany, with webmail, mobile apps, calendar and cloud storage.",
      "website": "https://www.gmx.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 31,
      "coverage": 100,
      "summary": "GMX scores 31 out of 100 (grade F) on the email providers criteria. It meets 4 of 19 criteria: TLS configuration, open protocols, IMAP support and POP3 support. It partly meets security headers, end-to-end encryption, SMTP submission and mail transport security. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests, encrypted mailbox storage, custom domains, sign up without personal data, Sender Rewriting Scheme and ARC sealing. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/email-providers/gmx/",
      "markdown": "https://privacyratings.com/email-providers/gmx/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.gmx.com/company/privacypolicy/",
          "note": "The website loads Google Tag Manager, and the privacy policy describes usage analysis and interest-based advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.gmx.com/company/privacypolicy/",
          "note": "The free service is funded by advertising, including interest-based ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.gmx.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.gmx.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.gmx.com/security/encryption/",
          "note": "OpenPGP encryption is available through the Mailvelope browser extension and the GMX apps. Not on by default."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Encryption at rest for stored mail is not documented."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.gmx.com/pop-imap/index.html",
          "note": "IMAP, POP3 and SMTP work with other apps once enabled in settings."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Not supported. Addresses use GMX domains."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.gmx.com/company/privacypolicy/",
          "note": "Registration asks for personal data such as name, date of birth and a phone number or contact email address."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "imap.gmx.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "pop.gmx.com:995 (implicit TLS). CAPA: TOP, UIDL, USER, SASL, IMPLEMENTATION."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "mail.gmx.com:465 (implicit TLS). Missing: SMTPUTF8, PIPELINING."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "partial",
          "evidence": null,
          "note": "Passes: SPF, DMARC quarantine, TLS-RPT, DNSSEC, DANE all. Missing: MTA-STS testing."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:46:05.174Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "godaddy-email",
      "category": "email-providers",
      "name": "GoDaddy Email",
      "description": "Business email for custom domains sold by GoDaddy. It runs on Microsoft 365 (Exchange Online), with Outlook webmail and apps.",
      "website": "https://www.godaddy.com/email/professional-business-email",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 39,
      "coverage": 100,
      "summary": "GoDaddy Email scores 39 out of 100 (grade F) on the email providers criteria. It meets 6 of 19 criteria: TLS configuration, open protocols, custom domains, IMAP support, POP3 support and Sender Rewriting Scheme. It partly meets no ads or data sales, transparency report, tells users about requests, encrypted mailbox storage, SMTP submission and ARC sealing. It does not meet open source, no trackers or telemetry, independent audit, security headers, end-to-end encryption, sign up without personal data and mail transport security. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/email-providers/godaddy-email/",
      "markdown": "https://privacyratings.com/email-providers/godaddy-email/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.godaddy.com/legal/agreements/privacy-policy",
          "note": "The privacy policy lists Google Analytics and third-party cookies, web beacons and scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.godaddy.com/legal/agreements/privacy-policy",
          "note": "Funded by paid plans and personal data is not sold, but it is disclosed to marketers and advertisers for personalized advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.godaddy.com/legal/agreements/subpoena-policy",
          "note": "Publishes a subpoena policy for legal requests, but no request counts."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.godaddy.com/legal/agreements/subpoena-policy",
          "note": "Customers are notified of valid civil subpoenas. No notice policy is published for criminal requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.godaddy.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.godaddy.com",
          "note": "Grade F (10/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "No end-to-end encryption. Mail is handled by Microsoft 365 with keys Microsoft holds."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://learn.microsoft.com/en-us/purview/encryption",
          "note": "Microsoft 365 encrypts data at rest with keys Microsoft holds."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/pop3-and-imap4/pop3-and-imap4",
          "note": "IMAP, POP3 and SMTP work through Microsoft 365 servers. SMTP authentication must be turned on per user in the GoDaddy dashboard."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.godaddy.com/email/professional-business-email",
          "note": "The service is built for custom domains on every plan."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.godaddy.com/legal/agreements/privacy-policy",
          "note": "A GoDaddy account and purchase require contact details such as an email address and payment information."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "outlook.office365.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "outlook.office365.com:995 (implicit TLS). CAPA: TOP, UIDL, SASL."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "smtp.office365.com:587 (STARTTLS). SMTPUTF8, 8BITMIME, PIPELINING and AUTH advertised."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF, DMARC reject. Missing: MTA-STS missing, TLS-RPT, DNSSEC, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://learn.microsoft.com/en-us/exchange/reference/sender-rewriting-scheme",
          "note": "Microsoft 365 rewrites the envelope sender with SRS on forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://learn.microsoft.com/en-us/defender-office-365/email-authentication-arc-configure",
          "note": "Microsoft 365 validates ARC chains on inbound mail. ARC sealing of forwarded mail is not documented."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:46:45.233Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "hey",
      "category": "email-providers",
      "name": "HEY",
      "description": "Paid email service from 37signals with a screening-based inbox and its own apps. Works only through the HEY apps, without IMAP or POP3.",
      "website": "https://www.hey.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 32,
      "coverage": 100,
      "summary": "HEY scores 32 out of 100 (grade F) on the email providers criteria. It meets 5 of 19 criteria: no ads or data sales, tells users about requests, TLS configuration, security headers and custom domains. It partly meets independent audit, transparency report, encrypted mailbox storage and mail transport security. It does not meet open source, no trackers or telemetry, end-to-end encryption, open protocols, sign up without personal data, IMAP support, POP3 support, SMTP submission, Sender Rewriting Scheme and ARC sealing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/email-providers/hey/",
      "markdown": "https://privacyratings.com/email-providers/hey/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://37signals.com/policies/privacy",
          "note": "The privacy policy describes web analytics and some third-party cookies for analytics and ad measurement."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.hey.com/faqs/#does-hey-serve-ads-or-sell-my-personal-data",
          "note": "Funded by subscriptions. No ads, and data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.hey.com/security/external-audits/trail-of-bits-june-2020.pdf",
          "note": "Trail of Bits and Doyensec reviewed HEY before launch and the full reports are public, but they are more than three years old."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://37signals.com/policies/privacy",
          "note": "Publishes a policy for government data requests, but no request counts."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://37signals.com/policies/privacy",
          "note": "Affected users are notified before data is disclosed, unless legally prohibited or in some emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.hey.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.hey.com",
          "note": "Grade A+ (120/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.hey.com/security/",
          "note": "Not supported."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.hey.com/security/",
          "note": "Content is encrypted at rest and per field in the database, with keys HEY holds."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.hey.com/faqs/#can-i-check-my-hey-email-with-my-existing-email-app",
          "note": "Only the HEY apps work. IMAP and POP3 are not supported."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.hey.com/domains/",
          "note": "Available with HEY for Domains."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.hey.com/faqs/#what-if-i-forget-my-password",
          "note": "A backup email address is required at sign-up."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Not offered."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Not offered."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Not offered."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "partial",
          "evidence": null,
          "note": "Passes: SPF, DMARC quarantine, MTA-STS enforce, TLS-RPT. Missing: DNSSEC, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:00.423Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "icloud-mail",
      "category": "email-providers",
      "name": "iCloud Mail",
      "description": "Email service included with every Apple Account, with @icloud.com addresses and custom domains for iCloud+ subscribers.",
      "website": "https://www.icloud.com/mail",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 47,
      "coverage": 100,
      "summary": "iCloud Mail scores 47 out of 100 (grade D) on the email providers criteria. It meets 8 of 19 criteria: no trackers or telemetry, no ads or data sales, transparency report, tells users about requests, TLS configuration, security headers, open protocols and custom domains. It partly meets encrypted mailbox storage, IMAP support and SMTP submission. It does not meet open source, independent audit, end-to-end encryption, sign up without personal data, POP3 support, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/email-providers/icloud-mail/",
      "markdown": "https://privacyratings.com/email-providers/icloud-mail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/data/en/device-analytics/",
          "note": "Analytics are only shared with Apple with consent, and iCloud.com loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/en-ww/",
          "note": "Funded by device sales and iCloud+ subscriptions. No ads, and Apple states that it does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/transparency/",
          "note": "Apple publishes counts of government and private party requests twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/law-enforcement-guidelines-us.pdf",
          "note": "Apple notifies customers when their account information is sought, unless prohibited by law or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.icloud.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.icloud.com",
          "note": "Grade A+ (130/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "no",
          "evidence": "https://support.apple.com/en-us/102651",
          "note": "iCloud Mail is not end-to-end encrypted, even with Advanced Data Protection. S/MIME works in Apple Mail."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://support.apple.com/en-us/102651",
          "note": "Mail is encrypted on the server with keys Apple holds."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.apple.com/en-us/102525",
          "note": "IMAP and SMTP work with other apps. POP3 is not supported."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://support.apple.com/en-us/102540",
          "note": "Available with any iCloud+ subscription."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://support.apple.com/en-us/108647",
          "note": "Creating an Apple Account asks for a birth date, an email address and a phone number."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "imap.mail.me.com:993 (implicit TLS). IMAP4rev1 advertised, no IDLE before login."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Not offered."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "smtp.mail.me.com:587 (STARTTLS). SMTPUTF8, 8BITMIME, PIPELINING and AUTH advertised."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF, DMARC quarantine. Missing: MTA-STS missing, TLS-RPT, DNSSEC, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:15.898Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "infomaniak-mail",
      "category": "email-providers",
      "name": "Infomaniak Mail",
      "description": "Email service from Swiss company Infomaniak, with free ik.me addresses and paid hosting for custom domains, plus web and mobile apps.",
      "website": "https://www.infomaniak.com/en/ksuite/service-mail",
      "source": "https://github.com/Infomaniak/android-kMail",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 53,
      "coverage": 100,
      "summary": "Infomaniak Mail scores 53 out of 100 (grade D) on the email providers criteria. It meets 6 of 19 criteria: no ads or data sales, TLS configuration, open protocols, custom domains, IMAP support and POP3 support. It partly meets open source, no trackers or telemetry, transparency report, end-to-end encryption, encrypted mailbox storage, SMTP submission and mail transport security. It does not meet independent audit, tells users about requests, security headers, sign up without personal data, Sender Rewriting Scheme and ARC sealing. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C-.",
      "url": "https://privacyratings.com/email-providers/infomaniak-mail/",
      "markdown": "https://privacyratings.com/email-providers/infomaniak-mail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/Infomaniak/android-kMail/blob/main/LICENSE",
          "note": "The Infomaniak Mail apps are GPL-3.0, but the server is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.infomaniak.mail/latest/",
          "note": "Exodus finds Matomo and Sentry in the Android app. The website uses self-hosted Matomo and ad-measurement tools only with consent."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.infomaniak.com/en/free-email",
          "note": "Funded by paid services. No ads, and data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.infomaniak.com/en/legal/confidentiality-policy",
          "note": "The privacy policy states that data is only disclosed to authorities under a decision valid under Swiss law. No request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=ksuite.infomaniak.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=ksuite.infomaniak.com",
          "note": "Grade C- (45/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.infomaniak.com/en/support/faq/1582/secure-an-email-sending-with-an-encryption-key",
          "note": "Optional OpenPGP encryption with keys stored by Infomaniak, and password-protected mail for outside recipients. Not on by default."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.infomaniak.com/en/support/faq/1582/secure-an-email-sending-with-an-encryption-key",
          "note": "Encrypted messages are stored with keys Infomaniak holds and unlocks at login."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.infomaniak.com/en/support/faq/2430/configure-thunderbird-with-imap-email",
          "note": "IMAP, POP3 and SMTP work with any client."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.infomaniak.com/en/ksuite/service-mail",
          "note": "Available with the paid Mail Service."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.infomaniak.com/en/support/faq/2232/create-an-infomaniak-account",
          "note": "A valid email address is required to verify a new account."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "mail.infomaniak.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "mail.infomaniak.com:995 (implicit TLS). CAPA: LAST, TOP, USER, PIPELINING, UIDL, SASL."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "mail.infomaniak.com:465 (implicit TLS). Missing: SMTPUTF8."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "partial",
          "evidence": null,
          "note": "Passes: SPF, DMARC reject, DNSSEC, DANE all. Missing: MTA-STS missing, TLS-RPT."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:09.134Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "kolab-now",
      "category": "email-providers",
      "name": "Kolab Now",
      "description": "Paid email and groupware service from Apheleia IT in Switzerland, built on the open-source Kolab platform, with calendars, contacts, files and video calls.",
      "website": "https://kolabnow.com",
      "source": "https://git.kolab.org/source/kolab/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 64,
      "coverage": 100,
      "summary": "Kolab Now scores 64 out of 100 (grade C) on the email providers criteria. It meets 10 of 19 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, open protocols, custom domains, IMAP support, POP3 support, SMTP submission and mail transport security. It partly meets transparency report and end-to-end encryption. It does not meet independent audit, tells users about requests, security headers, encrypted mailbox storage, sign up without personal data, Sender Rewriting Scheme and ARC sealing. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/email-providers/kolab-now/",
      "markdown": "https://privacyratings.com/email-providers/kolab-now/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://git.kolab.org/source/kolab/",
          "note": "Runs on the open-source Kolab platform, and the terms state that all software used is free software."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kb.kolabnow.com/documentation/why-kolab-now-is-the-right-thing-for-you",
          "note": "User data is not sold or used for statistical analysis, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kolabnow.com/tos",
          "note": "Funded by subscriptions. No advertising and no sale of personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://kolabnow.com/tos",
          "note": "The terms state that data is only given to third parties with a warrant from a Swiss judge. No request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=kolabnow.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=kolabnow.com",
          "note": "Grade D (35/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://kb.kolabnow.com/documentation/kolab-now-a-guide",
          "note": "PGP encryption can be set up in the webmail settings. Not on by default."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Encryption at rest for stored mail is not documented."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kb.kolabnow.com/documentation/generic-imap-client-setup-guide",
          "note": "IMAP, SMTP, CalDAV and CardDAV work with any client."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://kb.kolabnow.com/faq/what-is-the-price-for-a-kolab-now-subscription",
          "note": "The first custom domain is free and extra domains cost a small monthly fee."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "An existing email address is required to verify a new account."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "imap.kolabnow.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "pop.kolabnow.com:995 (implicit TLS). CAPA: SASL, EXPIRE, LOGIN-DELAY, TOP, UIDL, PIPELINING, RESP-CODES, AUTH-RESP-CODE, USER, IMPLEMENTATION."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "smtp.kolabnow.com:465 (implicit TLS). SMTPUTF8, 8BITMIME, PIPELINING and AUTH advertised."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "yes",
          "evidence": null,
          "note": "Passes: SPF, DMARC quarantine, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:09.063Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "mail-com",
      "category": "email-providers",
      "name": "Mail.com",
      "description": "Free, ad-supported email service from 1&1 Mail & Media, part of United Internet, offering addresses on many domains such as mail.com and email.com. A paid Premium plan adds IMAP, POP3 and phone support.",
      "website": "https://www.mail.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 27,
      "coverage": 100,
      "summary": "Mail.com scores 27 out of 100 (grade F) on the email providers criteria. It meets 4 of 19 criteria: TLS configuration, open protocols, IMAP support and POP3 support. It partly meets security headers, SMTP submission and mail transport security. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests, end-to-end encryption, encrypted mailbox storage, custom domains, sign up without personal data, Sender Rewriting Scheme and ARC sealing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/email-providers/mail-com/",
      "markdown": "https://privacyratings.com/email-providers/mail-com/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.mail.com/company/privacypolicy/",
          "note": "The website loads Google Tag Manager, and the privacy policy allows third-party ad companies to collect data with cookies and web beacons."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.mail.com/company/privacypolicy/",
          "note": "The free service is funded by advertising, including behavioral ads from third-party companies."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.mail.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.mail.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Not supported."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Encryption at rest for stored mail is not documented."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.mail.com/pop-imap/index.html",
          "note": "IMAP, POP3 and SMTP work with other apps on the paid Premium plan. Free accounts cannot use them."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Not supported. Addresses use domains owned by mail.com."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://signup.mail.com/",
          "note": "Registration asks for name and date of birth and requires a recovery email address or mobile number."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "imap.mail.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "pop.mail.com:995 (implicit TLS). CAPA: TOP, UIDL, USER, SASL, IMPLEMENTATION."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "smtp.mail.com:465 (implicit TLS). Missing: SMTPUTF8, PIPELINING."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "partial",
          "evidence": null,
          "note": "Passes: SPF, DMARC quarantine, TLS-RPT, DNSSEC, DANE all. Missing: MTA-STS testing."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:46:37.781Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "mailbox-org",
      "category": "email-providers",
      "name": "mailbox.org",
      "description": "Paid email, calendar and office service from Berlin, Germany, with built-in PGP encryption and support for custom domains.",
      "website": "https://mailbox.org",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 70,
      "coverage": 100,
      "summary": "mailbox.org scores 70 out of 100 (grade C) on the email providers criteria. It meets 11 of 19 criteria: no trackers or telemetry, no ads or data sales, transparency report, TLS configuration, security headers, open protocols, custom domains, sign up without personal data, IMAP support, POP3 support and mail transport security. It partly meets independent audit, end-to-end encryption, encrypted mailbox storage and SMTP submission. It does not meet open source, tells users about requests, Sender Rewriting Scheme and ARC sealing. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/email-providers/mailbox-org/",
      "markdown": "https://privacyratings.com/email-providers/mailbox-org/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. Parts of the underlying software, such as Open-Xchange and Dovecot, are open source, but the service code is not published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://mailbox.org/en/data-protection/",
          "note": "The website uses a self-hosted, cookieless Matomo instance with anonymized data. No third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mailbox.org/en/prices/",
          "note": "Funded by paid plans. No ads and no data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://mailbox.org/en/certified-quality/",
          "note": "Holds ISO 27001 and BSI C5 certifications from independent auditors. The audit reports are not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mailbox.org/en/transparency-report/",
          "note": "Publishes yearly counts of authority requests by type, origin and outcome."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mailbox.org&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mailbox.org",
          "note": "Grade A+ (115/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://mailbox.org/en/security/",
          "note": "PGP and S/MIME are built into the webmail through mailbox Guard, but must be turned on by the user."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://kb.mailbox.org/en/private/encryption/your-encrypted-mailbox/",
          "note": "Incoming mail can optionally be encrypted with the user's own PGP key. This is off by default and sent mail is not encrypted."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kb.mailbox.org/en/private/e-mail/e-mail-configuration/",
          "note": "IMAP, POP3 and SMTP work with any client."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://mailbox.org/en/prices/",
          "note": "Available from the Standard plan up."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kb.mailbox.org/en/private/security-and-privacy/anonymous-new-registration/",
          "note": "A name is required but not verified, so a pseudonym can be used. No phone number is needed."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "imap.mailbox.org:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "pop3.mailbox.org:995 (implicit TLS). CAPA: CAPA, TOP, UIDL, RESP-CODES, PIPELINING, AUTH-RESP-CODE, USER, SASL."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "smtp.mailbox.org:465 (implicit TLS). Missing: SMTPUTF8."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "yes",
          "evidence": null,
          "note": "Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:53.995Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "mailfence",
      "category": "email-providers",
      "name": "Mailfence",
      "description": "Email service from Belgium with built-in OpenPGP encryption and signing, plus calendar, contacts and document storage.",
      "website": "https://mailfence.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "BE",
        "name": "Belgium",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 54,
      "coverage": 100,
      "summary": "Mailfence scores 54 out of 100 (grade D) on the email providers criteria. It meets 8 of 19 criteria: no trackers or telemetry, no ads or data sales, transparency report, TLS configuration, custom domains, IMAP support, POP3 support and mail transport security. It partly meets security headers, end-to-end encryption, open protocols and SMTP submission. It does not meet open source, independent audit, tells users about requests, encrypted mailbox storage, sign up without personal data, Sender Rewriting Scheme and ARC sealing. It is based in Belgium: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/email-providers/mailfence/",
      "markdown": "https://privacyratings.com/email-providers/mailfence/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://mailfence.com/en/privacy.jsp",
          "note": "The privacy policy states that only authentication cookies are used and no Google Analytics or other trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mailfence.com/en/privacy.jsp",
          "note": "Funded by paid plans. No ads, and user data is not sold or shared."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://blog.mailfence.com/transparency-report-and-warrant-canary/",
          "note": "Publishes counts of legal requests and disclosures every six months, with a warrant canary."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mailfence.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mailfence.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://mailfence.com/en/end-to-end-encryption.jsp",
          "note": "OpenPGP and password-protected messages are built into the webmail, but encryption is not on by default."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "no",
          "evidence": "https://mailfence.com/en/threat-model.jsp",
          "note": "Only messages encrypted with OpenPGP stay unreadable on the server. Encryption of other stored mail is not documented."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://mailfence.com/en/faq.jsp",
          "note": "IMAP, POP3 and SMTP need the Entry plan or higher. The free and Base plans are webmail and app only."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://mailfence.com/en/faq.jsp",
          "note": "Available from the Entry plan up."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://mailfence.com/en/privacy.jsp",
          "note": "An existing external email address is required to receive the activation code."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "imap.mailfence.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "pop.mailfence.com:995 (implicit TLS). CAPA: USER, EXPIRE, TOP, UIDL, PIPELINING, RESP-CODES, SASL."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "smtp.mailfence.com:465 (implicit TLS). Missing: SMTPUTF8, PIPELINING."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "yes",
          "evidence": null,
          "note": "Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:26.112Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "migadu",
      "category": "email-providers",
      "name": "Migadu",
      "description": "Swiss email hosting service for custom domains, priced by usage rather than per mailbox, with standard IMAP, POP3 and SMTP access.",
      "website": "https://migadu.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "Migadu scores 38 out of 100 (grade F) on the email providers criteria. It meets 7 of 19 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, open protocols, custom domains, POP3 support and SMTP submission. It partly meets IMAP support. It does not meet open source, independent audit, transparency report, tells users about requests, security headers, end-to-end encryption, encrypted mailbox storage, sign up without personal data, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/email-providers/migadu/",
      "markdown": "https://privacyratings.com/email-providers/migadu/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://migadu.com/privacy/",
          "note": "No tracking or analytics cookies, and no website analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://migadu.com/about/",
          "note": "Funded by paid plans. No ads and no outside investors."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=migadu.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=migadu.com",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "no",
          "evidence": "https://migadu.com/procon/",
          "note": "Not supported. Migadu recommends OpenPGP tools in the mail client."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "no",
          "evidence": "https://migadu.com/procon/",
          "note": "Stored mail is not encrypted. Data is split across disks instead."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://migadu.com/guides/thunderbird/",
          "note": "IMAP, POP3 and SMTP work with any client."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://migadu.com/pricing/",
          "note": "The service is built for custom domains on every plan."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://admin.migadu.com/public/signup",
          "note": "An existing email address is needed to verify the account."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "imap.migadu.com:993 (implicit TLS). IMAP4rev2 advertised, no IDLE before login."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "pop.migadu.com:995 (implicit TLS). CAPA: TOP, UIDL, USER, RESP-CODES, PIPELINING, SASL, AUTH-RESP-CODE, IMPLEMENTATION."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "smtp.migadu.com:465 (implicit TLS). SMTPUTF8, 8BITMIME, PIPELINING and AUTH advertised."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF, DNSSEC. Missing: DMARC missing, MTA-STS missing, TLS-RPT, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:15.166Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "namecheap-private-email",
      "category": "email-providers",
      "name": "Namecheap Private Email",
      "description": "Paid email hosting from Namecheap for custom domains, with webmail, calendar and standard protocol access.",
      "website": "https://www.namecheap.com/hosting/email/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 36,
      "coverage": 100,
      "summary": "Namecheap Private Email scores 36 out of 100 (grade F) on the email providers criteria. It meets 6 of 19 criteria: no ads or data sales, TLS configuration, open protocols, custom domains, IMAP support and POP3 support. It partly meets tells users about requests, security headers, encrypted mailbox storage and SMTP submission. It does not meet open source, no trackers or telemetry, independent audit, transparency report, end-to-end encryption, sign up without personal data, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/email-providers/namecheap-private-email/",
      "markdown": "https://privacyratings.com/email-providers/namecheap-private-email/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.namecheap.com/legal/general/privacy-policy/",
          "note": "The privacy policy allows cookies from partners and tracking companies and sharing pseudonymous data with analytics partners."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.namecheap.com/legal/general/privacy-policy/",
          "note": "Funded by paid plans. The policy states personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.namecheap.com/legal/general/privacy-policy/",
          "note": "The policy says Namecheap may take reasonable steps to notify users of legal process where permitted, with no firm commitment."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=privateemail.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=privateemail.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Not supported."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.namecheap.com/hosting/email/",
          "note": "Stored data is encrypted on the servers, with keys Namecheap holds."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.namecheap.com/support/knowledgebase/article.aspx/1179/2175/general-private-email-configuration-for-mail-clients-and-mobile-devices/",
          "note": "IMAP, POP3 and SMTP work with any client on every plan."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.namecheap.com/hosting/email/",
          "note": "The service is built for custom domains on every plan."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.namecheap.com/myaccount/signup/",
          "note": "A Namecheap account requires a name and an existing email address."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "mail.privateemail.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "mail.privateemail.com:995 (implicit TLS). CAPA: CAPA, TOP, UIDL, RESP-CODES, PIPELINING, AUTH-RESP-CODE, USER, SASL."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "mail.privateemail.com:465 (implicit TLS). Missing: SMTPUTF8."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF, DMARC reject, DNSSEC. Missing: MTA-STS missing, TLS-RPT, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:46:38.634Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "outlook-com",
      "category": "email-providers",
      "name": "Outlook.com",
      "description": "Microsoft's free email service, also used for Hotmail and Live addresses.",
      "website": "https://outlook.live.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 36,
      "coverage": 100,
      "summary": "Outlook.com scores 36 out of 100 (grade F) on the email providers criteria. It meets 6 of 19 criteria: transparency report, tells users about requests, TLS configuration, open protocols, IMAP support and POP3 support. It partly meets security headers, encrypted mailbox storage, custom domains and SMTP submission. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, end-to-end encryption, sign up without personal data, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/email-providers/outlook-com/",
      "markdown": "https://privacyratings.com/email-providers/outlook-com/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "Microsoft collects usage and diagnostic data and uses data about users for personalized advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "The free service shows ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit of Outlook.com is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Publishes counts of government requests for consumer data, including Outlook.com, twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Microsoft gives prior notice to Outlook.com users whose data is requested, except where prohibited by law or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=outlook.live.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=outlook.live.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "No end-to-end encryption. The Encrypt option for Microsoft 365 subscribers uses keys Microsoft holds."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://learn.microsoft.com/en-us/purview/encryption",
          "note": "Data is encrypted at rest with keys Microsoft holds."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.microsoft.com/en-us/outlook/pop-imap-and-smtp-settings-for-outlook-com",
          "note": "IMAP, POP3 and SMTP work with other apps on free and paid accounts."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://learn.microsoft.com/en-us/microsoft-365/admin/setup/add-domain?view=o365-worldwide",
          "note": "Custom domains are supported through Microsoft 365 business plans, not free Outlook.com accounts."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement#mainmicrosoftaccountmodule",
          "note": "Creating a Microsoft account asks for personal data such as a birthdate, and a phone number may be requested for verification."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "outlook.office365.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "outlook.office365.com:995 (implicit TLS). CAPA: TOP, UIDL, SASL."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "smtp-mail.outlook.com:587 (STARTTLS). SMTPUTF8, 8BITMIME, PIPELINING and AUTH advertised."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF, MTA-STS enforce, TLS-RPT, DNSSEC. Missing: DMARC none, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/exchange/reference/sender-rewriting-scheme",
          "note": "Microsoft documents SRS for Microsoft 365 business mail, not for Outlook.com."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC for Outlook.com. Microsoft's ARC documentation covers Microsoft 365 business mail."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:47:04.317Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "posteo",
      "category": "email-providers",
      "name": "Posteo",
      "description": "Paid, ad-free email service from Germany that runs without collecting names or addresses and accepts anonymous payment.",
      "website": "https://posteo.de/en",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 62,
      "coverage": 100,
      "summary": "Posteo scores 62 out of 100 (grade C) on the email providers criteria. It meets 9 of 19 criteria: no trackers or telemetry, no ads or data sales, transparency report, TLS configuration, encrypted mailbox storage, open protocols, sign up without personal data, IMAP support and POP3 support. It partly meets independent audit, security headers, end-to-end encryption and SMTP submission. It does not meet open source, tells users about requests, custom domains, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/email-providers/posteo/",
      "markdown": "https://privacyratings.com/email-providers/posteo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://posteo.de/en/site/encryption",
          "note": "Closed source. The crypto mail storage plugin for Dovecot is published, but the rest of the service code is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://posteo.de/en/site/privacy_policy",
          "note": "The privacy policy states that the website and webmail have no tracking, no Google products and no third-party captchas."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://posteo.de/en/site/privacy_policy",
          "note": "Funded by paid accounts. No ads and no advertising partners."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://posteo.de/en/site/encryption",
          "note": "Cure53 audited the crypto mail storage feature, but the report is not published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://posteo.de/site/transparenzbericht",
          "note": "Publishes yearly counts of authority requests by type, legality and outcome. The German version is the most current."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": "https://posteo.de/en/site/transparency_report",
          "note": "Posteo states that German law does not allow it to inform affected users."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=posteo.de&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=posteo.de",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://posteo.de/en/site/encryption",
          "note": "PGP, S/MIME and password-encrypted mail are built into the webmail, but must be set up by the user."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://posteo.de/en/site/encryption",
          "note": "Optional crypto mail storage encrypts all stored mail with a key protected by the user's password. It is off by default."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://posteo.de/en/help/how-do-i-set-up-posteo-in-an-email-client-pop3-imap-and-smtp",
          "note": "IMAP, POP3 and SMTP work with any client."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "no",
          "evidence": "https://posteo.de/en/site/faq",
          "note": "Posteo does not support custom domains."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://posteo.de/en/site/privacy_policy",
          "note": "No name, address, phone number or other email address is required to register."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "posteo.de:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "posteo.de:995 (implicit TLS). CAPA: CAPA, TOP, UIDL, RESP-CODES, PIPELINING, AUTH-RESP-CODE, USER, SASL."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "posteo.de:465 (implicit TLS). Missing: SMTPUTF8."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all. Missing: DMARC none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:26.442Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "protonmail",
      "category": "email-providers",
      "name": "Proton Mail",
      "description": "End-to-end encrypted email service from Switzerland, with apps for web, Android, iOS and desktop.",
      "website": "https://proton.me/mail",
      "source": "https://github.com/ProtonMail/WebClients",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 64,
      "coverage": 100,
      "summary": "Proton Mail scores 64 out of 100 (grade C) on the email providers criteria. It meets 8 of 19 criteria: no ads or data sales, transparency report, tells users about requests, TLS configuration, end-to-end encryption, encrypted mailbox storage, custom domains and mail transport security. It partly meets open source, no trackers or telemetry, independent audit, security headers, open protocols and sign up without personal data. It does not meet IMAP support, POP3 support, SMTP submission, Sender Rewriting Scheme and ARC sealing. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/email-providers/protonmail/",
      "markdown": "https://privacyratings.com/email-providers/protonmail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/ProtonMail/WebClients/blob/main/LICENSE",
          "note": "Apps are open source under GPL-3.0. The server is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://proton.me/legal/privacy",
          "note": "Website analytics are self-hosted. The apps include crash reporting and usage statistics, which are on by default and can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://proton.me/mail/pricing",
          "note": "No ads on any plan, including the free plan."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://proton.me/blog/soc-2",
          "note": "Proton completed a SOC 2 Type II audit, but the report is not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://proton.me/legal/transparency",
          "note": "Publishes yearly counts of legal orders received, complied with and contested."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://proton.me/legal/law-enforcement",
          "note": "Targeted users are notified of data requests, with delays only when Swiss law, a court order or a risk to life requires it."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=proton.me&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=proton.me",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://proton.me/support/proton-mail-encryption-explained",
          "note": "Always end-to-end encrypted between Proton users. Password-protected messages or PGP for other recipients. Subject lines are not end-to-end encrypted."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://proton.me/support/proton-mail-encryption-explained",
          "note": "Stored mail uses zero-access encryption that Proton cannot read."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://proton.me/support/imap-smtp-and-pop3-setup",
          "note": "IMAP and SMTP need the Proton Mail Bridge app on a paid plan. POP3 is not supported."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://proton.me/mail/pricing",
          "note": "From the Mail Plus plan up. Not on the free plan."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://proton.me/legal/privacy",
          "note": "No personal data is needed by default, but some sign-ups must be verified by email or SMS."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Not offered."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Not offered."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Not offered."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "yes",
          "evidence": null,
          "note": "Passes: SPF, DMARC quarantine, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:21.987Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "purelymail",
      "category": "email-providers",
      "name": "Purelymail",
      "description": "Low-cost email hosting from the United States with custom domains, standard protocols and mail stored encrypted with the user's password.",
      "website": "https://purelymail.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 55,
      "coverage": 100,
      "summary": "Purelymail scores 55 out of 100 (grade D) on the email providers criteria. It meets 8 of 19 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, encrypted mailbox storage, open protocols, custom domains, sign up without personal data and IMAP support. It partly meets security headers, POP3 support, SMTP submission and mail transport security. It does not meet open source, independent audit, transparency report, tells users about requests, end-to-end encryption, Sender Rewriting Scheme and ARC sealing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/email-providers/purelymail/",
      "markdown": "https://privacyratings.com/email-providers/purelymail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://purelymail.com/privacy",
          "note": "The privacy policy lists only diagnostic and billing data, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://purelymail.com/docs/security",
          "note": "Funded by paid plans. Purelymail states it will never sell or monetize user data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=purelymail.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=purelymail.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "no",
          "evidence": "https://purelymail.com/docs/security",
          "note": "Not supported. Purelymail suggests S/MIME in the mail client."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://purelymail.com/docs/security",
          "note": "Mail is encrypted with a key derived from the user's password when password reset is turned off. Search indexes may hold partial content."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://purelymail.com/docs/setup/technical",
          "note": "IMAP, POP3 and SMTP work with any client."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://purelymail.com/docs/features",
          "note": "Unlimited custom domains at no extra charge."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://purelymail.com/signup/",
          "note": "Recovery email and phone are optional for paid sign-ups. Only the free trial needs an SMS-capable phone."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "imap.purelymail.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "partial",
          "evidence": null,
          "note": "pop3.purelymail.com:995 (implicit TLS). CAPA: PIPELINING, USER, STLS."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "smtp.purelymail.com:465 (implicit TLS). Missing: SMTPUTF8."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "partial",
          "evidence": null,
          "note": "Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT. Missing: DNSSEC, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:10.782Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "riseup",
      "category": "email-providers",
      "name": "Riseup",
      "description": "Email, mailing list and VPN service run by an autonomous tech collective in Seattle for activists and social movements. Accounts need an invite, and the service is funded by donations.",
      "website": "https://riseup.net",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 59,
      "coverage": 100,
      "summary": "Riseup scores 59 out of 100 (grade D) on the email providers criteria. It meets 9 of 19 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, encrypted mailbox storage, open protocols, sign up without personal data, IMAP support, POP3 support and SMTP submission. It partly meets open source, transparency report and security headers. It does not meet independent audit, tells users about requests, end-to-end encryption, custom domains, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/email-providers/riseup/",
      "markdown": "https://privacyratings.com/email-providers/riseup/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://0xacab.org/riseuplabs",
          "note": "The service runs on free software and some of Riseup's own tools are published, but the full service setup is not public."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://riseup.net/en/about-us/policy/privacy-policy",
          "note": "No third-party cookies or tracking of any kind, and no IP addresses are kept."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://riseup.net/en/donate",
          "note": "Funded by donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://riseup.net/en/canary",
          "note": "Publishes a signed warrant canary updated four times a year, but no request counts."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=riseup.net&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=riseup.net",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "No built-in end-to-end encryption. OpenPGP only works in third-party apps."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://riseup.net/en/email",
          "note": "Mail is stored encrypted per user and can only be unlocked with the user's password. Older accounts must opt in."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://riseup.net/en/email/clients",
          "note": "IMAP, POP3 and SMTP work with any client."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Not supported. Addresses use riseup.net."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://riseup.net/en/about-us/policy/privacy-policy",
          "note": "Sign-up needs an invite code, but no phone number or email address. A reset email is optional."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "mail.riseup.net:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "mail.riseup.net:995 (implicit TLS). CAPA: CAPA, TOP, UIDL, RESP-CODES, PIPELINING, AUTH-RESP-CODE, USER, SASL."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "mail.riseup.net:465 (implicit TLS). SMTPUTF8, 8BITMIME, PIPELINING and AUTH advertised."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all. Missing: DMARC none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:12.632Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "runbox",
      "category": "email-providers",
      "name": "Runbox",
      "description": "Paid email service from Norway with custom domain hosting, standard protocols and an open-source webmail app.",
      "website": "https://runbox.com",
      "source": "https://github.com/runbox/runbox7",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "NO",
        "name": "Norway",
        "eyes": "Nine Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 49,
      "coverage": 100,
      "summary": "Runbox scores 49 out of 100 (grade D) on the email providers criteria. It meets 7 of 18 criteria: no trackers or telemetry, no ads or data sales, transparency report, open protocols, custom domains, IMAP support and POP3 support. It partly meets open source, end-to-end encryption and SMTP submission. It does not meet independent audit, tells users about requests, security headers, encrypted mailbox storage, sign up without personal data, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in Norway: Nine Eyes member; EEA member (GDPR). Automated tests: Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/email-providers/runbox/",
      "markdown": "https://privacyratings.com/email-providers/runbox/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/runbox/runbox7/blob/master/LICENSE",
          "note": "The Runbox 7 webmail app is open source under GPL-3.0. The server components are not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://runbox.com/about/privacy-policy/",
          "note": "The privacy policy states that no third-party tracking, statistics or web beacons are used."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://runbox.com/about/privacy-policy/",
          "note": "Funded by paid plans. No ads, and user data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://runbox.com/features/privacy-security/transparency-report/",
          "note": "Publishes yearly counts of disclosure requests received, complied with and rejected."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Could not test: No endpoint could be graded"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=runbox.com",
          "note": "Grade D- (25/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://help.runbox.com/encrypting-your-runbox-email/",
          "note": "PGP and S/MIME work in desktop clients or in the webmail with browser extensions such as Mailvelope. Not built in."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Encryption of stored mail is not documented."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://help.runbox.com/email-program-settings/",
          "note": "IMAP, POP3 and SMTP work with any client."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://runbox.com/pricing/",
          "note": "Every plan includes at least one custom domain."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://runbox.com/about/privacy-policy/",
          "note": "Registration asks for a name, country and an alternative email address."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "mail.runbox.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "mail.runbox.com:995 (implicit TLS). CAPA: TOP, USER, UIDL, SASL."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "mail.runbox.com:465 (implicit TLS). Missing: SMTPUTF8."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF, DMARC quarantine, TLS-RPT, DNSSEC. Missing: MTA-STS testing, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:51.555Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "startmail",
      "category": "email-providers",
      "name": "StartMail",
      "description": "Paid email service from the Netherlands with built-in PGP encryption, unlimited aliases and custom domains.",
      "website": "https://www.startmail.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 66,
      "coverage": 100,
      "summary": "StartMail scores 66 out of 100 (grade C) on the email providers criteria. It meets 10 of 19 criteria: no ads or data sales, transparency report, TLS configuration, encrypted mailbox storage, open protocols, custom domains, sign up without personal data, IMAP support, SMTP submission and mail transport security. It partly meets no trackers or telemetry, security headers and end-to-end encryption. It does not meet open source, independent audit, tells users about requests, POP3 support, Sender Rewriting Scheme and ARC sealing. It is based in the Netherlands: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/email-providers/startmail/",
      "markdown": "https://privacyratings.com/email-providers/startmail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.startmail.com/privacy",
          "note": "No third-party tracking or advertising data sharing, but website analytics use self-hosted Matomo, which sets cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.startmail.com/pricing",
          "note": "Funded by paid plans. No ads and no data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.startmail.com/transparency",
          "note": "Publishes yearly counts of legal orders processed and what information was provided."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.startmail.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.startmail.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.startmail.com/encrypted-email",
          "note": "PGP and password-protected messages are built into the webmail, but encryption is chosen per message."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.startmail.com/whitepaper",
          "note": "All mail is stored in an encrypted User Vault that opens only with the account password or a recovery key."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.startmail.com/hc/en-us/articles/360006596718-Server-addresses",
          "note": "IMAP and SMTP work with any client. POP3 is not supported."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.startmail.com/pricing",
          "note": "The Personal plan includes one custom domain. The Business plan allows unlimited domains."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.startmail.com/privacy",
          "note": "A name and recovery email address are optional. Sign-up uses an hCaptcha check."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "imap.startmail.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Not offered."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "smtp.startmail.com:465 (implicit TLS). SMTPUTF8, 8BITMIME, PIPELINING and AUTH advertised."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "yes",
          "evidence": null,
          "note": "Passes: SPF, DMARC quarantine, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:24.361Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "titan",
      "category": "email-providers",
      "name": "Titan",
      "description": "Business email service for custom domains, sold through hosting and domain providers rather than directly. Includes webmail, mobile apps and a free plan with fewer features.",
      "website": "https://titan.email",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "KY",
        "name": "Cayman Islands",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 31,
      "coverage": 100,
      "summary": "Titan scores 31 out of 100 (grade F) on the email providers criteria. It meets 5 of 19 criteria: no ads or data sales, TLS configuration, open protocols, custom domains and POP3 support. It partly meets transparency report, security headers, IMAP support and SMTP submission. It does not meet open source, no trackers or telemetry, independent audit, tells users about requests, end-to-end encryption, encrypted mailbox storage, sign up without personal data, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in the Cayman Islands: Not in the Five, Nine or Fourteen Eyes. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/email-providers/titan/",
      "markdown": "https://privacyratings.com/email-providers/titan/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://support.titan.email/hc/en-us/articles/360038535773-Titan-Privacy-Policy",
          "note": "The website loads Google Tag Manager, and the privacy policy allows third-party cookies to track visitor behavior."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.titan.email/hc/en-us/articles/360038535773-Titan-Privacy-Policy",
          "note": "Funded by paid plans sold through partners. The privacy policy states cookie data is not sold or shared with third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.titan.email/hc/en-us/articles/52034516413977-Submit-a-Legal-Request",
          "note": "Publishes a policy for legal requests, but no request counts."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.titan.email&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.titan.email",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Not supported."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Encryption at rest for stored mail is not documented beyond a general claim that messages are encrypted."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.titan.email/hc/en-us/articles/900000215446-Configure-Titan-on-other-apps-using-IMAP-POP",
          "note": "IMAP, POP3 and SMTP work with other apps once third-party access is turned on in settings."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://support.titan.email/hc/en-us/articles/26786062519321-Titan-Email-Pricing",
          "note": "The service is built for custom domains and is sold through domain and hosting partners."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://support.titan.email/hc/en-us/articles/26786062519321-Titan-Email-Pricing",
          "note": "Titan is only sold through partner providers, which require an account with personal contact details."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "imap.titan.email:993 (implicit TLS). IMAP4rev1 advertised, no IDLE before login."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "pop.titan.email:995 (implicit TLS). CAPA: CAPA, USER, UIDL, TOP, RESP-CODES, LOGIN-DELAY, EXPIRE, SASL."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "smtp.titan.email:465 (implicit TLS). Missing: SMTPUTF8."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF, DMARC reject. Missing: MTA-STS missing, TLS-RPT, DNSSEC, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          },
          {
            "name": "WordPress.com Stats",
            "host": "stats.wp.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:46:40.071Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "tuta",
      "category": "email-providers",
      "name": "Tuta",
      "description": "End-to-end encrypted email and calendar service from Germany, with open-source apps for web, desktop and mobile.",
      "website": "https://tuta.com",
      "source": "https://github.com/tutao/tutanota",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 61,
      "coverage": 100,
      "summary": "Tuta scores 61 out of 100 (grade C) on the email providers criteria. It meets 9 of 18 criteria: no trackers or telemetry, no ads or data sales, transparency report, security headers, end-to-end encryption, encrypted mailbox storage, custom domains, sign up without personal data and mail transport security. It partly meets open source. It does not meet independent audit, tells users about requests, open protocols, IMAP support, POP3 support, SMTP submission, Sender Rewriting Scheme and ARC sealing. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/email-providers/tuta/",
      "markdown": "https://privacyratings.com/email-providers/tuta/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/tutao/tutanota/blob/master/LICENSE.txt",
          "note": "Apps are open source under GPL-3.0. The server is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://tuta.com/privacy-policy",
          "note": "No Google Analytics or other third-party analysis tools. Anonymized usage statistics are collected only with prior consent."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tuta.com/pricing",
          "note": "Funded by paid plans. No ads on any plan, including the free plan."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tuta.com/blog/transparency-report",
          "note": "Publishes counts of requests by type and how many led to data being released."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Could not test: No endpoint could be graded"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=tuta.com",
          "note": "Grade A+ (105/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://tuta.com/encryption",
          "note": "Mail between Tuta users is always end-to-end encrypted, including subject lines. Password-protected mail is available for other recipients."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://tuta.com/encryption",
          "note": "The whole mailbox, including the search index, is encrypted with keys only the user holds."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "no",
          "evidence": "https://tuta.com/blog/desktop-clients-tutanota#security-first-approach-no-imap-no-compromises",
          "note": "No IMAP, POP3 or SMTP access. Mail can only be used in Tuta's own apps."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://tuta.com/pricing",
          "note": "Available on paid plans from Revolutionary up."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tuta.com/blog/anonymous-email",
          "note": "No phone number or other email address is needed to register."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Not offered."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Not offered."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Not offered."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "yes",
          "evidence": null,
          "note": "Passes: SPF, DMARC quarantine, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:41.134Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "yahoo-mail",
      "category": "email-providers",
      "name": "Yahoo Mail",
      "description": "Free, ad-supported email service from Yahoo with webmail and mobile apps. A paid Yahoo Mail Plus plan removes ads.",
      "website": "https://mail.yahoo.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Yahoo Mail scores 30 out of 100 (grade F) on the email providers criteria. It meets 6 of 19 criteria: transparency report, tells users about requests, TLS configuration, open protocols, IMAP support and POP3 support. It partly meets SMTP submission. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, security headers, end-to-end encryption, encrypted mailbox storage, custom domains, sign up without personal data, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B-.",
      "url": "https://privacyratings.com/email-providers/yahoo-mail/",
      "markdown": "https://privacyratings.com/email-providers/yahoo-mail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://legal.yahoo.com/us/en/yahoo/privacy/index.html",
          "note": "Yahoo Mail loads Yahoo analytics and a consent platform for advertising partners, and the privacy policy covers ad targeting across services."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://legal.yahoo.com/us/en/yahoo/privacy/index.html",
          "note": "The free service shows ads. Yahoo Mail Plus removes them."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit report is published. Yahoo states its controls are assessed by an external auditor, but no report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.yahooinc.com/transparency/",
          "note": "Publishes counts of government data requests by country and how they were answered."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.yahooinc.com/transparency/about/global-principles.html",
          "note": "Yahoo notifies users about third-party requests for their information before disclosure, unless prohibited by law."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mail.yahoo.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mail.yahoo.com",
          "note": "Grade B- (65/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Not supported."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Encryption at rest for stored mail is not documented."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://help.yahoo.com/kb/SLN4075.html",
          "note": "IMAP, POP3 and SMTP work with other apps."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Not available for Yahoo Mail accounts."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://help.yahoo.com/kb/SLN2056.html",
          "note": "Sign-up requires a date of birth and a verified mobile number."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "imap.mail.yahoo.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "pop.mail.yahoo.com:995 (implicit TLS). CAPA: IMPLEMENTATION, EXPIRE-NEVER, PIPELINING, RESP-CODES, TOP, UIDL, USER, SASL."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "smtp.mail.yahoo.com:465 (implicit TLS). Missing: SMTPUTF8."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF, DMARC reject, TLS-RPT. Missing: MTA-STS testing, DNSSEC, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:46:46.496Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "yandex-mail",
      "category": "email-providers",
      "name": "Yandex Mail",
      "description": "Free, ad-supported email service from Yandex in Russia, part of Yandex 360 with calendar and cloud storage. Custom domains are available through Yandex 360 for Business.",
      "website": "https://360.yandex.com/mail/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "RU",
        "name": "Russia",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 26,
      "coverage": 100,
      "summary": "Yandex Mail scores 26 out of 100 (grade F) on the email providers criteria. It meets 4 of 19 criteria: transparency report, open protocols, IMAP support and POP3 support. It partly meets TLS configuration, custom domains and SMTP submission. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, tells users about requests, security headers, end-to-end encryption, encrypted mailbox storage, sign up without personal data, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in Russia: Not in the Five, Nine or Fourteen Eyes. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/email-providers/yandex-mail/",
      "markdown": "https://privacyratings.com/email-providers/yandex-mail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://yandex.com/legal/confidential/en/",
          "note": "The privacy policy covers analytics and third-party tracking and advertising cookies used across Yandex services."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://yandex.com/legal/confidential/en/",
          "note": "The free service shows ads, and the privacy policy describes personalizing ads based on user data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://yandex.com/company/privacy/transparencyreport",
          "note": "Publishes twice-yearly counts of government data requests, including for Mail, and how many were refused."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": "https://yandex.com/company/privacy/transparencyreport",
          "note": "Yandex states it does not notify users about data requests, citing legal prohibitions in Russia and other countries."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mail.yandex.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mail.yandex.com",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Not supported."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Encryption at rest for stored mail is not documented."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://yandex.com/support/yandex-360/customers/mail/en/mail-clients/others",
          "note": "IMAP and SMTP work with other apps once enabled in settings, using an app password. POP3 is also offered but not maintained."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://yandex.com/support/yandex-360/business/admin/en/domains/",
          "note": "Custom domains require a Yandex 360 for Business organization."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://yandex.com/support/id/en/authorization/registration",
          "note": "Registration requires a phone number or another email address."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "imap.yandex.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "pop.yandex.com:995 (implicit TLS). CAPA: STLS, TOP, USER, LOGIN-DELAY, PIPELINING, EXPIRE, UIDL, RESP-CODE, AUTH-RESP-CODE, IMPLEMENTATION."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "smtp.yandex.com:465 (implicit TLS). Missing: SMTPUTF8."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF. Missing: DMARC none, MTA-STS missing, TLS-RPT, DNSSEC, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Yandex Metrica",
            "host": "mc.yandex.ru",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:46:48.819Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "zoho-mail",
      "category": "email-providers",
      "name": "Zoho Mail",
      "description": "Email service from Zoho for businesses and individuals, with custom domains, calendar and contacts, and an ad-free free plan.",
      "website": "https://www.zoho.com/mail/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "IN",
        "name": "India",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "Zoho Mail scores 45 out of 100 (grade D) on the email providers criteria. It meets 7 of 19 criteria: no ads or data sales, TLS configuration, security headers, open protocols, custom domains, IMAP support and POP3 support. It partly meets no trackers or telemetry, end-to-end encryption, encrypted mailbox storage and SMTP submission. It does not meet open source, independent audit, transparency report, tells users about requests, sign up without personal data, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in India: Not in the Five, Nine or Fourteen Eyes. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/email-providers/zoho-mail/",
      "markdown": "https://privacyratings.com/email-providers/zoho-mail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.zoho.com/privacy.html",
          "note": "Zoho states it blocks non-essential third-party cookies on its sites and mostly uses first-party cookies for analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.zoho.com/privacy.html",
          "note": "Funded by paid plans. Zoho states that it never shows ads or sells data, including on free plans."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mail.zoho.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mail.zoho.com",
          "note": "Grade A+ (110/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.zoho.com/mail/secure-email.html",
          "note": "S/MIME and OpenPGP encryption are available but not on by default."
        },
        "encrypted_storage": {
          "title": "Encrypted mailbox storage",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.zoho.com/mail/secure-email.html",
          "note": "Mail is encrypted at rest with keys Zoho holds."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.zoho.com/mail/help/imap-access.html",
          "note": "IMAP, POP3 and SMTP work on paid plans. New free accounts have no IMAP or POP3."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.zoho.com/mail/zohomail-pricing.html",
          "note": "Available on every plan, including the free one."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.zoho.com/privacy.html",
          "note": "Sign-up asks for a name, contact number and email address."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "imap_standards": {
          "title": "IMAP support",
          "weight": 2,
          "answer": "yes",
          "evidence": null,
          "note": "imap.zoho.com:993 (implicit TLS). IMAP4rev1 advertised with IDLE."
        },
        "pop3_standards": {
          "title": "POP3 support",
          "weight": 1,
          "answer": "yes",
          "evidence": null,
          "note": "pop.zoho.com:995 (implicit TLS). CAPA: USER, TOP, UIDL, SASL."
        },
        "smtp_standards": {
          "title": "SMTP submission",
          "weight": 2,
          "answer": "partial",
          "evidence": null,
          "note": "smtp.zoho.com:465 (implicit TLS). Missing: SMTPUTF8, 8BITMIME, PIPELINING."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF, DMARC reject, TLS-RPT. Missing: MTA-STS missing, DNSSEC, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:15.954Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "33mail",
      "category": "email-forwarding",
      "name": "33mail",
      "description": "Email alias service that creates addresses on a personal 33mail.com subdomain or a custom domain and forwards mail to an existing inbox, with anonymous replies.",
      "website": "https://www.33mail.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "IE",
        "name": "Ireland",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 9,
      "coverage": 100,
      "summary": "33mail scores 9 out of 100 (grade F) on the email forwarding and aliases criteria. It meets 1 of 16 criteria: custom domains. It partly meets transparency report and TLS configuration. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, tells users about requests, security headers, end-to-end encryption, no stored mail, open protocols, sign up without personal data, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in Ireland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/email-forwarding/33mail/",
      "markdown": "https://privacyratings.com/email-forwarding/33mail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.33mail.com",
          "note": "The website loads Google Analytics and the Facebook SDK."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.33mail.com/tos",
          "note": "Short ads may be added to forwarded mail on the free plan. Paid plans remove them."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.33mail.com/tos",
          "note": "The terms state that data is shared with law enforcement when required, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.33mail.com&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.33mail.com",
          "note": "Grade F (0/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Not supported. Forwarded mail is not encrypted end to end."
        },
        "no_mail_storage": {
          "title": "No stored mail",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "No published information on whether forwarded mail is stored."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.33mail.com/faq",
          "note": "No IMAP or SMTP access. Mail is forwarded to an existing inbox and replies go through anonymous reply addresses."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.33mail.com/pricing",
          "note": "Available on the low-cost Premium plan and up."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "An existing email address is required to receive forwarded mail."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF. Missing: DMARC missing, MTA-STS missing, TLS-RPT, DNSSEC, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cookiebot",
            "host": "consent.cookiebot.com",
            "effect": "none"
          },
          {
            "name": "Facebook SDK",
            "host": "connect.facebook.net",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Meta Pixel",
            "host": "www.facebook.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:46:16.120Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "addy",
      "category": "email-forwarding",
      "name": "Addy",
      "description": "Open-source email alias service that forwards mail from unlimited aliases to real mailboxes, with optional OpenPGP encryption. Has a free plan and can be self-hosted.",
      "website": "https://addy.io",
      "source": "https://github.com/anonaddy/anonaddy",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 58,
      "coverage": 100,
      "summary": "Addy scores 58 out of 100 (grade D) on the email forwarding and aliases criteria. It meets 7 of 16 criteria: open source, no trackers or telemetry, no ads or data sales, security headers, no stored mail, custom domains and mail transport security. It partly meets TLS configuration, end-to-end encryption and ARC sealing. It does not meet independent audit, transparency report, tells users about requests, open protocols, sign up without personal data and Sender Rewriting Scheme. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/email-forwarding/addy/",
      "markdown": "https://privacyratings.com/email-forwarding/addy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/anonaddy/anonaddy/blob/master/LICENSE.md",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://addy.io/faq/#why-should-i-use-this-instead-of-a-similar-service",
          "note": "No analytics or trackers, only server access logs, and no third-party content."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://addy.io/privacy/",
          "note": "Funded by paid plans. No ads, and personal information is never sold or shared."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=addy.io&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=addy.io",
          "note": "Grade A+ (120/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://addy.io/faq/#are-forwarded-emails-signed-when-encryption-is-enabled",
          "note": "Forwarded mail can be encrypted with the user's own OpenPGP key. Not on by default."
        },
        "no_mail_storage": {
          "title": "No stored mail",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://addy.io/faq/#do-you-store-emails",
          "note": "Mail is not stored. Failed deliveries are kept only if the user turns that option on."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "no",
          "evidence": "https://addy.io/faq/#do-you-provide-smtp-credentials-for-aliases",
          "note": "No IMAP or SMTP access. Mail is forwarded to an existing mailbox and replies go through the alias."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://addy.io/#pricing",
          "note": "From the Lite plan up."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "An existing email address is required to create an account and receive forwarded mail."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "yes",
          "evidence": null,
          "note": "Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 2,
          "answer": "no",
          "evidence": "https://github.com/anonaddy/anonaddy/blob/master/app/Mail/ForwardEmail.php",
          "note": "No SRS. Forwarded mail is re-sent with a VERP return address on addy.io's domain."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://github.com/anonaddy/anonaddy/blob/master/SELF-HOSTING.md",
          "note": "The documented setup adds ARC signatures with Rspamd. Validation of inbound ARC chains is not documented."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:27.561Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "cloudflare-email-routing",
      "category": "email-forwarding",
      "name": "Cloudflare Email Routing",
      "description": "Free Cloudflare service that forwards mail sent to addresses on a custom domain to existing inboxes or to Cloudflare Workers.",
      "website": "https://www.cloudflare.com/products/email-routing/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 48,
      "coverage": 100,
      "summary": "Cloudflare Email Routing scores 48 out of 100 (grade D) on the email forwarding and aliases criteria. It meets 7 of 15 criteria: no ads or data sales, transparency report, tells users about requests, TLS configuration, no stored mail, custom domains and Sender Rewriting Scheme. It partly meets security headers and ARC sealing. It does not meet open source, no trackers or telemetry, independent audit, end-to-end encryption, open protocols and sign up without personal data. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/email-forwarding/cloudflare-email-routing/",
      "markdown": "https://privacyratings.com/email-forwarding/cloudflare-email-routing/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.cloudflare.com/privacypolicy/",
          "note": "The website loads Google Tag Manager and uses cookies for interest-based advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.cloudflare.com/privacypolicy/",
          "note": "Funded by paid Cloudflare plans. The privacy policy states that personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published. Compliance reports are only available to customers."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.cloudflare.com/transparency/",
          "note": "Publishes counts of legal requests and how they were handled twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://cf-assets.www.cloudflare.com/slt3lc6tev37/zItVXCvbb4LZpYG4Uh10R/7b27bba39755f0a4344acb946977704d/2H_2025_Cloudflare_s_Transparency_Report_Legal-v2.pdf",
          "note": "Customers are notified of legal requests for their information unless legally prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=dash.cloudflare.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=dash.cloudflare.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Not supported. Forwarded mail is not encrypted end to end."
        },
        "no_mail_storage": {
          "title": "No stored mail",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.cloudflare.com/products/email-routing/",
          "note": "Cloudflare states that Email Routing does not store or access email content."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No IMAP access. Mail is forwarded to existing inboxes, and SMTP sending belongs to the separate Email Sending product."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developers.cloudflare.com/email-service/",
          "note": "Works only with custom domains and is free on all plans."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "A Cloudflare account with an existing email address is required."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "No mail domain to test."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://developers.cloudflare.com/email-service/reference/postmaster/#sender-rewriting",
          "note": "The envelope sender of forwarded mail is rewritten with SRS."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developers.cloudflare.com/email-service/reference/postmaster/#authenticated-received-chain-arc",
          "note": "ARC is supported for forwarded mail. Validation of inbound ARC chains is not documented."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:31:58.587Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "duckduckgo-email-protection",
      "category": "email-forwarding",
      "name": "DuckDuckGo Email Protection",
      "description": "Free email alias service from DuckDuckGo that gives out @duck.com addresses and forwards mail to an existing inbox after removing email trackers.",
      "website": "https://duckduckgo.com/email/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 34,
      "coverage": 100,
      "summary": "DuckDuckGo Email Protection scores 34 out of 100 (grade F) on the email forwarding and aliases criteria. It meets 3 of 16 criteria: no trackers or telemetry, TLS configuration and no stored mail. It partly meets open source, no ads or data sales and security headers. It does not meet independent audit, transparency report, tells users about requests, end-to-end encryption, open protocols, custom domains, sign up without personal data, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/email-forwarding/duckduckgo-email-protection/",
      "markdown": "https://privacyratings.com/email-forwarding/duckduckgo-email-protection/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/duckduckgo/duckduckgo-privacy-extension/blob/main/LICENSE.md",
          "note": "The DuckDuckGo browser extension that creates Duck Addresses is Apache-2.0, but the forwarding service is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://duckduckgo.com/privacy",
          "note": "The privacy policy states that DuckDuckGo does not track users, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://duckduckgo.com/duckduckgo-help-pages/company/how-duckduckgo-makes-money",
          "note": "Email Protection is free and shows no ads. DuckDuckGo is funded by search ads based on the search query rather than user profiles."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=duckduckgo.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=duckduckgo.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Not supported. Forwarded mail is not encrypted end to end."
        },
        "no_mail_storage": {
          "title": "No stored mail",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://duckduckgo.com/email/privacy",
          "note": "Mail is processed in memory to remove trackers and forwarded without being written to disk."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No IMAP or SMTP access. Mail is forwarded to an existing inbox and replies go through the Duck Address."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Not supported. Addresses are on duck.com."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://duckduckgo.com/email/privacy",
          "note": "An existing email address is required to receive forwarded mail."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF, DMARC quarantine, TLS-RPT. Missing: MTA-STS missing, DNSSEC, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:20.945Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "firefox-private-relay",
      "category": "email-forwarding",
      "name": "Firefox Private Relay",
      "description": "Email masking service from Mozilla that creates aliases and forwards mail to a real inbox. Works on the web and through a Firefox add-on.",
      "website": "https://relay.firefox.com",
      "source": "https://github.com/mozilla/fx-private-relay",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 33,
      "coverage": 100,
      "summary": "Firefox Private Relay scores 33 out of 100 (grade F) on the email forwarding and aliases criteria. It meets 4 of 16 criteria: open source, no ads or data sales, transparency report and tells users about requests. It partly meets TLS configuration and no stored mail. It does not meet no trackers or telemetry, independent audit, security headers, end-to-end encryption, open protocols, custom domains, sign up without personal data, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade C+.",
      "url": "https://privacyratings.com/email-forwarding/firefox-private-relay/",
      "markdown": "https://privacyratings.com/email-forwarding/firefox-private-relay/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mozilla/fx-private-relay/blob/main/LICENSE",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/mozilla/fx-private-relay/blob/main/METRICS.md",
          "note": "The Relay website and extension use Google Analytics unless the browser sends Do Not Track."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://relay.firefox.com/premium/",
          "note": "Funded by the Premium subscription. Relay shows no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.mozilla.org/en-US/about/policy/transparency/",
          "note": "Mozilla publishes counts of government and legal requests for user data twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.mozilla.org/en-US/about/policy/transparency/",
          "note": "Mozilla notifies affected users of requests unless legally prohibited, and after any required delay ends."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=relay.firefox.com&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=relay.firefox.com",
          "note": "Grade C+ (60/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Not supported. Relay has no PGP or other end-to-end encryption for forwarded mail."
        },
        "no_mail_storage": {
          "title": "No stored mail",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.mozilla.org/en-US/privacy/subscription-services/#relay",
          "note": "Mail is not stored after delivery. Undeliverable mail is kept for up to three days."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No IMAP or SMTP access. Mail is forwarded to an existing inbox and replies go through the mask."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "no",
          "evidence": "https://relay.firefox.com/premium/",
          "note": "Own domains are not supported. Premium offers a custom subdomain of mozmail.com."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "A Mozilla account with an existing email address is required."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF, DMARC quarantine. Missing: MTA-STS missing, TLS-RPT, DNSSEC, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "C+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:26.630Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "forward-email",
      "category": "email-forwarding",
      "name": "Forward Email",
      "description": "Email forwarding and alias service for custom domains. Mail is forwarded in memory to existing mailboxes or webhooks, with optional OpenPGP encryption, and paid plans add SMTP sending and encrypted IMAP mailboxes.",
      "website": "https://forwardemail.net",
      "source": "https://github.com/forwardemail/forwardemail.net",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": "Privacy Ratings is maintained by the team behind Forward Email. This entry is scored by the same criteria as every other entry in this category, and changes to it are reviewed under the published conflict-of-interest rules.",
      "grade": "B",
      "score": 86,
      "coverage": 100,
      "summary": "Forward Email scores 86 out of 100 (grade B) on the email forwarding and aliases criteria. It meets 12 of 16 criteria: open source, no ads or data sales, independent audit, tells users about requests, TLS configuration, security headers, no stored mail, open protocols, custom domains, mail transport security, Sender Rewriting Scheme and ARC sealing. It partly meets no trackers or telemetry, transparency report, end-to-end encryption and sign up without personal data. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/email-forwarding/forward-email/",
      "markdown": "https://privacyratings.com/email-forwarding/forward-email/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/forwardemail/forwardemail.net/blob/master/LICENSE.md",
          "note": "All code is public, including the MX forwarding servers that run the service. Core mail storage and protocol code is MPL-2.0 and the rest is under the source-available Business Source License 1.1 (BUSL-1.1), which becomes MPL-2.0 four years after each release."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://forwardemail.net/en/privacy#analytics",
          "note": "No third-party analytics. First-party anonymized analytics of page views and service usage is on by default, and Cloudflare Turnstile loads on sign-in and sign-up forms."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/private-business-email",
          "note": "Funded by paid plans. No ads, and the privacy policy states user data is not shared with third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cure53.de/pentest-report_forward-email.pdf",
          "note": "Two independent Cure53 audits of the code, including the MX servers, and the infrastructure are published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://forwardemail.net/technical-whitepaper.pdf",
          "note": "The technical whitepaper (section 9.3) publishes the government request policy and commits to transparency reports with request counts. A report with counts is not published yet."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://forwardemail.net/technical-whitepaper.pdf",
          "note": "Users are notified of requests when legally allowed, with notice after disclosure when advance notice is prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=forwardemail.net&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=forwardemail.net",
          "note": "Grade A+ (125/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://forwardemail.net/en/faq#do-you-support-openpgpmime-end-to-end-encryption-e2ee-and-web-key-directory-wkd",
          "note": "Forwarded mail is encrypted with OpenPGP when the recipient has an uploaded key or publishes one through Web Key Directory. Mail to webhooks and mail from senders with a DMARC reject policy is not encrypted."
        },
        "no_mail_storage": {
          "title": "No stored mail",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/faq#where-is-inbound-email-for-my-domain-processed-and-stored-and-for-how-long",
          "note": "Forwarded mail is processed in memory and never written to disk. SMTP error logs keep the envelope and headers, not the body, for 7 days."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/faq#do-you-support-receiving-email-with-imap",
          "note": "IMAP, POP3 and SMTP work with any client on every paid plan, with no bridge app."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/private-business-email",
          "note": "Custom domains are supported on every plan, including the free plan."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://forwardemail.net/en/faq#how-do-i-get-started-and-set-up-email-forwarding",
          "note": "The free plan needs no account. Forwarding is set up with MX and TXT records on the domain, and the destination address in the TXT record is public unless encrypted. Paid plans need an account with an existing email address. No phone number is asked for."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "yes",
          "evidence": null,
          "note": "Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/faq#how-do-i-set-up-srs-for-forward-email",
          "note": "Applied automatically to all forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/faq#do-you-support-email-best-practices",
          "note": "ARC is supported on all plans, with inbound chains validated and forwarded mail ARC-sealed."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:52.313Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "hide-my-email",
      "category": "email-forwarding",
      "name": "Hide My Email",
      "description": "Apple iCloud+ feature that creates random email addresses which forward to a personal inbox. Also used by Sign in with Apple.",
      "website": "https://support.apple.com/en-us/102548",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 44,
      "coverage": 100,
      "summary": "Hide My Email scores 44 out of 100 (grade D) on the email forwarding and aliases criteria. It meets 7 of 16 criteria: no trackers or telemetry, no ads or data sales, transparency report, tells users about requests, TLS configuration, security headers and no stored mail. It does not meet open source, independent audit, end-to-end encryption, open protocols, custom domains, sign up without personal data, mail transport security, Sender Rewriting Scheme and ARC sealing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/email-forwarding/hide-my-email/",
      "markdown": "https://privacyratings.com/email-forwarding/hide-my-email/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/data/en/device-analytics/",
          "note": "Analytics are only shared with Apple with consent, and iCloud.com loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/en-ww/",
          "note": "Included with the paid iCloud+ subscription. Apple states that it does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/transparency/",
          "note": "Apple publishes counts of government and private party requests twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/law-enforcement-guidelines-us.pdf",
          "note": "Apple notifies customers when their account information is sought, unless prohibited by law or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.icloud.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.icloud.com",
          "note": "Grade A+ (130/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Not supported. Forwarded mail is not encrypted end to end."
        },
        "no_mail_storage": {
          "title": "No stored mail",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://support.apple.com/en-us/102548",
          "note": "Messages are deleted from the relay servers after delivery, usually within seconds, and their content is not processed beyond spam filtering."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No IMAP or SMTP access for aliases. Mail is forwarded to an existing inbox."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Not supported for Hide My Email addresses. Custom email domains are a separate iCloud Mail feature."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://support.apple.com/en-us/108647",
          "note": "An Apple Account is required, and creating one asks for a phone number and an email address."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Passes: SPF, DMARC quarantine. Missing: MTA-STS missing, TLS-RPT, DNSSEC, DANE none."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS for forwarded mail."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:39.755Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "improvmx",
      "category": "email-forwarding",
      "name": "ImprovMX",
      "description": "Email forwarding service for custom domains, with aliases, catch-all addresses, forwarding rules and SMTP sending on paid plans.",
      "website": "https://improvmx.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 34,
      "coverage": 100,
      "summary": "ImprovMX scores 34 out of 100 (grade F) on the email forwarding and aliases criteria. It meets 4 of 15 criteria: no ads or data sales, TLS configuration, custom domains and Sender Rewriting Scheme. It partly meets no stored mail, open protocols and ARC sealing. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests, security headers, end-to-end encryption and sign up without personal data. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/email-forwarding/improvmx/",
      "markdown": "https://privacyratings.com/email-forwarding/improvmx/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://improvmx.com/guides/why-are-you-not-open-source/",
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://improvmx.com/transparency/privacy-policy/",
          "note": "The website loads the Intercom chat widget, and the privacy policy describes receiving data from advertising networks such as Google and LinkedIn."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://improvmx.com/pricing/",
          "note": "Funded by paid plans. The privacy policy states that personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": "https://improvmx.com/guides/are-you-soc2-or-iso27001-compliant/",
          "note": "No independent audit is published. Annual penetration tests are described, but no report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.improvmx.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.improvmx.com",
          "note": "Grade D- (25/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Not supported. Forwarded mail is not encrypted end to end."
        },
        "no_mail_storage": {
          "title": "No stored mail",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://improvmx.com/transparency/security-and-reliability/",
          "note": "Mail is stored temporarily for delivery and then deleted. Undelivered mail is kept when the full log level is chosen."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://improvmx.com/guides/improvmx-imap-pop-and-incoming-protocols/",
          "note": "SMTP sending is included on paid plans. There is no IMAP or POP3 because mail is forwarded to another mailbox."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://improvmx.com/pricing/",
          "note": "Works with custom domains on every plan, including the free one."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "An existing email address is required to create an account and receive forwarded mail."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "No mail domain to test."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://improvmx.com/guides/do-you-support-srs-sender-rewriting-scheme/",
          "note": "The envelope sender of forwarded mail is rewritten to a domain ImprovMX controls."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://improvmx.com/guides/do-you-support-arc-authenticated-received-chain/",
          "note": "Forwarded mail is ARC signed, but inbound ARC chains are not validated."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Intercom",
            "host": "widget.intercom.io",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:31:58.911Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "simplelogin",
      "category": "email-forwarding",
      "name": "SimpleLogin",
      "description": "Open-source email alias service run by Proton. Creates aliases that forward to real mailboxes and lets replies go out from the alias. Can also be self-hosted.",
      "website": "https://simplelogin.io",
      "source": "https://github.com/simple-login/app",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 58,
      "coverage": 100,
      "summary": "SimpleLogin scores 58 out of 100 (grade D) on the email forwarding and aliases criteria. It meets 6 of 16 criteria: open source, no ads or data sales, tells users about requests, TLS configuration, custom domains and mail transport security. It partly meets no trackers or telemetry, independent audit, transparency report, security headers, end-to-end encryption and no stored mail. It does not meet open protocols, sign up without personal data, Sender Rewriting Scheme and ARC sealing. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/email-forwarding/simplelogin/",
      "markdown": "https://privacyratings.com/email-forwarding/simplelogin/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/simple-login/app/blob/master/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://simplelogin.io/privacy/",
          "note": "No advertising trackers. The privacy policy lists cookieless Plausible analytics on the website and crash reporting in the apps. The Android app has no trackers in Exodus."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://simplelogin.io/pricing/",
          "note": "Funded by the Premium plan. No ads, and the privacy policy states data is never sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://simplelogin.io/audit2022/web.pdf",
          "note": "Securitum audited the web app, browser extensions and mobile apps. The full report is public but older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://simplelogin.io/privacy/",
          "note": "The privacy policy describes how legal requests are handled, but no request counts are published for SimpleLogin."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://simplelogin.io/privacy/",
          "note": "Users are informed of legal requests unless legally prevented."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=simplelogin.io&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=simplelogin.io",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee": {
          "title": "End-to-end encryption",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://simplelogin.io/pricing/",
          "note": "Forwarded mail can be encrypted with the user's PGP key on the Premium plan. Not on by default."
        },
        "no_mail_storage": {
          "title": "No stored mail",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://simplelogin.io/privacy/",
          "note": "Mail is deleted once delivered. Undeliverable mail is kept for 7 days so the user can review it."
        },
        "open_protocols": {
          "title": "Open protocols",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No IMAP or SMTP access. Mail is forwarded to an existing mailbox and replies go through reverse aliases."
        },
        "custom_domains": {
          "title": "Custom domains",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://simplelogin.io/pricing/",
          "note": "Unlimited custom domains on the Premium plan."
        },
        "anonymous_signup": {
          "title": "Sign up without personal data",
          "weight": 2,
          "answer": "no",
          "evidence": "https://simplelogin.io/privacy/",
          "note": "An existing email address is required to create an account and receive forwarded mail."
        },
        "mail_standards": {
          "title": "Email security standards",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "transport_security": {
          "title": "Mail transport security",
          "weight": 3,
          "answer": "yes",
          "evidence": null,
          "note": "Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all."
        },
        "srs": {
          "title": "Sender Rewriting Scheme",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on SRS. Forwarded mail is sent with a VERP return address on SimpleLogin's domain."
        },
        "arc": {
          "title": "ARC sealing",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published documentation on ARC signing or validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:46:27.432Z"
      },
      "last_modified": "2026-10-01T07:47:04Z"
    },
    {
      "slug": "aerc",
      "category": "email-clients",
      "name": "aerc",
      "description": "Terminal email client for Linux and macOS with IMAP, JMAP, Maildir and Notmuch support and PGP encryption through GnuPG.",
      "website": "https://aerc-mail.org",
      "source": "https://git.sr.ht/~rjarry/aerc",
      "license": null,
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 89,
      "coverage": 100,
      "summary": "aerc scores 89 out of 100 (grade B) on the email clients criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, OpenPGP support, connects directly, blocks remote content and works with any provider. It does not meet independent audit.",
      "url": "https://privacyratings.com/email-clients/aerc/",
      "markdown": "https://privacyratings.com/email-clients/aerc/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rjarry/aerc/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rjarry/aerc",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://aerc-mail.org",
          "note": "Volunteer free software project. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://aerc-mail.org",
          "note": "PGP signing, encryption and verification are built in through GnuPG."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://aerc-mail.org",
          "note": "Connects directly to IMAP, JMAP and SMTP servers. No vendor service is involved."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/rjarry/aerc/blob/master/filters/html",
          "note": "The default HTML filter renders mail with network access disabled. A separate html-unsafe filter must be chosen to load remote content."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://aerc-mail.org",
          "note": "Works with any IMAP, JMAP and SMTP provider."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:35.533Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "airmail",
      "category": "email-clients",
      "name": "Airmail",
      "description": "Closed-source email client for macOS, iPhone and iPad with support for Gmail, Outlook, Exchange and IMAP accounts, rules, snooze and send later.",
      "website": "https://airmailapp.com",
      "license": null,
      "platforms": [
        "macos",
        "ios"
      ],
      "jurisdiction": {
        "code": "IT",
        "name": "Italy",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 44,
      "coverage": 100,
      "summary": "Airmail scores 44 out of 100 (grade D) on the email clients criteria. It meets 2 of 8 criteria: no ads or data sales and works with any provider. It partly meets no trackers or telemetry, OpenPGP support, connects directly and blocks remote content. It does not meet open source and independent audit. It is based in Italy: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/email-clients/airmail/",
      "markdown": "https://privacyratings.com/email-clients/airmail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.iubenda.com/privacy-policy/649502/legal",
          "note": "No third-party advertising trackers, but the app sends first-party usage analytics by default, which can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.iubenda.com/privacy-policy/649502/legal",
          "note": "Funded by subscriptions. Personal data is not sold or used for third-party advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://help.airmailapp.com/en-us/article/plugins-airmail-for-macos-lenvq3/",
          "note": "PGP needs a separate GPG plugin on macOS. Not available on iOS."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.iubenda.com/privacy-policy/649502/legal",
          "note": "Connects directly to mail servers, but optional real-time notifications, send later and snooze store account credentials on Airmail servers."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://help.airmailapp.com/en-us/article/autoload-remote-images-1pwguyc/",
          "note": "Automatic loading of remote images can be turned off in settings."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://help.airmailapp.com/en-us/article/account-setup-imap-in-ios-hz7t46/",
          "note": "Works with any IMAP provider, plus Gmail, Outlook and Exchange accounts."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Crisp",
            "host": "client.crisp.chat",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:47.757Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "alpine",
      "category": "email-clients",
      "name": "Alpine",
      "description": "Text-based email client derived from Pine, for Unix-like systems and Windows, with built-in IMAP, POP3 and SMTP support and S/MIME encryption.",
      "website": "https://alpineapp.email",
      "source": "https://repo.or.cz/alpine.git",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 83,
      "coverage": 100,
      "summary": "Alpine scores 83 out of 100 (grade B) on the email clients criteria. It meets 6 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, connects directly, blocks remote content and works with any provider. It partly meets OpenPGP support. It does not meet independent audit.",
      "url": "https://privacyratings.com/email-clients/alpine/",
      "markdown": "https://privacyratings.com/email-clients/alpine/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://repo.or.cz/alpine.git/blob/HEAD:/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://repo.or.cz/alpine.git",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://alpineapp.email",
          "note": "Free software distributed at no cost. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://repo.or.cz/alpine.git/blob/HEAD:/pith/pine.hlp",
          "note": "S/MIME is built in. PGP needs an external display and sending filter such as GnuPG wrappers."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://repo.or.cz/alpine.git",
          "note": "Connects directly to IMAP, POP3 and SMTP servers. No vendor service is involved."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://repo.or.cz/alpine.git/blob/HEAD:/pith/pine.hlp",
          "note": "Text-based client that does not load remote content. When a message is opened in an external browser, links to external images are removed by default."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://repo.or.cz/alpine.git/blob/HEAD:/pith/pine.hlp",
          "note": "Works with any IMAP, POP3 and SMTP provider."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:47.937Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "apple-mail",
      "category": "email-clients",
      "name": "Apple Mail",
      "description": "Email app built into macOS, iOS and iPadOS. Works with iCloud Mail and any IMAP, POP3 or Exchange account.",
      "website": "https://support.apple.com/mail",
      "license": null,
      "platforms": [
        "macos",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 47,
      "coverage": 100,
      "summary": "Apple Mail scores 47 out of 100 (grade D) on the email clients criteria. It meets 3 of 8 criteria: no ads or data sales, connects directly and works with any provider. It partly meets no trackers or telemetry and blocks remote content. It does not meet open source, independent audit and OpenPGP support. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/email-clients/apple-mail/",
      "markdown": "https://privacyratings.com/email-clients/apple-mail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/device-analytics/",
          "note": "No third-party trackers in the app, and sharing device analytics with Apple is opt-in. Apple web pages load Apple's own analytics (ac-analytics, sent to metrics.apple.com) by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/en-ww/",
          "note": "Included with Apple devices and shows no ads. Apple states that it does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Not supported. S/MIME is built in."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/data/en/mail-privacy-protection/",
          "note": "Connects directly to mail servers. With Mail Privacy Protection, only remote content is fetched through Apple relays."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.apple.com/guide/iphone/use-mail-privacy-protection-iphf084865c7/ios",
          "note": "Mail Privacy Protection loads remote content privately through relays instead of blocking it. Remote content can be fully blocked in settings."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://support.apple.com/guide/mail/add-and-manage-email-accounts-mail35803/mac",
          "note": "Works with any IMAP, POP3 and Exchange provider."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:34.508Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "betterbird",
      "category": "email-clients",
      "name": "Betterbird",
      "description": "Fork of Mozilla Thunderbird that follows its Extended Support Releases and adds extra fixes and features. Available for Windows, macOS and Linux.",
      "website": "https://www.betterbird.eu",
      "source": "https://github.com/Betterbird/thunderbird-patches",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": true,
      "pick_reason": "Open-source (MPL-2.0) fork of Thunderbird with telemetry reporting turned off and built-in OpenPGP and S/MIME. It connects directly to any IMAP, POP3 and SMTP provider and blocks remote content by default.",
      "disclosure": null,
      "grade": "B",
      "score": 89,
      "coverage": 100,
      "summary": "Betterbird scores 89 out of 100 (grade B) on the email clients criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, OpenPGP support, connects directly, blocks remote content and works with any provider. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/email-clients/betterbird/",
      "markdown": "https://privacyratings.com/email-clients/betterbird/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Betterbird/thunderbird-patches/blob/main/LICENSE",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Betterbird/thunderbird-patches/blob/main/153/mozconfig",
          "note": "Builds are made with telemetry reporting turned off, and the website has no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.betterbird.eu/donate/",
          "note": "Funded by donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.betterbird.eu/faq/",
          "note": "OpenPGP and S/MIME are built in, as in Thunderbird."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.betterbird.eu/faq/",
          "note": "Connects directly to mail servers, as Thunderbird does. No vendor service is involved."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.mozilla.org/en-US/kb/remote-content-in-messages",
          "note": "Remote content is blocked by default, as in Thunderbird."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://support.mozilla.org/en-US/kb/manual-account-configuration",
          "note": "Works with any IMAP, POP3 and SMTP provider."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:30.693Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bluemail",
      "category": "email-clients",
      "name": "BlueMail",
      "description": "Closed-source email client for Android, iOS, Windows, macOS and Linux that works with IMAP, POP3 and Exchange accounts, with a unified inbox, PGP and S/MIME encryption and optional AI features.",
      "website": "https://bluemail.me",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 42,
      "coverage": 100,
      "summary": "BlueMail scores 42 out of 100 (grade D) on the email clients criteria. It meets 3 of 8 criteria: no ads or data sales, OpenPGP support and works with any provider. It partly meets connects directly and blocks remote content. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/email-clients/bluemail/",
      "markdown": "https://privacyratings.com/email-clients/bluemail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/me.bluemail.mail/latest/",
          "note": "Exodus finds Google AdMob, Crashlytics and Firebase Analytics in the Android app, and the privacy policy lists Google Analytics cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://bluemail.me/privacy/",
          "note": "Funded by paid plans. The privacy policy states that user data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://bluemail.me/help/pgp-keys/",
          "note": "PGP and S/MIME are built in on all platforms."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://bluemail.me/privacy/",
          "note": "Desktop apps connect directly to mail servers, but instant push on mobile processes OAuth tokens or credentials and incoming mail through a Blix push proxy."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://bluemail.me/help/disable-images/",
          "note": "Remote images can be blocked in settings."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://bluemail.me/help/imap-pop3-provider-support-bluemail/",
          "note": "Works with any IMAP or POP3 provider, plus Exchange accounts."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:48.366Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "canary-mail",
      "category": "email-clients",
      "name": "Canary Mail",
      "description": "Email app for macOS, iOS, Android and Windows with built-in PGP encryption, tracker blocking and AI features.",
      "website": "https://canarymail.io",
      "license": null,
      "platforms": [
        "macos",
        "ios",
        "android",
        "windows"
      ],
      "jurisdiction": {
        "code": "SG",
        "name": "Singapore",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 42,
      "coverage": 100,
      "summary": "Canary Mail scores 42 out of 100 (grade D) on the email clients criteria. It meets 3 of 8 criteria: no ads or data sales, OpenPGP support and works with any provider. It partly meets connects directly and blocks remote content. It does not meet open source, no trackers or telemetry and independent audit. It is based in Singapore: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/email-clients/canary-mail/",
      "markdown": "https://privacyratings.com/email-clients/canary-mail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/io.canarymail.android/latest/",
          "note": "Exodus finds Facebook Analytics, Firebase Analytics and Crashlytics in the Android app, and the website uses Google Tag Manager and HubSpot."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://canarymail.io/pricing",
          "note": "Funded by paid plans. The app shows no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://canarymail.io/faq",
          "note": "PGP is built into all apps, with key generation and management. Encryption requires the Pro+ plan."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://canarymail.io/privacy",
          "note": "Mail and credentials stay on the device, but push notifications on mobile and Cloud Sync store credentials and message details on Canary servers."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://canarymail.io/features/security",
          "note": "Tracking pixels are blocked by default, but other remote images still load."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://canarymail.io/help/whats-new",
          "note": "Works with any IMAP and SMTP provider, plus Gmail, Outlook and Exchange accounts."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js-na2.hs-scripts.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:34.649Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "claws-mail",
      "category": "email-clients",
      "name": "Claws Mail",
      "description": "Lightweight GTK email and news client for Linux and Windows, extended through plugins for OpenPGP, HTML rendering and spam filtering.",
      "website": "https://www.claws-mail.org",
      "source": "https://git.claws-mail.org/?p=claws.git;a=summary",
      "license": null,
      "platforms": [
        "linux",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 89,
      "coverage": 100,
      "summary": "Claws Mail scores 89 out of 100 (grade B) on the email clients criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, OpenPGP support, connects directly, blocks remote content and works with any provider. It does not meet independent audit.",
      "url": "https://privacyratings.com/email-clients/claws-mail/",
      "markdown": "https://privacyratings.com/email-clients/claws-mail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://git.claws-mail.org/?p=claws.git;a=blob;f=COPYING;hb=HEAD",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://git.claws-mail.org/?p=claws.git;a=summary",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.claws-mail.org/donations.php",
          "note": "Funded by donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.claws-mail.org/plugins.php",
          "note": "OpenPGP is handled by the PGP/MIME and PGP/Inline plugins that ship with Claws Mail."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.claws-mail.org/features.php",
          "note": "Connects directly to POP3, IMAP and SMTP servers. No vendor service is involved."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://git.claws-mail.org/?p=claws.git;a=blob;f=src/plugins/litehtml_viewer/lh_prefs.c;hb=HEAD",
          "note": "HTML mail is shown as text by default, and the HTML viewer plugins keep remote content off unless enabled."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.claws-mail.org/features.php",
          "note": "Works with any IMAP, POP3 and SMTP provider."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:35.845Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "delta-chat",
      "category": "email-clients",
      "name": "Delta Chat",
      "description": "Decentralized messenger that uses email servers for delivery, with automatic end-to-end encryption through Autocrypt and OpenPGP. Works with chatmail relays or existing email accounts.",
      "website": "https://delta.chat",
      "source": "https://github.com/chatmail/core",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 92,
      "coverage": 100,
      "summary": "Delta Chat scores 92 out of 100 (grade A) on the email clients criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, independent audit, OpenPGP support, blocks remote content and works with any provider. It partly meets connects directly. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/email-clients/delta-chat/",
      "markdown": "https://privacyratings.com/email-clients/delta-chat/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/chatmail/core/blob/main/LICENSE",
          "note": "The core library is MPL-2.0 and the apps are GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.b44t.messenger/latest/",
          "note": "Exodus finds 0 trackers. Usage statistics are only sent if turned on in settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://delta.chat/en/help#how-are-delta-chat-developments-funded",
          "note": "Funded by public grants and donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/rpgp/docs/blob/main/audits/NGI%20Core%20rPGP%20penetration%20test%20report%202024%201.0.pdf",
          "note": "Radically Open Security tested rPGP, the OpenPGP library Delta Chat uses, and published the full report."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://delta.chat/en/help#which-standards-are-used-for-end-to-end-encryption",
          "note": "End-to-end encryption with Autocrypt and OpenPGP is built in and automatic."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://delta.chat/en/privacy",
          "note": "Connects directly to mail servers, but push notifications on iOS and Android go through a notification proxy run by the developers."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/deltachat/deltachat-android/blob/main/src/main/java/org/thoughtcrime/securesms/FullMsgActivity.java",
          "note": "HTML messages are shown with network loads blocked until the user chooses to load remote content."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://delta.chat/en/help#can-i-use-a-classic-email-address-with-delta-chat",
          "note": "Works with any IMAP and SMTP provider, but the address should only be used with chatmail apps."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:35.306Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "edison-mail",
      "category": "email-clients",
      "name": "Edison Mail",
      "description": "Closed-source email client for iOS, Android and macOS from Edison Software, an affiliate of YipitData, that sorts messages into categories such as packages, travel and receipts.",
      "website": "https://www.edisonmail.com",
      "license": null,
      "platforms": [
        "ios",
        "android",
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 11,
      "coverage": 100,
      "summary": "Edison Mail scores 11 out of 100 (grade F) on the email clients criteria. It meets 1 of 8 criteria: works with any provider. It partly meets blocks remote content. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, OpenPGP support and connects directly. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/email-clients/edison-mail/",
      "markdown": "https://privacyratings.com/email-clients/edison-mail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.easilydo.mail/latest/",
          "note": "Exodus finds 7 trackers in the Android app, including Google AdMob, Google Analytics, Firebase Analytics and Mixpanel, and the website loads Google, Facebook, LinkedIn and TikTok trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.edisonmail.com/privacy",
          "note": "The privacy policy describes creating de-identified data from commercial emails and selling it to business subscribers, and using data to tailor ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No PGP or S/MIME support is documented."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "no",
          "evidence": "https://mailsupport.edison.tech/hc/en-us/articles/360016157331-Does-Edison-store-my-messages",
          "note": "Commercial messages such as receipts, shipments and travel alerts are processed and stored on Edison servers."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.edisonmail.com/privacy-commitments",
          "note": "Read receipt tracking pixels are blocked, but other remote images still load."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://mailsupport.edison.tech/hc/en-us/articles/115000591046-Which-types-of-accounts-does-Edison-Mail-support",
          "note": "Works with any IMAP provider, plus Gmail, Outlook and Exchange accounts. POP3 is not supported."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Meta Pixel",
            "host": "www.facebook.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Clarity",
            "host": "www.clarity.ms",
            "effect": "no"
          },
          {
            "name": "TikTok Pixel",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:48.449Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "em-client",
      "category": "email-clients",
      "name": "eM Client",
      "description": "Desktop and mobile email client for Windows, macOS, Android and iOS with calendar, contacts, chat and built-in PGP and S/MIME.",
      "website": "https://www.emclient.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CZ",
        "name": "Czechia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 42,
      "coverage": 100,
      "summary": "eM Client scores 42 out of 100 (grade D) on the email clients criteria. It meets 3 of 8 criteria: no ads or data sales, OpenPGP support and works with any provider. It partly meets connects directly and blocks remote content. It does not meet open source, no trackers or telemetry and independent audit. It is based in Czechia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/email-clients/em-client/",
      "markdown": "https://privacyratings.com/email-clients/em-client/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.emclient.com/privacy-policy",
          "note": "The website loads Google Tag Manager, and the privacy policy lists Google Analytics, Google Optimize and Smartlook."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.emclient.com/pricing",
          "note": "Funded by paid licenses. The app shows no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.emclient.com/webdocumentation/en/10.3/eMClient/Content/E-mail/PGP.htm",
          "note": "PGP key generation, encryption and signing are built in, along with S/MIME."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.emclient.com/privacy-policy",
          "note": "Connects directly to mail servers. Optional mobile push notifications send login tokens and message headers through eM Client servers, and translation uses its servers."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.emclient.com/webdocumentation/en/10.3/eMClient/Content/Settings/Privacy.htm",
          "note": "External content and tracking pixels can be blocked in the privacy settings."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.emclient.com/webdocumentation/en/10.3/eMClient/Content/Accounts/Create%20New%20Account.htm",
          "note": "Works with any IMAP, POP3 and SMTP provider, as well as Exchange and Google accounts."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "widget.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:19.581Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "evolution",
      "category": "email-clients",
      "name": "Evolution",
      "description": "GNOME groupware application for Linux that combines email, calendar, contacts and tasks, with support for IMAP, POP3, Exchange and OpenPGP.",
      "website": "https://gitlab.gnome.org/GNOME/evolution/-/wikis/home",
      "source": "https://gitlab.gnome.org/GNOME/evolution",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 89,
      "coverage": 100,
      "summary": "Evolution scores 89 out of 100 (grade B) on the email clients criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, OpenPGP support, connects directly, blocks remote content and works with any provider. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/email-clients/evolution/",
      "markdown": "https://privacyratings.com/email-clients/evolution/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/GNOME/evolution/-/blob/master/COPYING",
          "note": "LGPL-2.1."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/GNOME/evolution",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://donate.gnome.org/en/",
          "note": "GNOME project funded by donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://help.gnome.org/evolution/mail-encryption-gpg-set-up.html",
          "note": "OpenPGP through GnuPG and S/MIME are built in."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://help.gnome.org/evolution/intro-account-types.html",
          "note": "Connects directly to mail servers. No vendor service is involved."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://help.gnome.org/evolution/mail-displaying-images-in-html.html",
          "note": "Remote images are not downloaded unless the user requests it."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://help.gnome.org/evolution/intro-account-types.html",
          "note": "Works with any IMAP, POP3 and SMTP provider."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:34.509Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fairemail",
      "category": "email-clients",
      "name": "FairEmail",
      "description": "Open-source email app for Android that works with any IMAP, POP3 and SMTP provider and supports multiple accounts with a unified inbox.",
      "website": "https://email.faircode.eu",
      "source": "https://github.com/M66B/FairEmail",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 83,
      "coverage": 100,
      "summary": "FairEmail scores 83 out of 100 (grade B) on the email clients criteria. It meets 6 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, connects directly, blocks remote content and works with any provider. It partly meets OpenPGP support. It does not meet independent audit.",
      "url": "https://privacyratings.com/email-clients/fairemail/",
      "markdown": "https://privacyratings.com/email-clients/fairemail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/M66B/FairEmail/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/eu.faircode.email/latest/",
          "note": "Exodus finds 0 trackers. Error reporting through Bugsnag is opt-in and off by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/M66B/FairEmail/blob/master/README.md",
          "note": "No ads. Funded by optional paid pro features."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/M66B/FairEmail/blob/master/FAQ.md#faq12",
          "note": "PGP needs the separate OpenKeychain or PGPony app. S/MIME is built in."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/M66B/FairEmail/blob/master/PRIVACY.md",
          "note": "Connects directly to mail servers. Apart from opt-in error reports, no data is sent to the developer."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/M66B/FairEmail/blob/master/README.md",
          "note": "Remote images must be confirmed before they load, and known tracking images are disabled."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/M66B/FairEmail/blob/master/README.md",
          "note": "Works with any IMAP, POP3 and SMTP provider."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:19.770Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "forward-email",
      "category": "email-clients",
      "name": "Forward Email",
      "description": "Email client for Forward Email accounts, available as webmail and as desktop and mobile apps built from one source-available codebase, with built-in OpenPGP and optional encryption of locally stored data.",
      "website": "https://forwardemail.net/en/download",
      "source": "https://github.com/forwardemail/mail.forwardemail.net",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": true,
      "pick_reason": "Source-available webmail, desktop and mobile client with built-in OpenPGP and no third-party analytics. It works only with Forward Email accounts, not other IMAP and SMTP providers.",
      "disclosure": "Privacy Ratings is maintained by the team behind Forward Email. This entry is scored by the same criteria as every other email client, and changes to it are reviewed under the published conflict-of-interest rules.",
      "grade": "B",
      "score": 81,
      "coverage": 100,
      "summary": "Forward Email scores 81 out of 100 (grade B) on the email clients criteria. It meets 5 of 8 criteria: open source, no ads or data sales, independent audit, OpenPGP support and connects directly. It partly meets no trackers or telemetry and blocks remote content. It does not meet works with any provider. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/email-clients/forward-email/",
      "markdown": "https://privacyratings.com/email-clients/forward-email/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/forwardemail/mail.forwardemail.net/blob/main/LICENSE.md",
          "note": "All code is public. The apps are under the source-available Business Source License 1.1, which becomes MPL-2.0 four years after each release."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://forwardemail.net/en/privacy#analytics",
          "note": "No third-party analytics in the website or apps, but the website runs first-party cookieless analytics by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/privacy",
          "note": "Funded by paid plans. No ads, and user data is not shared with third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cure53.de/pentest-report_forward-email.pdf",
          "note": "Cure53's audit scope includes the mail.forwardemail.net client code together with the Forward Email service."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/forwardemail/mail.forwardemail.net/blob/main/src/utils/pgp-send.ts",
          "note": "OpenPGP encryption and signing are built in."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/forwardemail/mail.forwardemail.net/blob/main/README.md",
          "note": "Connects directly to the Forward Email API, which is the mail server, with no separate sync service. Mobile push goes through APNs, FCM or UnifiedPush."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/forwardemail/mail.forwardemail.net/blob/main/src/stores/settingsRegistry.ts",
          "note": "Tracking pixels are blocked by default, but other remote images load unless blocking is turned on in settings."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "no",
          "evidence": "https://forwardemail.net/en/faq#do-you-offer-a-webmail-client",
          "note": "Works only with Forward Email accounts. The maintainers state that a future version will support any IMAP and SMTP provider."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:48.501Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "geary",
      "category": "email-clients",
      "name": "Geary",
      "description": "Email app for the GNOME desktop on Linux that groups messages into conversations and works with IMAP accounts.",
      "website": "https://gitlab.gnome.org/GNOME/geary",
      "source": "https://gitlab.gnome.org/GNOME/geary",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 78,
      "coverage": 100,
      "summary": "Geary scores 78 out of 100 (grade B) on the email clients criteria. It meets 6 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, connects directly, blocks remote content and works with any provider. It does not meet independent audit and OpenPGP support. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/email-clients/geary/",
      "markdown": "https://privacyratings.com/email-clients/geary/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/GNOME/geary/-/blob/main/COPYING",
          "note": "LGPL-2.1."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/GNOME/geary",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://donate.gnome.org/en/",
          "note": "GNOME project funded by donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Not supported."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/GNOME/geary/-/blob/main/help/C/accounts.page",
          "note": "Connects directly to IMAP and SMTP servers. No vendor service is involved."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/GNOME/geary/-/blob/main/src/client/conversation-viewer/conversation-message.vala",
          "note": "Remote images are not shown until the user allows them for a message or sender."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/GNOME/geary/-/blob/main/help/C/accounts.page",
          "note": "Works with any IMAP and SMTP provider. POP3 is not supported."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:34.509Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gmail-app",
      "category": "email-clients",
      "name": "Gmail app",
      "description": "Google's email app for Android and iOS. Works with Gmail and Google Workspace accounts, and can also add Outlook, Yahoo and other IMAP accounts.",
      "website": "https://workspace.google.com/gmail/",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 19,
      "coverage": 100,
      "summary": "Gmail app scores 19 out of 100 (grade F) on the email clients criteria. It meets 1 of 8 criteria: works with any provider. It partly meets connects directly and blocks remote content. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit and OpenPGP support. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/email-clients/gmail-app/",
      "markdown": "https://privacyratings.com/email-clients/gmail-app/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Exodus finds no third-party trackers, but Google collects activity data across its services and uses it for analytics and personalized ads."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://support.google.com/mail/answer/6603",
          "note": "Ads are shown in Gmail."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit of the Gmail app is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Not supported. S/MIME is limited to some Google Workspace plans."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://support.google.com/mail/answer/6304825",
          "note": "Other accounts can be added to the app, but Gmailify links Yahoo, AOL and Outlook accounts through Google servers. Gmail accounts sync with Google."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.google.com/mail/answer/145919",
          "note": "Images are shown by default through Google proxies. Gmail can be set to ask before showing external images."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://support.google.com/mail/answer/6078445",
          "note": "Works with Gmail and with other providers such as Outlook, iCloud Mail, Yahoo and IMAP accounts."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:34.640Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "himalaya",
      "category": "email-clients",
      "name": "Himalaya",
      "description": "Command-line email client that manages mail over IMAP, JMAP, SMTP, Maildir, the Gmail API and Microsoft Graph, with composing and reading handled by the companion MML tool.",
      "website": "https://github.com/pimalaya/himalaya",
      "source": "https://github.com/pimalaya/himalaya",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 83,
      "coverage": 100,
      "summary": "Himalaya scores 83 out of 100 (grade B) on the email clients criteria. It meets 6 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, connects directly, blocks remote content and works with any provider. It partly meets OpenPGP support. It does not meet independent audit.",
      "url": "https://privacyratings.com/email-clients/himalaya/",
      "markdown": "https://privacyratings.com/email-clients/himalaya/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pimalaya/himalaya/blob/master/LICENSE-MIT",
          "note": "MIT or Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pimalaya/himalaya",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/pimalaya/himalaya/blob/master/README.md",
          "note": "Funded by NLnet grants and donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/pimalaya/mml/blob/master/README.md",
          "note": "PGP signing and encryption are handled by the separate MML tool from the same project, built with its gpg feature."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pimalaya/himalaya/blob/master/README.md",
          "note": "Connects directly to mail servers. Passwords are read from a local password manager command."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/pimalaya/mml/blob/master/README.md",
          "note": "Command-line client that does not load remote content. HTML is rendered to plain text."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/pimalaya/himalaya/blob/master/README.md",
          "note": "Works with any IMAP, JMAP and SMTP provider, plus Gmail and Microsoft 365 through their APIs."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:48.367Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kmail",
      "category": "email-clients",
      "name": "KMail",
      "description": "KDE email client for Linux, part of the Kontact suite, with support for IMAP, POP3, OpenPGP and S/MIME.",
      "website": "https://apps.kde.org/kmail2/",
      "source": "https://invent.kde.org/pim/kmail",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 89,
      "coverage": 100,
      "summary": "KMail scores 89 out of 100 (grade B) on the email clients criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, OpenPGP support, connects directly, blocks remote content and works with any provider. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/email-clients/kmail/",
      "markdown": "https://privacyratings.com/email-clients/kmail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://apps.kde.org/kmail2/",
          "note": "GPL-2.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kde.org/privacypolicy-apps/",
          "note": "No third-party trackers. Any telemetry in KDE apps is opt-in and off by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kde.org/donate/",
          "note": "KDE project funded by donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.kde.org/stable_kf6/en/kmail/kmail2/pgp.html",
          "note": "Inline OpenPGP, PGP/MIME and S/MIME are built in."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://docs.kde.org/stable_kf6/en/kmail/kmail2/getting-started.html",
          "note": "Connects directly to mail servers. No vendor service is involved."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.kde.org/stable_kf6/en/kmail/kmail2/configure-security.html",
          "note": "External references in HTML mail are not loaded unless enabled in settings."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.kde.org/stable_kf6/en/kmail/kmail2/getting-started.html",
          "note": "Works with any IMAP, POP3 and SMTP provider."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:35.460Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mailbird",
      "category": "email-clients",
      "name": "Mailbird",
      "description": "Closed-source desktop email client for Windows, with a separate Mailbird Next app for macOS, that combines several accounts in a unified inbox with calendar and app integrations.",
      "website": "https://www.getmailbird.com",
      "license": null,
      "platforms": [
        "windows",
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 33,
      "coverage": 100,
      "summary": "Mailbird scores 33 out of 100 (grade F) on the email clients criteria. It meets 3 of 8 criteria: connects directly, blocks remote content and works with any provider. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit and OpenPGP support. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/email-clients/mailbird/",
      "markdown": "https://privacyratings.com/email-clients/mailbird/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.getmailbird.com/privacy-policy/",
          "note": "The website loads Google Tag Manager, Mixpanel, PostHog, LinkedIn and TikTok trackers, and the policy lists Google Analytics, Mixpanel and Hotjar."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.getmailbird.com/privacy-policy/",
          "note": "Sells paid plans, but the privacy policy allows targeted third-party advertising on the site and in the applications."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "no",
          "evidence": "https://support.getmailbird.com/hc/en-us/articles/15014091847575-Is-PGP-encryption-supported-in-Mailbird",
          "note": "PGP encryption is not supported."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://support.getmailbird.com/hc/en-us/articles/360006261473-I-have-forgotten-my-email-password",
          "note": "Connects directly to mail servers. Usernames and passwords are stored encrypted on the local drive."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.getmailbird.com/hc/en-us/articles/220107267-Always-Show-Remote-Images",
          "note": "Remote images load only when allowed for a message or sender, unless Always show remote images is turned on."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://support.getmailbird.com/hc/en-us/articles/220106687-IMAP-Support-in-Mailbird",
          "note": "Works with any IMAP and POP3 provider, plus Exchange on paid plans."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Mixpanel",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "PostHog",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:48.542Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mailspring",
      "category": "email-clients",
      "name": "Mailspring",
      "description": "Open-source desktop email client for Windows, macOS and Linux with a unified inbox and optional paid features such as read receipts and send later.",
      "website": "https://www.getmailspring.com",
      "source": "https://github.com/Foundry376/Mailspring",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 39,
      "coverage": 100,
      "summary": "Mailspring scores 39 out of 100 (grade F) on the email clients criteria. It meets 2 of 8 criteria: no ads or data sales and works with any provider. It partly meets open source, connects directly and blocks remote content. It does not meet no trackers or telemetry, independent audit and OpenPGP support. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/email-clients/mailspring/",
      "markdown": "https://privacyratings.com/email-clients/mailspring/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/Foundry376/Mailspring/blob/master/LICENSE.md",
          "note": "The app and its sync engine are GPL-3.0, but the Mailspring ID service behind the Pro features is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.getmailspring.com/privacy-policy",
          "note": "The website loads Google Analytics, and the privacy policy lists Mixpanel, Intercom and Google Analytics for tracking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.getmailspring.com/pro",
          "note": "Funded by the Mailspring Pro subscription. The app shows no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Not supported."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.getmailspring.com/privacy-policy",
          "note": "Credentials stay in the system keychain and mail syncs directly, but linked addresses are sent to Mailspring servers for features such as read receipts."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/Foundry376/Mailspring/blob/master/app/src/config-schema.ts",
          "note": "Images load automatically by default. Automatic loading can be turned off in settings."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.getmailspring.com",
          "note": "Works with any IMAP and SMTP provider."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "X (Twitter) Pixel",
            "host": "static.ads-twitter.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:35.346Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "microsoft-outlook",
      "category": "email-clients",
      "name": "Microsoft Outlook",
      "description": "Microsoft's email and calendar app for Windows, macOS, Android, iOS and the web. Works with Outlook.com, Microsoft 365, Exchange and other IMAP accounts.",
      "website": "https://www.microsoft.com/en-us/microsoft-365/outlook",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 11,
      "coverage": 100,
      "summary": "Microsoft Outlook scores 11 out of 100 (grade F) on the email clients criteria. It meets 1 of 8 criteria: works with any provider. It partly meets blocks remote content. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, OpenPGP support and connects directly. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/email-clients/microsoft-outlook/",
      "markdown": "https://privacyratings.com/email-clients/microsoft-outlook/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.microsoft.office.outlook/latest/",
          "note": "Exodus finds six trackers in the Android app, including AppNexus, Facebook Ads and Singular."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "The free Outlook apps show ads to users without a paid Microsoft 365 plan."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit of the Outlook apps is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Not supported. S/MIME and Microsoft Purview encryption are available instead."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement#mainoutlookmodule",
          "note": "The mobile app syncs mail from all added accounts, including third-party ones, to Microsoft servers. Desktop sync to Microsoft servers is optional."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.microsoft.com/en-us/outlook/block-or-unblock-automatic-picture-downloads-in-classic-outlook-email-messages",
          "note": "Classic Outlook for Windows blocks automatic picture downloads by default. Other Outlook apps differ."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement#mainoutlookmodule",
          "note": "Works with Microsoft accounts and accounts from third-party providers."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:37.285Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mimestream",
      "category": "email-clients",
      "name": "Mimestream",
      "description": "Closed-source macOS email client for Gmail and Google Workspace accounts that syncs through the Gmail API and supports labels, filters and inbox categories.",
      "website": "https://mimestream.com",
      "license": null,
      "platforms": [
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Mimestream scores 50 out of 100 (grade D) on the email clients criteria. It meets 2 of 8 criteria: no trackers or telemetry and no ads or data sales. It partly meets independent audit, connects directly, blocks remote content and works with any provider. It does not meet open source and OpenPGP support. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/email-clients/mimestream/",
      "markdown": "https://privacyratings.com/email-clients/mimestream/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://mimestream.com/trust/subprocessors",
          "note": "No analytics services are listed among subprocessors or in the privacy policy, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mimestream.com/pricing/",
          "note": "Funded by paid subscriptions. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://mimestream.com/trust/assets/Mimestream_CASA_2026.pdf",
          "note": "A CASA Tier 2 assessment by TAC Security is published only as a letter of validation, not a full report."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "no",
          "evidence": "https://mimestream.com/trust/security-and-privacy",
          "note": "Neither PGP nor S/MIME is supported."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://mimestream.com/trust/private-push",
          "note": "Syncs directly with the Gmail API and keeps tokens on the device, but Private Push notifications, on by default on recent macOS, pass through a Mimestream relay that never receives credentials or message content."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://mimestream.com/help/user-guide/viewing-settings",
          "note": "Remote images can be blocked in settings, and a tracker blocker is available."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://mimestream.com/help/user-guide/supported-accounts",
          "note": "Works only with Gmail and Google Workspace accounts."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:48.673Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mozilla-thunderbird",
      "category": "email-clients",
      "name": "Mozilla Thunderbird",
      "description": "Open-source desktop email client for Windows, macOS and Linux with calendar, contacts and built-in OpenPGP and S/MIME encryption.",
      "website": "https://www.thunderbird.net",
      "source": "https://github.com/mozilla/releases-comm-central",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 86,
      "coverage": 100,
      "summary": "Mozilla Thunderbird scores 86 out of 100 (grade B) on the email clients criteria. It meets 6 of 8 criteria: open source, no ads or data sales, OpenPGP support, connects directly, blocks remote content and works with any provider. It partly meets no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/email-clients/mozilla-thunderbird/",
      "markdown": "https://privacyratings.com/email-clients/mozilla-thunderbird/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.mozilla.org/en-US/MPL/2.0/",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://support.mozilla.org/en-US/kb/thunderbird-telemetry",
          "note": "Sends first-party telemetry to Mozilla by default, which can be turned off in settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.thunderbird.net/en-US/donate/",
          "note": "Funded by user donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://posteo.de/en/blog/security-warning-for-thunderbird-users-and-enigmail-users-vulnerabilities-threaten-confidentiality-of-communication",
          "note": "Cure53 audited Thunderbird and Enigmail, but only a summary is public and the audit is more than three years old."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.mozilla.org/en-US/kb/openpgp-thunderbird-howto-and-faq",
          "note": "OpenPGP and S/MIME are built in."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.mozilla.org/en-US/privacy/thunderbird/",
          "note": "Connects directly to mail servers. Mail, contacts and account details stay on the device."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.mozilla.org/en-US/kb/remote-content-in-messages",
          "note": "Remote content is blocked by default."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://support.mozilla.org/en-US/kb/manual-account-configuration",
          "note": "Works with any IMAP, POP3 and SMTP provider."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:51.432Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mutt",
      "category": "email-clients",
      "name": "Mutt",
      "description": "Text-based terminal email client for Unix-like systems with built-in IMAP, POP3 and SMTP support, message threading and OpenPGP and S/MIME encryption.",
      "website": "https://gitlab.com/muttmua/mutt",
      "source": "https://gitlab.com/muttmua/mutt",
      "license": null,
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 89,
      "coverage": 100,
      "summary": "Mutt scores 89 out of 100 (grade B) on the email clients criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, OpenPGP support, connects directly, blocks remote content and works with any provider. It does not meet independent audit.",
      "url": "https://privacyratings.com/email-clients/mutt/",
      "markdown": "https://privacyratings.com/email-clients/mutt/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/muttmua/mutt/-/blob/master/COPYRIGHT",
          "note": "GPL-2.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/muttmua/mutt",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gitlab.com/muttmua/mutt/-/blob/master/README",
          "note": "Volunteer free software project. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gitlab.com/muttmua/mutt/-/blob/master/doc/PGP-Notes.txt",
          "note": "OpenPGP and S/MIME are built in, through GnuPG or GPGME."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/muttmua/mutt/-/blob/master/doc/manual.xml.head",
          "note": "Connects directly to IMAP, POP3 and SMTP servers. No vendor service is involved."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gitlab.com/muttmua/mutt/-/blob/master/doc/manual.xml.head",
          "note": "Text-based client that does not load remote content. HTML is passed to an external viewer set in mailcap."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://gitlab.com/muttmua/mutt/-/blob/master/doc/manual.xml.head",
          "note": "Works with any IMAP, POP3 and SMTP provider."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:48.476Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "neomutt",
      "category": "email-clients",
      "name": "NeoMutt",
      "description": "Terminal email client for Linux and macOS based on Mutt, with built-in IMAP, POP3, SMTP and OpenPGP support.",
      "website": "https://neomutt.org",
      "source": "https://github.com/neomutt/neomutt",
      "license": "GPL-2.0",
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 89,
      "coverage": 100,
      "summary": "NeoMutt scores 89 out of 100 (grade B) on the email clients criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, OpenPGP support, connects directly, blocks remote content and works with any provider. It does not meet independent audit.",
      "url": "https://privacyratings.com/email-clients/neomutt/",
      "markdown": "https://privacyratings.com/email-clients/neomutt/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/neomutt/neomutt/blob/main/LICENSE.md",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/neomutt/neomutt",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://neomutt.org/sponsor",
          "note": "Volunteer project funded by sponsorship. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://neomutt.org/guide/gettingstarted#sending-crypto",
          "note": "OpenPGP and S/MIME are built in through GPGME."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://neomutt.org/guide/optionalfeatures",
          "note": "Connects directly to IMAP, POP3 and SMTP servers. Credentials and mail stay on the device."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://neomutt.org/guide/mimesupport",
          "note": "Text-based client that does not load remote content. HTML is passed to an external viewer set in mailcap."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://neomutt.org/guide/optionalfeatures",
          "note": "Works with any IMAP, POP3 and SMTP provider."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:35.547Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nine",
      "category": "email-clients",
      "name": "Nine",
      "description": "Closed-source email and calendar app for Android and iOS built around Exchange ActiveSync, with email-only support for IMAP accounts.",
      "website": "https://www.9folders.com/en/",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "KR",
        "name": "South Korea",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 39,
      "coverage": 100,
      "summary": "Nine scores 39 out of 100 (grade F) on the email clients criteria. It meets 3 of 8 criteria: no ads or data sales, connects directly and works with any provider. It partly meets blocks remote content. It does not meet open source, no trackers or telemetry, independent audit and OpenPGP support. It is based in South Korea: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/email-clients/nine/",
      "markdown": "https://privacyratings.com/email-clients/nine/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.ninefolders.hd3/latest/",
          "note": "Exodus finds Crashlytics, Firebase Analytics and OpenTelemetry in the Android app, and the website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.9folders.com/privacy-policy/",
          "note": "Funded by paid licenses. The privacy policy states user information is not sold, shared or rented."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "PGP is not supported."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.9folders.com/privacy-policy/",
          "note": "Connects directly to mail servers. Passwords and messages are stored only on the device."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://nextintelligence-ai.gitbook.io/9folders/nine/nine/documents/android-manual/settings/nine-settings",
          "note": "Automatic loading of remote images can be turned off in settings."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.9folders.com/en/",
          "note": "Works with Exchange ActiveSync servers and any IMAP provider, with IMAP limited to email."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:48.714Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "spark-mail",
      "category": "email-clients",
      "name": "Spark Mail",
      "description": "Email app for macOS, Windows, iOS and Android with a smart inbox, team sharing and AI features. Push notifications and several features run through its servers.",
      "website": "https://sparkmailapp.com",
      "license": null,
      "platforms": [
        "macos",
        "windows",
        "ios",
        "android"
      ],
      "jurisdiction": {
        "code": "IE",
        "name": "Ireland",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 17,
      "coverage": 100,
      "summary": "Spark Mail scores 17 out of 100 (grade F) on the email clients criteria. It meets 2 of 8 criteria: no ads or data sales and works with any provider. It does not meet open source, no trackers or telemetry, independent audit, OpenPGP support, connects directly and blocks remote content. It is based in Ireland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/email-clients/spark-mail/",
      "markdown": "https://privacyratings.com/email-clients/spark-mail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.readdle.spark/latest/",
          "note": "Exodus finds Amplitude, AppsFlyer, Firebase Analytics and Crashlytics in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://sparkmailapp.com/legal/privacy-app",
          "note": "Funded by paid plans. The privacy policy states that personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Not supported."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "no",
          "evidence": "https://sparkmailapp.com/help/privacy-data/spark-email-privacy-everything-you-need-to-know",
          "note": "Login credentials or access tokens are stored on Spark servers to send notifications and run features such as send later and shared drafts."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No documented option to block remote images or tracking pixels."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://sparkmailapp.com/help/add-manage-accounts/connect-to-your-email-account-in-spark",
          "note": "Works with Gmail, Outlook, iCloud, Yahoo, Exchange and custom IMAP accounts."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Amplitude",
            "host": "cdn.amplitude.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Meta Pixel",
            "host": "www.facebook.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:36.113Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "spike",
      "category": "email-clients",
      "name": "Spike",
      "description": "Closed-source email app that shows messages as chat conversations and adds team chat, notes and video meetings, available for web, Windows, macOS, iOS and Android.",
      "website": "https://www.spikenow.com",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "ios",
        "android"
      ],
      "jurisdiction": {
        "code": "IL",
        "name": "Israel",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 17,
      "coverage": 100,
      "summary": "Spike scores 17 out of 100 (grade F) on the email clients criteria. It meets 1 of 8 criteria: works with any provider. It partly meets no ads or data sales and independent audit. It does not meet open source, no trackers or telemetry, OpenPGP support, connects directly and blocks remote content. It is based in Israel: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/email-clients/spike/",
      "markdown": "https://privacyratings.com/email-clients/spike/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.pingapp.app/latest/",
          "note": "Exodus finds AppsFlyer, Appcelerator Analytics and Firebase Analytics in the Android app, and the website loads Google, Facebook, LinkedIn and TikTok trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.spikenow.com/privacy-policy/",
          "note": "Funded by paid plans with no ads in the app, but the website shares visitor data with ad networks to promote Spike."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.spikenow.com/security/",
          "note": "Bishop Fox audited Spike, but no report is published and the audit is more than three years old."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "PGP is not supported."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.spikenow.com/privacy-policy/",
          "note": "Spike servers access and store account credentials, emails and contacts to provide the service."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No documented option to block remote images or tracking pixels."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.spikenow.com/help/setting-up-your-spike-account/",
          "note": "Works with Gmail, Office 365, Exchange, iCloud, Yahoo and any IMAP account."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Facebook SDK",
            "host": "connect.facebook.net",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:48.969Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "superhuman",
      "category": "email-clients",
      "name": "Superhuman Mail",
      "description": "Closed-source email client for Gmail and Microsoft 365 accounts with keyboard-driven triage, read statuses and AI writing features, available for desktop, web and mobile.",
      "website": "https://superhuman.com/mail",
      "license": null,
      "platforms": [
        "macos",
        "windows",
        "web",
        "ios",
        "android"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 14,
      "coverage": 100,
      "summary": "Superhuman Mail scores 14 out of 100 (grade F) on the email clients criteria. It partly meets no ads or data sales, independent audit and works with any provider. It does not meet open source, no trackers or telemetry, OpenPGP support, connects directly and blocks remote content. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/email-clients/superhuman/",
      "markdown": "https://privacyratings.com/email-clients/superhuman/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://superhuman.com/legal/privacy-policy",
          "note": "The website loads Google Tag Manager, HubSpot, FullStory, LinkedIn and TikTok trackers, and the policy describes advertising cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://superhuman.com/legal/privacy-policy",
          "note": "Funded by paid plans and user content is not sold, but identifiers are shared with advertising partners to promote Superhuman products."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://trust.superhuman.com/",
          "note": "SOC 2 Type 2 and ISO 27001 audits are listed, but the reports are available only on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No PGP or S/MIME support is documented."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "no",
          "evidence": "https://superhuman.com/legal/privacy-policy",
          "note": "The privacy policy states that Superhuman receives the emails and drafts the product is given access to."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No documented option to block remote images or tracking pixels."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://help.superhuman.com/hc/en-us/articles/46005777934733-Managing-Accounts",
          "note": "Works only with Gmail and Microsoft 365 accounts."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:48.908Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sylpheed",
      "category": "email-clients",
      "name": "Sylpheed",
      "description": "Lightweight GTK email client for Linux, Windows and macOS with POP3, IMAP and SMTP support, junk mail filtering and GnuPG encryption.",
      "website": "https://sylpheed.sraoss.jp/en/",
      "source": "https://github.com/sylpheed-mail/sylpheed",
      "license": null,
      "platforms": [
        "linux",
        "windows",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 72,
      "coverage": 100,
      "summary": "Sylpheed scores 72 out of 100 (grade C) on the email clients criteria. It meets 6 of 8 criteria: open source, no ads or data sales, OpenPGP support, connects directly, blocks remote content and works with any provider. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/email-clients/sylpheed/",
      "markdown": "https://privacyratings.com/email-clients/sylpheed/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sylpheed-mail/sylpheed/blob/main/LICENSE",
          "note": "GPL-2.0, with the LibSylph library under LGPL."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://sylpheed.sraoss.jp/en/",
          "note": "The application has no telemetry, but the website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://sylpheed.sraoss.jp/en/",
          "note": "Free software. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://sylpheed.sraoss.jp/en/features.html",
          "note": "Signing and encryption with GnuPG are built in."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://sylpheed.sraoss.jp/en/features.html",
          "note": "Connects directly to POP3, IMAP and SMTP servers. No vendor service is involved."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sylpheed-mail/sylpheed/blob/main/libsylph/html.c",
          "note": "HTML mail is converted to plain text for display, so remote content is never loaded."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://sylpheed.sraoss.jp/en/features.html",
          "note": "Works with any POP3, IMAP and SMTP provider."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:48.733Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "thunderbird-for-android",
      "category": "email-clients",
      "name": "Thunderbird for Android",
      "description": "Open-source email app for Android from the Thunderbird project, based on K-9 Mail, which remains available as a variant. Works with any IMAP, POP3 and SMTP provider.",
      "website": "https://www.thunderbird.net/en-US/mobile/",
      "source": "https://github.com/thunderbird/thunderbird-android",
      "license": "Apache-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 89,
      "coverage": 100,
      "summary": "Thunderbird for Android scores 89 out of 100 (grade B) on the email clients criteria. It meets 6 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, connects directly, blocks remote content and works with any provider. It partly meets independent audit and OpenPGP support. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/email-clients/thunderbird-for-android/",
      "markdown": "https://privacyratings.com/email-clients/thunderbird-for-android/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/thunderbird/thunderbird-android/blob/main/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://support.mozilla.org/en-US/kb/thunderbird-android-telemetry",
          "note": "Collects no telemetry, and any future telemetry is opt-in. Exodus finds 0 trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.thunderbird.net/en-US/mobile/",
          "note": "Free app funded by donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://7asecurity.com/reports/pentest-report_k-9_mail.pdf",
          "note": "7ASecurity audited K-9 Mail, now Thunderbird for Android, with OSTIF and published the full report, but it is more than three years old. The app also passes Google's annual CASA Tier 2 assessment, and only the certification is public (github.com/thunderbird/thunderbird-android/security)."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://docs.k9mail.app/en/6.400/security/pgp/",
          "note": "PGP needs the separate OpenKeychain app."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.mozilla.org/en-US/privacy/thunderbird/",
          "note": "Connects directly to mail servers. Mail, contacts and account details stay on the device."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.k9mail.app/en/6.400/settings/account/#always-show-images",
          "note": "Images load only after tapping Show pictures unless the user changes this setting."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.k9mail.app/en/6.400/accounts/incoming_imap/",
          "note": "Works with any IMAP, POP3 and SMTP provider."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:27.960Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "afterlogic-webmail-lite",
      "category": "webmail",
      "name": "Afterlogic WebMail Lite",
      "description": "Self-hosted, open-source PHP webmail for an existing IMAP server, with contacts, OpenPGP in the browser and a module system. A paid Pro edition adds more features.",
      "website": "https://afterlogic.org/webmail-lite",
      "source": "https://github.com/afterlogic/webmail-lite-8",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 74,
      "coverage": 100,
      "summary": "Afterlogic WebMail Lite scores 74 out of 100 (grade C) on the webmail criteria. It meets 7 of 9 criteria: open source, no ads or data sales, OpenPGP support, connects directly, blocks remote content, works with any provider and self-hostable. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/webmail/afterlogic-webmail-lite/",
      "markdown": "https://privacyratings.com/webmail/afterlogic-webmail-lite/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/afterlogic/webmail-lite-8/blob/master/LICENSE",
          "note": "AGPL-3.0, with a commercial license also offered."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Analytics and Google ad tracking (DoubleClick)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://afterlogic.org/webmail-lite",
          "note": "Free edition of a product funded by the paid Pro edition and support. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://afterlogic.org/webmail-lite",
          "note": "OpenPGP encryption and signing are built in and run in the browser."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://afterlogic.com/docs/webmail-lite-8/installation/installation-instructions",
          "note": "Self-hosted. Connects from the server where it is installed directly to the IMAP and SMTP servers, with no vendor service involved."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/afterlogic/aurora-module-mail/blob/master/Settings.php",
          "note": "The AlwaysShowImagesInMessage setting is off by default, so external images load only on request."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://afterlogic.org/webmail-lite",
          "note": "Works with any IMAP and SMTP server."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://afterlogic.com/docs/webmail-lite-8/installation/installation-instructions",
          "note": "Self-hosted software with an official installation guide."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google DoubleClick",
            "host": "googleads.g.doubleclick.net",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:34.820Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cypht",
      "category": "webmail",
      "name": "Cypht",
      "description": "Self-hosted, open-source webmail that combines several IMAP, JMAP and SMTP accounts, plus feeds, in one interface, built from optional modules.",
      "website": "https://www.cypht.org",
      "source": "https://github.com/cypht-org/cypht",
      "license": "LGPL-2.1",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 84,
      "coverage": 100,
      "summary": "Cypht scores 84 out of 100 (grade B) on the webmail criteria. It meets 7 of 9 criteria: open source, no trackers or telemetry, no ads or data sales, connects directly, blocks remote content, works with any provider and self-hostable. It partly meets OpenPGP support. It does not meet independent audit.",
      "url": "https://privacyratings.com/webmail/cypht/",
      "markdown": "https://privacyratings.com/webmail/cypht/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cypht-org/cypht/blob/master/LICENSE",
          "note": "LGPL-2.1."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cypht-org/cypht",
          "note": "No telemetry or analytics in the source code. Error reporting to a GlitchTip server runs only when the administrator configures one."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/cypht-org/cypht",
          "note": "Free open-source software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/cypht-org/cypht/blob/master/modules/pgp/README.md",
          "note": "PGP signing and encryption come from a bundled module that is experimental and off by default."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cypht-org/cypht",
          "note": "Self-hosted. Connects from the server where it is installed directly to the IMAP and SMTP servers, with no vendor service involved."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/cypht-org/cypht/blob/master/.env.example",
          "note": "External image sources are disabled by default with ALLOW_EXTERNAL_IMAGE_SOURCES=false."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/cypht-org/cypht",
          "note": "Works with any IMAP, JMAP and SMTP server."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.cypht.org/install/",
          "note": "Self-hosted software with an official installation guide."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:34.291Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "forward-email-webmail",
      "category": "webmail",
      "name": "Forward Email Webmail",
      "description": "Hosted webmail for Forward Email accounts, with mail, calendar and contacts, built-in OpenPGP and optional encryption of locally cached data. It shares one source-available codebase with the Forward Email desktop and mobile apps.",
      "website": "https://mail.forwardemail.net",
      "source": "https://github.com/forwardemail/mail.forwardemail.net",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": true,
      "pick_reason": "Source-available webmail with built-in OpenPGP and no third-party analytics, covered by Cure53's audit. It works only with Forward Email accounts, not other IMAP and SMTP providers.",
      "disclosure": "Privacy Ratings is maintained by the team behind Forward Email. This entry is scored by the same criteria as every other entry in this category, and changes to it are reviewed under the published conflict-of-interest rules.",
      "grade": "C",
      "score": 74,
      "coverage": 100,
      "summary": "Forward Email Webmail scores 74 out of 100 (grade C) on the webmail criteria. It meets 6 of 13 criteria: open source, no ads or data sales, independent audit, tells users about requests, OpenPGP support and connects directly. It partly meets no trackers or telemetry, transparency report, TLS configuration, security headers, blocks remote content and self-hostable. It does not meet works with any provider. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/webmail/forward-email-webmail/",
      "markdown": "https://privacyratings.com/webmail/forward-email-webmail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/forwardemail/mail.forwardemail.net/blob/main/LICENSE.md",
          "note": "All code is public. The webmail app is under the source-available Business Source License 1.1, which becomes MPL-2.0 four years after each release, and the Forward Email service behind it is published under MPL-2.0 and BUSL-1.1."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://forwardemail.net/en/privacy#analytics",
          "note": "No third-party analytics in the webmail. The privacy policy describes first-party anonymized analytics of page views and service usage, including API use, that is on by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/privacy",
          "note": "Funded by paid plans. No ads, and user data is not shared with third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cure53.de/pentest-report_forward-email.pdf",
          "note": "Cure53 audited the webmail source code, including its client-side logic, together with the Forward Email service."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://forwardemail.net/technical-whitepaper.pdf",
          "note": "The technical whitepaper (section 9.3) publishes the government request policy and commits to transparency reports with request counts. A report with counts is not published yet."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://forwardemail.net/technical-whitepaper.pdf",
          "note": "Users are notified of requests when legally allowed, with notice after disclosure when advance notice is prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mail.forwardemail.net&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mail.forwardemail.net",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/forwardemail/mail.forwardemail.net/blob/main/src/utils/pgp-send.ts",
          "note": "OpenPGP encryption and signing are built in."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/forwardemail/mail.forwardemail.net/blob/main/README.md",
          "note": "The browser connects directly to the Forward Email API, which is the mail server, with no separate sync service."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/forwardemail/mail.forwardemail.net/blob/main/src/stores/settingsRegistry.ts",
          "note": "Tracking pixels are blocked by default, but other remote images load unless blocking is turned on in settings."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "no",
          "evidence": "https://forwardemail.net/en/faq#do-you-offer-a-webmail-client",
          "note": "Works only with Forward Email accounts. The maintainers state that a future version is planned to support any IMAP and SMTP provider."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://github.com/forwardemail/mail.forwardemail.net/blob/main/README.md",
          "note": "The static web app can be built and served from another server, with a configurable API address, but there is no official self-hosting guide and it only works with the Forward Email API."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:06:27.819Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "horde-groupware",
      "category": "webmail",
      "name": "Horde Groupware Webmail Edition",
      "description": "Self-hosted, open-source groupware suite built on the Horde framework, with the IMP webmail client, mail filters, calendar, contacts, tasks and notes.",
      "website": "https://www.horde.org/apps/webmail/",
      "source": "https://github.com/horde/imp",
      "license": "GPL-2.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 89,
      "coverage": 100,
      "summary": "Horde Groupware Webmail Edition scores 89 out of 100 (grade B) on the webmail criteria. It meets 8 of 9 criteria: open source, no trackers or telemetry, no ads or data sales, OpenPGP support, connects directly, blocks remote content, works with any provider and self-hostable. It does not meet independent audit.",
      "url": "https://privacyratings.com/webmail/horde-groupware/",
      "markdown": "https://privacyratings.com/webmail/horde-groupware/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/horde/imp/blob/FRAMEWORK_6_0/LICENSE",
          "note": "GPL-2.0, with the Horde framework libraries under LGPL."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/horde/imp",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.horde.org/apps/webmail/",
          "note": "Free open-source software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.horde.org/apps/webmail/",
          "note": "PGP and S/MIME encryption and signing are built into IMP, using GnuPG on the server once the administrator configures it."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/horde/imp",
          "note": "Self-hosted. Connects from the server where it is installed directly to the IMAP and SMTP servers, with no vendor service involved."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/horde/imp/blob/FRAMEWORK_6_0/config/prefs.php",
          "note": "The default image_replacement preference shows inline images and blocks remote images."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/horde/imp/blob/FRAMEWORK_6_0/doc/INSTALL.rst",
          "note": "Works with any IMAP, POP3 and SMTP server."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/horde/imp/blob/FRAMEWORK_6_0/doc/INSTALL.rst",
          "note": "Self-hosted software with an official installation guide."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:34.760Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nextcloud-mail",
      "category": "webmail",
      "name": "Nextcloud Mail",
      "description": "Open-source mail app for self-hosted Nextcloud servers that adds webmail for any IMAP account, with S/MIME, Mailvelope support and integration with Nextcloud contacts and calendar.",
      "website": "https://apps.nextcloud.com/apps/mail",
      "source": "https://github.com/nextcloud/mail",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 84,
      "coverage": 100,
      "summary": "Nextcloud Mail scores 84 out of 100 (grade B) on the webmail criteria. It meets 7 of 9 criteria: open source, no trackers or telemetry, no ads or data sales, connects directly, blocks remote content, works with any provider and self-hostable. It partly meets OpenPGP support. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/webmail/nextcloud-mail/",
      "markdown": "https://privacyratings.com/webmail/nextcloud-mail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nextcloud/mail/blob/main/COPYING",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nextcloud/mail",
          "note": "No telemetry or analytics in the source code, and the app store page loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://nextcloud.com/pricing/",
          "note": "Free software funded by Nextcloud enterprise subscriptions. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit of the Mail app is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/nextcloud/mail/blob/main/README.md",
          "note": "OpenPGP works through the Mailvelope browser extension. S/MIME is built in."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://docs.nextcloud.com/server/latest/admin_manual/groupware/mail.html",
          "note": "Self-hosted. Connects from the Nextcloud server directly to the IMAP and SMTP servers, with no vendor service involved."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/nextcloud/mail/blob/main/lib/Service/HtmlPurify/TransformImageSrc.php",
          "note": "External images are proxied and hidden until the user chooses to show them, and tracking pixels are blocked."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.nextcloud.com/server/latest/admin_manual/groupware/mail.html",
          "note": "Works with any IMAP and SMTP server."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.nextcloud.com/server/latest/admin_manual/groupware/mail.html",
          "note": "Installed as an app on a self-hosted Nextcloud server, with official administrator documentation."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:43.772Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "roundcube",
      "category": "webmail",
      "name": "RoundCube",
      "description": "Browser-based multilingual IMAP client with an application-like user interface.",
      "website": "https://roundcube.net",
      "source": "https://github.com/roundcube/roundcubemail",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 84,
      "coverage": 100,
      "summary": "RoundCube scores 84 out of 100 (grade B) on the webmail criteria. It meets 7 of 9 criteria: open source, no trackers or telemetry, no ads or data sales, connects directly, blocks remote content, works with any provider and self-hostable. It partly meets OpenPGP support. It does not meet independent audit.",
      "url": "https://privacyratings.com/webmail/roundcube/",
      "markdown": "https://privacyratings.com/webmail/roundcube/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/roundcube/roundcubemail/blob/master/LICENSE.md",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/roundcube/roundcubemail",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://roundcube.net/about/",
          "note": "Free software developed with support from Nextcloud and hosting partners. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/roundcube/roundcubemail/blob/master/plugins/enigma/README",
          "note": "PGP needs the bundled Enigma plugin enabled by the server admin, or the Mailvelope browser extension."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/roundcube/roundcubemail",
          "note": "Self-hosted. Connects from the server where it is installed directly to the IMAP and SMTP servers, with no vendor service involved."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/roundcube/roundcubemail/blob/master/config/defaults.inc.php",
          "note": "The default show_images setting never loads remote images without asking."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/roundcube/roundcubemail",
          "note": "Works with any IMAP and SMTP server."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/roundcube/roundcubemail/blob/master/docs/INSTALL.md",
          "note": "Self-hosted software with an official installation guide."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:28.206Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "snappymail",
      "category": "webmail",
      "name": "SnappyMail",
      "description": "Self-hosted, IMAP-only webmail client forked from RainLoop, with built-in OpenPGP support.",
      "website": "https://snappymail.eu",
      "source": "https://github.com/the-djmaze/snappymail",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 89,
      "coverage": 100,
      "summary": "SnappyMail scores 89 out of 100 (grade B) on the webmail criteria. It meets 8 of 9 criteria: open source, no trackers or telemetry, no ads or data sales, OpenPGP support, connects directly, blocks remote content, works with any provider and self-hostable. It does not meet independent audit.",
      "url": "https://privacyratings.com/webmail/snappymail/",
      "markdown": "https://privacyratings.com/webmail/snappymail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/the-djmaze/snappymail/blob/master/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/the-djmaze/snappymail/blob/master/README.md",
          "note": "No telemetry or analytics in the source code. Sentry error tracking and social integrations from RainLoop were removed."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/the-djmaze/snappymail",
          "note": "Free open-source software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/the-djmaze/snappymail/blob/master/README.md",
          "note": "OpenPGP is built in through OpenPGP.js and GnuPG, with optional Mailvelope support."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/the-djmaze/snappymail",
          "note": "Self-hosted. Connects from the server where it is installed directly to the IMAP and SMTP servers, with no vendor service involved."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/the-djmaze/snappymail/blob/master/snappymail/v/0.0.0/app/libraries/RainLoop/Config/Application.php",
          "note": "The default view_images setting asks before loading external images."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/the-djmaze/snappymail",
          "note": "Works with any IMAP and SMTP server."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/the-djmaze/snappymail/wiki/Installation-instructions",
          "note": "Self-hosted software with official installation instructions."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:58.207Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sogo",
      "category": "webmail",
      "name": "SOGo",
      "description": "Self-hosted, open-source groupware server with webmail, calendars and address books, supporting CalDAV, CardDAV and ActiveSync. It uses an existing IMAP server for mail.",
      "website": "https://www.sogo.nu",
      "source": "https://github.com/Alinto/sogo",
      "license": "GPL-2.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 63,
      "coverage": 100,
      "summary": "SOGo scores 63 out of 100 (grade C) on the webmail criteria. It meets 6 of 9 criteria: open source, no ads or data sales, connects directly, blocks remote content, works with any provider and self-hostable. It does not meet no trackers or telemetry, independent audit and OpenPGP support.",
      "url": "https://privacyratings.com/webmail/sogo/",
      "markdown": "https://privacyratings.com/webmail/sogo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Alinto/sogo/blob/master/COPYING.GPL",
          "note": "GPL-2.0, with libraries under LGPL-2.1."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Analytics. The self-hosted software itself has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.sogo.nu/support.html",
          "note": "Free software funded by commercial support subscriptions from Alinto. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "OpenPGP is not supported. Only S/MIME signing and encryption are built in."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.sogo.nu/files/docs/SOGoInstallationGuide.html",
          "note": "Self-hosted. Connects from the server where it is installed directly to the IMAP and SMTP servers, with no vendor service involved."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Alinto/sogo/blob/master/SoObjects/SOGo/SOGoDefaults.plist",
          "note": "The default SOGoMailDisplayRemoteInlineImages setting is never, so remote images load only on request."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.sogo.nu/files/docs/SOGoInstallationGuide.html",
          "note": "Works with any IMAP and SMTP server configured by the administrator."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.sogo.nu/files/docs/SOGoInstallationGuide.html",
          "note": "Self-hosted software with an official installation guide."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:35.264Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "squirrelmail",
      "category": "webmail",
      "name": "SquirrelMail",
      "description": "Self-hosted PHP webmail with built-in IMAP and SMTP support that renders plain HTML pages without JavaScript and is extended through plugins.",
      "website": "https://squirrelmail.org",
      "source": "https://sourceforge.net/p/squirrelmail/code/",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 79,
      "coverage": 100,
      "summary": "SquirrelMail scores 79 out of 100 (grade B) on the webmail criteria. It meets 7 of 9 criteria: open source, no trackers or telemetry, no ads or data sales, connects directly, blocks remote content, works with any provider and self-hostable. It does not meet independent audit and OpenPGP support.",
      "url": "https://privacyratings.com/webmail/squirrelmail/",
      "markdown": "https://privacyratings.com/webmail/squirrelmail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://squirrelmail.org/about/",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://squirrelmail.org/download.php",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://squirrelmail.org/about/",
          "note": "Free software supported by donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Not supported. The third-party GPG plugin does not work with current versions."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://squirrelmail.org/about/",
          "note": "Self-hosted. Connects from the server where it is installed directly to the IMAP and SMTP servers, with no vendor service involved."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://squirrelmail.org/download.php",
          "note": "The source code blocks remote images in HTML mail until the user chooses to view unsafe images."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://squirrelmail.org/about/",
          "note": "Works with any IMAP and SMTP server."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://squirrelmail.org/docs/admin/admin.html",
          "note": "Self-hosted software with an official administrator guide."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:35.488Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "zimbra",
      "category": "webmail",
      "name": "Zimbra Collaboration",
      "description": "Self-hosted email and collaboration server from Synacor, with a web client for mail, calendar, contacts and files. An open-source edition and a commercial Network Edition with extra features are offered.",
      "website": "https://www.zimbra.com",
      "source": "https://github.com/Zimbra/zm-web-client",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Zimbra Collaboration scores 50 out of 100 (grade D) on the webmail criteria. It meets 4 of 9 criteria: no ads or data sales, connects directly, blocks remote content and self-hostable. It partly meets open source. It does not meet no trackers or telemetry, independent audit, OpenPGP support and works with any provider. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/webmail/zimbra/",
      "markdown": "https://privacyratings.com/webmail/zimbra/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.zimbra.com/product/licenses-and-terms-of-use/",
          "note": "The open-source edition, including the web client, is public under CPAL-1.0 and GPL-2.0, but the commercial Network Edition adds closed-source features."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Analytics, HubSpot and New Relic."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.zimbra.com/product/edition-comparison/",
          "note": "Funded by commercial licenses and support. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "openpgp": {
          "title": "OpenPGP support",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "OpenPGP is not supported. S/MIME is offered in the Network Edition."
        },
        "no_cloud_relay": {
          "title": "Connects directly",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://zimbra.github.io/installguides/latest/single.html",
          "note": "Self-hosted. The web client talks to the Zimbra server where it is installed, with no vendor service involved."
        },
        "remote_content_blocked": {
          "title": "Blocks remote content",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Zimbra/zm-web-client/blob/develop/WebRoot/js/zimbraMail/mail/ZmMailApp.js",
          "note": "The zimbraPrefDisplayExternalImages preference is off by default, so external images load only on request."
        },
        "any_provider": {
          "title": "Works with any provider",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "The web client works only with a Zimbra server. Other IMAP and POP3 accounts can only be pulled into a Zimbra mailbox."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://zimbra.github.io/installguides/latest/single.html",
          "note": "Self-hosted software with an official installation guide."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          },
          {
            "name": "TrustArc",
            "host": "consent.trustarc.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:35.112Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dkim-verifier",
      "category": "email-security-tools",
      "name": "DKIM Verifier",
      "description": "Thunderbird add-on that verifies DKIM signatures and shows the result in the message header, to help spot spoofed email.",
      "website": "https://addons.thunderbird.net/en-US/thunderbird/addon/dkim-verifier/",
      "source": "https://github.com/lieser/dkim_verifier",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "DKIM Verifier scores 80 out of 100 (grade B) on the email security tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/email-security-tools/dkim-verifier/",
      "markdown": "https://privacyratings.com/email-security-tools/dkim-verifier/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/lieser/dkim_verifier/blob/master/LICENSE.txt",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/lieser/dkim_verifier",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/lieser/dkim_verifier",
          "note": "Free open-source add-on with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:30.897Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "email-privacy-tester",
      "category": "email-security-tools",
      "name": "Email Privacy Tester",
      "description": "Tests whether your mail client \"reads\" emails before you open them, and what analytics, read-receipts or other tracking data it leaks back to the sender.",
      "website": "https://www.emailprivacytester.com",
      "source": "https://gitlab.com/grepular/ept3",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Email Privacy Tester scores 80 out of 100 (grade B) on the email security tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/email-security-tools/email-privacy-tester/",
      "markdown": "https://privacyratings.com/email-security-tools/email-privacy-tester/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/grepular/ept3/-/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.emailprivacytester.com/privacy",
          "note": "The site uses no cookies and makes no cross-origin requests to third parties."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.emailprivacytester.com/donate",
          "note": "Funded by donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:31.997Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "paperweight",
      "category": "email-security-tools",
      "name": "Paperweight",
      "description": "Local-first desktop app that scans an inbox to list the services holding your data, then helps unsubscribe and send data deletion requests.",
      "website": "https://www.paperweight.email",
      "source": "https://github.com/wslyvh/paperweight",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Paperweight scores 80 out of 100 (grade B) on the email security tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/email-security-tools/paperweight/",
      "markdown": "https://privacyratings.com/email-security-tools/paperweight/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/wslyvh/paperweight/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/wslyvh/paperweight",
          "note": "No telemetry or analytics in the app's source code. The website uses cookieless Umami analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.paperweight.email/pricing",
          "note": "Funded by paid Pro plans. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:32.214Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "amavis",
      "category": "spam-filters",
      "name": "Amavis",
      "description": "Self-hosted content filter written in Perl that sits between a mail server and scanners such as SpamAssassin and ClamAV, passing each message to them and acting on the results.",
      "website": "https://www.amavis.org",
      "source": "https://gitlab.com/amavis/amavis",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Amavis scores 80 out of 100 (grade B) on the spam and virus filtering criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/spam-filters/amavis/",
      "markdown": "https://privacyratings.com/spam-filters/amavis/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/amavis/amavis/-/blob/master/LICENSE",
          "note": "Licensed under the GNU GPL version 2."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/amavis/amavis",
          "note": "No telemetry or analytics in the source code, and the project website loads no analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.amavis.org/",
          "note": "Free software maintained by volunteers, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:36.280Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "check-point-harmony-email",
      "category": "spam-filters",
      "name": "Check Point Email Security",
      "description": "Cloud email security service from Check Point, formerly Harmony Email & Collaboration and Avanan. It connects to Microsoft 365 and Google Workspace by API to filter phishing, malware and spam before messages reach the inbox.",
      "website": "https://www.checkpoint.com/harmony/email-security/",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "IL",
        "name": "Israel",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 28,
      "coverage": 100,
      "summary": "Check Point Email Security scores 28 out of 100 (grade F) on the spam and virus filtering criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales, independent audit and security headers. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in Israel: Not in the Five, Nine or Fourteen Eyes. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/spam-filters/check-point-harmony-email/",
      "markdown": "https://privacyratings.com/spam-filters/check-point-harmony-email/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.checkpoint.com/privacy/",
          "note": "The website loads Google Tag Manager, and the privacy policy allows third parties to collect data through cookies for analytics and advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.checkpoint.com/privacy/",
          "note": "Paid business service with no ads, but the privacy policy lets third parties collect website data through cookies for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.checkpoint.com/about-us/product-certifications/",
          "note": "Check Point lists ISO/IEC 27000-series certifications and SOC 2 reports for some cloud services, but no audit report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.checkpoint.com/privacy/",
          "note": "No transparency report or government request policy is published. The privacy policy only says data may be disclosed to comply with legal process."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=portal.checkpoint.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=portal.checkpoint.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Drift",
            "host": "js.driftt.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          },
          {
            "name": "VWO",
            "host": "dev.visualwebsiteoptimizer.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:06:27.956Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "duocircle",
      "category": "spam-filters",
      "name": "DuoCircle",
      "description": "Email services company whose products include cloud spam and phishing filtering, backup MX, email forwarding, outbound SMTP relay, and SPF and DMARC management.",
      "website": "https://www.duocircle.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "DuoCircle scores 38 out of 100 (grade F) on the spam and virus filtering criteria. It meets 2 of 8 criteria: tells users about requests and TLS configuration. It partly meets no ads or data sales, independent audit and transparency report. It does not meet open source, no trackers or telemetry and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/spam-filters/duocircle/",
      "markdown": "https://privacyratings.com/spam-filters/duocircle/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.duocircle.com/legal/cookies/",
          "note": "The website uses Google Analytics 4, plus Google Ads, Meta, LinkedIn and Microsoft Advertising cookies when accepted."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.duocircle.com/legal/cookies/",
          "note": "Paid service with no ads, and the privacy notice says personal data is not sold. The website uses Google, Meta, LinkedIn and Microsoft ad cookies to measure its own ad campaigns."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://trust.duocircle.com/compliance/",
          "note": "SOC 2 Type II examinations by Hancock Askew & Co are done yearly, but the report is only shared under NDA."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.duocircle.com/legal/legal-requests/",
          "note": "A legal request response policy describes the process and legal standards required, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.duocircle.com/legal/legal-requests/",
          "note": "The policy promises to notify the affected customer before producing data, unless notice is prohibited by law."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=portal.duocircle.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=portal.duocircle.com",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:06:28.002Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "egress",
      "category": "spam-filters",
      "name": "Egress",
      "description": "Cloud email security for Microsoft 365 and Google Workspace from Egress, a KnowBe4 company, covering inbound phishing detection, outbound data loss prevention and email encryption.",
      "website": "https://www.egress.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 16,
      "coverage": 100,
      "summary": "Egress scores 16 out of 100 (grade F) on the spam and virus filtering criteria. It partly meets no ads or data sales, TLS configuration and security headers. It does not meet open source, no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/spam-filters/egress/",
      "markdown": "https://privacyratings.com/spam-filters/egress/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.knowbe4.com/legal/website-privacy-notice",
          "note": "The website loads Google Tag Manager and HubSpot, and the KnowBe4 privacy notice lists Google Analytics, AdRoll and Microsoft advertising tracking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.knowbe4.com/legal/website-privacy-notice",
          "note": "Funded by paid subscriptions and personal data is not sold, but website visitor data is shared with AdRoll and Microsoft for retargeting ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=switch.egress.com&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=switch.egress.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:06:28.053Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "heimdal-email-security",
      "category": "spam-filters",
      "name": "Heimdal Email Security",
      "description": "Cloud email filtering from Heimdal, a Danish security company, that blocks spam, phishing, malware and business email compromise, managed from the Heimdal dashboard alongside its endpoint security products.",
      "website": "https://heimdalsecurity.com/enterprise-security/products/email-security",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DK",
        "name": "Denmark",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 19,
      "coverage": 100,
      "summary": "Heimdal Email Security scores 19 out of 100 (grade F) on the spam and virus filtering criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in Denmark: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/spam-filters/heimdal-email-security/",
      "markdown": "https://privacyratings.com/spam-filters/heimdal-email-security/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://heimdalsecurity.com/enterprise-security/products/email-security",
          "note": "The website loads Google Analytics, Microsoft Clarity, LinkedIn, Bing, Reddit, Capterra and G2 tags through Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://heimdalsecurity.com/enterprise-security/products/email-security",
          "note": "Funded by paid subscriptions, but the website shares visitor data with Google Ads, LinkedIn, Bing and Reddit to advertise its own products."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published. Heimdal states SOC 2 Type II certification, but the report is not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=dashboard.heimdalsecurity.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=dashboard.heimdalsecurity.com",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "VWO",
            "host": "dev.visualwebsiteoptimizer.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:06:28.096Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "libraesva",
      "category": "spam-filters",
      "name": "Libraesva",
      "description": "Email security gateway from an Italian vendor, deployed on premises or in a private cloud, that filters spam, phishing and malware with local sandboxing and AI models. The company also sells email archiving, DMARC management and phishing training.",
      "website": "https://www.libraesva.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "IT",
        "name": "Italy",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Libraesva scores 20 out of 100 (grade F) on the spam and virus filtering criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in Italy: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/spam-filters/libraesva/",
      "markdown": "https://privacyratings.com/spam-filters/libraesva/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.libraesva.com/privacy-policy",
          "note": "The website loads Google Tag Manager, and the privacy policy says browsing data may be used to build customer profiles."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.libraesva.com/privacy-policy",
          "note": "Paid product with no ads. The privacy policy says data is not shared with third parties other than regional partners."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:36.459Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mailinblack",
      "category": "spam-filters",
      "name": "Mailinblack",
      "description": "French cloud email security service that filters spam, phishing, ransomware and malicious links for business mailboxes, sold with a password manager and security awareness training.",
      "website": "https://www.mailinblack.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 19,
      "coverage": 100,
      "summary": "Mailinblack scores 19 out of 100 (grade F) on the spam and virus filtering criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/spam-filters/mailinblack/",
      "markdown": "https://privacyratings.com/spam-filters/mailinblack/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.mailinblack.com/cookies/",
          "note": "The website loads Google Tag Manager, HubSpot, LinkedIn and Cloudflare Web Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.mailinblack.com/politique-de-confidentialite/",
          "note": "Funded by paid subscriptions, but the privacy policy covers targeted advertising based on prospect and visitor data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.mailinblack.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.mailinblack.com",
          "note": "Grade D- (25/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-analytics.net",
            "effect": "no"
          },
          {
            "name": "Matomo Cloud",
            "host": "cdn.matomo.cloud",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:06:28.143Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mailscanner",
      "category": "spam-filters",
      "name": "MailScanner",
      "description": "Self-hosted email security system written in Perl that scans mail for spam, viruses and phishing using SpamAssassin and antivirus engines, with Postfix, Sendmail and Exim.",
      "website": "https://github.com/MailScanner/v5",
      "source": "https://github.com/MailScanner/v5",
      "license": "GPL-2.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "MailScanner scores 80 out of 100 (grade B) on the spam and virus filtering criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/spam-filters/mailscanner/",
      "markdown": "https://privacyratings.com/spam-filters/mailscanner/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/MailScanner/v5/blob/master/LICENSE",
          "note": "Licensed under the GNU GPL version 2."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/MailScanner/v5",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/MailScanner/v5",
          "note": "Free software maintained by volunteers, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:35.858Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "microsoft-defender-for-office-365",
      "category": "spam-filters",
      "name": "Microsoft Defender for Office 365",
      "description": "Email and collaboration security add-on for Microsoft 365 that scans mail, links and attachments for phishing and malware on top of Exchange Online Protection spam filtering. It also covers Teams, SharePoint and OneDrive.",
      "website": "https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-office-365",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Microsoft Defender for Office 365 scores 50 out of 100 (grade D) on the spam and virus filtering criteria. It meets 4 of 8 criteria: no ads or data sales, transparency report, tells users about requests and TLS configuration. It partly meets independent audit. It does not meet open source, no trackers or telemetry and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B-.",
      "url": "https://privacyratings.com/spam-filters/microsoft-defender-for-office-365/",
      "markdown": "https://privacyratings.com/spam-filters/microsoft-defender-for-office-365/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "Microsoft collects required diagnostic data from its products that cannot be turned off, and its websites use analytics and advertising cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/trust-center/privacy",
          "note": "Paid business service with no ads. Microsoft states it does not use customer data from its cloud services for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2",
          "note": "Office 365 is covered by yearly SOC 2 Type 2 audits, but the full reports are only available through the Service Trust Portal after sign-in."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Publishes counts of government requests for consumer and enterprise customer data twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Microsoft gives prior notice to enterprise customers of requests for their data, except where prohibited by law."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=security.microsoft.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=security.microsoft.com",
          "note": "Grade B- (65/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:06:28.190Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "n-able-mail-assure",
      "category": "spam-filters",
      "name": "N-able Mail Assure",
      "description": "Cloud email security service sold to managed service providers that filters inbound and outbound mail for spam, phishing and malware, with email continuity and encrypted archiving. It works with Microsoft 365 and other mail servers.",
      "website": "https://www.n-able.com/products/mail-assure",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "N-able Mail Assure scores 25 out of 100 (grade F) on the spam and virus filtering criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales and independent audit. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/spam-filters/n-able-mail-assure/",
      "markdown": "https://privacyratings.com/spam-filters/n-able-mail-assure/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.n-able.com/legal/privacy",
          "note": "The privacy notice says website data is shared with advertising and analytics partners."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.n-able.com/legal/privacy",
          "note": "Paid service with no ads, and N-able says it does not sell personal information, but website data is shared with advertising partners for campaign measurement."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.n-able.com/trust-center",
          "note": "N-able has a SOC 2 Type II report and ISO/IEC 27001 certification from Schellman, but the report is not public and Mail Assure is not named in scope."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.n-able.com/legal/privacy",
          "note": "No transparency report or government request policy is published. The privacy notice only says data may be disclosed in response to subpoenas and court orders."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=securemail.management&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=securemail.management",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "VWO",
            "host": "dev.visualwebsiteoptimizer.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:06:28.244Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "oopspam",
      "category": "spam-filters",
      "name": "OOPSpam",
      "description": "Anti-spam API that scores form submissions, comments, sign-ups and messages for spam and fraud using machine learning, IP and email reputation checks. Plugins connect it to WordPress, form builders and other platforms.",
      "website": "https://www.oopspam.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 19,
      "coverage": 100,
      "summary": "OOPSpam scores 19 out of 100 (grade F) on the spam and virus filtering criteria. It meets 1 of 8 criteria: no ads or data sales. It partly meets TLS configuration. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/spam-filters/oopspam/",
      "markdown": "https://privacyratings.com/spam-filters/oopspam/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. Only integration plugins are published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.oopspam.com/privacypolicy",
          "note": "The privacy policy names Cabin and Microsoft Clarity for website analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.oopspam.com/gdpr",
          "note": "Funded by paid API plans billed through Paddle, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.oopspam.com/privacypolicy",
          "note": "No transparency report or government request policy is published. The privacy policy only says data may be disclosed to comply with a legal obligation."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.oopspam.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.oopspam.com",
          "note": "Grade D- (25/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:06:28.324Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "proofpoint-email-protection",
      "category": "spam-filters",
      "name": "Proofpoint Email Protection",
      "description": "Secure email gateway for organizations that filters inbound and outbound mail for spam, phishing, malware and impersonation. It runs as a cloud service or on premises in front of Microsoft 365, Google Workspace or other mail servers.",
      "website": "https://www.proofpoint.com/us/products/email-protection",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 41,
      "coverage": 100,
      "summary": "Proofpoint Email Protection scores 41 out of 100 (grade D) on the spam and virus filtering criteria. It meets 2 of 8 criteria: tells users about requests and TLS configuration. It partly meets no ads or data sales, independent audit, transparency report and security headers. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/spam-filters/proofpoint-email-protection/",
      "markdown": "https://privacyratings.com/spam-filters/proofpoint-email-protection/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.proofpoint.com/us/legal/privacy-policy",
          "note": "The website uses third-party analytics and a DoubleClick advertising tag, and the privacy policy describes behavioral retargeting by an ad partner."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.proofpoint.com/us/legal/privacy-policy",
          "note": "Paid business service with no ads, but a third-party partner uses website cookies to retarget visitors with Proofpoint ads on other sites."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.proofpoint.com/us/legal/trust/faqs",
          "note": "Proofpoint holds ISO 27001 certification for in-scope products, but no audit report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.proofpoint.com/us/legal/trust/information-disclosure-and-law-enforcement-statement",
          "note": "A law enforcement statement describes legal review of each request and challenges to overbroad ones, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.proofpoint.com/us/legal/trust/information-disclosure-and-law-enforcement-statement",
          "note": "Proofpoint promises to promptly notify affected customers of requests whenever permitted by law."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=admin.proofpoint.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=admin.proofpoint.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Ads",
            "host": "www.googleadservices.com",
            "effect": "no"
          },
          {
            "name": "Google DoubleClick",
            "host": "googleads.g.doubleclick.net",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:06:28.386Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "proxmox-mail-gateway",
      "category": "spam-filters",
      "name": "Proxmox Mail Gateway",
      "description": "Self-hosted email gateway distribution from Proxmox that filters inbound and outbound mail for spam, viruses and phishing, managed through a web interface.",
      "website": "https://www.proxmox.com/en/products/proxmox-mail-gateway/overview",
      "source": "https://git.proxmox.com/?p=pmg-api.git",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "AT",
        "name": "Austria",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Proxmox Mail Gateway scores 65 out of 100 (grade C) on the spam and virus filtering criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in Austria: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/spam-filters/proxmox-mail-gateway/",
      "markdown": "https://privacyratings.com/spam-filters/proxmox-mail-gateway/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://git.proxmox.com/?p=pmg-api.git;a=blob;f=debian/copyright;hb=HEAD",
          "note": "Licensed under the GNU AGPL version 3. Paid subscriptions add support and the enterprise update repository."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.proxmox.com/en/privacy-policy",
          "note": "The Proxmox website uses self-hosted Matomo analytics with anonymized IP addresses. The software itself has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.proxmox.com/en/products/proxmox-mail-gateway/pricing",
          "note": "Funded by paid support subscriptions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:37.192Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "rspamd",
      "category": "spam-filters",
      "name": "Rspamd",
      "description": "Self-hosted spam filtering system written in C and Lua that checks mail with rules, statistics, fuzzy hashes and DNS lists, and integrates with Postfix, Exim and other mail servers.",
      "website": "https://rspamd.com",
      "source": "https://github.com/rspamd/rspamd",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Rspamd scores 80 out of 100 (grade B) on the spam and virus filtering criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/spam-filters/rspamd/",
      "markdown": "https://privacyratings.com/spam-filters/rspamd/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rspamd/rspamd/blob/master/LICENSE.md",
          "note": "Licensed under the Apache License 2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rspamd/rspamd",
          "note": "No telemetry or analytics in the source code. By default, hashes of message parts are checked against the public fuzzy storage run by the Rspamd project."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.rspamd.com/other/usage_policy/",
          "note": "Free software funded by paid commercial feed and support subscriptions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:38.087Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "spamassassin",
      "category": "spam-filters",
      "name": "Apache SpamAssassin",
      "description": "Self-hosted spam filter from the Apache Software Foundation that scores mail with rules, DNS blocklists and Bayesian filtering, used alongside mail servers such as Postfix.",
      "website": "https://spamassassin.apache.org",
      "source": "https://github.com/apache/spamassassin",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Apache SpamAssassin scores 80 out of 100 (grade B) on the spam and virus filtering criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/spam-filters/spamassassin/",
      "markdown": "https://privacyratings.com/spam-filters/spamassassin/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://svn.apache.org/repos/asf/spamassassin/trunk/LICENSE",
          "note": "Licensed under the Apache License 2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://svn.apache.org/repos/asf/spamassassin/trunk/",
          "note": "No telemetry or analytics in the source code, and the project website loads no analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apache.org/foundation/sponsorship",
          "note": "Free software from a nonprofit foundation funded by sponsors and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:36.783Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "spamhero",
      "category": "spam-filters",
      "name": "SpamHero",
      "description": "Hosted spam and virus filtering service for organizations with their own domain, set up by pointing MX records at it. It also offers outbound SMTP relay, quarantine, delivery logs and reseller controls for managed service providers.",
      "website": "https://www.spamhero.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 22,
      "coverage": 100,
      "summary": "SpamHero scores 22 out of 100 (grade F) on the spam and virus filtering criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales and security headers. It does not meet open source, no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/spam-filters/spamhero/",
      "markdown": "https://privacyratings.com/spam-filters/spamhero/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.spamhero.com/privacy",
          "note": "The website loads Google Analytics, Microsoft Clarity and a Reddit pixel, and the privacy policy allows third-party tracking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.spamhero.com/privacy",
          "note": "Paid service with no ads, but website visitor data is used to track the effectiveness of its own advertising, including a Reddit ads pixel."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.spamhero.com/privacy",
          "note": "No transparency report or government request policy is published. The privacy policy only says data may be disclosed in response to lawful requests by public authorities."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.spamhero.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.spamhero.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Clarity",
            "host": "www.clarity.ms",
            "effect": "no"
          },
          {
            "name": "Reddit Pixel",
            "host": "www.redditstatic.com",
            "effect": "no"
          },
          {
            "name": "Tawk.to",
            "host": "embed.tawk.to",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:06:28.512Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "spamscanner",
      "category": "spam-filters",
      "name": "SpamScanner",
      "description": "Spam, phishing and malware scanner for email written in Node.js by the Forward Email team, used as a library or a command-line tool on your own server.",
      "website": "https://spamscanner.net",
      "source": "https://github.com/spamscanner/spamscanner",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": true,
      "pick_reason": "Self-hosted spam, phishing and malware scanning for Node.js with no telemetry, built by the Forward Email team and used to filter Forward Email's mail.",
      "disclosure": "Privacy Ratings is maintained by the team behind Forward Email, which also makes SpamScanner. This entry is scored by the same criteria as every other entry in this category, and changes to it are reviewed under the published conflict-of-interest rules.",
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "SpamScanner scores 80 out of 100 (grade B) on the spam and virus filtering criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/spam-filters/spamscanner/",
      "markdown": "https://privacyratings.com/spam-filters/spamscanner/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/spamscanner/spamscanner/blob/master/LICENSE",
          "note": "All code is public under the source-available Business Source License 1.1, which bars offering it as a commercial spam detection service. The license names Apache-2.0 as its change license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/spamscanner/spamscanner",
          "note": "No telemetry or analytics in the source code. The Forward Email reputation lookup is off by default, and hostnames of links in scanned mail are checked against Cloudflare's 1.1.1.3 resolver."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/spamscanner/spamscanner",
          "note": "Free software distributed through npm and GitHub, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:37.412Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "trustifi",
      "category": "spam-filters",
      "name": "Trustifi",
      "description": "Cloud email security service that filters inbound phishing, impersonation and malware, and adds outbound encryption, data loss prevention and archiving for Microsoft 365, Google Workspace and other mail servers.",
      "website": "https://trustifi.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 22,
      "coverage": 100,
      "summary": "Trustifi scores 22 out of 100 (grade F) on the spam and virus filtering criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales and security headers. It does not meet open source, no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/spam-filters/trustifi/",
      "markdown": "https://privacyratings.com/spam-filters/trustifi/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://trustifi.com/cookie-policy/",
          "note": "The cookie policy names Google Analytics, and the website loads a LinkedIn ads pixel."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://trustifi.com/cookie-policy/",
          "note": "Paid business service with no ads, but the website uses targeting cookies and a LinkedIn ads pixel to advertise its own product."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published. The website shows an ISO 27001 compliance badge but no certificate or report."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://trustifi.com/privacy-policy/",
          "note": "No transparency report or government request policy is published. The privacy policy only says data may be disclosed to comply with legal process."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.trustifi.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.trustifi.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js-na2.hsforms.net",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "snap.licdn.com",
            "effect": "no"
          },
          {
            "name": "Matomo Cloud",
            "host": "cdn.matomo.cloud",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:06:28.572Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vade",
      "category": "spam-filters",
      "name": "Vade",
      "description": "AI-based email filtering for Microsoft 365, Google Workspace, internet service providers and mail servers that blocks spam, phishing and malware. Vade merged with Hornetsecurity and is being folded into the Hornetsecurity brand.",
      "website": "https://www.vadesecure.com/en/",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Vade scores 25 out of 100 (grade F) on the spam and virus filtering criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales and independent audit. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and security headers. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C-.",
      "url": "https://privacyratings.com/spam-filters/vade/",
      "markdown": "https://privacyratings.com/spam-filters/vade/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.vadesecure.com/en/privacy",
          "note": "The website uses HubSpot, Google Analytics, Twitter Analytics and Microsoft Clarity."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.vadesecure.com/en/privacy",
          "note": "Paid service with no ads, and the privacy policy says personal data is not sold, but the website sets third-party advertising cookies and Google Analytics audiences."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.vadesecure.com/en/company-vade/our-commitments",
          "note": "Hornetsecurity holds ISO 27001 certification, but no audit report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.vadesecure.com/en/privacy",
          "note": "No transparency report or government request policy is published. The privacy policy only says data may be disclosed when required by law or a court order."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=cloud.vadesecure.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=cloud.vadesecure.com",
          "note": "Grade C- (45/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Clarity",
            "host": "www.clarity.ms",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:06:28.651Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "forward-email-backups",
      "category": "email-backup",
      "name": "Forward Email Backups",
      "description": "Built-in mailbox backup and export for Forward Email accounts. Mailboxes are backed up as encrypted SQLite files, optionally to the user's own S3-compatible storage, and can be downloaded as encrypted SQLite or password-protected EML or MBOX archives with contacts and calendars.",
      "website": "https://forwardemail.net/en/faq#how-do-i-export-and-backup-my-mailbox",
      "source": "https://github.com/forwardemail/forwardemail.net",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": "Privacy Ratings is maintained by the team behind Forward Email. This entry is scored by the same criteria as every other entry in this category, and changes to it are reviewed under the published conflict-of-interest rules.",
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "Forward Email Backups scores 85 out of 100 (grade B) on the email backup tools criteria. It meets 3 of 4 criteria: open source, no ads or data sales and independent audit. It partly meets no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/email-backup/forward-email-backups/",
      "markdown": "https://privacyratings.com/email-backup/forward-email-backups/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/forwardemail/forwardemail.net/blob/master/LICENSE.md",
          "note": "All code is public, as part of the Forward Email service code. Core mail storage and protocol code is MPL-2.0 and the rest is under the source-available Business Source License 1.1 (BUSL-1.1), which becomes MPL-2.0 four years after each release."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://forwardemail.net/en/privacy#analytics",
          "note": "No third-party analytics. First-party anonymized analytics of page views and service usage is on by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/private-business-email",
          "note": "Included with paid Forward Email plans. No ads, and the privacy policy states user data is not shared with third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cure53.de/pentest-report_forward-email.pdf",
          "note": "Cure53 audited the Forward Email service code, including the encrypted mailbox storage and the S3 backup storage settings."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:51.873Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "getmail6",
      "category": "email-backup",
      "name": "getmail6",
      "description": "Command-line mail retriever that downloads mail from POP3 and IMAP accounts into local Maildir or mbox files, or passes it to a delivery program. It is the Python 3 fork of getmail.",
      "website": "https://getmail6.org/",
      "source": "https://github.com/getmail6/getmail6",
      "license": null,
      "platforms": [
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "getmail6 scores 80 out of 100 (grade B) on the email backup tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/email-backup/getmail6/",
      "markdown": "https://privacyratings.com/email-backup/getmail6/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/getmail6/getmail6/blob/master/docs/COPYING",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/getmail6/getmail6",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://getmail6.org/",
          "note": "Free open-source software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:38.193Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "google-takeout",
      "category": "email-backup",
      "name": "Google Takeout",
      "description": "Google's data export service for Google accounts. It exports Gmail as an MBOX file, along with data from other Google products, as a download or to a cloud storage service, once or on a schedule.",
      "website": "https://takeout.google.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Google Takeout scores 0 out of 100 (grade F) on the email backup tools criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/email-backup/google-takeout/",
      "markdown": "https://privacyratings.com/email-backup/google-takeout/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "The Google privacy policy covers collection of activity data across Google services, including for advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/technologies/ads",
          "note": "Google is funded by advertising and uses account data to personalize ads unless this is turned off."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit of Google Takeout is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:51.961Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "got-your-back",
      "category": "email-backup",
      "name": "Got Your Back",
      "description": "Command-line tool that backs up and restores Gmail and Google Workspace mailboxes through the Gmail API, saving messages as local files with an index.",
      "website": "https://github.com/GAM-team/got-your-back",
      "source": "https://github.com/GAM-team/got-your-back",
      "license": "Apache-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Got Your Back scores 80 out of 100 (grade B) on the email backup tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/email-backup/got-your-back/",
      "markdown": "https://privacyratings.com/email-backup/got-your-back/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/GAM-team/got-your-back/blob/main/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/GAM-team/got-your-back",
          "note": "No telemetry or analytics in the source code. Sign-in links are shortened through the maintainer's own URL shortener."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/GAM-team/got-your-back",
          "note": "Free open-source software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:37.413Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "imap-backup",
      "category": "email-backup",
      "name": "imap-backup",
      "description": "Command-line Ruby tool that backs up IMAP accounts to local files, with incremental updates, and can restore or migrate the backups to another IMAP server.",
      "website": "https://github.com/joeyates/imap-backup",
      "source": "https://github.com/joeyates/imap-backup",
      "license": "MIT",
      "platforms": [
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "imap-backup scores 80 out of 100 (grade B) on the email backup tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/email-backup/imap-backup/",
      "markdown": "https://privacyratings.com/email-backup/imap-backup/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/joeyates/imap-backup/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/joeyates/imap-backup",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/joeyates/imap-backup",
          "note": "Free open-source software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:37.413Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "imapsync",
      "category": "email-backup",
      "name": "imapsync",
      "description": "Command-line tool that copies or migrates mail between two IMAP accounts, often used for mailbox migrations and incremental backups to another IMAP server.",
      "website": "https://imapsync.lamiral.info/",
      "source": "https://github.com/imapsync/imapsync",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "imapsync scores 40 out of 100 (grade D) on the email backup tools criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/email-backup/imapsync/",
      "markdown": "https://privacyratings.com/email-backup/imapsync/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/imapsync/imapsync/blob/master/LICENSE",
          "note": "All code is public under the NO LIMIT Public License, a source-available license that is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Analytics and Google Ads tags. The tool's release check is off by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://imapsync.lamiral.info/",
          "note": "Funded by paid downloads and support, with no ads in the tool, but the website sends visitor data to Google Ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:38.329Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "importexporttools-ng",
      "category": "email-backup",
      "name": "ImportExportTools NG",
      "description": "Thunderbird add-on that exports and imports messages and folders as EML, MBOX, HTML, PDF, plain text or CSV, and can back up the Thunderbird profile.",
      "website": "https://addons.thunderbird.net/en-US/thunderbird/addon/importexporttools-ng/",
      "source": "https://github.com/thunderbird/import-export-tools-ng",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "ImportExportTools NG scores 80 out of 100 (grade B) on the email backup tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/email-backup/importexporttools-ng/",
      "markdown": "https://privacyratings.com/email-backup/importexporttools-ng/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/thunderbird/import-export-tools-ng/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/thunderbird/import-export-tools-ng",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/thunderbird/import-export-tools-ng",
          "note": "Free open-source add-on with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:38.156Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "isync",
      "category": "email-backup",
      "name": "isync",
      "description": "Command-line tool, run as mbsync, that synchronizes IMAP mailboxes with local Maildir folders in both directions, including deletions and flag changes.",
      "website": "https://isync.sourceforge.io",
      "source": "https://sourceforge.net/p/isync/isync/",
      "license": null,
      "platforms": [
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "isync scores 80 out of 100 (grade B) on the email backup tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/email-backup/isync/",
      "markdown": "https://privacyratings.com/email-backup/isync/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://isync.sourceforge.io/",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://isync.sourceforge.io/",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://isync.sourceforge.io/",
          "note": "Free open-source software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:38.644Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mailstore-home",
      "category": "email-backup",
      "name": "MailStore Home",
      "description": "Free Windows program for private use that archives mail from IMAP and POP3 accounts, Gmail, Outlook.com, Outlook, Thunderbird and PST or EML files into one searchable local archive, and can restore messages.",
      "website": "https://www.mailstore.com/en/products/mailstore-home/",
      "license": null,
      "platforms": [
        "windows"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "MailStore Home scores 10 out of 100 (grade F) on the email backup tools criteria. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/email-backup/mailstore-home/",
      "markdown": "https://privacyratings.com/email-backup/mailstore-home/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Tag Manager, and the OpenText privacy policy describes third-party tracking cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.opentext.com/about/privacy",
          "note": "Free for private use and funded by the paid MailStore Server product, with no ads in the program. The OpenText privacy policy covers sharing website data with service providers for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:39.309Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "offlineimap",
      "category": "email-backup",
      "name": "OfflineIMAP",
      "description": "Command-line tool that synchronizes IMAP mailboxes with local Maildir folders in both directions, so mail can be read offline and kept as a local copy.",
      "website": "https://www.offlineimap.org",
      "source": "https://github.com/OfflineIMAP/offlineimap3",
      "license": null,
      "platforms": [
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "OfflineIMAP scores 80 out of 100 (grade B) on the email backup tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/email-backup/offlineimap/",
      "markdown": "https://privacyratings.com/email-backup/offlineimap/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/OfflineIMAP/offlineimap3/blob/master/COPYING",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/OfflineIMAP/offlineimap3",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.offlineimap.org/",
          "note": "Free open-source software maintained by volunteers. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:38.830Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "docker-mailserver",
      "category": "mail-server-software",
      "name": "Docker Mailserver",
      "description": "Self-hosted mail server in a single Docker container, with SMTP, IMAP, POP3, spam and virus filtering, configured through files and environment variables.",
      "website": "https://docker-mailserver.github.io/docker-mailserver/latest/",
      "source": "https://github.com/docker-mailserver/docker-mailserver",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Docker Mailserver scores 80 out of 100 (grade B) on the mail server software criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mail-server-software/docker-mailserver/",
      "markdown": "https://privacyratings.com/mail-server-software/docker-mailserver/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/docker-mailserver/docker-mailserver/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/docker-mailserver/docker-mailserver",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/docker-mailserver/docker-mailserver",
          "note": "Free open-source software maintained by volunteers. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:32.357Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dovecot",
      "category": "mail-server-software",
      "name": "Dovecot",
      "description": "IMAP and POP3 server for Linux and Unix that stores and serves mailboxes, with support for Sieve filtering through Pigeonhole. The Community Edition is open source.",
      "website": "https://dovecot.org",
      "source": "https://github.com/dovecot/core",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "FI",
        "name": "Finland",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 90,
      "coverage": 100,
      "summary": "Dovecot scores 90 out of 100 (grade A) on the mail server software criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It partly meets independent audit. It is based in Finland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/mail-server-software/dovecot/",
      "markdown": "https://privacyratings.com/mail-server-software/dovecot/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dovecot/core/blob/main/COPYING",
          "note": "LGPL-2.1 and MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dovecot/core",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.dovecotpro.com/",
          "note": "Funded by the commercial Dovecot Pro edition sold by Open-Xchange. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cure53.de/pentest-report_dovecot.pdf",
          "note": "Code audit by Cure53, older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:36.519Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "forward-email",
      "category": "mail-server-software",
      "name": "Forward Email",
      "description": "Self-hosted version of the Forward Email service, installed with a script that deploys Docker containers. It includes MX, SMTP, IMAP, POP3, CalDAV and CardDAV servers, encrypted SQLite mailboxes, a web interface and optional backups to S3-compatible storage.",
      "website": "https://forwardemail.net/en/self-hosted",
      "source": "https://github.com/forwardemail/forwardemail.net",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": "Privacy Ratings is maintained by the team behind Forward Email. This entry is scored by the same criteria as every other entry in this category, and changes to it are reviewed under the published conflict-of-interest rules.",
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "Forward Email scores 85 out of 100 (grade B) on the mail server software criteria. It meets 3 of 4 criteria: open source, no ads or data sales and independent audit. It partly meets no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/mail-server-software/forward-email/",
      "markdown": "https://privacyratings.com/mail-server-software/forward-email/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/forwardemail/forwardemail.net/blob/master/LICENSE.md",
          "note": "All code is public. Core mail storage and protocol code is MPL-2.0 and the rest is under the source-available Business Source License 1.1 (BUSL-1.1), which becomes MPL-2.0 four years after each release. BUSL-1.1 allows production use except offering the software as a hosted service that competes with Forward Email."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://forwardemail.net/en/self-hosted",
          "note": "The self-hosting guide states no information is sent outside the server. The forwardemail.net website runs first-party anonymized analytics by default, with no third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/private-business-email",
          "note": "Free to self-host. The company is funded by paid plans of its hosted service, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://forwardemail.net/pentest-report_forward-email.pdf",
          "note": "Two independent Cure53 audits are published. The latest covers the full forwardemail.net code repository, including the self-hosting setup."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:22.835Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "iredmail",
      "category": "mail-server-software",
      "name": "iRedMail",
      "description": "Installer script that sets up a complete mail server on Linux or BSD from open-source components such as Postfix, Dovecot, Roundcube and SpamAssassin.",
      "website": "https://www.iredmail.org",
      "source": "https://github.com/iredmail/iRedMail",
      "license": "GPL-3.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "iRedMail scores 80 out of 100 (grade B) on the mail server software criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mail-server-software/iredmail/",
      "markdown": "https://privacyratings.com/mail-server-software/iredmail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/iredmail/iRedMail/blob/master/LICENSE",
          "note": "GPL-3.0. The paid iRedAdmin-Pro panel and Enterprise Edition are separate products."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.iredmail.org/",
          "note": "No third-party trackers. The website uses GoatCounter, which is cookieless and aggregate-only, and the installer has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.iredmail.org/pricing.html",
          "note": "Funded by sales of iRedAdmin-Pro, the Enterprise Edition and support. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:36.197Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "maddy",
      "category": "mail-server-software",
      "name": "Maddy",
      "description": "All-in-one mail server written in Go that replaces Postfix, Dovecot and OpenDKIM with a single daemon, handling SMTP, IMAP, DKIM, SPF, DMARC, DANE and MTA-STS.",
      "website": "https://maddy.email",
      "source": "https://github.com/foxcpp/maddy",
      "license": "GPL-3.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Maddy scores 80 out of 100 (grade B) on the mail server software criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mail-server-software/maddy/",
      "markdown": "https://privacyratings.com/mail-server-software/maddy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/foxcpp/maddy/blob/master/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/foxcpp/maddy",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/foxcpp/maddy",
          "note": "Free open-source software maintained by volunteers. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:36.607Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mail-in-a-box",
      "category": "mail-server-software",
      "name": "Mail-in-a-box",
      "description": "Self-hosted mail server setup for a single Ubuntu machine, with SMTP, IMAP, webmail, contacts, calendar, spam filtering and backups preconfigured.",
      "website": "https://mailinabox.email",
      "source": "https://github.com/mail-in-a-box/mailinabox",
      "license": "CC0-1.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Mail-in-a-box scores 80 out of 100 (grade B) on the mail server software criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mail-server-software/mail-in-a-box/",
      "markdown": "https://privacyratings.com/mail-server-software/mail-in-a-box/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mail-in-a-box/mailinabox/blob/main/LICENSE",
          "note": "CC0-1.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mail-in-a-box/mailinabox",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/mail-in-a-box/mailinabox",
          "note": "Free open-source software maintained by volunteers. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:32.841Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mailcow",
      "category": "mail-server-software",
      "name": "mailcow",
      "description": "Self-hosted mail server suite based on Docker, with SMTP, IMAP, the SOGo webmail and groupware, spam filtering and a web admin interface.",
      "website": "https://mailcow.email",
      "source": "https://github.com/mailcow/mailcow-dockerized",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "mailcow scores 80 out of 100 (grade B) on the mail server software criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mail-server-software/mailcow/",
      "markdown": "https://privacyratings.com/mail-server-software/mailcow/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mailcow/mailcow-dockerized/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mailcow/mailcow-dockerized",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mailcow.email/",
          "note": "Funded by sponsorships and optional paid supporter licenses. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:33.478Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mailu",
      "category": "mail-server-software",
      "name": "Mailu",
      "description": "Self-hosted mail server built from Docker containers, with SMTP, IMAP, webmail, spam and virus filtering and a web admin interface.",
      "website": "https://mailu.io",
      "source": "https://github.com/Mailu/Mailu",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Mailu scores 80 out of 100 (grade B) on the mail server software criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mail-server-software/mailu/",
      "markdown": "https://privacyratings.com/mail-server-software/mailu/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Mailu/Mailu/blob/master/LICENSE.md",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Mailu/Mailu",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Mailu/Mailu",
          "note": "Free open-source software maintained by volunteers. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:53.105Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "microsoft-exchange-server",
      "category": "mail-server-software",
      "name": "Microsoft Exchange Server",
      "description": "Microsoft's on-premises mail, calendar and contacts server for Windows Server, used by organizations with Outlook clients. Sold as a subscription edition.",
      "website": "https://www.microsoft.com/en-us/microsoft-365/exchange/exchange-server",
      "license": null,
      "platforms": [
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Microsoft Exchange Server scores 20 out of 100 (grade F) on the mail server software criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/mail-server-software/microsoft-exchange-server/",
      "markdown": "https://privacyratings.com/mail-server-software/microsoft-exchange-server/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement#maincookiessimilartechnologiesmodule",
          "note": "Microsoft websites use third-party cookies and web beacons, including for personalized ads. The server sends diagnostic data to Microsoft through the Emergency Mitigation service unless it is disabled."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/microsoft-365/exchange/exchange-server",
          "note": "Funded by server and client access licenses. The server shows no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:40.430Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "modoboa",
      "category": "mail-server-software",
      "name": "Modoboa",
      "description": "Self-hosted mail hosting and management platform built on Postfix and Dovecot, with a web admin interface, webmail, calendars, contacts and spam filtering.",
      "website": "https://modoboa.org",
      "source": "https://github.com/modoboa/modoboa",
      "license": "ISC",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Modoboa scores 65 out of 100 (grade C) on the mail server software criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/mail-server-software/modoboa/",
      "markdown": "https://privacyratings.com/mail-server-software/modoboa/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/modoboa/modoboa/blob/master/LICENSE",
          "note": "ISC."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/modoboa/modoboa/blob/master/modoboa/core/management/commands/communicate_with_public_api.py",
          "note": "By default the server registers with api.modoboa.org and sends its hostname, version and domain and mailbox counts. This can be turned off in the settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://modoboa.org/en/sponsoring/",
          "note": "Funded by sponsoring, grants and paid professional services. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:53.418Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mox",
      "category": "mail-server-software",
      "name": "Mox",
      "description": "Mail server written in Go for low-maintenance self-hosting, combining SMTP, IMAP, webmail, SPF, DKIM, DMARC, MTA-STS, automatic TLS and spam filtering in one program.",
      "website": "https://www.xmox.nl",
      "source": "https://github.com/mjl-/mox",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Mox scores 80 out of 100 (grade B) on the mail server software criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mail-server-software/mox/",
      "markdown": "https://privacyratings.com/mail-server-software/mox/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mjl-/mox/blob/main/LICENSE.MIT",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mjl-/mox",
          "note": "No telemetry or analytics in the source code. The optional update check is a single DNS lookup."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.xmox.nl/#sponsors",
          "note": "Funded by NLnet grants. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:37.883Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "postfix",
      "category": "mail-server-software",
      "name": "Postfix",
      "description": "Mail transfer agent that routes and delivers email over SMTP, used on many Linux and Unix servers as the default mail server.",
      "website": "https://www.postfix.org",
      "source": "https://github.com/vdukhovni/postfix",
      "license": null,
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Postfix scores 80 out of 100 (grade B) on the mail server software criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mail-server-software/postfix/",
      "markdown": "https://privacyratings.com/mail-server-software/postfix/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/vdukhovni/postfix/blob/master/postfix/LICENSE",
          "note": "Dual-licensed under EPL-2.0 and IPL-1.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/vdukhovni/postfix",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.postfix.org/",
          "note": "Free open-source software maintained by its authors. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:38.396Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "stalwart-mail-server",
      "category": "mail-server-software",
      "name": "Stalwart",
      "description": "Self-hosted mail and collaboration server written in Rust, with JMAP, IMAP, POP3, SMTP, CalDAV, CardDAV and WebDAV support, built-in spam filtering and a web admin interface.",
      "website": "https://stalw.art",
      "source": "https://github.com/stalwartlabs/stalwart",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 100,
      "coverage": 100,
      "summary": "Stalwart scores 100 out of 100 (grade A) on the mail server software criteria. It meets 4 of 4 criteria: open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/mail-server-software/stalwart-mail-server/",
      "markdown": "https://privacyratings.com/mail-server-software/stalwart-mail-server/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/stalwartlabs/stalwart/blob/main/LICENSES/AGPL-3.0-only.txt",
          "note": "All code is public. Most is AGPL-3.0, and enterprise features in the same repository use the source-available Stalwart Enterprise License, which is not open source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://stalw.art/legal/privacy",
          "note": "The websites load no third-party analytics, and the self-hosted server does not send data to Stalwart Labs."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://stalw.art/pricing/",
          "note": "Funded by paid enterprise licenses and support. The privacy policy says personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://stalw.art/blog/security-audit/ros-report.pdf",
          "note": "Code review and penetration test by Radically Open Security, full report public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:36.766Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "amazon-ses",
      "category": "email-sending",
      "name": "Amazon SES",
      "description": "Amazon Simple Email Service, an email API and SMTP relay on AWS for sending and receiving email, billed per message.",
      "website": "https://aws.amazon.com/ses/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 54,
      "coverage": 88,
      "summary": "Amazon SES scores 54 out of 100 (grade D) on the email sending services criteria. It meets 7 of 12 criteria: transparency report, tells users about requests, TLS configuration, security headers, open and click tracking off by default, encrypted delivery can be enforced and EU data location. It partly meets no ads or data sales and independent audit. It does not meet open source and no trackers or telemetry. Still needing evidence: message content deleted after delivery. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A.",
      "url": "https://privacyratings.com/email-sending/amazon-ses/",
      "markdown": "https://privacyratings.com/email-sending/amazon-ses/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Amplitude, DoubleClick and Marketo scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://aws.amazon.com/compliance/data-privacy-faq/",
          "note": "Customer content is not used for marketing or advertising, but the website loads DoubleClick advertising scripts to promote AWS."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://aws.amazon.com/compliance/soc-faqs/",
          "note": "A SOC 3 summary report is public. The full SOC 2 report is only available to customers through AWS Artifact."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://aws.amazon.com/compliance/data-privacy-faq/",
          "note": "Amazon regularly publishes a report on the types and volume of information requests it receives."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://aws.amazon.com/compliance/data-privacy-faq/",
          "note": "AWS gives customers notice of demands for their content unless legally prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=aws.amazon.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=aws.amazon.com",
          "note": "Grade A (95/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted after delivery",
          "weight": 3,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tracking_off_by_default": {
          "title": "Open and click tracking off by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.aws.amazon.com/ses/latest/dg/faqs-metrics.html",
          "note": "Open and click tracking only apply to mail sent with a configuration set that publishes those events."
        },
        "enforced_tls": {
          "title": "Encrypted delivery can be enforced",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.aws.amazon.com/ses/latest/dg/security-protocols.html",
          "note": "TLS is opportunistic by default. A configuration set with the TLS policy set to Require drops mail that cannot be sent over TLS."
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.aws.amazon.com/general/latest/gr/ses.html",
          "note": "Available in several EU regions, including Frankfurt, Ireland, Paris, Milan and Stockholm."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:26:05.317Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "brevo",
      "category": "email-sending",
      "name": "Brevo",
      "description": "Marketing and transactional email platform, formerly Sendinblue, with an SMTP relay, email API, SMS and a CRM. Data is hosted in the EU.",
      "website": "https://www.brevo.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 29,
      "coverage": 71,
      "summary": "Brevo scores 29 out of 100 (grade F) on the email sending services criteria. It meets 2 of 12 criteria: TLS configuration and EU data location. It partly meets no ads or data sales, security headers, message content deleted after delivery and open and click tracking off by default. It does not meet open source and no trackers or telemetry. Still needing evidence: independent audit, transparency report, tells users about requests and encrypted delivery can be enforced. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/email-sending/brevo/",
      "markdown": "https://privacyratings.com/email-sending/brevo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads HubSpot and TikTok scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.brevo.com/legal/privacypolicy/",
          "note": "Funded by paid plans and states personal data is not sold, but offers an opt-out of sharing for targeted advertising, and the website loads a TikTok pixel."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=brevo.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=brevo.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted after delivery",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://help.brevo.com/hc/en-us/articles/4415743225746-Manage-the-retention-period-of-transactional-logs-and-email-previews",
          "note": "Transactional logs and email previews are kept indefinitely by default. Previews can be turned off, and logs can be set to be deleted after 1 to 24 months."
        },
        "tracking_off_by_default": {
          "title": "Open and click tracking off by default",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://help.brevo.com/hc/en-us/articles/11643306229906-Can-I-anonymize-the-tracking-of-opens-and-clicks-for-my-emails",
          "note": "Opens and clicks are tracked per recipient by default. Tracking can be made anonymous for campaign and transactional mail."
        },
        "enforced_tls": {
          "title": "Encrypted delivery can be enforced",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://help.brevo.com/hc/en-us/articles/360001005510-Data-storage-location",
          "note": "Data is hosted by OVH in France and Germany and on Google Cloud in Belgium."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:26:05.480Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "elastic-email",
      "category": "email-sending",
      "name": "Elastic Email",
      "description": "Email API, SMTP relay and marketing email platform for transactional and bulk email.",
      "website": "https://elasticemail.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": null,
      "score": 15,
      "coverage": 46,
      "summary": "Elastic Email is not graded yet: 46% of its criteria have evidence, and 60% is needed. It meets 1 of 12 criteria: TLS configuration. It partly meets security headers and open and click tracking off by default. It does not meet open source and no trackers or telemetry. Still needing evidence: no ads or data sales, independent audit, transparency report, tells users about requests, message content deleted after delivery, encrypted delivery can be enforced and EU data location. It is based in Canada: Five Eyes member. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/email-sending/elastic-email/",
      "markdown": "https://privacyratings.com/email-sending/elastic-email/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads HubSpot scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=elasticemail.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=elasticemail.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted after delivery",
          "weight": 3,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tracking_off_by_default": {
          "title": "Open and click tracking off by default",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://help.elasticemail.com/en/articles/4867123-tracking-opens-and-clicks",
          "note": "Open and click tracking are on by default and can be turned off in the account's tracking settings."
        },
        "enforced_tls": {
          "title": "Encrypted delivery can be enforced",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:26:05.526Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "forward-email",
      "category": "email-sending",
      "name": "Forward Email",
      "description": "Email service whose paid plans include outbound SMTP and an email API for sending from apps and websites with a custom domain. Message bodies are purged after delivery by default.",
      "website": "https://forwardemail.net",
      "source": "https://github.com/forwardemail/forwardemail.net",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": "Privacy Ratings is maintained by the team behind Forward Email. This entry is scored by the same criteria as every other entry in this category, and changes to it are reviewed under the published conflict-of-interest rules.",
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "Forward Email scores 85 out of 100 (grade B) on the email sending services criteria. It meets 9 of 12 criteria: open source, no ads or data sales, independent audit, tells users about requests, TLS configuration, security headers, message content deleted after delivery, open and click tracking off by default and encrypted delivery can be enforced. It partly meets no trackers or telemetry and transparency report. It does not meet EU data location. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/email-sending/forward-email/",
      "markdown": "https://privacyratings.com/email-sending/forward-email/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/forwardemail/forwardemail.net/blob/master/LICENSE.md",
          "note": "All code is public, including the outbound SMTP servers that run the service. Core mail storage and protocol code is MPL-2.0 and the rest is under the source-available Business Source License 1.1 (BUSL-1.1), which becomes MPL-2.0 four years after each release."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://forwardemail.net/en/privacy#analytics",
          "note": "No third-party analytics. First-party anonymized analytics of page views and service usage is on by default, and Cloudflare Turnstile loads on sign-in and sign-up forms."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/private-business-email",
          "note": "Funded by paid plans. No ads, and the privacy policy states user data is not shared with third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cure53.de/pentest-report_forward-email.pdf",
          "note": "Two independent Cure53 audits of the code and the infrastructure are published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://forwardemail.net/technical-whitepaper.pdf",
          "note": "The technical whitepaper (section 9.3) publishes the government request policy and commits to transparency reports with request counts. A report with counts is not published yet."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://forwardemail.net/technical-whitepaper.pdf",
          "note": "Users are notified of requests when legally allowed, with notice after disclosure when advance notice is prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=forwardemail.net&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=forwardemail.net",
          "note": "Grade A+ (125/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted after delivery",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/privacy#outbound-smtp-emails",
          "note": "Outbound mail is queued for up to about 30 days until it is delivered or fails permanently. The body is then purged by default, and can be kept for up to 30 days if the sender turns this on."
        },
        "tracking_off_by_default": {
          "title": "Open and click tracking off by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/email-api#outbound-emails",
          "note": "The email API and SMTP documentation describe no open or click tracking."
        },
        "enforced_tls": {
          "title": "Encrypted delivery can be enforced",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/faq#do-you-use-tls-encryption-for-email-forwarding",
          "note": "Outbound delivery enforces the recipient domain's MTA-STS policy and retries later instead of sending without TLS."
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "no",
          "evidence": "https://forwardemail.net/en/faq#can-i-keep-my-email-processing-and-storage-in-the-eu-data-residency",
          "note": "All processing and storage, including outbound SMTP, is in the United States. An EU location is not available."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:26:05.785Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "loops",
      "category": "email-sending",
      "name": "Loops",
      "description": "Email platform for software companies that combines marketing campaigns, automated sequences and a transactional email API.",
      "website": "https://loops.so",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": null,
      "score": 23,
      "coverage": 54,
      "summary": "Loops is not graded yet: 54% of its criteria have evidence, and 60% is needed. It meets 2 of 12 criteria: TLS configuration and open and click tracking off by default. It partly meets no ads or data sales and security headers. It does not meet open source and no trackers or telemetry. Still needing evidence: independent audit, transparency report, tells users about requests, message content deleted after delivery, encrypted delivery can be enforced and EU data location. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/email-sending/loops/",
      "markdown": "https://privacyratings.com/email-sending/loops/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://loops.so/privacy",
          "note": "The privacy policy lists Google Analytics and Segment, and the website loads Google Tag Manager, Amplitude, PostHog and VWO."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://loops.so/privacy",
          "note": "Funded by paid plans and states personal data is not sold, but advertising cookies are used on the website."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=loops.so&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=loops.so",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted after delivery",
          "weight": 3,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tracking_off_by_default": {
          "title": "Open and click tracking off by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://loops.so/docs/transactional",
          "note": "Open and click tracking are off for transactional email. Marketing campaigns are tracked."
        },
        "enforced_tls": {
          "title": "Encrypted delivery can be enforced",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Amplitude",
            "host": "cdn.amplitude.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "X (Twitter) Pixel",
            "host": "static.ads-twitter.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:26:05.616Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mailchimp-transactional",
      "category": "email-sending",
      "name": "Mailchimp Transactional",
      "description": "Transactional email API and SMTP relay from Mailchimp, formerly Mandrill, sold as an add-on to Mailchimp plans.",
      "website": "https://mailchimp.com/features/transactional-email/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 33,
      "coverage": 92,
      "summary": "Mailchimp Transactional scores 33 out of 100 (grade F) on the email sending services criteria. It meets 1 of 12 criteria: TLS configuration. It partly meets no ads or data sales, independent audit, transparency report, tells users about requests, message content deleted after delivery and open and click tracking off by default. It does not meet open source, no trackers or telemetry, security headers and EU data location. Still needing evidence: encrypted delivery can be enforced. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C+.",
      "url": "https://privacyratings.com/email-sending/mailchimp-transactional/",
      "markdown": "https://privacyratings.com/email-sending/mailchimp-transactional/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.intuit.com/privacy/statement/",
          "note": "The Intuit privacy statement covers advertising cookies, pixels and session-replay tools, and the website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.intuit.com/privacy/statement/",
          "note": "Funded by subscriptions and states data is not sold, but personal information is shared with advertising networks for targeted ads unless users opt out."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://mailchimp.com/about/security/",
          "note": "SOC 2 and ISO 27001 audits are done, but the reports are only available through the Intuit compliance portal."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://mailchimp.com/legal/service-of-legal-process/",
          "note": "Publishes how it accepts legal process from governments, but no request counts."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://mailchimp.com/legal/service-of-legal-process/",
          "note": "Mailchimp reserves the right to notify customers of legal process, and some customer agreements require notice unless prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mandrillapp.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mandrillapp.com",
          "note": "Grade C+ (60/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted after delivery",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://mailchimp.com/developer/transactional/docs/activity-reports/",
          "note": "A copy of the HTML and text parts of each sent email is kept for 30 days."
        },
        "tracking_off_by_default": {
          "title": "Open and click tracking off by default",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://mailchimp.com/developer/transactional/docs/activity-reports/",
          "note": "Click tracking is on by default for HTML and text email. Open and click tracking can be turned off in account settings or for each message."
        },
        "enforced_tls": {
          "title": "Encrypted delivery can be enforced",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "no",
          "evidence": "https://mailchimp.com/help/mailchimp-european-data-transfers/",
          "note": "Servers are located in the United States. No EU storage option is offered."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          },
          {
            "name": "Optimizely",
            "host": "cdn.optimizely.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:29:16.374Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mailersend",
      "category": "email-sending",
      "name": "MailerSend",
      "description": "Transactional email API and SMTP relay from the makers of MailerLite, with templates, inbound routing and SMS.",
      "website": "https://www.mailersend.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 27,
      "coverage": 71,
      "summary": "MailerSend scores 27 out of 100 (grade F) on the email sending services criteria. It meets 2 of 12 criteria: TLS configuration and EU data location. It partly meets no ads or data sales, message content deleted after delivery and open and click tracking off by default. It does not meet open source, no trackers or telemetry and security headers. Still needing evidence: independent audit, transparency report, tells users about requests and encrypted delivery can be enforced. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/email-sending/mailersend/",
      "markdown": "https://privacyratings.com/email-sending/mailersend/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Tag Manager and PostHog."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.mailersend.com/legal/privacy-policy",
          "note": "Funded by paid plans and states personal data is never sold, but third-party partners use cookies on the website for advertising on other sites."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mailersend.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mailersend.com",
          "note": "Grade F (5/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted after delivery",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.mailersend.com/whats-new/data-retention-add-on",
          "note": "Activity data is kept for 7 or 30 days depending on the plan. A \"Don't store content\" option is available."
        },
        "tracking_off_by_default": {
          "title": "Open and click tracking off by default",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://developers.mailersend.com/api/v1/email/domains",
          "note": "Domain settings for open, click and content tracking are on by default and can be turned off."
        },
        "enforced_tls": {
          "title": "Encrypted delivery can be enforced",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.mailersend.com/legal/privacy-policy",
          "note": "The privacy policy states data storage centers are in the European Union."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Fathom",
            "host": "cdn.usefathom.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "PostHog",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:26:05.840Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mailgun",
      "category": "email-sending",
      "name": "Mailgun",
      "description": "Email API and SMTP relay from Sinch for transactional and bulk email, with US and EU regions, event logs and optional open and click tracking.",
      "website": "https://www.mailgun.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 88,
      "summary": "Mailgun scores 50 out of 100 (grade D) on the email sending services criteria. It meets 5 of 12 criteria: no ads or data sales, TLS configuration, open and click tracking off by default, encrypted delivery can be enforced and EU data location. It partly meets independent audit, security headers and message content deleted after delivery. It does not meet open source and no trackers or telemetry. Still needing evidence: transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/email-sending/mailgun/",
      "markdown": "https://privacyratings.com/email-sending/mailgun/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.mailgun.com/legal/privacy-policy/",
          "note": "The privacy policy lists Google Analytics and Optimizely on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.mailgun.com/legal/privacy-policy/",
          "note": "Funded by paid plans. The privacy policy states personal data is not sold or used by third parties for their own interests without consent."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.mailgun.com/security/",
          "note": "SOC 2 Type II and ISO 27001 certified, but the audit reports are not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mailgun.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mailgun.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted after delivery",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://help.mailgun.com/hc/en-us/articles/8841411163035-Adjusting-a-domain-s-message-retention-settings",
          "note": "Messages are kept for up to 3 days by default, depending on the plan, and retention can be set to 0 days for each domain."
        },
        "tracking_off_by_default": {
          "title": "Open and click tracking off by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://documentation.mailgun.com/docs/mailgun/user-manual/tracking-messages/tracking-messages",
          "note": "Open, click and unsubscribe tracking are off until turned on for a domain."
        },
        "enforced_tls": {
          "title": "Encrypted delivery can be enforced",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mailgun-docs.redoc.ly/docs/mailgun/user-manual/tls-sending/",
          "note": "TLS is opportunistic by default. A require-tls setting for each domain or message stops delivery without TLS."
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://documentation.mailgun.com/docs/mailgun/api-reference/api-overview",
          "note": "Domains created in the EU region keep messages, event logs and statistics in the EU. Account and billing data is replicated globally."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google DoubleClick",
            "host": "pubads.g.doubleclick.net",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "snap.licdn.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Clarity",
            "host": "www.clarity.ms",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          },
          {
            "name": "Segment",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:29:06.002Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mailjet",
      "category": "email-sending",
      "name": "Mailjet",
      "description": "Email API, SMTP relay and marketing email platform from Sinch, with data hosted in the EU.",
      "website": "https://www.mailjet.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": null,
      "score": 19,
      "coverage": 50,
      "summary": "Mailjet is not graded yet: 50% of its criteria have evidence, and 60% is needed. It meets 2 of 12 criteria: TLS configuration and EU data location. It partly meets independent audit and security headers. It does not meet open source and no trackers or telemetry. Still needing evidence: no ads or data sales, transparency report, tells users about requests, message content deleted after delivery, open and click tracking off by default and encrypted delivery can be enforced. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/email-sending/mailjet/",
      "markdown": "https://privacyratings.com/email-sending/mailjet/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics, Google Tag Manager, LinkedIn Insight, Meta Pixel, Microsoft Clarity, Reddit Pixel and Segment (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.mailjet.com/products/data-security-and-privacy/",
          "note": "ISO 27001 and SOC 2 are listed, but the audit reports are not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mailjet.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mailjet.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted after delivery",
          "weight": 3,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tracking_off_by_default": {
          "title": "Open and click tracking off by default",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "enforced_tls": {
          "title": "Encrypted delivery can be enforced",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://documentation.mailjet.com/hc/en-us/articles/360042712274-Where-is-my-personal-data-stored",
          "note": "Data is hosted on Google Cloud in Frankfurt and Saint-Ghislain, Belgium."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "snap.licdn.com",
            "effect": "no"
          },
          {
            "name": "Meta Pixel",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Microsoft Clarity",
            "host": "www.clarity.ms",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          },
          {
            "name": "Reddit Pixel",
            "host": "www.redditstatic.com",
            "effect": "no"
          },
          {
            "name": "Segment",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:26:21.020Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mailtrap",
      "category": "email-sending",
      "name": "Mailtrap",
      "description": "Email API and SMTP relay for transactional and bulk email, with an email testing sandbox and marketing campaigns.",
      "website": "https://mailtrap.io",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": null,
      "score": 13,
      "coverage": 46,
      "summary": "Mailtrap is not graded yet: 46% of its criteria have evidence, and 60% is needed. It meets 1 of 12 criteria: TLS configuration. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry and security headers. Still needing evidence: independent audit, transparency report, tells users about requests, message content deleted after delivery, open and click tracking off by default, encrypted delivery can be enforced and EU data location. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/email-sending/mailtrap/",
      "markdown": "https://privacyratings.com/email-sending/mailtrap/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Tag Manager, Microsoft Clarity, HubSpot and Meta, TikTok, LinkedIn and X advertising scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://mailtrap.io/privacy/",
          "note": "Funded by paid plans, but Meta, LinkedIn and X are listed as processors for marketing analytics."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mailtrap.io&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mailtrap.io",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted after delivery",
          "weight": 3,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tracking_off_by_default": {
          "title": "Open and click tracking off by default",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "enforced_tls": {
          "title": "Encrypted delivery can be enforced",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cookiebot",
            "host": "consentcdn.cookiebot.com",
            "effect": "none"
          },
          {
            "name": "Facebook SDK",
            "host": "connect.facebook.net",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "snap.licdn.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Clarity",
            "host": "scripts.clarity.ms",
            "effect": "no"
          },
          {
            "name": "X (Twitter) Pixel",
            "host": "static.ads-twitter.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:26:21.309Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "plunk",
      "category": "email-sending",
      "name": "Plunk",
      "description": "Open-source email platform for transactional email, campaigns and automations, hosted in the EU or self-hosted with Docker.",
      "website": "https://www.useplunk.com",
      "source": "https://github.com/useplunk/plunk",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": null,
      "score": 42,
      "coverage": 50,
      "summary": "Plunk is not graded yet: 50% of its criteria have evidence, and 60% is needed. It meets 4 of 12 criteria: open source, no trackers or telemetry, no ads or data sales and EU data location. It partly meets TLS configuration. It does not meet security headers. Still needing evidence: independent audit, transparency report, tells users about requests, message content deleted after delivery, open and click tracking off by default and encrypted delivery can be enforced. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/email-sending/plunk/",
      "markdown": "https://privacyratings.com/email-sending/plunk/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/useplunk/plunk/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.useplunk.com/privacy",
          "note": "The privacy policy states no Google Analytics, Meta pixel or other third-party tracking scripts are used, with only a login cookie."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.useplunk.com/privacy",
          "note": "Funded by per-email pricing. The privacy policy states data is never sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=useplunk.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=useplunk.com",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted after delivery",
          "weight": 3,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tracking_off_by_default": {
          "title": "Open and click tracking off by default",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "enforced_tls": {
          "title": "Encrypted delivery can be enforced",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.useplunk.com/privacy",
          "note": "The hosted service stores data with Hetzner in Germany and sends mail through Amazon SES. Self-hosting is also supported."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:29:21.474Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "postal",
      "category": "email-sending",
      "name": "Postal",
      "description": "Open-source mail delivery platform for running your own SMTP relay and email API, with web-based management, webhooks and click and open tracking.",
      "website": "https://docs.postalserver.io",
      "source": "https://github.com/postalserver/postal",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": null,
      "score": 44,
      "coverage": 44,
      "summary": "Postal is not graded yet: 44% of its criteria have evidence, and 60% is needed. It meets 4 of 8 criteria: open source, no ads or data sales, open and click tracking off by default and EU data location. Still needing evidence: no trackers or telemetry, independent audit, message content deleted after delivery and encrypted delivery can be enforced.",
      "url": "https://privacyratings.com/email-sending/postal/",
      "markdown": "https://privacyratings.com/email-sending/postal/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/postalserver/postal/blob/main/MIT-LICENCE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/postalserver/postal",
          "note": "Free open source software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "content_retention": {
          "title": "Message content deleted after delivery",
          "weight": 3,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tracking_off_by_default": {
          "title": "Open and click tracking off by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.postalserver.io/features/click-and-open-tracking",
          "note": "Tracking only works after a tracking domain is added to a mail server."
        },
        "enforced_tls": {
          "title": "Encrypted delivery can be enforced",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.postalserver.io/",
          "note": "Self-hosted, so message data stays on servers the operator chooses."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:24.300Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "postmark",
      "category": "email-sending",
      "name": "Postmark",
      "description": "Email API and SMTP service from ActiveCampaign for transactional and broadcast email, with separate message streams and 45 days of message history by default.",
      "website": "https://postmarkapp.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 27,
      "coverage": 79,
      "summary": "Postmark scores 27 out of 100 (grade F) on the email sending services criteria. It meets 2 of 12 criteria: TLS configuration and open and click tracking off by default. It partly meets message content deleted after delivery and encrypted delivery can be enforced. It does not meet open source, no trackers or telemetry, no ads or data sales, security headers and EU data location. Still needing evidence: independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C-.",
      "url": "https://privacyratings.com/email-sending/postmark/",
      "markdown": "https://privacyratings.com/email-sending/postmark/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Tag Manager and Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.activecampaign.com/legal/privacy-policy",
          "note": "The ActiveCampaign privacy policy covers Postmark and discloses personal information to data enrichment providers and shares it with advertising networks for cross-context behavioral advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=postmarkapp.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=postmarkapp.com",
          "note": "Grade C- (45/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted after delivery",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://postmarkapp.com/support/article/can-i-hide-or-turn-off-saving-of-message-content-in-my-activity-page",
          "note": "Message content is kept for 45 days by default and cannot be turned off. A paid add-on sets retention between 7 and 365 days."
        },
        "tracking_off_by_default": {
          "title": "Open and click tracking off by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://postmarkapp.com/developer/user-guide/tracking-links",
          "note": "Link tracking is off by default for all servers and messages, and open tracking is turned on per server or message."
        },
        "enforced_tls": {
          "title": "Encrypted delivery can be enforced",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://postmarkapp.com/security",
          "note": "Outbound mail uses opportunistic TLS. No setting to require TLS is documented."
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "no",
          "evidence": "https://postmarkapp.com/eu-privacy",
          "note": "Data is hosted in a data center near Chicago and on Amazon Web Services outside the EU."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "ssl.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:27:29.076Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "resend",
      "category": "email-sending",
      "name": "Resend",
      "description": "Email API for developers with SMTP support, React Email templates, broadcasts and webhooks.",
      "website": "https://resend.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 46,
      "coverage": 88,
      "summary": "Resend scores 46 out of 100 (grade D) on the email sending services criteria. It meets 4 of 12 criteria: no ads or data sales, TLS configuration, open and click tracking off by default and encrypted delivery can be enforced. It partly meets independent audit, security headers and message content deleted after delivery. It does not meet open source, no trackers or telemetry and EU data location. Still needing evidence: transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/email-sending/resend/",
      "markdown": "https://privacyratings.com/email-sending/resend/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://resend.com/legal/privacy-policy",
          "note": "The privacy policy lists Plausible and Mixpanel, and the website loads PostHog."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://resend.com/legal/privacy-policy",
          "note": "Funded by paid plans. The privacy policy states personal information is not sold or rented."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://resend.com/security",
          "note": "States SOC 2 compliance and third-party audits, but no report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=resend.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=resend.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted after delivery",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://resend.com/docs/knowledge-base/account-quotas-and-limits",
          "note": "Email content, metadata and logs are kept for 30 days on all plans. Other retention periods need an enterprise plan."
        },
        "tracking_off_by_default": {
          "title": "Open and click tracking off by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://resend.com/docs/dashboard/domains/tracking",
          "note": "Open and click tracking are off by default for all domains."
        },
        "enforced_tls": {
          "title": "Encrypted delivery can be enforced",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://resend.com/docs/api-reference/domains/create-domain",
          "note": "TLS is opportunistic by default and can be set to enforced for each domain."
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "no",
          "evidence": "https://resend.com/docs/dashboard/domains/regions",
          "note": "An EU sending region is offered, but customer data, logs and metadata stay in the United States."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "PostHog",
            "host": "us.i.posthog.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:28:24.576Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sendgrid",
      "category": "email-sending",
      "name": "SendGrid",
      "description": "Email API and SMTP relay from Twilio for transactional and marketing email, with open and click tracking, event webhooks and an activity feed.",
      "website": "https://www.twilio.com/en-us/sendgrid",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 52,
      "coverage": 100,
      "summary": "SendGrid scores 52 out of 100 (grade D) on the email sending services criteria. It meets 4 of 12 criteria: transparency report, tells users about requests, message content deleted after delivery and encrypted delivery can be enforced. It partly meets no ads or data sales, independent audit, TLS configuration, open and click tracking off by default and EU data location. It does not meet open source, no trackers or telemetry and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/email-sending/sendgrid/",
      "markdown": "https://privacyratings.com/email-sending/sendgrid/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Tag Manager, Segment, Adobe Launch and VWO."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.twilio.com/en-us/legal/privacy",
          "note": "Funded by paid plans and states data is not sold, but website tracking for targeted advertising counts as sharing under some US state laws."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://security.twilio.com/",
          "note": "SOC 2 and ISO 27001 audits and a SendGrid penetration test report are listed, but reports are only available on request through the Twilio Trust Center."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.twilio.com/en-us/legal/transparency",
          "note": "Twilio publishes annual transparency reports with government request counts, responses and how often users were notified."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.twilio.com/en-us/legal/law-enforcement-guidelines",
          "note": "Twilio uses reasonable efforts to notify customers of requests for their information unless prohibited by law."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=sendgrid.com&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=sendgrid.com",
          "note": "Grade D- (25/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted after delivery",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://support.sendgrid.com/hc/en-us/articles/18961023703963-How-to-Find-the-Body-or-Contents-of-Emails",
          "note": "Message content is not stored. Delivery data such as addresses, timestamps and engagement events is kept."
        },
        "tracking_off_by_default": {
          "title": "Open and click tracking off by default",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.twilio.com/docs/sendgrid/ui/account-and-settings/tracking",
          "note": "Open tracking is turned on by default for Marketing Campaigns. Open and click tracking can be turned off in the account's tracking settings."
        },
        "enforced_tls": {
          "title": "Encrypted delivery can be enforced",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.twilio.com/docs/sendgrid/for-developers/sending-email/enforced-tls",
          "note": "Enforced TLS settings can require TLS and a valid certificate. Mail to servers that do not meet them is dropped."
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.twilio.com/docs/sendgrid/data-residency/faq.md",
          "note": "EU data residency is available only on Pro, Premier and Custom plans."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Segment",
            "host": "cdn.segment.com",
            "effect": "no"
          },
          {
            "name": "TrustArc",
            "host": "consent.trustarc.com",
            "effect": "none"
          },
          {
            "name": "VWO",
            "host": "dev.visualwebsiteoptimizer.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:28:24.921Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "smtp2go",
      "category": "email-sending",
      "name": "SMTP2GO",
      "description": "SMTP relay and email API for transactional and bulk email, with an EU data center in Amsterdam and optional email archiving.",
      "website": "https://www.smtp2go.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "NZ",
        "name": "New Zealand",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": null,
      "score": 25,
      "coverage": 58,
      "summary": "SMTP2GO is not graded yet: 58% of its criteria have evidence, and 60% is needed. It meets 3 of 12 criteria: TLS configuration, open and click tracking off by default and EU data location. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry and security headers. Still needing evidence: independent audit, transparency report, tells users about requests, message content deleted after delivery and encrypted delivery can be enforced. It is based in New Zealand: Five Eyes member. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/email-sending/smtp2go/",
      "markdown": "https://privacyratings.com/email-sending/smtp2go/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Tag Manager and the Microsoft Advertising tag."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.smtp2go.com/privacy/",
          "note": "Funded by paid plans and states personal information is not sold, traded or rented, but the website loads the Microsoft Advertising tag."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=smtp2go.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=smtp2go.com",
          "note": "Grade F (20/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted after delivery",
          "weight": 3,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tracking_off_by_default": {
          "title": "Open and click tracking off by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.smtp2go.com/hc/en-gb/articles/360003124714-Open-Tracking",
          "note": "Open and click tracking are turned on for each SMTP user, IP address or API key."
        },
        "enforced_tls": {
          "title": "Encrypted delivery can be enforced",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://support.smtp2go.com/hc/en-gb/articles/12974008254873-EU-Data-Center",
          "note": "Accounts for EU and UK customers can send only through the EU data center in Amsterdam, with inbound servers in London and Frankfurt."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Intercom",
            "host": "widget.intercom.io",
            "effect": "none"
          },
          {
            "name": "Trustpilot",
            "host": "widget.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:29:35.286Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sparkpost",
      "category": "email-sending",
      "name": "SparkPost",
      "description": "Email API and SMTP relay for transactional and bulk email, now part of Bird, with a separate EU-hosted service.",
      "website": "https://bird.com/email-api",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": null,
      "score": 15,
      "coverage": 29,
      "summary": "SparkPost is not graded yet: 29% of its criteria have evidence, and 60% is needed. It meets 2 of 12 criteria: TLS configuration and EU data location. It partly meets security headers. It does not meet open source. Still needing evidence: no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests, message content deleted after delivery, open and click tracking off by default and encrypted delivery can be enforced. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/email-sending/sparkpost/",
      "markdown": "https://privacyratings.com/email-sending/sparkpost/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=sparkpost.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=sparkpost.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted after delivery",
          "weight": 3,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tracking_off_by_default": {
          "title": "Open and click tracking off by default",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "enforced_tls": {
          "title": "Encrypted delivery can be enforced",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developers.sparkpost.com/api/",
          "note": "SparkPost EU is the full service hosted in Western Europe, with separate accounts that any customer can create."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:28:58.015Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "basilisk-browser",
      "category": "browsers",
      "name": "Basilisk Browser",
      "description": "Desktop browser built on the Unified XUL Platform (UXP) and Goanna engine, a fork of Mozilla's older code base. Keeps support for NPAPI plugins and XUL extensions.",
      "website": "https://www.basilisk-browser.org",
      "source": "https://repo.palemoon.org/Basilisk-Dev/Basilisk",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Basilisk Browser scores 50 out of 100 (grade D) on the browsers criteria. It meets 4 of 8 criteria: open source, no trackers or telemetry, no ads or data sales and no calls to big-tech services. It does not meet independent audit, blocks trackers by default, fingerprinting protection and timely security updates.",
      "url": "https://privacyratings.com/browsers/basilisk-browser/",
      "markdown": "https://privacyratings.com/browsers/basilisk-browser/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://repo.palemoon.org/Basilisk-Dev/Basilisk/src/branch/master/LICENSE.md",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.basilisk-browser.org/privacy.html",
          "note": "No analytics or telemetry are collected. The only default third-party service is IP-based geolocation when a site requests it."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.basilisk-browser.org/privacy.html",
          "note": "No ads and no data sales. Funded by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "No built-in tracker blocking. Requires add-ons."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.basilisk-browser.org/privacy.html",
          "note": "Not configured to resist fingerprinting out of the box."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.basilisk-browser.org/privacy.html",
          "note": "The listed default third-party services do not include Google, Microsoft or Apple."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.basilisk-browser.org/releasenotes.html",
          "note": "Releases come roughly monthly on the forked UXP platform, with Mozilla security fixes ported selectively, so fixes can lag weeks."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:33.985Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "brave-browser",
      "category": "browsers",
      "name": "Brave Browser",
      "description": "Chromium-based browser with built-in ad, tracker and fingerprinting protection through Brave Shields.",
      "website": "https://brave.com",
      "source": "https://github.com/brave/brave-browser",
      "license": "MPL-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 73,
      "coverage": 100,
      "summary": "Brave Browser scores 73 out of 100 (grade C) on the browsers criteria. It meets 4 of 8 criteria: open source, blocks trackers by default, fingerprinting protection and timely security updates. It partly meets no trackers or telemetry, no ads or data sales and no calls to big-tech services. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/browsers/brave-browser/",
      "markdown": "https://privacyratings.com/browsers/brave-browser/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/brave/brave-browser/blob/master/LICENSE",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://brave.com/privacy/browser/",
          "note": "Privacy-Preserving Product Analytics are on by default and can be turned off. No third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://brave.com/privacy/browser/",
          "note": "Brave Ads, including New Tab Page ads, can appear by default and can be turned off. Ad matching happens on the device."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://brave.com/shields/",
          "note": "Brave Shields blocks trackers and ads by default."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://brave.com/shields/",
          "note": "Randomizes fingerprinting data by default."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://brave.com/privacy/browser/",
          "note": "Google Safe Browsing is proxied on desktop, but on Android requests reach Google directly. It can be turned off."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://brave.com/latest/",
          "note": "Chromium security fixes ship within days and install automatically."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:34.078Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cromite",
      "category": "browsers",
      "name": "Cromite",
      "description": "Chromium fork and successor of Bromite for Android, Windows and Linux. Adds built-in ad blocking, removes Google service integrations and adds fingerprinting mitigations.",
      "website": "https://github.com/uazo/cromite",
      "source": "https://github.com/uazo/cromite",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 75,
      "coverage": 100,
      "summary": "Cromite scores 75 out of 100 (grade B) on the browsers criteria. It meets 6 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, blocks trackers by default, fingerprinting protection and no calls to big-tech services. It does not meet independent audit and timely security updates.",
      "url": "https://privacyratings.com/browsers/cromite/",
      "markdown": "https://privacyratings.com/browsers/cromite/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/uazo/cromite/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/uazo/cromite/blob/master/docs/FEATURES.md",
          "note": "Google telemetry, Safe Browsing reporting and sign-in are removed."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/uazo/cromite#readme",
          "note": "No ads. Funded by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/uazo/cromite/blob/master/docs/FEATURES.md",
          "note": "Built-in ad and tracker blocking is enabled by default."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/uazo/cromite/blob/master/docs/FEATURES.md",
          "note": "Canvas, client rect, media and audio fingerprinting mitigations are built in. The project notes they are not comprehensive."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/uazo/cromite/blob/master/docs/FEATURES.md",
          "note": "Google sign-in, sync, Translate, Safe Browsing and Play Services integrations are removed or disabled."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/uazo/cromite/releases",
          "note": "Stable releases often trail Chromium by several weeks or more."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:34.078Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "duckduckgo-browser",
      "category": "browsers",
      "name": "DuckDuckGo Browser",
      "description": "Browser from DuckDuckGo that uses the system web engine, blocks third-party trackers, and includes a one-tap Fire Button for clearing data, email protection and DuckDuckGo search by default.",
      "website": "https://duckduckgo.com/app",
      "source": "https://github.com/duckduckgo/Android",
      "license": "Apache-2.0",
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 70,
      "coverage": 100,
      "summary": "DuckDuckGo Browser scores 70 out of 100 (grade C) on the browsers criteria. It meets 4 of 8 criteria: blocks trackers by default, fingerprinting protection, no calls to big-tech services and timely security updates. It partly meets open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/browsers/duckduckgo-browser/",
      "markdown": "https://privacyratings.com/browsers/duckduckgo-browser/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/duckduckgo/Android/blob/develop/LICENSE",
          "note": "The Android, iOS and macOS apps are Apache-2.0. The Windows app is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://duckduckgo.com/duckduckgo-help-pages/privacy/atb",
          "note": "The Android app has 0 trackers in Exodus. The apps send anonymous usage pixels without identifiers by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://duckduckgo.com/privacy",
          "note": "The browser has no ads, but the default DuckDuckGo search shows ads based on the search query, not the user. No data is sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://duckduckgo.com/duckduckgo-help-pages/privacy/web-tracking-protections",
          "note": "Third-party tracker scripts on its block list are blocked by default."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://duckduckgo.com/duckduckgo-help-pages/privacy/web-tracking-protections",
          "note": "Fingerprinting scripts are blocked and browser APIs used for fingerprinting are overridden by default."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://duckduckgo.com/duckduckgo-help-pages/threat-protection/scam-blocker",
          "note": "Uses its own malicious-site list instead of Google Safe Browsing, with no data sent to third parties."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/duckduckgo/apple-browsers",
          "note": "Uses the operating system's web engine (WebKit, WebView2 or Android System WebView), which receives security fixes through automatic system updates."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:52.604Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "falkon",
      "category": "browsers",
      "name": "Falkon",
      "description": "KDE web browser built on QtWebEngine, with a built-in ad blocker, session management, and integration with the Plasma desktop.",
      "website": "https://www.falkon.org",
      "source": "https://invent.kde.org/network/falkon",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 57,
      "coverage": 100,
      "summary": "Falkon scores 57 out of 100 (grade D) on the browsers criteria. It meets 4 of 8 criteria: open source, no trackers or telemetry, no ads or data sales and no calls to big-tech services. It partly meets blocks trackers by default. It does not meet independent audit, fingerprinting protection and timely security updates.",
      "url": "https://privacyratings.com/browsers/falkon/",
      "markdown": "https://privacyratings.com/browsers/falkon/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://invent.kde.org/network/falkon/-/blob/master/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://invent.kde.org/network/falkon",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kde.org/donate/",
          "note": "Developed by the KDE community and funded by donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/KDE/falkon/blob/master/src/lib/adblock/adblockmanager.cpp",
          "note": "The built-in ad blocker is on by default with EasyList and NoCoin, but tracker lists such as EasyPrivacy must be added by hand."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No fingerprinting protection is documented."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://invent.kde.org/network/falkon",
          "note": "QtWebEngine has no Google Safe Browsing or other Google services, and no such connections are in the source code."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "no",
          "evidence": "https://wiki.qt.io/QtWebEngine/ChromiumVersions",
          "note": "QtWebEngine is based on an older Chromium branch, and backported security fixes arrive with Qt releases, often weeks after Chrome."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:37.711Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fennec-f-droid",
      "category": "browsers",
      "name": "Fennec F-Droid",
      "description": "Build of Firefox for Android published by F-Droid, with proprietary components and telemetry removed. It still connects to some Mozilla services.",
      "website": "https://f-droid.org/packages/org.mozilla.fennec_fdroid/",
      "source": "https://gitlab.com/relan/fennecbuild",
      "license": null,
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 57,
      "coverage": 100,
      "summary": "Fennec F-Droid scores 57 out of 100 (grade D) on the browsers criteria. It meets 2 of 8 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry, blocks trackers by default, fingerprinting protection, no calls to big-tech services and timely security updates. It does not meet independent audit.",
      "url": "https://privacyratings.com/browsers/fennec-f-droid/",
      "markdown": "https://privacyratings.com/browsers/fennec-f-droid/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/relan/fennecbuild/-/blob/master/COPYING",
          "note": "Build scripts are AGPL-3.0, and Firefox code is MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://f-droid.org/packages/org.mozilla.fennec_fdroid/",
          "note": "Telemetry is removed, but F-Droid flags the app for connecting to Mozilla services that can track users."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gitlab.com/relan/fennecbuild/-/blob/master/fenix-liberate.patch",
          "note": "Sponsored shortcuts and sponsored stories are disabled in the build. Volunteer project."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://support.mozilla.org/en-US/kb/enhanced-tracking-protection-android",
          "note": "Uses Firefox Enhanced Tracking Protection in Standard mode, which blocks social trackers and cross-site cookies but not all tracking content."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.mozilla.org/en-US/kb/firefox-protection-against-fingerprinting",
          "note": "Known fingerprinters are blocked, but fingerprinting data is only altered in Strict mode or private tabs."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://f-droid.org/packages/org.mozilla.fennec_fdroid/",
          "note": "Google Play components are removed, but Firefox's Google Safe Browsing lists and some Mozilla services remain."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://f-droid.org/packages/org.mozilla.fennec_fdroid/",
          "note": "New Firefox versions usually reach F-Droid within about a week and are installed through an F-Droid client."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:36.408Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "firefox-focus",
      "category": "browsers",
      "name": "Firefox Focus",
      "description": "Browser from Mozilla for Android and iOS that blocks trackers by default and erases history, cookies and passwords with one tap. Sold as Firefox Klar in some countries.",
      "website": "https://www.firefox.com/en-US/mobile/focus/",
      "source": "https://github.com/mozilla-firefox/firefox/tree/main/mobile/android/focus-android",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 55,
      "coverage": 100,
      "summary": "Firefox Focus scores 55 out of 100 (grade D) on the browsers criteria. It meets 3 of 8 criteria: open source, blocks trackers by default and timely security updates. It partly meets no ads or data sales and no calls to big-tech services. It does not meet no trackers or telemetry, independent audit and fingerprinting protection. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/browsers/firefox-focus/",
      "markdown": "https://privacyratings.com/browsers/firefox-focus/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mozilla-firefox/firefox/blob/main/LICENSE",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.mozilla.focus/latest/",
          "note": "Exodus finds Mozilla Telemetry and Sentry crash reporting in the Android app, and a daily usage ping is sent by default unless turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.mozilla.org/en-US/privacy/firefox-focus/",
          "note": "The app shows no ads, but Mozilla earns revenue from the default search engines, whose results pages carry ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.firefox.com/en-US/mobile/focus/",
          "note": "Blocks advertising, analytics, social and other trackers by default."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Blocks known fingerprinting scripts, but no randomization or standardization of fingerprinting data is documented."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.mozilla.org/en-US/privacy/firefox-focus/",
          "note": "Uses Google Safe Browsing, and Google is the default search engine, which can be changed."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.mozilla.org/en-US/security/advisories/",
          "note": "Releases follow Firefox security releases and install automatically through the app stores."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:36.691Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "firefox",
      "category": "browsers",
      "name": "Firefox",
      "description": "Mozilla's open-source browser, built on its own Gecko engine rather than Chromium. Supports a wide range of extensions and extensive customization.",
      "website": "https://www.firefox.com",
      "source": "https://github.com/mozilla-firefox/firefox",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 48,
      "coverage": 100,
      "summary": "Firefox scores 48 out of 100 (grade D) on the browsers criteria. It meets 2 of 8 criteria: open source and timely security updates. It partly meets blocks trackers by default, fingerprinting protection and no calls to big-tech services. It does not meet no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/browsers/firefox/",
      "markdown": "https://privacyratings.com/browsers/firefox/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mozilla-firefox/firefox/blob/main/LICENSE",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.mozilla.org/en-US/privacy/firefox/",
          "note": "The home page loads Google Tag Manager (automated test), and the browser sends technical and interaction telemetry by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.mozilla.org/en-US/privacy/firefox/",
          "note": "Shows sponsored content on the New Tab page by default and shares de-identified data with advertising partners. Mainly funded by search engine deals."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://support.mozilla.org/en-US/kb/enhanced-tracking-protection-firefox-desktop",
          "note": "Blocks social media trackers, cross-site tracking cookies, cryptominers and known fingerprinters by default, but tracking content only in private windows or Strict mode."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.mozilla.org/en-US/kb/firefox-protection-against-fingerprinting",
          "note": "Known fingerprinters are blocked by default, but fingerprinting data is only altered in private windows or Strict mode."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.mozilla.org/en-US/kb/how-does-phishing-and-malware-protection-work",
          "note": "Google Safe Browsing lists are downloaded by default. The feature can be turned off."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.mozilla.org/en-US/security/advisories/",
          "note": "Mozilla publishes security fixes with each release, and Firefox installs updates automatically."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:57.625Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "floorp",
      "category": "browsers",
      "name": "Floorp",
      "description": "Firefox-based browser from Japan with workspaces, split view, web panels, mouse gestures and a customizable interface. Mozilla telemetry is off by default.",
      "website": "https://floorp.app",
      "source": "https://github.com/Floorp-Projects/Floorp",
      "license": "MPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "JP",
        "name": "Japan",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 48,
      "coverage": 100,
      "summary": "Floorp scores 48 out of 100 (grade D) on the browsers criteria. It meets 2 of 8 criteria: open source and timely security updates. It partly meets blocks trackers by default, fingerprinting protection and no calls to big-tech services. It does not meet no trackers or telemetry, no ads or data sales and independent audit. It is based in Japan: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/browsers/floorp/",
      "markdown": "https://privacyratings.com/browsers/floorp/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Floorp-Projects/Floorp/blob/main/LICENSE",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://floorp.app/privacy",
          "note": "The website and blog use Google AdSense, which sets advertising cookies. Mozilla telemetry is off in the browser."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://floorp.app/privacy",
          "note": "The website and blog carry Google AdSense ads, including personalized ads, and the new tab page can show sponsored links."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://support.mozilla.org/en-US/kb/enhanced-tracking-protection-firefox-desktop",
          "note": "Uses Firefox Enhanced Tracking Protection in Standard mode, which blocks social trackers and cross-site cookies but not all tracking content."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.mozilla.org/en-US/kb/firefox-protection-against-fingerprinting",
          "note": "Known fingerprinters are blocked, but fingerprinting data is only altered in Strict mode or private windows."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://floorp.app/privacy",
          "note": "Missing shortcut and web panel icons are fetched from Google's favicon service, and Firefox's Google Safe Browsing lists are downloaded by default."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://blog.floorp.app/categories/release/",
          "note": "Releases move to each new Firefox version within days, and the browser updates itself."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:37.357Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gnome-web",
      "category": "browsers",
      "name": "GNOME Web",
      "description": "Web browser for the GNOME desktop, also called Epiphany, built on WebKitGTK, with ad blocking and Intelligent Tracking Prevention on by default.",
      "website": "https://apps.gnome.org/Epiphany/",
      "source": "https://gitlab.gnome.org/GNOME/epiphany",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 68,
      "coverage": 100,
      "summary": "GNOME Web scores 68 out of 100 (grade C) on the browsers criteria. It meets 4 of 8 criteria: open source, no trackers or telemetry, no ads or data sales and blocks trackers by default. It partly meets no calls to big-tech services and timely security updates. It does not meet independent audit and fingerprinting protection.",
      "url": "https://privacyratings.com/browsers/gnome-web/",
      "markdown": "https://privacyratings.com/browsers/gnome-web/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/GNOME/epiphany/blob/main/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/GNOME/epiphany",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://donate.gnome.org/en/",
          "note": "Developed by the GNOME community and funded by donations to the GNOME Foundation. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/GNOME/epiphany/blob/main/data/org.gnome.epiphany.gschema.xml",
          "note": "The ad blocker with uBlock Origin filter lists and Intelligent Tracking Prevention are on by default."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No fingerprinting protection is documented."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/GNOME/epiphany/blob/main/data/org.gnome.epiphany.gschema.xml",
          "note": "There is no Google Safe Browsing, but the default filter lists are downloaded from GitHub, which is owned by Microsoft. Turning off the ad blocker stops these downloads."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://webkitgtk.org/security.html",
          "note": "WebKitGTK publishes security fixes regularly, and they are installed through the distribution's package manager or Flatpak."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:36.886Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "google-chrome",
      "category": "browsers",
      "name": "Google Chrome",
      "description": "Google's browser, built on the open-source Chromium project.",
      "website": "https://www.google.com/chrome/",
      "source": "https://chromium.googlesource.com/chromium/src",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 23,
      "coverage": 100,
      "summary": "Google Chrome scores 23 out of 100 (grade F) on the browsers criteria. It meets 1 of 8 criteria: timely security updates. It partly meets open source. It does not meet no trackers or telemetry, no ads or data sales, independent audit, blocks trackers by default, fingerprinting protection and no calls to big-tech services. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/browsers/google-chrome/",
      "markdown": "https://privacyratings.com/browsers/google-chrome/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://chromium.googlesource.com/chromium/src",
          "note": "Built on open-source Chromium, but Chrome adds closed-source components."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics and Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Made by an advertising company. Browsing data supports Google's ad business."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Third-party trackers are not blocked by default."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No fingerprinting protection."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Signs in to and syncs with Google services, and sends usage data to Google by default."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://chromereleases.googleblog.com/",
          "note": "Security fixes ship in frequent stable updates that install automatically."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:34.171Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "helium",
      "category": "browsers",
      "name": "Helium",
      "description": "Chromium-based desktop browser from imput built on ungoogled-chromium, with uBlock Origin built in, Google services removed and no telemetry.",
      "website": "https://helium.computer",
      "source": "https://github.com/imputnet/helium",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 90,
      "coverage": 100,
      "summary": "Helium scores 90 out of 100 (grade A) on the browsers criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, blocks trackers by default, fingerprinting protection, no calls to big-tech services and timely security updates. It does not meet independent audit.",
      "url": "https://privacyratings.com/browsers/helium/",
      "markdown": "https://privacyratings.com/browsers/helium/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/imputnet/helium/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://helium.computer/",
          "note": "No third-party trackers. The browser collects no data, and the website's Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://helium.computer/",
          "note": "Crowdfunded by users. No browser ads and no data collection."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://helium.computer/",
          "note": "Blocks ads, trackers, cookie banners and third-party cookies by default."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://helium.computer/",
          "note": "Adds noise to certain web APIs by default to resist fingerprinting."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://helium.computer/",
          "note": "All Google service dependencies are removed, and no background requests are made without consent."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://helium.computer/",
          "note": "Releases follow Chromium stable updates within days and install automatically on macOS and Windows."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:37.708Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "icecat",
      "category": "browsers",
      "name": "IceCat",
      "description": "GNU's build of Firefox ESR containing only free software. Removes non-free components such as DRM and bundles LibreJS and JShelter to restrict JavaScript and fingerprinting.",
      "website": "https://www.gnu.org/software/gnuzilla/",
      "source": "https://cgit.git.savannah.gnu.org/cgit/gnuzilla.git",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 83,
      "coverage": 100,
      "summary": "IceCat scores 83 out of 100 (grade B) on the browsers criteria. It meets 6 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, blocks trackers by default, fingerprinting protection and no calls to big-tech services. It partly meets timely security updates. It does not meet independent audit.",
      "url": "https://privacyratings.com/browsers/icecat/",
      "markdown": "https://privacyratings.com/browsers/icecat/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://cgit.git.savannah.gnu.org/cgit/gnuzilla.git/tree/COPYING",
          "note": "Build scripts under GPL-3.0; the browser code is MPL-2.0 from Firefox."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://cgit.git.savannah.gnu.org/cgit/gnuzilla.git/tree/data/settings.js",
          "note": "Telemetry and health reports are disabled in the default settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.gnu.org/software/gnuzilla/",
          "note": "GNU volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://cgit.git.savannah.gnu.org/cgit/gnuzilla.git/tree/data/settings.js",
          "note": "Tracking protection is enabled for all windows by default."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cgit.git.savannah.gnu.org/cgit/gnuzilla.git/tree/data/settings.js",
          "note": "Resist Fingerprinting is enabled by default, and JShelter is bundled."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cgit.git.savannah.gnu.org/cgit/gnuzilla.git/tree/data/settings.js",
          "note": "Google Safe Browsing and its update URLs are disabled."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.gnu.org/software/gnuzilla/",
          "note": "Source updates follow Firefox ESR releases within days, but no official binaries are published, so updates come through GNU Guix or distribution packages."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:04.172Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "iridium",
      "category": "browsers",
      "name": "Iridium",
      "description": "Chromium fork that disables or makes opt-in the transmission of queries, keywords and metrics to Google and other services. Distributed as source code tarballs only.",
      "website": "https://iridiumbrowser.de",
      "source": "https://iridiumbrowser.de/downloads/source",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "Iridium scores 45 out of 100 (grade D) on the browsers criteria. It meets 3 of 8 criteria: open source, no trackers or telemetry and no ads or data sales. It partly meets no calls to big-tech services. It does not meet independent audit, blocks trackers by default, fingerprinting protection and timely security updates. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/browsers/iridium/",
      "markdown": "https://privacyratings.com/browsers/iridium/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://iridiumbrowser.de/faq",
          "note": "Uses the same open-source licenses as Chromium. Source is published as tarballs and in a Git repository."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://iridiumbrowser.de/about",
          "note": "Metrics and partial queries are only sent with the user's approval."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://iridiumbrowser.de/about",
          "note": "No ads in the browser and no data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "No built-in tracker blocking."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No fingerprinting protection beyond Chromium defaults."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://iridiumbrowser.de/faq",
          "note": "Google Safe Browsing is on by default and contacts Google servers, but can be turned off. Google sign-in and sync are not available."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "no",
          "evidence": "https://iridiumbrowser.de/news/archive/",
          "note": "Only source tarballs are published, with no automatic updates, and releases trail current Chromium by several weeks."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:36.009Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ironfox",
      "category": "browsers",
      "name": "IronFox",
      "description": "Firefox-based browser for Android, a fork of Mull, with telemetry removed, uBlock Origin preinstalled, Strict tracking protection and hardened privacy settings.",
      "website": "https://ironfoxoss.org",
      "source": "https://gitlab.com/ironfox-oss/IronFox",
      "license": null,
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "IronFox scores 85 out of 100 (grade B) on the browsers criteria. It meets 6 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, blocks trackers by default, fingerprinting protection and timely security updates. It partly meets no calls to big-tech services. It does not meet independent audit.",
      "url": "https://privacyratings.com/browsers/ironfox/",
      "markdown": "https://privacyratings.com/browsers/ironfox/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/ironfox-oss/IronFox/src/branch/dev/COPYING",
          "note": "Build scripts are AGPL-3.0, and patches are MPL-2.0 or Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://ironfoxoss.org/docs/features/",
          "note": "Telemetry and data collection are disabled at build time, and tracking libraries such as Adjust and Sentry are removed."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ironfoxoss.org/",
          "note": "Volunteer project. It does not collect, store or sell user data and has no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://ironfoxoss.org/docs/features/",
          "note": "Ships uBlock Origin and enables Strict Enhanced Tracking Protection by default."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ironfoxoss.org/docs/features/",
          "note": "Enables Firefox's fingerprinting protection by default, which alters fingerprinting data."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://ironfoxoss.org/docs/safe-browsing/",
          "note": "Google Safe Browsing is on by default through a privacy proxy and can be turned off in settings. Google Play Services are not required."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://ironfoxoss.org/releases/",
          "note": "Releases follow each Firefox release, and Accrescent installs updates automatically."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:38.791Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ladybird",
      "category": "browsers",
      "name": "Ladybird",
      "description": "Independent web browser with a new engine written from scratch, developed by a US non-profit. Still in development with no stable release; it can be built from source on Linux and macOS.",
      "website": "https://ladybird.org",
      "source": "https://github.com/LadybirdBrowser/ladybird",
      "license": "BSD-2-Clause",
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 59,
      "coverage": 100,
      "summary": "Ladybird scores 59 out of 100 (grade D) on the browsers criteria. It meets 4 of 7 criteria: open source, no trackers or telemetry, no ads or data sales and no calls to big-tech services. It does not meet independent audit, blocks trackers by default and fingerprinting protection. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/browsers/ladybird/",
      "markdown": "https://privacyratings.com/browsers/ladybird/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/LadybirdBrowser/ladybird/blob/master/LICENSE",
          "note": "BSD-2-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://ladybird.org/",
          "note": "No data collection, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ladybird.org/",
          "note": "Funded by donations and sponsorships, with no search deals, data collection or ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/LadybirdBrowser/ladybird/blob/master/Libraries/LibWebView/Settings.cpp",
          "note": "Content blocking with EasyList and EasyPrivacy is built in but the lists are off by default."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No fingerprinting protection is documented."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ladybird.org/",
          "note": "An independent engine with no Google, Microsoft or Apple services built in."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "n/a",
          "evidence": null,
          "note": "No releases are published yet. The browser is only available by building it from source."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:37.737Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "librewolf",
      "category": "browsers",
      "name": "LibreWolf",
      "description": "Independent fork of Firefox with telemetry removed, uBlock Origin included and Resist Fingerprinting enabled by default.",
      "website": "https://librewolf.net",
      "source": "https://codeberg.org/librewolf/source",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 83,
      "coverage": 100,
      "summary": "LibreWolf scores 83 out of 100 (grade B) on the browsers criteria. It meets 6 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, blocks trackers by default, fingerprinting protection and no calls to big-tech services. It partly meets timely security updates. It does not meet independent audit.",
      "url": "https://privacyratings.com/browsers/librewolf/",
      "markdown": "https://privacyratings.com/browsers/librewolf/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/librewolf/source/src/branch/main/LICENSE",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://librewolf.net/docs/features/",
          "note": "Telemetry, crash reports, studies and experiments are disabled."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://librewolf.net/docs/faq/#why-dont-you-accept-donations",
          "note": "Volunteer project with no ads. It does not accept donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://librewolf.net/docs/features/",
          "note": "Ships uBlock Origin and Enhanced Tracking Protection in Strict mode."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://librewolf.net/docs/features/",
          "note": "Resist Fingerprinting is enabled by default."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://librewolf.net/docs/faq/#why-do-you-disable-google-safe-browsing",
          "note": "Google Safe Browsing is disabled, and the remaining outgoing connections are for updates and block lists."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://librewolf.net/docs/faq/#how-often-do-you-update-librewolf",
          "note": "Releases usually follow Firefox within three days, but there is no built-in auto-update."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:35.694Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "microsoft-edge",
      "category": "browsers",
      "name": "Microsoft Edge",
      "description": "Microsoft's browser, built on Chromium and bundled with Windows.",
      "website": "https://www.microsoft.com/edge",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Microsoft Edge scores 30 out of 100 (grade F) on the browsers criteria. It meets 1 of 8 criteria: timely security updates. It partly meets open source and blocks trackers by default. It does not meet no trackers or telemetry, no ads or data sales, independent audit, fingerprinting protection and no calls to big-tech services. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/browsers/microsoft-edge/",
      "markdown": "https://privacyratings.com/browsers/microsoft-edge/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://chromium.googlesource.com/chromium/src",
          "note": "Built on open-source Chromium, but Edge itself is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/legal/microsoft-edge/privacy",
          "note": "Required diagnostic data is sent to Microsoft and cannot be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/legal/microsoft-edge/privacy",
          "note": "Shows ads and sponsored content on the New Tab page, and browsing activity can be used to personalize Microsoft ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://learn.microsoft.com/en-us/microsoft-edge/web-platform/tracking-prevention",
          "note": "Tracking prevention is on in Balanced mode by default, which blocks some trackers."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/microsoft-edge/web-platform/tracking-prevention",
          "note": "Tracking prevention blocks some known fingerprinting scripts by list, but fingerprinting data is not randomized or standardized."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/legal/microsoft-edge/privacy",
          "note": "Required diagnostic data and other Microsoft services are built in and cannot be fully turned off."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security",
          "note": "Chromium security fixes ship within days and install automatically."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:55.018Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mullvad-browser",
      "category": "browsers",
      "name": "Mullvad Browser",
      "description": "Firefox-based browser developed by the Tor Project and Mullvad for use without the Tor network. Uses Tor Browser's anti-fingerprinting defenses, has no telemetry and includes uBlock Origin.",
      "website": "https://mullvad.net/en/browser",
      "source": "https://github.com/mullvad/mullvad-browser",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "SE",
        "name": "Sweden",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": true,
      "pick_reason": "Tor Browser's protections without the Tor network: fingerprinting resistance that makes users look alike, uBlock Origin built in, no telemetry, and fast security updates. Built by the Tor Project and Mullvad, free, and works with any VPN.",
      "disclosure": null,
      "grade": "A",
      "score": 90,
      "coverage": 100,
      "summary": "Mullvad Browser scores 90 out of 100 (grade A) on the browsers criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, blocks trackers by default, fingerprinting protection, no calls to big-tech services and timely security updates. It does not meet independent audit. It is based in Sweden: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/browsers/mullvad-browser/",
      "markdown": "https://privacyratings.com/browsers/mullvad-browser/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://mullvad.net/en/browser",
          "note": "MPL-2.0, built by the Tor Project on Firefox ESR."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://mullvad.net/en/browser",
          "note": "Telemetry is removed."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mullvad.net/en/browser",
          "note": "Free of charge, with no ads, whether or not the user has a Mullvad VPN account."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://mullvad.net/en/browser/hard-facts",
          "note": "uBlock Origin is included and enabled by default."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mullvad.net/en/browser/hard-facts",
          "note": "Resist Fingerprinting and letterboxing are enabled by default so users look alike."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mullvad.net/en/browser/hard-facts",
          "note": "The listed default connections go to Mullvad, Mozilla, and filter list and certificate providers, not Google, Microsoft or Apple services."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://mullvad.net/en/browser/hard-facts",
          "note": "Releases follow Firefox ESR security updates alongside Tor Browser, and the built-in updater installs them."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:36.811Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "opera",
      "category": "browsers",
      "name": "Opera",
      "description": "Chromium-based browser from Opera with a built-in ad blocker, free VPN proxy, sidebar messengers and an AI assistant.",
      "website": "https://www.opera.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "NO",
        "name": "Norway",
        "eyes": "Nine Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 5,
      "coverage": 100,
      "summary": "Opera scores 5 out of 100 (grade F) on the browsers criteria. It partly meets no calls to big-tech services. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, blocks trackers by default, fingerprinting protection and timely security updates. It is based in Norway: Nine Eyes member; EEA member (GDPR).",
      "url": "https://privacyratings.com/browsers/opera/",
      "markdown": "https://privacyratings.com/browsers/opera/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.opera.com/legal/privacy",
          "note": "The home page loads Google Tag Manager, Meta Pixel and Microsoft Clarity. The browsers send usage statistics by default and the mobile apps include Firebase Analytics and AppsFlyer."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.opera.com/legal/privacy",
          "note": "The privacy statement describes the apps as ad-supported, with sponsored content and data shared with advertising partners."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "no",
          "evidence": "https://help.opera.com/en/latest/features/",
          "note": "The built-in ad and tracker blocker must be turned on in settings."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No fingerprinting protection is documented."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.opera.com/legal/privacy",
          "note": "Uses Google Safe Browsing and Google search suggestions by default. Both can be turned off in settings."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "no",
          "evidence": "https://blogs.opera.com/desktop/2026/09/opera-136-0-6008-52-stable-update/",
          "note": "Stable releases are built on an older Chromium branch and pick up upstream security patches one to two weeks after Chromium Extended Stable."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Facebook SDK",
            "host": "connect.facebook.net",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Ads",
            "host": "bat.bing.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Clarity",
            "host": "www.clarity.ms",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:38.296Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "orion-browser",
      "category": "browsers",
      "name": "Orion Browser",
      "description": "WebKit-based browser from Kagi for macOS and iOS that blocks ads and trackers by default, has no telemetry, and supports many Chrome and Firefox extensions.",
      "website": "https://orionbrowser.com",
      "license": null,
      "platforms": [
        "macos",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Orion Browser scores 65 out of 100 (grade C) on the browsers criteria. It meets 5 of 8 criteria: no trackers or telemetry, no ads or data sales, blocks trackers by default, no calls to big-tech services and timely security updates. It does not meet open source, independent audit and fingerprinting protection. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/browsers/orion-browser/",
      "markdown": "https://privacyratings.com/browsers/orion-browser/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. Kagi says some components have been published and more are planned."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://help.kagi.com/orion/privacy-and-security/respecting-privacy.html",
          "note": "Orion has no built-in telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://orionbrowser.com/",
          "note": "Funded by users through Orion+ subscriptions and lifetime licenses, with no ads and no third-party deals."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://help.kagi.com/orion/privacy-and-security/ad-tracking-blocking.html",
          "note": "Blocks first-party and third-party ads and trackers by default."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "no",
          "evidence": "https://help.kagi.com/orion/privacy-and-security/preventing-fingerprinting.html",
          "note": "Relies on blocking fingerprinting scripts and does not randomize or standardize fingerprinting data."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://help.kagi.com/orion/privacy-and-security/respecting-privacy.html",
          "note": "The browser does not phone home and includes no Google services."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://help.kagi.com/orion/faq/faq.html",
          "note": "Built on Apple's WebKit, whose security fixes arrive through automatic macOS and iOS updates."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:38.077Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "palemoon",
      "category": "browsers",
      "name": "PaleMoon",
      "description": "Independent desktop browser built on the Unified XUL Platform (UXP) and Goanna engine, forked from older Mozilla code. Collects no telemetry and supports legacy XUL extensions.",
      "website": "https://www.palemoon.org",
      "source": "https://repo.palemoon.org/MoonchildProductions/Pale-Moon",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "PaleMoon scores 50 out of 100 (grade D) on the browsers criteria. It meets 4 of 8 criteria: open source, no trackers or telemetry, no ads or data sales and no calls to big-tech services. It does not meet independent audit, blocks trackers by default, fingerprinting protection and timely security updates.",
      "url": "https://privacyratings.com/browsers/palemoon/",
      "markdown": "https://privacyratings.com/browsers/palemoon/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://repo.palemoon.org/MoonchildProductions/Pale-Moon/src/branch/master/LICENSE",
          "note": "Source under MPL-2.0 and other Mozilla licenses. Official branding and binaries carry a redistribution license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.palemoon.org/policies/privacy.shtml",
          "note": "No telemetry on browser or extension use, and no tracking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.palemoon.org/donations.shtml",
          "note": "No ads in the browser. Supported by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "No built-in tracker blocking. Requires extensions."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No fingerprinting protection is enabled by default."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.palemoon.org/policies/privacy.shtml",
          "note": "Default connections go to Pale Moon servers, IP-API geolocation and the chosen search engine, not to Google, Microsoft or Apple."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.palemoon.org/releasenotes-archived.shtml",
          "note": "Mozilla security fixes are ported selectively to its own platform in releases every few weeks to months."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:36.344Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "qutebrowser",
      "category": "browsers",
      "name": "qutebrowser",
      "description": "Keyboard-driven browser with a minimal interface and Vim-style key bindings, built on Python and QtWebEngine.",
      "website": "https://qutebrowser.org",
      "source": "https://github.com/qutebrowser/qutebrowser",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "qutebrowser scores 65 out of 100 (grade C) on the browsers criteria. It meets 5 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, blocks trackers by default and no calls to big-tech services. It does not meet independent audit, fingerprinting protection and timely security updates.",
      "url": "https://privacyratings.com/browsers/qutebrowser/",
      "markdown": "https://privacyratings.com/browsers/qutebrowser/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/qutebrowser/qutebrowser/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/qutebrowser/qutebrowser",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://qutebrowser.org/",
          "note": "Funded by donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://qutebrowser.org/doc/help/settings.html#content.blocking.enabled",
          "note": "The ad and host blocker is on by default, using EasyList and EasyPrivacy or a hosts list."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No fingerprinting protection is documented."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/qutebrowser/qutebrowser",
          "note": "QtWebEngine has no Google Safe Browsing or other Google services, and no such connections are in the source code."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "no",
          "evidence": "https://wiki.qt.io/QtWebEngine/ChromiumVersions",
          "note": "QtWebEngine is based on an older Chromium branch, and backported security fixes arrive with Qt releases, often weeks after Chrome."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:39.385Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "safari",
      "category": "browsers",
      "name": "Safari",
      "description": "Apple's browser for macOS and iOS, built on the open-source WebKit engine.",
      "website": "https://www.apple.com/safari/",
      "source": "https://github.com/WebKit/WebKit",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 63,
      "coverage": 100,
      "summary": "Safari scores 63 out of 100 (grade C) on the browsers criteria. It meets 3 of 8 criteria: no ads or data sales, fingerprinting protection and timely security updates. It partly meets open source, no trackers or telemetry, blocks trackers by default and no calls to big-tech services. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/browsers/safari/",
      "markdown": "https://privacyratings.com/browsers/safari/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/WebKit/WebKit",
          "note": "The WebKit engine is open source. Safari itself is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/device-analytics/",
          "note": "No third-party trackers in the app, and sharing device analytics with Apple is opt-in. Apple web pages load Apple's own analytics (ac-analytics, sent to metrics.apple.com) by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/en-ww/",
          "note": "No ads in the browser. Apple states it does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://webkit.org/tracking-prevention/",
          "note": "Intelligent Tracking Prevention limits cross-site tracking by default but does not block tracker requests."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://webkit.org/tracking-prevention/",
          "note": "Standardizes fingerprinting data by default, such as limiting fonts to system and web fonts and freezing the user agent string."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/safari/",
          "note": "Fraudulent Website Warning sends data to Google Safe Browsing and Apple, and can be turned off. Safari is built into Apple's operating systems and services."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://support.apple.com/en-us/100100",
          "note": "Security fixes ship in Apple software updates, which can install automatically."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:35.856Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "samsung-internet",
      "category": "browsers",
      "name": "Samsung Browser",
      "description": "Chromium-based browser from Samsung, formerly called Samsung Internet, preinstalled on Galaxy phones and tablets and also available for Windows. Includes Smart anti-tracking, Secret mode and ad-blocker add-ons.",
      "website": "https://browser.samsung.com",
      "license": null,
      "platforms": [
        "android",
        "windows"
      ],
      "jurisdiction": {
        "code": "KR",
        "name": "South Korea",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 8,
      "coverage": 100,
      "summary": "Samsung Browser scores 8 out of 100 (grade F) on the browsers criteria. It partly meets blocks trackers by default. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, fingerprinting protection, no calls to big-tech services and timely security updates. It is based in South Korea: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/browsers/samsung-internet/",
      "markdown": "https://privacyratings.com/browsers/samsung-internet/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.samsung.com/us/account/privacy-policy/",
          "note": "The Samsung privacy policy lists Google Analytics, Firebase Analytics and Adobe Analytics, and the product site loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.samsung.com/us/account/privacy-policy/",
          "note": "Samsung uses personal information for personalized advertising and shares it for targeted advertising, which the policy says may count as a sale."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://developer.samsung.com/browser/release-note.html",
          "note": "Smart anti-tracking is on by default and limits third-party cookie access for known trackers. Ad blocking needs an add-on."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No fingerprinting protection is documented."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Samsung does not document which Google services the browser contacts or how to turn them off."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "no",
          "evidence": "https://developer.samsung.com/browser/release-note.html",
          "note": "Releases are built on Chromium versions several releases behind Chrome, and the release notes do not list security fixes."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:38.763Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "seamonkey",
      "category": "browsers",
      "name": "SeaMonkey",
      "description": "Internet suite with a browser, mail and news client, IRC chat and HTML editor, continuing the Mozilla Application Suite. Built on an older Mozilla platform with backported fixes.",
      "website": "https://www.seamonkey-project.org",
      "source": "https://gitlab.com/seamonkey-project/seamonkey-2.53-comm",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "SeaMonkey scores 45 out of 100 (grade D) on the browsers criteria. It meets 3 of 8 criteria: open source, no trackers or telemetry and no ads or data sales. It partly meets no calls to big-tech services. It does not meet independent audit, blocks trackers by default, fingerprinting protection and timely security updates. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/browsers/seamonkey/",
      "markdown": "https://privacyratings.com/browsers/seamonkey/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.seamonkey-project.org/legal/",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.seamonkey-project.org/legal/privacy",
          "note": "No analytics. Crash reports are only sent when the user chooses to."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.seamonkey-project.org/donate/",
          "note": "No ads. Supported by donations to the SeaMonkey association."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Third-party trackers are not blocked by default."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No fingerprinting protection is enabled by default."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.seamonkey-project.org/legal/third-party",
          "note": "Uses Google Geolocation when a site requests location, which can be turned off."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.seamonkey-project.org/releases/",
          "note": "Releases on the older 2.53 platform come every few months with backported fixes, so security fixes lag upstream by weeks or more."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:36.643Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "tor-browser",
      "category": "browsers",
      "name": "Tor Browser",
      "description": "Firefox-based browser that routes traffic through the Tor network to hide the user's IP address and location. Isolates each site and makes users look alike to resist tracking and fingerprinting.",
      "website": "https://www.torproject.org",
      "source": "https://gitlab.torproject.org/tpo/applications/tor-browser",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 93,
      "coverage": 100,
      "summary": "Tor Browser scores 93 out of 100 (grade A) on the browsers criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, independent audit, fingerprinting protection, no calls to big-tech services and timely security updates. It partly meets blocks trackers by default. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/browsers/tor-browser/",
      "markdown": "https://privacyratings.com/browsers/tor-browser/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.torproject.org/about/history/",
          "note": "MPL-2.0, built on Firefox ESR. Source releases are published at dist.torproject.org. The Tor GitLab now requires sign-in to view files."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.torproject.org/about/privacy_policy/",
          "note": "No tracking, telemetry or analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://donate.torproject.org/",
          "note": "Nonprofit funded by donations and grants. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.torproject.org/static/findoc/code_audits/Cure53_audit_jan_2024.pdf",
          "note": "Cure53 audited changes in Tor Browser for desktop and Android, with the full report published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.torproject.org/",
          "note": "Isolates each site so third-party trackers cannot follow users across sites, but does not block tracker requests."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.torproject.org/tor-browser/features/fingerprinting-protections/",
          "note": "Standardizes fingerprinting data by default so users look alike."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.torproject.org/about/privacy_policy/",
          "note": "No background connections to Google, Microsoft or Apple services. Traffic goes through the Tor network."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://support.torproject.org/tor-browser/getting-started/updating/",
          "note": "Releases follow Firefox ESR security updates and can install automatically."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:36.476Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ungoogled-chromium",
      "category": "browsers",
      "name": "Ungoogled Chromium",
      "description": "Chromium with all Google web services, background requests and Google-specific code removed, while keeping the familiar Chromium experience.",
      "website": "https://github.com/ungoogled-software/ungoogled-chromium",
      "source": "https://github.com/ungoogled-software/ungoogled-chromium",
      "license": "BSD-3-Clause",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": true,
      "pick_reason": "The speed and site compatibility of Chromium without the constant connections to Google. Pair it with uBlock Origin for tracker blocking.",
      "disclosure": null,
      "grade": "C",
      "score": 63,
      "coverage": 100,
      "summary": "Ungoogled Chromium scores 63 out of 100 (grade C) on the browsers criteria. It meets 4 of 8 criteria: open source, no trackers or telemetry, no ads or data sales and no calls to big-tech services. It partly meets fingerprinting protection and timely security updates. It does not meet independent audit and blocks trackers by default.",
      "url": "https://privacyratings.com/browsers/ungoogled-chromium/",
      "markdown": "https://privacyratings.com/browsers/ungoogled-chromium/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ungoogled-software/ungoogled-chromium/blob/master/LICENSE",
          "note": null
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ungoogled-software/ungoogled-chromium#readme",
          "note": "Removes all background requests to web services while building and running the browser."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/ungoogled-software/ungoogled-chromium",
          "note": "Community project with no ads or commercial funding."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "No built-in blocker. Install uBlock Origin or uBlock Origin Lite."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/ungoogled-software/ungoogled-chromium/blob/master/docs/flags.md",
          "note": "Canvas and client-rect noise flags exist but are off by default."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/ungoogled-software/ungoogled-chromium#readme",
          "note": null
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://ungoogled-software.github.io/ungoogled-chromium-binaries/",
          "note": "No built-in auto-update. Builds come from package managers and community packagers."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:36.345Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vanadium",
      "category": "browsers",
      "name": "Vanadium",
      "description": "Hardened Chromium-based browser and system WebView from GrapheneOS, with JIT disabled by default, built-in content filtering and remote services removed. Only available on GrapheneOS.",
      "website": "https://grapheneos.org/features#vanadium",
      "source": "https://github.com/GrapheneOS/Vanadium",
      "license": null,
      "platforms": [
        "android"
      ],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 90,
      "coverage": 100,
      "summary": "Vanadium scores 90 out of 100 (grade A) on the browsers criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, blocks trackers by default, fingerprinting protection, no calls to big-tech services and timely security updates. It does not meet independent audit. It is based in Canada: Five Eyes member.",
      "url": "https://privacyratings.com/browsers/vanadium/",
      "markdown": "https://privacyratings.com/browsers/vanadium/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/GrapheneOS/Vanadium/blob/main/LICENSE",
          "note": "Patches are GPL-2.0, on top of the BSD-licensed Chromium code."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://grapheneos.org/features#vanadium",
          "note": "Nearly all remote services are disabled or removed, and the browser only connects to GrapheneOS servers by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://grapheneos.org/donate",
          "note": "Funded by donations to the non-profit GrapheneOS Foundation. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://grapheneos.org/features#vanadium",
          "note": "Content filtering with EasyList and EasyPrivacy is on by default, and third-party cookies are blocked."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://grapheneos.org/features#vanadium",
          "note": "Standardizes the user agent, client hints and battery status by default, and aims for identical configuration across users."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://grapheneos.org/features#vanadium",
          "note": "Only connects to GrapheneOS servers by default, for component updates and optional DNS-over-HTTPS checks."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/GrapheneOS/Vanadium/tags",
          "note": "New Chromium releases are usually tagged the same day or within a few days, and the GrapheneOS app repository installs updates automatically."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:52.723Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vivaldi",
      "category": "browsers",
      "name": "Vivaldi",
      "description": "Chromium-based browser from Vivaldi Technologies with a customizable interface, built-in mail, calendar and feed reader, and optional tracker and ad blocking.",
      "website": "https://vivaldi.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "NO",
        "name": "Norway",
        "eyes": "Nine Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 28,
      "coverage": 100,
      "summary": "Vivaldi scores 28 out of 100 (grade F) on the browsers criteria. It meets 1 of 8 criteria: timely security updates. It partly meets open source and no ads or data sales. It does not meet no trackers or telemetry, independent audit, blocks trackers by default, fingerprinting protection and no calls to big-tech services. It is based in Norway: Nine Eyes member; EEA member (GDPR).",
      "url": "https://privacyratings.com/browsers/vivaldi/",
      "markdown": "https://privacyratings.com/browsers/vivaldi/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://help.vivaldi.com/desktop/privacy/is-vivaldi-open-source/",
          "note": "Changes to Chromium are published under a BSD license, but the user interface code is not under an open-source license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://vivaldi.com/privacy/browser/",
          "note": "The browser sends a daily message with a unique installation ID, version and screen resolution to count users, and no setting to turn it off is documented. The website uses Umami analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://vivaldi.com/privacy/browser/",
          "note": "Default bookmarks and search engines include revenue-sharing partners, which can be removed. No data is sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "no",
          "evidence": "https://vivaldi.com/features/ad-blocker/",
          "note": "The ad blocker is off by default. Tracker blocking is a setting that the user chooses."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No fingerprinting protection is documented."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "no",
          "evidence": "https://vivaldi.com/privacy/browser/",
          "note": "Google Safe Browsing is used on desktop and Android and can only be turned off on desktop."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://vivaldi.com/blog/desktop/minor-update-six-8-2/",
          "note": "Minor updates bring Chromium security fixes within days and install automatically on Windows and macOS."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:15.490Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "waterfox",
      "category": "browsers",
      "name": "WaterFox",
      "description": "Firefox-based browser with telemetry, studies and sponsored content removed, and a built-in ad and tracker blocker. Available for desktop and Android.",
      "website": "https://www.waterfox.com",
      "source": "https://github.com/BrowserWorks/waterfox",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "WaterFox scores 85 out of 100 (grade B) on the browsers criteria. It meets 6 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, blocks trackers by default, no calls to big-tech services and timely security updates. It partly meets fingerprinting protection. It does not meet independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/browsers/waterfox/",
      "markdown": "https://privacyratings.com/browsers/waterfox/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/BrowserWorks/waterfox/blob/current/LICENSE",
          "note": "MPL-2.0 and other Mozilla licenses."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.waterfox.com/docs/policies/privacy/",
          "note": "No telemetry or analytics. Telemetry modules are disabled at build time."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.waterfox.com/docs/policies/privacy/",
          "note": "No sponsored content in the browser. Funded through search partner revenue sharing, not data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.waterfox.com/docs/policies/privacy/",
          "note": "A built-in ad and tracker blocker with bundled filter lists works from first launch."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.waterfox.com/support/enhanced-tracking-protection/",
          "note": "Standard Enhanced Tracking Protection is the default. Stronger fingerprinting protections require Strict or custom settings."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.waterfox.com/docs/policies/privacy/",
          "note": "Google Safe Browsing is removed. Google's Widevine module is only downloaded when DRM video is played."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.waterfox.com/releases/",
          "note": "Releases include Mozilla ESR security fixes, usually within about a week, and install through the built-in updater."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:36.494Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "zen-browser",
      "category": "browsers",
      "name": "Zen Browser",
      "description": "Firefox-based desktop browser with vertical tabs, workspaces, split view and a compact interface. Mozilla telemetry is removed.",
      "website": "https://zen-browser.app",
      "source": "https://github.com/zen-browser/desktop",
      "license": "MPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 73,
      "coverage": 100,
      "summary": "Zen Browser scores 73 out of 100 (grade C) on the browsers criteria. It meets 4 of 8 criteria: open source, no trackers or telemetry, no ads or data sales and timely security updates. It partly meets blocks trackers by default, fingerprinting protection and no calls to big-tech services. It does not meet independent audit.",
      "url": "https://privacyratings.com/browsers/zen-browser/",
      "markdown": "https://privacyratings.com/browsers/zen-browser/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/zen-browser/desktop/blob/dev/LICENSE",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://zen-browser.app/privacy-policy/",
          "note": "Telemetry and crash reporting from Firefox are removed, and no third-party trackers are used."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://zen-browser.app/donate/",
          "note": "Funded by donations. The privacy policy says data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tracker_blocking": {
          "title": "Blocks trackers by default",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://support.mozilla.org/en-US/kb/enhanced-tracking-protection-firefox-desktop",
          "note": "Uses Firefox Enhanced Tracking Protection in Standard mode, which blocks social trackers and cross-site cookies but not all tracking content."
        },
        "fingerprinting_protection": {
          "title": "Fingerprinting protection",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.mozilla.org/en-US/kb/firefox-protection-against-fingerprinting",
          "note": "Known fingerprinters are blocked, but fingerprinting data is only altered in Strict mode or private windows."
        },
        "no_google_services": {
          "title": "No calls to big-tech services",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://zen-browser.app/privacy-policy/",
          "note": "Firefox background connections, including Google Safe Browsing lists, remain and can be turned off in about:config."
        },
        "security_updates": {
          "title": "Timely security updates",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://zen-browser.app/release-notes/",
          "note": "Releases follow each Firefox release within days, and the browser updates itself."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:38.195Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "1blocker",
      "category": "ad-blockers",
      "name": "1Blocker",
      "description": "Safari content blocker for iPhone, iPad, Mac and Vision Pro with filters for ads, trackers, annoyances and adult content, plus custom rules and an in-app tracker filter.",
      "website": "https://1blocker.com",
      "license": null,
      "platforms": [
        "macos",
        "ios"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 53,
      "coverage": 100,
      "summary": "1Blocker scores 53 out of 100 (grade D) on the ad and tracker blockers criteria. It meets 4 of 7 criteria: no trackers or telemetry, no ads or data sales, no browsing data collected and custom filters. It does not meet open source, independent audit and effective by default.",
      "url": "https://privacyratings.com/ad-blockers/1blocker/",
      "markdown": "https://privacyratings.com/ad-blockers/1blocker/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://1blocker.com/privacy",
          "note": "The app contains no analytics tracking code and does not track visited sites."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://1blocker.com/privacy",
          "note": "Funded by Premium subscriptions and lifetime licenses. No data is collected or sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "blocks_by_default": {
          "title": "Effective by default",
          "weight": 3,
          "answer": "no",
          "evidence": "https://support.1blocker.com/en/articles/9311963-free-version-vs-1blocker-premium",
          "note": "The free version allows only one filter category at a time, so blocking ads and trackers together requires Premium."
        },
        "no_data_collection": {
          "title": "No browsing data collected",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://1blocker.com/privacy",
          "note": "Filtering happens in Safari on the device, and the app does not collect browsing data."
        },
        "custom_filters": {
          "title": "Custom filters",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://support.1blocker.com/en/articles/9312016-custom-rules-overview",
          "note": "Custom rules are available for free."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Intercom",
            "host": "widget.intercom.io",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:38.919Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "adblock-plus",
      "category": "ad-blockers",
      "name": "Adblock Plus",
      "description": "Ad blocker from eyeo for browsers and mobile, which shows ads approved under the Acceptable Ads program by default.",
      "website": "https://adblockplus.org",
      "source": "https://gitlab.com/eyeo/browser-extensions-and-premium/extensions/extensions",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 24,
      "coverage": 100,
      "summary": "Adblock Plus scores 24 out of 100 (grade F) on the ad and tracker blockers criteria. It meets 1 of 7 criteria: custom filters. It partly meets open source and no browsing data collected. It does not meet no trackers or telemetry, no ads or data sales, independent audit and effective by default. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/ad-blockers/adblock-plus/",
      "markdown": "https://privacyratings.com/ad-blockers/adblock-plus/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://gitlab.com/eyeo/browser-extensions-and-premium/extensions/extensions/-/blob/main/COPYING",
          "note": "The browser extension is GPL-3.0, but some versions such as the iOS Safari app are proprietary."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://adblockplus.org/privacy",
          "note": "The website uses Google Analytics and Google Tag Manager for visitors outside the EU, and the mobile apps use crash reporting and event tracking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://adblockplus.org/about",
          "note": "Shows Acceptable Ads by default, and large platforms pay a licensing fee to take part."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "blocks_by_default": {
          "title": "Effective by default",
          "weight": 3,
          "answer": "no",
          "evidence": "https://adblockplus.org/acceptable-ads",
          "note": "Acceptable Ads are allowed by default, including ads from companies that pay a licensing fee."
        },
        "no_data_collection": {
          "title": "No browsing data collected",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://adblockplus.org/privacy",
          "note": "Filtering happens on the device, but filter list downloads send the extension version, browser, operating system and active lists. Mobile event tracking can be turned off."
        },
        "custom_filters": {
          "title": "Custom filters",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://help.adblockplus.org/adblock-plus-help-center/how-to-write-filters",
          "note": "Supports custom filter lists and user filters."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:38.532Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "adblock",
      "category": "ad-blockers",
      "name": "AdBlock",
      "description": "Ad blocker for browsers and mobile, owned by eyeo, which shows ads approved under the Acceptable Ads program by default on desktop.",
      "website": "https://getadblock.com",
      "source": "https://gitlab.com/eyeo/browser-extensions-and-premium/extensions/extensions",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 24,
      "coverage": 100,
      "summary": "AdBlock scores 24 out of 100 (grade F) on the ad and tracker blockers criteria. It meets 1 of 7 criteria: custom filters. It partly meets open source and no browsing data collected. It does not meet no trackers or telemetry, no ads or data sales, independent audit and effective by default. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/ad-blockers/adblock/",
      "markdown": "https://privacyratings.com/ad-blockers/adblock/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://gitlab.com/eyeo/browser-extensions-and-premium/extensions/extensions/-/blob/main/COPYING",
          "note": "The browser extension is GPL-3.0, but the mobile apps are closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://getadblock.com/en/privacy/",
          "note": "The website loads Google Tag Manager, Google Analytics is used for the website, extensions and apps outside the EU, and the mobile apps use Firebase analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://helpcenter.getadblock.com/adblock-help-center/introduction-to-filter-lists",
          "note": "Shows Acceptable Ads by default on desktop, a program in which large platforms pay eyeo a licensing fee."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "blocks_by_default": {
          "title": "Effective by default",
          "weight": 3,
          "answer": "no",
          "evidence": "https://helpcenter.getadblock.com/adblock-help-center/introduction-to-filter-lists",
          "note": "Acceptable Ads are enabled by default in the Chrome, Edge and Firefox extensions."
        },
        "no_data_collection": {
          "title": "No browsing data collected",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://getadblock.com/en/privacy/",
          "note": "Filtering happens on the device, but the extension sends anonymous usage information with a unique installation ID, such as counts of blocked ads."
        },
        "custom_filters": {
          "title": "Custom filters",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://helpcenter.getadblock.com/adblock-help-center/how-to-use-custom-filters",
          "note": "Supports custom filters and additional filter lists."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:52.973Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "adguard-home",
      "category": "ad-blockers",
      "name": "AdGuard Home",
      "description": "Self-hosted DNS server that blocks ads and trackers for every device on a network. Includes a web dashboard, encrypted DNS support and parental controls.",
      "website": "https://adguard.com/en/adguard-home/overview.html",
      "source": "https://github.com/AdguardTeam/AdGuardHome",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "CY",
        "name": "Cyprus",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 88,
      "coverage": 100,
      "summary": "AdGuard Home scores 88 out of 100 (grade B) on the ad and tracker blockers criteria. It meets 6 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, effective by default, no browsing data collected and custom filters. It does not meet independent audit. It is based in Cyprus: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/ad-blockers/adguard-home/",
      "markdown": "https://privacyratings.com/ad-blockers/adguard-home/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/AdguardTeam/AdGuardHome/blob/master/LICENSE.txt",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/AdguardTeam/AdGuardHome#readme",
          "note": "Collects no usage statistics and uses no web services unless configured to."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/AdguardTeam/AdGuardHome#readme",
          "note": "Free and open source with no ads. Developed by AdGuard, which sells other products."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "blocks_by_default": {
          "title": "Effective by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/AdguardTeam/AdGuardHome/blob/master/internal/home/config.go",
          "note": "The AdGuard DNS filter is enabled in the default configuration, for free."
        },
        "no_data_collection": {
          "title": "No browsing data collected",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/AdguardTeam/AdGuardHome#readme",
          "note": "Filtering runs on the user's own server, and no usage statistics are sent to the developer."
        },
        "custom_filters": {
          "title": "Custom filters",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/AdguardTeam/AdGuardHome/wiki/Configuration",
          "note": "Supports additional filter lists and user-defined filtering rules."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Trustpilot",
            "host": "www.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:37.040Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "adguard",
      "category": "ad-blockers",
      "name": "AdGuard",
      "description": "Ad and tracker blocker from AdGuard, available as a free browser extension and Safari content blocker and as paid system-wide apps for Windows, macOS, Android and iOS.",
      "website": "https://adguard.com",
      "source": "https://github.com/AdguardTeam/AdguardBrowserExtension",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CY",
        "name": "Cyprus",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 62,
      "coverage": 100,
      "summary": "AdGuard scores 62 out of 100 (grade C) on the ad and tracker blockers criteria. It meets 3 of 7 criteria: no ads or data sales, effective by default and custom filters. It partly meets open source, no trackers or telemetry and no browsing data collected. It does not meet independent audit. It is based in Cyprus: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/ad-blockers/adguard/",
      "markdown": "https://privacyratings.com/ad-blockers/adguard/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/AdguardTeam/AdguardBrowserExtension/blob/master/LICENSE",
          "note": "The browser extension is GPL-3.0, but the Windows, Mac and Android apps are closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://adguard.com/en/website-privacy.html",
          "note": "The website uses first-party analytics with no third-party trackers. App telemetry is off by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://adguard.com/en/license.html",
          "note": "Funded by paid licenses. The privacy policy says personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "blocks_by_default": {
          "title": "Effective by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://adguard.com/kb/general/ad-filtering/search-ads/",
          "note": "Blocks ads and trackers by default in the free extension. There is no paid allowlist; an optional filter can show search ads and self-promotion."
        },
        "no_data_collection": {
          "title": "No browsing data collected",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://adguard.com/en/privacy/browser-extension.html",
          "note": "Filtering happens on the device. Phishing and malware protection sends hash prefixes of visited sites and can be turned off, and usage statistics are off by default."
        },
        "custom_filters": {
          "title": "Custom filters",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://adguard.com/kb/general/ad-filtering/create-own-filters/",
          "note": "Supports custom filter lists and user rules."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:53.766Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "diversion",
      "category": "ad-blockers",
      "name": "Diversion",
      "description": "Shell script ad blocker for routers running Asuswrt-Merlin firmware. Blocks ad and tracker domains through dnsmasq and can manage Entware and pixelserv-tls.",
      "website": "https://diversion.ch",
      "source": "https://diversion.ch/diversion_adblocking/diversion",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 79,
      "coverage": 100,
      "summary": "Diversion scores 79 out of 100 (grade B) on the ad and tracker blockers criteria. It meets 5 of 7 criteria: open source, no ads or data sales, effective by default, no browsing data collected and custom filters. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/ad-blockers/diversion/",
      "markdown": "https://privacyratings.com/ad-blockers/diversion/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://diversion.ch/diversion_adblocking/diversion",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://diversion.ch",
          "note": "The website uses self-hosted Matomo analytics. The script contains no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://diversion.ch",
          "note": "Free to use and supported by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "blocks_by_default": {
          "title": "Effective by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://diversion.ch/diversion_adblocking/diversion",
          "note": "Blocks domains from a selected blocking list once installed, with no paid tier."
        },
        "no_data_collection": {
          "title": "No browsing data collected",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://diversion.ch/diversion_adblocking/diversion",
          "note": "Filtering runs on the router, and no browsing data is sent to the developer."
        },
        "custom_filters": {
          "title": "Custom filters",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://diversion.ch/diversion_adblocking/diversion",
          "note": "Supports a user denylist and allowlist, and a custom secondary blocking list."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:38.079Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ghostery",
      "category": "ad-blockers",
      "name": "Ghostery",
      "description": "Browser extension from Ghostery that blocks ads, trackers and cookie pop-ups and shows which trackers each site uses.",
      "website": "https://www.ghostery.com",
      "source": "https://github.com/ghostery/ghostery-extension",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "ios"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Ghostery scores 65 out of 100 (grade C) on the ad and tracker blockers criteria. It meets 3 of 7 criteria: open source, effective by default and custom filters. It partly meets no trackers or telemetry, no ads or data sales and no browsing data collected. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/ad-blockers/ghostery/",
      "markdown": "https://privacyratings.com/ad-blockers/ghostery/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ghostery/ghostery-extension/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.ghostery.com/privacy/policy",
          "note": "The extension sends a daily non-personal installation ping by default. No third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ghostery.com/ghostery-manifesto",
          "note": "Funded by donations plus non-targeted sponsored links and search engine revenue sharing in Ghostery Private Search."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "blocks_by_default": {
          "title": "Effective by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.ghostery.com/ghostery-ad-blocker",
          "note": "Blocks ads, trackers and cookie pop-ups by default, for free."
        },
        "no_data_collection": {
          "title": "No browsing data collected",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.ghostery.com/privacy/policy",
          "note": "Filtering happens on the device, but a daily installation ping and anonymous tracker observations for WhoTracks.me are sent by default."
        },
        "custom_filters": {
          "title": "Custom filters",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/ghostery/ghostery-extension/tree/main/src/background/custom-filters",
          "note": "Supports custom filter rules in the settings."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:14.988Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "hblock",
      "category": "ad-blockers",
      "name": "hBlock",
      "description": "POSIX shell script for Unix-like systems that builds a hosts file blocking domains that serve ads, tracking scripts and malware, using several public blocklists.",
      "website": "https://hblock.molinero.dev",
      "source": "https://github.com/hectorm/hblock",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 88,
      "coverage": 100,
      "summary": "hBlock scores 88 out of 100 (grade B) on the ad and tracker blockers criteria. It meets 6 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, effective by default, no browsing data collected and custom filters. It does not meet independent audit.",
      "url": "https://privacyratings.com/ad-blockers/hblock/",
      "markdown": "https://privacyratings.com/ad-blockers/hblock/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hectorm/hblock/blob/master/LICENSE.md",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hectorm/hblock",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/hectorm/hblock#readme",
          "note": "Free, open-source script with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "blocks_by_default": {
          "title": "Effective by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hectorm/hblock/blob/master/SOURCES.md",
          "note": "Uses a default set of ad, tracking and malware blocklists."
        },
        "no_data_collection": {
          "title": "No browsing data collected",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hectorm/hblock",
          "note": "Runs locally and only downloads blocklists. No data is sent to the developer."
        },
        "custom_filters": {
          "title": "Custom filters",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/hectorm/hblock/blob/master/hblock",
          "note": "Supports custom sources, an allowlist and a denylist."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:36.877Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ublock-origin-lite",
      "category": "ad-blockers",
      "name": "uBlock Origin Lite",
      "description": "Manifest V3 content blocker from the uBlock Origin developer that filters ads and trackers through declarative browser rules, with no background process.",
      "website": "https://github.com/uBlockOrigin/uBOL-home",
      "source": "https://github.com/uBlockOrigin/uBOL-home",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "ios"
      ],
      "jurisdiction": null,
      "pick": true,
      "pick_reason": "For browsers that only allow Manifest V3 extensions, such as Chrome and Edge: uBlock Origin's filter lists with no data collection and no background process.",
      "disclosure": null,
      "grade": "B",
      "score": 88,
      "coverage": 100,
      "summary": "uBlock Origin Lite scores 88 out of 100 (grade B) on the ad and tracker blockers criteria. It meets 6 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, effective by default, no browsing data collected and custom filters. It does not meet independent audit.",
      "url": "https://privacyratings.com/ad-blockers/ublock-origin-lite/",
      "markdown": "https://privacyratings.com/ad-blockers/ublock-origin-lite/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/uBlockOrigin/uBOL-home/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/uBlockOrigin/uBOL-home/wiki/Privacy-policy",
          "note": "No analytics or telemetry in the code and no home server."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/uBlockOrigin/uBOL-home/wiki/Privacy-policy",
          "note": "No ads, and donations are not accepted."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "blocks_by_default": {
          "title": "Effective by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/uBlockOrigin/uBOL-home",
          "note": "The default rulesets include uBlock Origin's filters, EasyList, EasyPrivacy and Peter Lowe's list."
        },
        "no_data_collection": {
          "title": "No browsing data collected",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/uBlockOrigin/uBOL-home/wiki/Privacy-policy",
          "note": "No data of any kind is collected. The only remote requests are for filter lists the user subscribes to."
        },
        "custom_filters": {
          "title": "Custom filters",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/uBlockOrigin/uBOL-home/wiki/Frequently-asked-questions-(FAQ)",
          "note": "Custom filters and subscriptions to external filter lists are supported."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:38.297Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ublock-origin",
      "category": "ad-blockers",
      "name": "uBlock Origin",
      "description": "Free, open-source content blocker for ads, trackers and malware sites. Efficient, with no \"acceptable ads\" program.",
      "website": "https://github.com/gorhill/uBlock",
      "source": "https://github.com/gorhill/uBlock",
      "license": "GPL-3.0",
      "platforms": [
        "firefox",
        "chromium"
      ],
      "jurisdiction": null,
      "pick": true,
      "pick_reason": "The most effective blocker available, with no data collection, no home server, no acceptable-ads deals and not even a donation page. Install it through the links on its GitHub page to avoid look-alike extensions.",
      "disclosure": null,
      "grade": "B",
      "score": 88,
      "coverage": 100,
      "summary": "uBlock Origin scores 88 out of 100 (grade B) on the ad and tracker blockers criteria. It meets 6 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, effective by default, no browsing data collected and custom filters. It does not meet independent audit.",
      "url": "https://privacyratings.com/ad-blockers/ublock-origin/",
      "markdown": "https://privacyratings.com/ad-blockers/ublock-origin/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gorhill/uBlock/blob/master/LICENSE.txt",
          "note": null
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gorhill/uBlock/wiki/Privacy-policy",
          "note": null
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/gorhill/uBlock/wiki/Privacy-policy",
          "note": "No ads, no acceptable-ads program, and donations are not accepted."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "blocks_by_default": {
          "title": "Effective by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gorhill/uBlock#readme",
          "note": null
        },
        "no_data_collection": {
          "title": "No browsing data collected",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gorhill/uBlock/wiki/Privacy-policy",
          "note": "No data of any kind is collected. The only connections are filter list updates."
        },
        "custom_filters": {
          "title": "Custom filters",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/gorhill/uBlock/wiki/Dashboard:-My-filters",
          "note": null
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:36.812Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "wipr",
      "category": "ad-blockers",
      "name": "Wipr",
      "description": "Paid Safari content blocker for iPhone, iPad, Mac and Vision Pro that blocks ads, trackers, cookie notices and annoyances with no configuration.",
      "website": "https://kaylees.site/wipr2.html",
      "license": null,
      "platforms": [
        "macos",
        "ios"
      ],
      "jurisdiction": {
        "code": "ES",
        "name": "Spain",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Wipr scores 65 out of 100 (grade C) on the ad and tracker blockers criteria. It meets 4 of 7 criteria: no trackers or telemetry, no ads or data sales, effective by default and no browsing data collected. It does not meet open source, independent audit and custom filters. It is based in Spain: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/ad-blockers/wipr/",
      "markdown": "https://privacyratings.com/ad-blockers/wipr/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kaylees.site/privacy-policy.html",
          "note": "The privacy policy says no personal data is collected, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kaylees.site/wipr2.html",
          "note": "Paid app funded by its users, with no acceptable-ads program."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "blocks_by_default": {
          "title": "Effective by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kaylees.site/wipr2.html",
          "note": "Blocks ads, trackers and cookie notices by default with a single one-time purchase and no tiers; nobody can pay to have ads unblocked."
        },
        "no_data_collection": {
          "title": "No browsing data collected",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kaylees.site/privacy-policy.html",
          "note": "Filtering happens in Safari on the device, and no personal data is collected."
        },
        "custom_filters": {
          "title": "Custom filters",
          "weight": 1,
          "answer": "no",
          "evidence": "https://kaylees.site/wipr-help.html",
          "note": "No custom rules or filter lists. Sites can only be excluded from blocking."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:39.055Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "amiunique-timeline",
      "category": "browser-extensions",
      "name": "AmIUnique Timeline",
      "description": "Research extension from the AmIUnique project that periodically records the browser's fingerprint so users can see how it changes over time.",
      "website": "https://amiunique.org/timeline",
      "source": "https://github.com/plaperdr/amiunique-webextension-firefox",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "AmIUnique Timeline scores 50 out of 100 (grade D) on the browser extensions criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/browser-extensions/amiunique-timeline/",
      "markdown": "https://privacyratings.com/browser-extensions/amiunique-timeline/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/plaperdr/amiunique-webextension-firefox/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/amiunique/privacy/",
          "note": "No third-party trackers, but the extension sends a browser fingerprint and hashed IP address to the AmIUnique server every four hours, and this cannot be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/amiunique/privacy/",
          "note": "Run as an Inria research project with no ads; data is only shared as aggregated statistics."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:38.503Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "canvas-fingerprint-blocker",
      "category": "browser-extensions",
      "name": "Canvas Fingerprint Blocker",
      "description": "Browser extension that adds noise to HTML5 canvas output to resist canvas fingerprinting without disabling the canvas element.",
      "website": "https://webextension.org/listing/canvas-fingerprint-blocker.html",
      "source": "https://github.com/joue-quroi/canvas-fingerprint-blocker",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Canvas Fingerprint Blocker scores 30 out of 100 (grade F) on the browser extensions criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/browser-extensions/canvas-fingerprint-blocker/",
      "markdown": "https://privacyratings.com/browser-extensions/canvas-fingerprint-blocker/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/canvas-blocker-no-fingerprint/",
          "note": "Released under MPL-2.0 on the add-on listing; the source repository itself has no license file."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google AdSense, Google Analytics and Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "The project website shows Google AdSense ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:37.699Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "canvasblocker",
      "category": "browser-extensions",
      "name": "CanvasBlocker",
      "description": "Firefox extension that blocks or fakes the output of canvas and other JavaScript APIs that websites use for browser fingerprinting.",
      "website": "https://github.com/kkapsner/CanvasBlocker",
      "source": "https://github.com/kkapsner/CanvasBlocker",
      "license": "MPL-2.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "CanvasBlocker scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-extensions/canvasblocker/",
      "markdown": "https://privacyratings.com/browser-extensions/canvasblocker/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/kkapsner/CanvasBlocker/blob/master/LICENSE.txt",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/canvasblocker/privacy/",
          "note": "The extension does not collect any data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/kkapsner/CanvasBlocker",
          "note": "Free open-source extension with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:38.396Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "chameleon",
      "category": "browser-extensions",
      "name": "Chameleon",
      "description": "Browser extension that spoofs the user agent, screen size, time zone, language and other browser properties, and can apply privacy-related Firefox settings to reduce fingerprinting.",
      "website": "https://sereneblue.github.io/chameleon/",
      "source": "https://github.com/sereneblue/chameleon",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Chameleon scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-extensions/chameleon/",
      "markdown": "https://privacyratings.com/browser-extensions/chameleon/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sereneblue/chameleon/blob/master/LICENSE.md",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/chameleon-ext/privacy/",
          "note": "The extension collects no data; the optional time zone IP check contacts ipapi.co."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sereneblue/chameleon",
          "note": "Free open-source extension with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:38.586Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "clearurls",
      "category": "browser-extensions",
      "name": "ClearURLs",
      "description": "Browser extension that removes tracking parameters from URLs and skips tracking redirects using a public rule list.",
      "website": "https://clearurls.xyz",
      "source": "https://github.com/ClearURLs/Addon",
      "license": "LGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "ClearURLs scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-extensions/clearurls/",
      "markdown": "https://privacyratings.com/browser-extensions/clearurls/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ClearURLs/Addon/blob/master/LICENSE",
          "note": "LGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/clearurls/privacy/",
          "note": "The extension collects no usage data and contains no analytics; it only connects to fetch rule updates."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.clearurls.xyz/#donation",
          "note": "Free and funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:37.700Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "consent-o-matic",
      "category": "browser-extensions",
      "name": "Consent-O-Matic",
      "description": "Browser extension from Aarhus University that detects cookie consent pop-ups from common consent management platforms and fills them in automatically according to the user's preferences.",
      "website": "https://consentomatic.au.dk",
      "source": "https://github.com/cavi-au/Consent-O-Matic",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DK",
        "name": "Denmark",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Consent-O-Matic scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Denmark: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/browser-extensions/consent-o-matic/",
      "markdown": "https://privacyratings.com/browser-extensions/consent-o-matic/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cavi-au/Consent-O-Matic/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://consentomatic.au.dk/#privacy",
          "note": "The extension processes no personal data and only stores settings and counters locally; site reports are sent only when the user chooses to."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://consentomatic.au.dk/",
          "note": "Free research project developed at Aarhus University, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:15.745Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "cookie-autodelete",
      "category": "browser-extensions",
      "name": "Cookie AutoDelete",
      "description": "Browser extension that deletes cookies and other site data from closed tabs automatically, keeping data only for sites on a user-defined allow list.",
      "website": "https://github.com/Cookie-AutoDelete/Cookie-AutoDelete",
      "source": "https://github.com/Cookie-AutoDelete/Cookie-AutoDelete",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Cookie AutoDelete scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-extensions/cookie-autodelete/",
      "markdown": "https://privacyratings.com/browser-extensions/cookie-autodelete/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Cookie-AutoDelete/Cookie-AutoDelete/blob/3.X.X-Branch/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/cookie-autodelete/privacy/",
          "note": "All data stays on the local computer and the extension transmits nothing."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/cookie-autodelete/",
          "note": "Free open-source extension funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:38.586Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dearrow",
      "category": "browser-extensions",
      "name": "DeArrow",
      "description": "Crowdsourced browser extension that replaces YouTube video titles and thumbnails with community-submitted versions to reduce clickbait.",
      "website": "https://dearrow.ajay.app",
      "source": "https://github.com/ajayyy/DeArrow",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "DeArrow scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-extensions/dearrow/",
      "markdown": "https://privacyratings.com/browser-extensions/dearrow/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ajayyy/DeArrow/blob/master/LICENSE",
          "note": "GPL-3.0 and LGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/dearrow/privacy/",
          "note": "No analytics; the server stores only submissions, hashed user IDs and salted IP hashes for rate limiting."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://dearrow.ajay.app/donate/",
          "note": "Funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:38.680Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "decentraleyes",
      "category": "browser-extensions",
      "name": "Decentraleyes",
      "description": "Browser extension that serves common JavaScript libraries from local copies instead of third-party content delivery networks, reducing tracking by those CDNs.",
      "website": "https://decentraleyes.org",
      "source": "https://git.synz.io/Synzvato/decentraleyes",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Decentraleyes scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-extensions/decentraleyes/",
      "markdown": "https://privacyratings.com/browser-extensions/decentraleyes/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://git.synz.io/Synzvato/decentraleyes/-/blob/master/LICENSE.txt",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/decentraleyes/privacy/",
          "note": "The extension states it does not collect any data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://decentraleyes.org/donate/",
          "note": "Free and funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:39.732Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "facebook-container",
      "category": "browser-extensions",
      "name": "Facebook Container",
      "description": "Firefox extension from Mozilla that isolates Facebook, Instagram and Messenger in a separate container so that Facebook cannot easily link activity on other websites to the user's account.",
      "website": "https://addons.mozilla.org/en-US/firefox/addon/facebook-container/",
      "source": "https://github.com/mozilla/contain-facebook",
      "license": "MPL-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Facebook Container scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/browser-extensions/facebook-container/",
      "markdown": "https://privacyratings.com/browser-extensions/facebook-container/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mozilla/contain-facebook/blob/main/LICENSE",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mozilla/contain-facebook",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/facebook-container/",
          "note": "Free extension from Mozilla with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:38.587Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "firefox-multi-account-containers",
      "category": "browser-extensions",
      "name": "Firefox Multi-Account Containers",
      "description": "Mozilla add-on for Firefox that separates sites into color-coded container tabs with isolated cookies and storage.",
      "website": "https://support.mozilla.org/en-US/kb/containers",
      "source": "https://github.com/mozilla/multi-account-containers",
      "license": "MPL-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Firefox Multi-Account Containers scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/browser-extensions/firefox-multi-account-containers/",
      "markdown": "https://privacyratings.com/browser-extensions/firefox-multi-account-containers/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mozilla/multi-account-containers/blob/main/LICENSE",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mozilla/multi-account-containers/tree/main/src",
          "note": "No telemetry or analytics in the extension source code. The support page loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.mozilla.org/en-US/privacy/firefox/",
          "note": "The add-on shows no ads, and Mozilla states it never sells user data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:32.856Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "flagfox",
      "category": "browser-extensions",
      "name": "Flagfox",
      "description": "Firefox extension that shows a flag for the country where the current website's server is located, with shortcuts to lookup tools such as whois and site checks.",
      "website": "https://flagfox.wordpress.com",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Flagfox scores 40 out of 100 (grade D) on the browser extensions criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/browser-extensions/flagfox/",
      "markdown": "https://privacyratings.com/browser-extensions/flagfox/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/flagfox/license/",
          "note": "All code is public, distributed with the add-on under a custom source-available license that restricts redistribution and is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads WordPress.com Stats (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://flagfox.wordpress.com/faq/",
          "note": "The add-on shows no ads, but some lookup pages it links to, including the default Geotool, may show ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "WordPress.com Stats",
            "host": "stats.wp.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:39.269Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "i-still-dont-care-about-cookies",
      "category": "browser-extensions",
      "name": "I Still Don't Care About Cookies",
      "description": "Community-maintained fork of I Don't Care About Cookies, a browser extension that hides or dismisses cookie consent banners on websites.",
      "website": "https://github.com/OhMyGuus/I-Still-Dont-Care-About-Cookies",
      "source": "https://github.com/OhMyGuus/I-Still-Dont-Care-About-Cookies",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "I Still Don't Care About Cookies scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-extensions/i-still-dont-care-about-cookies/",
      "markdown": "https://privacyratings.com/browser-extensions/i-still-dont-care-about-cookies/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/OhMyGuus/I-Still-Dont-Care-About-Cookies/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/istilldontcareaboutcookies/privacy/",
          "note": "No data is collected during normal use; the optional report feature sends only the site hostname, browser and extension version."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/OhMyGuus/I-Still-Dont-Care-About-Cookies",
          "note": "Free open-source extension with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:38.587Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "jshelter",
      "category": "browser-extensions",
      "name": "JShelter",
      "description": "Browser extension that limits what JavaScript on web pages can access, such as precise geolocation, timing and fingerprinting-prone APIs, and warns about sites that try to fingerprint the browser.",
      "website": "https://jshelter.org",
      "source": "https://pagure.io/JShelter/webextension",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "JShelter scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-extensions/jshelter/",
      "markdown": "https://privacyratings.com/browser-extensions/jshelter/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://jshelter.org/license/",
          "note": "GPL-3.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://jshelter.org/permissions/",
          "note": "Configuration is stored in the browser and no data is uploaded to the project's servers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://jshelter.org/",
          "note": "Funded by NLnet NGI Zero grants from the European Commission, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:15.253Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "libredirect",
      "category": "browser-extensions",
      "name": "LibRedirect",
      "description": "Browser extension that redirects sites such as YouTube, Reddit and Twitter to alternative frontends.",
      "website": "https://libredirect.manerakai.com",
      "source": "https://github.com/libredirect/browser_extension",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "LibRedirect scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-extensions/libredirect/",
      "markdown": "https://privacyratings.com/browser-extensions/libredirect/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/libredirect/browser_extension/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/libredirect/browser_extension/blob/master/Privacy-Policy.md",
          "note": "The extension collects no data; redirections work locally."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/libredirect",
          "note": "Free and funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:39.671Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "linguist",
      "category": "browser-extensions",
      "name": "Linguist",
      "description": "Browser extension for translating web pages and text, with an offline translator and support for custom or self-hosted translation services.",
      "website": "https://linguister.io",
      "source": "https://github.com/translate-tools/linguist",
      "license": "BSD-3-Clause",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Linguist scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-extensions/linguist/",
      "markdown": "https://privacyratings.com/browser-extensions/linguist/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/translate-tools/linguist/blob/master/LICENSE",
          "note": "BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://linguister.io",
          "note": "The project states the extension does not collect user data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://linguister.io",
          "note": "Free and supported by donations; the project states it does not sell user data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:39.368Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "localcdn",
      "category": "browser-extensions",
      "name": "LocalCDN",
      "description": "Browser extension that emulates common web frameworks such as jQuery and Bootstrap from local copies, blocking requests to third-party CDNs.",
      "website": "https://www.localcdn.org",
      "source": "https://codeberg.org/nobody/LocalCDN",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "LocalCDN scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-extensions/localcdn/",
      "markdown": "https://privacyratings.com/browser-extensions/localcdn/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/nobody/LocalCDN/src/branch/main/LICENSE.txt",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/localcdn-fork-of-decentraleyes/privacy/",
          "note": "The extension collects no data, and the website uses no cookies or analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/LocalCDN",
          "note": "Free and funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:40.229Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "netcraft-extension",
      "category": "browser-extensions",
      "name": "Netcraft Extension",
      "description": "Anti-phishing browser extension from Netcraft that warns about known and suspected phishing sites and malicious JavaScript, and shows basic information about the current site.",
      "website": "https://www.netcraft.com/resources/apps-and-extensions/browser-extension",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Netcraft Extension scores 20 out of 100 (grade F) on the browser extensions criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/browser-extensions/netcraft-extension/",
      "markdown": "https://privacyratings.com/browser-extensions/netcraft-extension/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/netcraft-toolbar/license/",
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads HubSpot (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/netcraft-toolbar/privacy/",
          "note": "No ads in the extension, and Netcraft states it does not sell personal information."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "HubSpot",
            "host": "js-eu1.hs-scripts.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:39.833Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "noscript",
      "category": "browser-extensions",
      "name": "NoScript",
      "description": "Browser extension for Firefox and Chromium-based browsers that blocks JavaScript and other active content except on sites the user allows, with added protection against cross-site scripting and clickjacking.",
      "website": "https://noscript.net",
      "source": "https://github.com/hackademix/noscript",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "NoScript scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-extensions/noscript/",
      "markdown": "https://privacyratings.com/browser-extensions/noscript/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hackademix/noscript/blob/main/LICENSE",
          "note": "GPL-3.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/noscript/privacy/",
          "note": "The extension does not collect or share user data; the optional Site Info feature sends only the site domain when used."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://noscript.net/",
          "note": "Free open-source software funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:15.743Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "privacy-badger",
      "category": "browser-extensions",
      "name": "Privacy Badger",
      "description": "Browser extension from the Electronic Frontier Foundation that learns to block invisible third-party trackers based on their behavior and sends Global Privacy Control signals.",
      "website": "https://privacybadger.org",
      "source": "https://github.com/EFForg/privacybadger",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Privacy Badger scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/browser-extensions/privacy-badger/",
      "markdown": "https://privacyratings.com/browser-extensions/privacy-badger/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/EFForg/privacybadger/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.eff.org/code/privacy/policy",
          "note": "The extension collects no browsing data; bug reports are opt-in."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://privacybadger.org/#How-can-I-support-Privacy-Badger",
          "note": "Developed by the EFF, a nonprofit funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:40.313Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "privacy-essentials",
      "category": "browser-extensions",
      "name": "Privacy Essentials",
      "description": "DuckDuckGo browser extension that blocks trackers, upgrades connections to HTTPS and sets DuckDuckGo as the search engine.",
      "website": "https://duckduckgo.com/duckduckgo-help-pages/desktop/adding-duckduckgo-to-your-browser",
      "source": "https://github.com/duckduckgo/duckduckgo-privacy-extension",
      "license": "Apache-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Privacy Essentials scores 40 out of 100 (grade D) on the browser extensions criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/browser-extensions/privacy-essentials/",
      "markdown": "https://privacyratings.com/browser-extensions/privacy-essentials/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/duckduckgo/duckduckgo-privacy-extension/blob/main/LICENSE.md",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://duckduckgo.com/duckduckgo-help-pages/privacy/atb/",
          "note": "No third-party trackers, but the extension sends an anonymous usage-counting request with each search, with no documented way to turn it off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/duckduckgo-for-firefox/privacy/",
          "note": "The extension has no ads, but DuckDuckGo is funded by search ads based on the current search, not a profile."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:40.251Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "privacy-oriented-origin-policy",
      "category": "browser-extensions",
      "name": "Privacy-Oriented Origin Policy",
      "description": "Firefox extension that strips Origin headers from cross-origin requests where they are least likely to be needed, to limit information sent to third parties.",
      "website": "https://claustromaniac.github.io/poop",
      "source": "https://github.com/claustromaniac/poop",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Privacy-Oriented Origin Policy scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-extensions/privacy-oriented-origin-policy/",
      "markdown": "https://privacyratings.com/browser-extensions/privacy-oriented-origin-policy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/claustromaniac/poop/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/claustromaniac/poop",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/claustromaniac/poop",
          "note": "Free open-source add-on with no ads or data collection."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:40.077Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "privacyspy",
      "category": "browser-extensions",
      "name": "PrivacySpy",
      "description": "Companion extension for PrivacySpy, an open project that rates and annotates privacy policies; it shows the PrivacySpy score for the current website.",
      "website": "https://privacyspy.org",
      "source": "https://github.com/politiwatch/privacyspy",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "PrivacySpy scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-extensions/privacyspy/",
      "markdown": "https://privacyratings.com/browser-extensions/privacyspy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/politiwatch/privacyspy/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/privacyspy/privacy/",
          "note": "The extension collects no usage data beyond an aggregate count of requests to the PrivacySpy server."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://privacyspy.org/terms-and-privacy/",
          "note": "No ads, and the project states it does not collect personal data unless users provide it."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:40.489Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "skip-redirect",
      "category": "browser-extensions",
      "name": "Skip Redirect",
      "description": "Browser extension that detects intermediary redirect pages, extracts the final URL and goes there directly.",
      "website": "https://github.com/sblask/webextension-skip-redirect",
      "source": "https://github.com/sblask/webextension-skip-redirect",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Skip Redirect scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-extensions/skip-redirect/",
      "markdown": "https://privacyratings.com/browser-extensions/skip-redirect/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sblask/webextension-skip-redirect/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sblask/webextension-skip-redirect",
          "note": "The extension states it does not collect or send data of any kind to third parties."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sblask/webextension-skip-redirect",
          "note": "Free open-source add-on with no ads or data collection."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:40.229Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sponsorblock",
      "category": "browser-extensions",
      "name": "SponsorBlock",
      "description": "Crowdsourced browser extension that skips sponsored segments and other unwanted parts of YouTube videos using community-submitted timestamps.",
      "website": "https://sponsor.ajay.app",
      "source": "https://github.com/ajayyy/SponsorBlock",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "SponsorBlock scores 65 out of 100 (grade C) on the browser extensions criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-extensions/sponsorblock/",
      "markdown": "https://privacyratings.com/browser-extensions/sponsorblock/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ajayyy/SponsorBlock/blob/master/LICENSE",
          "note": "GPL-3.0 and LGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://gist.github.com/ajayyy/aa9f8ded2b573d4f73a3ffa0ef74f796",
          "note": "No third-party trackers; anonymous skip counting is on by default and can be turned off in settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://sponsor.ajay.app/donate/",
          "note": "Funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:00:40.820Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "tosdr",
      "category": "browser-extensions",
      "name": "Terms of Service; Didn't Read",
      "description": "Browser extension from the ToS;DR project that shows grades and summaries of a website's terms of service and privacy policy, written and reviewed by volunteer contributors.",
      "website": "https://tosdr.org",
      "source": "https://github.com/tosdr/browser-extensions",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Terms of Service; Didn't Read scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-extensions/tosdr/",
      "markdown": "https://privacyratings.com/browser-extensions/tosdr/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/tosdr/browser-extensions/blob/master/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/terms-of-service-didnt-read/privacy/",
          "note": "The extension only fetches ratings from the ToS;DR servers, which log anonymized IP addresses; it contains no analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tosdr.org/en/donate",
          "note": "Non-profit project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:54.394Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "web-archives",
      "category": "browser-extensions",
      "name": "Web Archives",
      "description": "Browser extension that looks up archived and cached copies of the current page on services such as the Wayback Machine and Archive.today.",
      "website": "https://github.com/dessant/web-archives",
      "source": "https://github.com/dessant/web-archives",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Web Archives scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-extensions/web-archives/",
      "markdown": "https://privacyratings.com/browser-extensions/web-archives/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dessant/web-archives/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/view-page-archive/privacy/",
          "note": "The developer states the extension collects no personal data; it only sends the selected URL to the chosen archive service."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/dessant/web-archives",
          "note": "Free and supported by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:40.251Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "webrtc-leak-prevent",
      "category": "browser-extensions",
      "name": "WebRTC-Leak-Prevent",
      "description": "Chromium extension that changes WebRTC privacy settings to stop WebRTC from exposing local and public IP addresses.",
      "website": "https://github.com/aghorler/WebRTC-Leak-Prevent",
      "source": "https://github.com/aghorler/WebRTC-Leak-Prevent",
      "license": "Apache-2.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "WebRTC-Leak-Prevent scores 80 out of 100 (grade B) on the browser extensions criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-extensions/webrtc-leak-prevent/",
      "markdown": "https://privacyratings.com/browser-extensions/webrtc-leak-prevent/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/aghorler/WebRTC-Leak-Prevent/blob/master/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/aghorler/WebRTC-Leak-Prevent",
          "note": "The extension states it does not collect any user data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/aghorler/WebRTC-Leak-Prevent",
          "note": "Free open-source extension with no ads or data collection."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:40.251Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "4get",
      "category": "search-engines",
      "name": "4get",
      "description": "Open-source metasearch engine and proxy that fetches results from other search engines and strips tracking, usable at 4get.ca or other public instances or self-hosted.",
      "website": "https://4get.ca",
      "source": "https://git.lolcat.ca/lolcat/4get",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 88,
      "coverage": 100,
      "summary": "4get scores 88 out of 100 (grade B) on the search engines criteria. It meets 6 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, no search history logs, no profile-based ads and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/search-engines/4get/",
      "markdown": "https://privacyratings.com/search-engines/4get/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://git.lolcat.ca/lolcat/4get/src/branch/master/license.txt",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://4get.ca/about",
          "note": "No ads, third-party scripts or trackers, and no user profiling."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://4get.ca/donate",
          "note": "Free software funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://4get.ca/about",
          "note": "IP addresses and user agents are not logged; encrypted pagination data is kept in memory for at most 15 minutes."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://4get.ca/about",
          "note": "No ads are shown."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://4get.ca/about",
          "note": "Search needs no account."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:15.446Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "bing",
      "category": "search-engines",
      "name": "Bing",
      "description": "Microsoft's search engine, which also supplies results to several other search engines. Searches are linked to cookies and Microsoft accounts to personalize results and ads.",
      "website": "https://www.bing.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 32,
      "coverage": 100,
      "summary": "Bing scores 32 out of 100 (grade F) on the search engines criteria. It meets 3 of 11 criteria: transparency report, tells users about requests and TLS configuration. It partly meets security headers, no profile-based ads and no account needed. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit and no search history logs. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/search-engines/bing/",
      "markdown": "https://privacyratings.com/search-engines/bing/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement#mainbingmodule",
          "note": "Searches are collected with IP addresses and cookie identifiers for personalization and advertising, and this cannot be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement#mainadvertisingmodule",
          "note": "Funded by advertising, including interest-based ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Microsoft publishes law enforcement request counts and outcomes twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Microsoft gives prior notice to consumer users whose data is sought, except where prohibited by law."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.bing.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.bing.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement#mainbingmodule",
          "note": "Search logs keep the IP address for six months and cookie identifiers for 18 months before de-identification."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement#mainadvertisingmodule",
          "note": "Personalized ads are on by default and can be turned off in Microsoft ad settings."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement#mainbingmodule",
          "note": "Search works without an account; synced history and personalization need a Microsoft account."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:03:54.990Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "brave-search",
      "category": "search-engines",
      "name": "Brave Search",
      "description": "Search engine from Brave Software built on its own independent web index, designed not to store searches with identifiers or build user profiles.",
      "website": "https://search.brave.com",
      "source": "https://github.com/brave/brave-browser",
      "license": "MPL-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 55,
      "coverage": 100,
      "summary": "Brave Search scores 55 out of 100 (grade D) on the search engines criteria. It meets 3 of 10 criteria: TLS configuration, no search history logs and no profile-based ads. It partly meets open source, no trackers or telemetry, no ads or data sales and no account needed. It does not meet independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+.",
      "url": "https://privacyratings.com/search-engines/brave-search/",
      "markdown": "https://privacyratings.com/search-engines/brave-search/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/brave/brave-browser/blob/master/LICENSE",
          "note": "The Brave browser is open source. The search engine itself is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://search.brave.com/help/usage-metrics",
          "note": "No third-party trackers; anonymous usage metrics are on by default and can be turned off in settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://search.brave.com/help/privacy-policy",
          "note": "Free search shows ads that are measured without personal data; an ad-free paid tier is available."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=search.brave.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://search.brave.com/help/privacy-policy",
          "note": "Queries are stored de-identified, and IP addresses are deleted within seconds after bot checks."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://search.brave.com/help/privacy-policy",
          "note": "Ads are not based on personal data or a profile."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://search.brave.com/help/premium",
          "note": "Search works without an account; the ad-free Search Premium tier needs a Brave account."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:03:55.299Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "duckduckgo",
      "category": "search-engines",
      "name": "DuckDuckGo",
      "description": "Search engine that does not save search history or tie searches to IP addresses. Ads are based on the search terms instead of a profile.",
      "website": "https://duckduckgo.com",
      "source": "https://github.com/duckduckgo",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": true,
      "pick_reason": "Results good enough to replace Google for most searches, no search history, no profile-based ads, and no account needed. Apps and browser extensions are open source.",
      "disclosure": null,
      "grade": "C",
      "score": 73,
      "coverage": 100,
      "summary": "DuckDuckGo scores 73 out of 100 (grade C) on the search engines criteria. It meets 6 of 11 criteria: no trackers or telemetry, tells users about requests, TLS configuration, no search history logs, no profile-based ads and no account needed. It partly meets open source, no ads or data sales, transparency report and security headers. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/search-engines/duckduckgo/",
      "markdown": "https://privacyratings.com/search-engines/duckduckgo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/duckduckgo/Android/blob/develop/LICENSE",
          "note": "Apps and extensions are open source, such as the Apache-2.0 Android app. The search engine itself is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://duckduckgo.com/privacy",
          "note": "No third-party trackers or tracking cookies; anonymous experiments store no identifiers, and the Android app has no known trackers in its Exodus report."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://duckduckgo.com/privacy",
          "note": "Funded by search ads based only on the current search, not a profile."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://duckduckgo.com/privacy",
          "note": "The privacy policy states how legal requests are handled and that search histories cannot be provided, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://duckduckgo.com/privacy",
          "note": "Users with an email address on file are notified of legal disclosures by email unless legally forbidden."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=duckduckgo.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=duckduckgo.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://duckduckgo.com/privacy",
          "note": "Search history is not saved, and IP addresses are not saved alongside searches."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://duckduckgo.com/privacy",
          "note": null
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://duckduckgo.com/privacy",
          "note": "Search needs no account. Only optional extras such as Email Protection need one."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:05:17.473Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ecosia",
      "category": "search-engines",
      "name": "Ecosia",
      "description": "Search engine from the Berlin company Ecosia that shows results and ads from Microsoft Bing or Google and uses its profits for tree planting and climate projects.",
      "website": "https://www.ecosia.org",
      "source": "https://github.com/ecosia",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 41,
      "coverage": 100,
      "summary": "Ecosia scores 41 out of 100 (grade D) on the search engines criteria. It meets 2 of 11 criteria: TLS configuration and no profile-based ads. It partly meets open source, no ads or data sales, security headers, no search history logs and no account needed. It does not meet no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/search-engines/ecosia/",
      "markdown": "https://privacyratings.com/search-engines/ecosia/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/ecosia/ios-browser/blob/main/LICENSE",
          "note": "The iOS browser app is open source under MPL-2.0. The search engine itself is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.ecosia.org/privacy",
          "note": "Uses third-party services including Microsoft Clarity and Braze, and the apps send device statistics and install attribution data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ecosia.org/privacy",
          "note": "Funded by search ads from Microsoft Bing or Google, which are non-personalized unless the user consents."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.ecosia.org&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.ecosia.org",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.ecosia.org/privacy",
          "note": "IP addresses are anonymized after at most seven days; search terms are shared with Bing or Google."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ecosia.org/privacy",
          "note": "Ads are non-personalized by default, and personalized ads are shown only with explicit consent."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.ecosia.org/privacy",
          "note": "Search works without an account; sync and AI chat history need an Ecosia account."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:15.403Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "google-search",
      "category": "search-engines",
      "name": "Google Search",
      "description": "Google's web search engine. Searches are linked to accounts, cookies and devices to personalize results and ads.",
      "website": "https://www.google.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Google Search scores 25 out of 100 (grade F) on the search engines criteria. It meets 2 of 11 criteria: transparency report and tells users about requests. It partly meets TLS configuration, no profile-based ads and no account needed. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, security headers and no search history logs. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/search-engines/google-search/",
      "markdown": "https://privacyratings.com/search-engines/google-search/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Search activity is collected with cookie, device and account identifiers for personalization and ads, and this cannot be fully turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Funded by advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://transparencyreport.google.com/user-data/overview",
          "note": "Google publishes counts of government requests for user data and how it responds, updated twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://policies.google.com/terms/information-requests",
          "note": "Google emails the user before disclosing data in response to a government request, unless prohibited by law."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.google.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.google.com",
          "note": "Grade C (55/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "no",
          "evidence": "https://policies.google.com/technologies/retention",
          "note": "Searches are tied to accounts and cookies; server logs keep part of the IP address for 9 months and cookie data for 18 months."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://policies.google.com/privacy",
          "note": "Personalized ads are on by default and can be turned off in Google account settings."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://policies.google.com/privacy",
          "note": "Search works without an account; saved history and some personalized features need a Google account."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:03:55.674Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kagi",
      "category": "search-engines",
      "name": "Kagi",
      "description": "Paid, ad-free search engine from Kagi Inc. that combines its own index with results from other providers and lets users rank, block or boost websites.",
      "website": "https://kagi.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Kagi scores 50 out of 100 (grade D) on the search engines criteria. It meets 3 of 11 criteria: no trackers or telemetry, no ads or data sales and no profile-based ads. It partly meets transparency report, TLS configuration, security headers and no search history logs. It does not meet open source, independent audit, tells users about requests and no account needed. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/search-engines/kagi/",
      "markdown": "https://privacyratings.com/search-engines/kagi/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kagi.com/privacy",
          "note": "The site loads no analytics or telemetry and does not track which results are clicked."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kagi.com/pricing",
          "note": "Funded by paid subscriptions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://kagi.com/privacy",
          "note": "The privacy policy includes a warrant canary, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=kagi.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=kagi.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://kagi.com/privacy",
          "note": "Searches are not linked to accounts; request logs kept for debugging are purged after seven days."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kagi.com/pricing",
          "note": "No ads are shown."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "no",
          "evidence": "https://kagi.com/pricing",
          "note": "A paid Kagi account is needed to search; Privacy Pass allows unlinkable authentication."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:15.516Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "marginalia-search",
      "category": "search-engines",
      "name": "Marginalia Search",
      "description": "Independent open-source search engine from Sweden with its own crawler and index, focused on finding small, non-commercial and text-heavy websites.",
      "website": "https://marginalia-search.com",
      "source": "https://github.com/MarginaliaSearch/MarginaliaSearch",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "SE",
        "name": "Sweden",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 70,
      "coverage": 100,
      "summary": "Marginalia Search scores 70 out of 100 (grade C) on the search engines criteria. It meets 6 of 11 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, no profile-based ads and no account needed. It partly meets transparency report and no search history logs. It does not meet independent audit, tells users about requests and security headers. It is based in Sweden: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/search-engines/marginalia-search/",
      "markdown": "https://privacyratings.com/search-engines/marginalia-search/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/MarginaliaSearch/MarginaliaSearch/blob/master/LICENSE.md",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://about.marginalia-search.com/article/privacy/",
          "note": "No tracking pixels, third-party requests or click tracking; cookies only store settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://about.marginalia-search.com/",
          "note": "Funded by donations, grants and API deals, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://about.marginalia-search.com/article/privacy/",
          "note": "The privacy policy explains that minimal retention limits what can be handed over in response to legal requests, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=marginalia-search.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=marginalia-search.com",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://about.marginalia-search.com/article/privacy/",
          "note": "Access logs with IP addresses are kept for up to 24 hours, and click data is not collected."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://about.marginalia-search.com/",
          "note": "No ads are shown."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://about.marginalia-search.com/article/privacy/",
          "note": "Search needs no account; settings are stored in a cookie."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:15.811Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "metager",
      "category": "search-engines",
      "name": "MetaGer",
      "description": "Open-source metasearch engine run by the German non-profit SUMA-EV that combines results from several search providers, paid for with a prepaid anonymous key, and includes an anonymizing proxy for opening results.",
      "website": "https://metager.org",
      "source": "https://gitlab.metager.de/open-source/MetaGer",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 73,
      "coverage": 100,
      "summary": "MetaGer scores 73 out of 100 (grade C) on the search engines criteria. It meets 6 of 11 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, no search history logs and no profile-based ads. It partly meets security headers and no account needed. It does not meet independent audit, transparency report and tells users about requests. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/search-engines/metager/",
      "markdown": "https://privacyratings.com/search-engines/metager/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.metager.de/open-source/MetaGer/-/blob/development/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://metager.org/datenschutz",
          "note": "No tracking or third-party analytics; error reports go to a self-hosted GlitchTip instance with IP addresses removed."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://metager.org/preise",
          "note": "Funded by prepaid search keys and donations to the non-profit SUMA-EV, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=metager.org&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=metager.org",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://metager.org/datenschutz",
          "note": "IP addresses and user agents are not saved, and queries are passed to search partners without identifiers."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://metager.org/",
          "note": "No ads are shown."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://metager.org/",
          "note": "No account or email is needed, but searching requires a prepaid, randomly generated MetaGer key."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:15.867Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "mojeek",
      "category": "search-engines",
      "name": "Mojeek",
      "description": "British search engine that uses its own crawler and index and states that it does not track users.",
      "website": "https://www.mojeek.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 55,
      "coverage": 100,
      "summary": "Mojeek scores 55 out of 100 (grade D) on the search engines criteria. It meets 5 of 11 criteria: no trackers or telemetry, TLS configuration, no search history logs, no profile-based ads and no account needed. It partly meets no ads or data sales. It does not meet open source, independent audit, transparency report, tells users about requests and security headers. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/search-engines/mojeek/",
      "markdown": "https://privacyratings.com/search-engines/mojeek/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.mojeek.com/about/privacy/",
          "note": "No user tracking, no cookies by default, and IP addresses are not recorded in logs."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.mojeek.com/ads/",
          "note": "Shows contextual ads based on the search query, not on user data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mojeek.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mojeek.com",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.mojeek.com/about/privacy/",
          "note": "IP addresses are replaced with a country code in logs, so searches are not tied to identifiers."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.mojeek.com/ads/",
          "note": "Ads are targeted only by keywords in the current search."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.mojeek.com/about/privacy/",
          "note": "Search and preferences work without an account."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:14.970Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mwmbl",
      "category": "search-engines",
      "name": "Mwmbl",
      "description": "Non-profit, open-source search engine with its own community-crawled index, where signed-in users can help curate search results.",
      "website": "https://mwmbl.org",
      "source": "https://github.com/mwmbl/mwmbl",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 70,
      "coverage": 100,
      "summary": "Mwmbl scores 70 out of 100 (grade C) on the search engines criteria. It meets 6 of 11 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, no search history logs and no profile-based ads. It partly meets no account needed. It does not meet independent audit, transparency report, tells users about requests and security headers. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/search-engines/mwmbl/",
      "markdown": "https://privacyratings.com/search-engines/mwmbl/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mwmbl/mwmbl/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://mwmbl.org/privacy",
          "note": "Only essential login cookies are used, with no tracking, analytics or advertising cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/mwmbl",
          "note": "Non-profit project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mwmbl.org&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mwmbl.org",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://mwmbl.org/privacy",
          "note": "IP addresses are not stored on disk and no log of searches linked to a user or account is kept."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mwmbl.org/privacy",
          "note": "No ads are shown."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://mwmbl.org/privacy",
          "note": "Search works without an account; Super Search and result curation need a Mwmbl account."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:15.877Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "presearch",
      "category": "search-engines",
      "name": "Presearch",
      "description": "Search engine from the Canadian company Presearch that serves queries through a network of community-run nodes and rewards searchers and node operators with its PRE crypto token.",
      "website": "https://presearch.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 43,
      "coverage": 100,
      "summary": "Presearch scores 43 out of 100 (grade D) on the search engines criteria. It meets 2 of 10 criteria: no search history logs and no profile-based ads. It partly meets no trackers or telemetry, no ads or data sales, TLS configuration and no account needed. It does not meet open source, independent audit, transparency report and tells users about requests. It is based in Canada: Five Eyes member. Automated tests: SSL Labs grade B.",
      "url": "https://privacyratings.com/search-engines/presearch/",
      "markdown": "https://privacyratings.com/search-engines/presearch/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://presearch.com/privacy",
          "note": "No third-party cookies are used, but first-party usage data such as clicked ads and links is collected."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://docs.presearch.io/keyword-staking/keyword-staking",
          "note": "Funded by keyword ads bought by staking PRE tokens, shown based on the search terms; an ad-free subscription is available."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=presearch.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://presearch.com/privacy",
          "note": "Searches are not stored, and IP addresses and browser details are not passed to the nodes that fulfil queries."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.presearch.io/keyword-staking/keyword-staking",
          "note": "Ads are matched to the keywords of the current search."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://docs.presearch.io/ad-free-search-feature/how-to-use-the-ad-free-search-feature",
          "note": "Search works without an account; token rewards and the ad-free subscription need a Presearch account."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:42.559Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "prieco",
      "category": "search-engines",
      "name": "PriEco",
      "description": "Open-source web search engine written in Rust that combines its own index with results from other sources and supports result customization through Goggles.",
      "website": "https://prieco.net",
      "source": "https://codeberg.org/JojoYou/PriEco",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 75,
      "coverage": 100,
      "summary": "PriEco scores 75 out of 100 (grade B) on the search engines criteria. It meets 7 of 11 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, no search history logs, no profile-based ads and no account needed. It partly meets security headers. It does not meet independent audit, transparency report and tells users about requests. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/search-engines/prieco/",
      "markdown": "https://privacyratings.com/search-engines/prieco/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/JojoYou/PriEco/src/branch/master/LICENCE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://prieco.net/privacy",
          "note": "No analytics or tracking cookies; only preference cookies are set."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://prieco.net/",
          "note": "No ads are shown, and the project states it never shares or sells user data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=prieco.net&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=prieco.net",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://prieco.net/privacy",
          "note": "IP addresses are never stored or logged."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://prieco.net/",
          "note": "No ads are shown."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://prieco.net/",
          "note": "Search needs no account."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:14.920Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "qwant",
      "category": "search-engines",
      "name": "Qwant",
      "description": "French search engine that combines results from Microsoft Bing with its own European index, shown with contextual ads by default.",
      "website": "https://www.qwant.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 23,
      "coverage": 100,
      "summary": "Qwant scores 23 out of 100 (grade F) on the search engines criteria. It meets 1 of 11 criteria: TLS configuration. It partly meets no ads or data sales, security headers, no profile-based ads and no account needed. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and no search history logs. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/search-engines/qwant/",
      "markdown": "https://privacyratings.com/search-engines/qwant/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://about.qwant.com/en/legal/confidentialite/",
          "note": "The site uses third-party analytics and measurement tools including Piwik Pro and Microsoft Clarity, subject to cookie consent."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://about.qwant.com/en/legal/confidentialite/",
          "note": "Ads are contextual by default; personalized ads are shown only with consent."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.qwant.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.qwant.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "no",
          "evidence": "https://about.qwant.com/en/legal/confidentialite/",
          "note": "Search data is shared with Microsoft, which keeps the IP address for six months and cookie identifiers for 18 months."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://about.qwant.com/en/legal/confidentialite/",
          "note": "Ads are contextual by default; profile-based ads are optional and require consent."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://about.qwant.com/en/legal/confidentialite/",
          "note": "Search works without an account; some newer features need a user account."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:15.977Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "searxng",
      "category": "search-engines",
      "name": "SearXNG",
      "description": "Free, open-source metasearch engine that combines results from many search services without storing information about its users. It can be self-hosted or used through public instances.",
      "website": "https://docs.searxng.org",
      "source": "https://github.com/searxng/searxng",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 88,
      "coverage": 100,
      "summary": "SearXNG scores 88 out of 100 (grade B) on the search engines criteria. It meets 6 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, no search history logs, no profile-based ads and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/search-engines/searxng/",
      "markdown": "https://privacyratings.com/search-engines/searxng/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/searxng/searxng/blob/master/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://docs.searxng.org/own-instance.html",
          "note": "The software serves no ads or tracking content; public instances depend on their operator."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.searxng.org/own-instance.html",
          "note": "Free software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://docs.searxng.org/user/about.html",
          "note": "The software does not store search data; operators of public instances control their own logging."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.searxng.org/own-instance.html",
          "note": "No ads are served."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.searxng.org/user/about.html",
          "note": "No accounts exist."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:41.084Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "startpage",
      "category": "search-engines",
      "name": "Startpage",
      "description": "Dutch search engine returning primarily Google results, proxied to strip IP and identifiers. Includes an \"Anonymous View\" proxy for previewing results privately.",
      "website": "https://www.startpage.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "Startpage scores 45 out of 100 (grade D) on the search engines criteria. It meets 3 of 11 criteria: TLS configuration, no search history logs and no profile-based ads. It partly meets no ads or data sales, transparency report, security headers and no account needed. It does not meet open source, no trackers or telemetry, independent audit and tells users about requests. It is based in the Netherlands: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/search-engines/startpage/",
      "markdown": "https://privacyratings.com/search-engines/startpage/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.startpage.com/en/privacy-policy/",
          "note": "The website has no tracking cookies, but the Startpage app sends crash reports through Sentry and anonymized product analytics, with no documented opt-out."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.startpage.com/en/privacy-policy/",
          "note": "Funded by non-personalized sponsored links from Google AdSense."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.startpage.com/en/privacy-policy/",
          "note": "The privacy policy describes how government requests are handled, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.startpage.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.startpage.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.startpage.com/en/privacy-policy/",
          "note": "IP addresses and search queries are not recorded, except for blocking automated abuse."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.startpage.com/en/privacy-policy/",
          "note": "Only non-personalized ads are shown."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.startpage.com/en/privacy-policy/",
          "note": "Search works without an account; the paid subscription needs a Startpage account."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:15.810Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "swisscows",
      "category": "search-engines",
      "name": "Swisscows",
      "description": "Search engine from the Swiss company Swisscows AG that filters out adult content, does not use tracking cookies or build user profiles, and offers an ad-free paid tier.",
      "website": "https://swisscows.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Swisscows scores 50 out of 100 (grade D) on the search engines criteria. It meets 3 of 11 criteria: TLS configuration, no search history logs and no profile-based ads. It partly meets no trackers or telemetry, no ads or data sales, transparency report and no account needed. It does not meet open source, independent audit, tells users about requests and security headers. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C-.",
      "url": "https://privacyratings.com/search-engines/swisscows/",
      "markdown": "https://privacyratings.com/search-engines/swisscows/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://swisscows.com/en/privacy",
          "note": "No tracking cookies, pixels or fingerprinting; anonymized usage data is stored in a self-hosted analytics system."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://swisscows.com/en/privacy",
          "note": "Funded partly by text ads chosen from the search query and region, with an ad-free paid tier."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://swisscows.com/en/privacy",
          "note": "The privacy policy describes how government requests are reviewed, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=swisscows.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=swisscows.com",
          "note": "Grade C- (45/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://swisscows.com/en/privacy",
          "note": "Search queries are anonymized and not tied to user profiles; IP addresses passed to ad partners have the last octet masked."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://swisscows.com/en/privacy",
          "note": "Ads are selected from the search query and region, not a profile."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://swisscows.com/en/privacy",
          "note": "Search works without registration; Swisscows Pro and other extra features need an account."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:13:47.295Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "uruky",
      "category": "search-engines",
      "name": "Uruky",
      "description": "Paid, ad-free search engine from Portugal that combines results from European and UK search providers such as Mojeek, and lets each user customize sources and domains.",
      "website": "https://uruky.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "PT",
        "name": "Portugal",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 57,
      "coverage": 100,
      "summary": "Uruky scores 57 out of 100 (grade D) on the search engines criteria. It meets 5 of 11 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, no search history logs and no profile-based ads. It partly meets security headers. It does not meet open source, independent audit, transparency report, tells users about requests and no account needed. It is based in Portugal: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/search-engines/uruky/",
      "markdown": "https://privacyratings.com/search-engines/uruky/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://uruky.com/faq",
          "note": "Source is only shared with customers after 12 months of payment, under the Business Source License, and is not public."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://uruky.com/about",
          "note": "The project states it is free from tracking, and search activity is not logged."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://uruky.com/faq",
          "note": "Funded by user payments, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=uruky.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=uruky.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://uruky.com/privacy",
          "note": "Search activity is not logged; accounts are random numbers with no email."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://uruky.com/faq",
          "note": "No ads are shown."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "no",
          "evidence": "https://uruky.com/faq",
          "note": "A paid account number is needed to search, apart from a short trial."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:17.334Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "yacy",
      "category": "search-engines",
      "name": "YaCy",
      "description": "Free search engine software that users run themselves, either as a personal or intranet search portal with its own crawler, or as a peer in a decentralized network that shares a web index.",
      "website": "https://yacy.net",
      "source": "https://github.com/yacy/yacy_search_server",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 88,
      "coverage": 100,
      "summary": "YaCy scores 88 out of 100 (grade B) on the search engines criteria. It meets 6 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, no search history logs, no profile-based ads and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/search-engines/yacy/",
      "markdown": "https://privacyratings.com/search-engines/yacy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/yacy/yacy_search_server/blob/master/COPYRIGHT",
          "note": "GPL-2.0-or-later, with some library code under LGPL."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://yacy.net/",
          "note": "The software collects no personal data and does not phone home."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://yacy.net/",
          "note": "Free software funded by donations and community support, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://yacy.net/",
          "note": "Searches run on the user's own server, and the peer-to-peer network does not store search requests."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://yacy.net/",
          "note": "No ads are shown."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/yacy/yacy_search_server",
          "note": "Self-hosted software that needs no account."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:16.509Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "yahoo-search",
      "category": "search-engines",
      "name": "Yahoo Search",
      "description": "Yahoo's web search engine. Searches are collected with cookie, device and account identifiers, shared with search partners, and used to personalize results and ads.",
      "website": "https://search.yahoo.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 32,
      "coverage": 100,
      "summary": "Yahoo Search scores 32 out of 100 (grade F) on the search engines criteria. It meets 3 of 11 criteria: transparency report, tells users about requests and TLS configuration. It partly meets security headers, no profile-based ads and no account needed. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit and no search history logs. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/search-engines/yahoo-search/",
      "markdown": "https://privacyratings.com/search-engines/yahoo-search/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://legal.yahoo.com/us/en/yahoo/privacy/products/searchservices/index.html",
          "note": "Search queries, IP addresses and browser identifiers are collected and may be shared with search partners, and this cannot be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://legal.yahoo.com/us/en/yahoo/privacy/adinfo/index.html",
          "note": "Funded by advertising, including interest-based ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.yahooinc.com/transparency/reports/government-data-requests/JUL-DEC-2024/index.html",
          "note": "Yahoo publishes counts of government data requests by country and how it responded, in half-yearly reports."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.yahooinc.com/transparency/about/faq-glossary.html",
          "note": "Yahoo's policy is to notify users about third-party requests for their data before disclosure, except where prohibited by law."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=search.yahoo.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=search.yahoo.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "no",
          "evidence": "https://legal.yahoo.com/us/en/yahoo/privacy/products/searchservices/index.html",
          "note": "Search queries are collected with IP addresses and browser identifiers, and search history is kept for signed-in users."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://legal.yahoo.com/us/en/yahoo/privacy/adinfo/index.html",
          "note": "Interest-based ads use activity and searches by default, and users can opt out in Yahoo's privacy controls."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://legal.yahoo.com/us/en/yahoo/privacy/products/searchservices/index.html",
          "note": "Search works without an account; some features are only available to registered users."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:15.834Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "yandex-search",
      "category": "search-engines",
      "name": "Yandex Search",
      "description": "Web search engine from the Russian company Yandex. Searches are linked to cookies, IP addresses and Yandex ID accounts to personalize results and ads.",
      "website": "https://yandex.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "RU",
        "name": "Russia",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 27,
      "coverage": 100,
      "summary": "Yandex Search scores 27 out of 100 (grade F) on the search engines criteria. It meets 2 of 11 criteria: transparency report and TLS configuration. It partly meets security headers, no profile-based ads and no account needed. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, tells users about requests and no search history logs. It is based in Russia: Not in the Five, Nine or Fourteen Eyes. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/search-engines/yandex-search/",
      "markdown": "https://privacyratings.com/search-engines/yandex-search/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://yandex.com/legal/confidential/en/",
          "note": "The site uses Yandex Metrica and third-party tracking and advertising cookies, and search activity is collected with cookie and account identifiers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://yandex.com/legal/confidential/en/",
          "note": "Funded by advertising, including ads personalized from search history."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://yandex.com/company/privacy/transparencyreport",
          "note": "Yandex publishes half-yearly counts of government requests for user data and refusals by service."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=yandex.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=yandex.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_search_logs": {
          "title": "No search history logs",
          "weight": 3,
          "answer": "no",
          "evidence": "https://yandex.com/company/privacy",
          "note": "Search history is collected with cookies, IP addresses and Yandex ID accounts and used to personalize results."
        },
        "no_personalized_ads": {
          "title": "No profile-based ads",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://yandex.com/tune/adv",
          "note": "Ads use interests and location by default, and personalization can be turned off in search settings."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://yandex.com/company/privacy",
          "note": "Search works without an account; profile features and synced history need a Yandex ID."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Yandex",
            "host": "yastatic.net",
            "effect": "no"
          },
          {
            "name": "Yandex Metrica",
            "host": "mc.yandex.ru",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:16.790Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "floccus",
      "category": "browser-sync",
      "name": "Floccus",
      "description": "Browser extension and Android app that syncs bookmarks through a user-chosen backend such as Nextcloud Bookmarks, WebDAV, Google Drive or Git.",
      "website": "https://floccus.org",
      "source": "https://github.com/marcelklehr/floccus",
      "license": "MPL-2.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Floccus scores 80 out of 100 (grade B) on the bookmarks and read-later criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-sync/floccus/",
      "markdown": "https://privacyratings.com/browser-sync/floccus/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/marcelklehr/floccus/blob/develop/LICENSE.txt",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/floccus/privacy/",
          "note": "The authors receive no user data; the website uses Plausible, a cookieless analytics service."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://floccus.org/donate/",
          "note": "Free and funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:00:41.067Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "instapaper",
      "category": "browser-sync",
      "name": "Instapaper",
      "description": "Hosted read-it-later service that saves web articles in a clean reading format for the web, mobile apps and Kindle and Kobo e-readers, with an optional Premium subscription.",
      "website": "https://www.instapaper.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Instapaper scores 0 out of 100 (grade F) on the bookmarks and read-later criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/browser-sync/instapaper/",
      "markdown": "https://privacyratings.com/browser-sync/instapaper/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.instapaper.com/about-legal/legal/privacy-policy",
          "note": "The service uses Google Analytics and Crashlytics, and the Android app contains Google Firebase Analytics and Crashlytics according to Exodus Privacy."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.instapaper.com/about-legal/about/instapaper",
          "note": "Mostly funded by Premium subscriptions, but the free website shows ads, newsletters carry sponsorships, and aggregate usage data is shared with advertisers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:16.342Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "karakeep",
      "category": "browser-sync",
      "name": "Karakeep",
      "description": "Bookmark manager, formerly called Hoarder, for saving links, notes, images and PDFs with full-text search, page archiving and optional AI tagging; it can be self-hosted or used as the paid Karakeep Cloud.",
      "website": "https://karakeep.app",
      "source": "https://github.com/karakeep-app/karakeep",
      "license": "AGPL-3.0",
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Karakeep scores 80 out of 100 (grade B) on the bookmarks and read-later criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/browser-sync/karakeep/",
      "markdown": "https://privacyratings.com/browser-sync/karakeep/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/karakeep-app/karakeep/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://karakeep.app/privacy/",
          "note": "No third-party trackers, and the apps have no telemetry by default. The website's Cloudflare Web Analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://karakeep.app/pricing/",
          "note": "Funded by Karakeep Cloud subscriptions; the self-hosted version is free, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:16.259Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "linkding",
      "category": "browser-sync",
      "name": "linkding",
      "description": "Self-hosted bookmark manager with tags, Markdown notes, page archiving, multi-user sharing, a REST API and browser extensions for Firefox and Chrome.",
      "website": "https://linkding.link",
      "source": "https://github.com/sissbruecker/linkding",
      "license": "MIT",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "linkding scores 80 out of 100 (grade B) on the bookmarks and read-later criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-sync/linkding/",
      "markdown": "https://privacyratings.com/browser-sync/linkding/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sissbruecker/linkding/blob/master/LICENSE.txt",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sissbruecker/linkding",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sissbruecker/linkding",
          "note": "Free open-source software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:16.220Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "linkwarden",
      "category": "browser-sync",
      "name": "Linkwarden",
      "description": "Bookmark manager that saves full copies of pages as HTML, screenshots and PDF, with collections, tags, reader view and highlights; it can be self-hosted or used as a paid cloud service.",
      "website": "https://linkwarden.app",
      "source": "https://github.com/linkwarden/linkwarden",
      "license": "AGPL-3.0",
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Linkwarden scores 50 out of 100 (grade D) on the bookmarks and read-later criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Canada: Five Eyes member.",
      "url": "https://privacyratings.com/browser-sync/linkwarden/",
      "markdown": "https://privacyratings.com/browser-sync/linkwarden/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/linkwarden/linkwarden/blob/main/LICENSE.md",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/linkwarden/linkwarden/blob/main/apps/mobile/app/_layout.tsx",
          "note": "The mobile app sends error reports to Sentry with no setting to turn it off, and the privacy policy lists third-party tracking cookies on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://linkwarden.app/pricing",
          "note": "Funded by paid cloud subscriptions; the self-hosted version is free, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:16.171Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "raindrop-io",
      "category": "browser-sync",
      "name": "Raindrop.io",
      "description": "Hosted bookmark manager for saving, tagging and organizing links, articles and files in collections, with a web app, browser extensions and desktop and mobile apps.",
      "website": "https://raindrop.io",
      "source": "https://github.com/raindropio/app",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Raindrop.io scores 35 out of 100 (grade F) on the bookmarks and read-later criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/browser-sync/raindrop-io/",
      "markdown": "https://privacyratings.com/browser-sync/raindrop-io/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/raindropio/app/blob/master/LICENSE.md",
          "note": "The web app, browser extensions and desktop app are MIT-licensed; the server and mobile apps are closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://help.raindrop.io/privacy",
          "note": "The web app sends error reports to Sentry and the privacy policy describes usage analytics and third-party cookies; the Android app has no known trackers in its Exodus report."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://raindrop.io/pro/buy",
          "note": "Funded by Pro subscriptions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:16.622Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "readeck",
      "category": "browser-sync",
      "name": "Readeck",
      "description": "Self-hosted read-it-later and bookmark application that saves articles, pictures and video transcripts, with labels, highlights, collections, e-book export and a browser extension.",
      "website": "https://readeck.org",
      "source": "https://codeberg.org/readeck/readeck",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Readeck scores 80 out of 100 (grade B) on the bookmarks and read-later criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-sync/readeck/",
      "markdown": "https://privacyratings.com/browser-sync/readeck/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/readeck/readeck/src/branch/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://readeck.org/en/privacy",
          "note": "No third-party trackers, and the server, extension and apps have no telemetry. The website's self-hosted Umami analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://readeck.org/en/privacy",
          "note": "Free open-source software that uses no advertising services."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:55.158Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "shiori",
      "category": "browser-sync",
      "name": "Shiori",
      "description": "Self-hosted bookmark manager written in Go, with a web interface, command-line tool, import and export, and offline archiving of saved pages.",
      "website": "https://github.com/go-shiori/shiori",
      "source": "https://github.com/go-shiori/shiori",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Shiori scores 80 out of 100 (grade B) on the bookmarks and read-later criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-sync/shiori/",
      "markdown": "https://privacyratings.com/browser-sync/shiori/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/go-shiori/shiori/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/go-shiori/shiori",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/go-shiori/shiori",
          "note": "Free open-source software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:40.489Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "unmark",
      "category": "browser-sync",
      "name": "Unmark",
      "description": "Open-source bookmark manager that treats saved links as a to-do list; it can be self-hosted or used through the hosted service at unmark.it.",
      "website": "https://unmark.it",
      "source": "https://github.com/cdevroe/unmark",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Unmark scores 80 out of 100 (grade B) on the bookmarks and read-later criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-sync/unmark/",
      "markdown": "https://privacyratings.com/browser-sync/unmark/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cdevroe/unmark/blob/main/license.txt",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cdevroe/unmark",
          "note": "No telemetry or analytics in the source code; the web interface loads Google Fonts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://unmark.it",
          "note": "Funded by optional paid accounts on the hosted service, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:41.419Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "wallabag",
      "category": "browser-sync",
      "name": "wallabag",
      "description": "Self-hostable read-it-later application that saves the text of web articles for distraction-free reading, with browser extensions, mobile apps, e-reader support and an official hosted service, wallabag.it.",
      "website": "https://wallabag.org",
      "source": "https://github.com/wallabag/wallabag",
      "license": "MIT",
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "wallabag scores 65 out of 100 (grade C) on the bookmarks and read-later criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-sync/wallabag/",
      "markdown": "https://privacyratings.com/browser-sync/wallabag/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/wallabag/wallabag/blob/master/COPYING.md",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://wallabag.org/",
          "note": "The software and Android app contain no trackers, but the project website uses a self-hosted Matomo analytics instance."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://wallabag.org/",
          "note": "Free open-source software funded by donations and the paid wallabag.it hosting, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:17.851Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "xbrowsersync",
      "category": "browser-sync",
      "name": "XBrowserSync",
      "description": "Browser extension and Android app that syncs bookmarks with end-to-end encryption through a community-run or self-hosted sync server, without an account.",
      "website": "https://www.xbrowsersync.org",
      "source": "https://github.com/xbrowsersync/app",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "XBrowserSync scores 80 out of 100 (grade B) on the bookmarks and read-later criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/browser-sync/xbrowsersync/",
      "markdown": "https://privacyratings.com/browser-sync/xbrowsersync/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/xbrowsersync/app/blob/master/LICENSE.md",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://addons.mozilla.org/en-US/firefox/addon/xbs/privacy/",
          "note": "The project states it collects no personal, usage or telemetry data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.xbrowsersync.org/",
          "note": "Free and funded by donations; the project states there are no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:41.859Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "accrescent",
      "category": "app-stores",
      "name": "Accrescent",
      "description": "Android app store with signing key pinning, signed repository metadata and unattended updates. Developers upload apps signed with their own keys, and it is still in alpha.",
      "website": "https://accrescent.app",
      "source": "https://github.com/accrescent/accrescent",
      "license": "Apache-2.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 77,
      "coverage": 100,
      "summary": "Accrescent scores 77 out of 100 (grade B) on the app stores criteria. It meets 4 of 6 criteria: open source, no trackers or telemetry, no ads or data sales and no account needed. It does not meet independent audit and shows trackers and anti-features.",
      "url": "https://privacyratings.com/app-stores/accrescent/",
      "markdown": "https://privacyratings.com/app-stores/accrescent/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/accrescent/accrescent/blob/main/LICENSE",
          "note": "Apache-2.0 for the client, and the server code is also public."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/accrescent/accrescent",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://accrescent.app/donate/",
          "note": "Funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://accrescent.app/",
          "note": "No account is needed to install apps."
        },
        "tracker_info": {
          "title": "Shows trackers and anti-features",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Accrescent does not show trackers or anti-features for apps."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:16.494Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "apple-app-store",
      "category": "app-stores",
      "name": "Apple App Store",
      "description": "Apple's app store for iPhone, iPad, Mac, Apple Watch, Apple TV and Vision Pro. It is the main way to install apps on Apple devices and requires an Apple Account.",
      "website": "https://www.apple.com/app-store/",
      "license": null,
      "platforms": [
        "ios",
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 15,
      "coverage": 100,
      "summary": "Apple App Store scores 15 out of 100 (grade F) on the app stores criteria. It partly meets no trackers or telemetry and shows trackers and anti-features. It does not meet open source, no ads or data sales, independent audit and no account needed. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/app-stores/apple-app-store/",
      "markdown": "https://privacyratings.com/app-stores/apple-app-store/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/app-store/",
          "note": "No third-party trackers are described, but Apple collects App Store usage, searches and downloads linked to the Apple Account by default, with personalization that can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.apple.com/legal/privacy/data/en/apple-advertising/",
          "note": "The App Store shows ads from Apple's ad platform, which can use Apple Account, download and purchase data for targeting."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.apple.com/legal/privacy/data/en/app-store/",
          "note": "Downloads, including free apps, require signing in with an Apple Account and are logged with it."
        },
        "tracker_info": {
          "title": "Shows trackers and anti-features",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.apple.com/app-store/app-privacy-details/",
          "note": "Listings show privacy labels, but their contents are self-reported by developers."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:16.587Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "aurora-store",
      "category": "app-stores",
      "name": "Aurora Store",
      "description": "Open source Android client for the Google Play Store that downloads apps from Google's servers without Google Play Services. It can use a personal Google account or shared anonymous accounts.",
      "website": "https://auroraoss.com",
      "source": "https://gitlab.com/AuroraOSS/AuroraStore",
      "license": null,
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 46,
      "coverage": 100,
      "summary": "Aurora Store scores 46 out of 100 (grade D) on the app stores criteria. It meets 3 of 6 criteria: open source, no account needed and shows trackers and anti-features. It does not meet no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/app-stores/aurora-store/",
      "markdown": "https://privacyratings.com/app-stores/aurora-store/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/AuroraOSS/AuroraStore/-/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://auroraoss.com/",
          "note": "The app has no known trackers, but the website loads Google Analytics and Google AdSense."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://auroraoss.com/",
          "note": "The app has no ads, but the website loads Google AdSense."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gitlab.com/AuroraOSS/AuroraStore/-/blob/master/README.md",
          "note": "Apps can be installed with a shared anonymous account instead of a personal Google account."
        },
        "tracker_info": {
          "title": "Shows trackers and anti-features",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://gitlab.com/AuroraOSS/AuroraStore/-/blob/master/README.md",
          "note": "App pages show the trackers found by Exodus Privacy."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:16.940Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "droid-ify",
      "category": "app-stores",
      "name": "Droid-ify",
      "description": "Open source Android client for F-Droid repositories with background updates, several install methods and one-tap repository adding.",
      "website": "https://codeberg.org/droidify/client",
      "source": "https://codeberg.org/droidify/client",
      "license": null,
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "Droid-ify scores 85 out of 100 (grade B) on the app stores criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, no account needed and shows trackers and anti-features. It does not meet independent audit.",
      "url": "https://privacyratings.com/app-stores/droid-ify/",
      "markdown": "https://privacyratings.com/app-stores/droid-ify/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/droidify/client/src/branch/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.looker.droidify/latest/",
          "note": "Exodus Privacy finds no trackers in the app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.looker.droidify/latest/",
          "note": "Free volunteer project with no ads or ad libraries."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://codeberg.org/droidify/client",
          "note": "Apps are installed from F-Droid repositories with no account."
        },
        "tracker_info": {
          "title": "Shows trackers and anti-features",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://codeberg.org/droidify/client/src/branch/main/app/src/main/kotlin/com/looker/droidify/ui/appDetail/AppDetailAdapter.kt",
          "note": "App pages show the anti-features declared in the repository metadata."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:16.509Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "f-droid",
      "category": "app-stores",
      "name": "F-Droid",
      "description": "Installable catalogue of FOSS applications for Android, with a client that browses, installs and tracks updates of apps on your device.",
      "website": "https://f-droid.org",
      "source": "https://gitlab.com/fdroid/fdroidclient",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 92,
      "coverage": 100,
      "summary": "F-Droid scores 92 out of 100 (grade A) on the app stores criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, no account needed and shows trackers and anti-features. It partly meets independent audit.",
      "url": "https://privacyratings.com/app-stores/f-droid/",
      "markdown": "https://privacyratings.com/app-stores/f-droid/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/fdroid/fdroidclient/-/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/fdroid/fdroidclient/-/blob/master/app/src/main/kotlin/org/fdroid/App.kt",
          "note": "The only library Exodus flags is ACRA, which the client uses to let users send crash reports by email after confirming a dialog."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://f-droid.org/donate/",
          "note": "Funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://f-droid.org/docs/Second_Audit_Report/",
          "note": "Radically Open Security audited the client, server and website; the full report is public but older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://f-droid.org/en/about/",
          "note": "No account is needed to download apps."
        },
        "tracker_info": {
          "title": "Shows trackers and anti-features",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://f-droid.org/docs/Anti-Features/",
          "note": "Apps are marked with anti-features such as tracking, ads and non-free network services."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:42.666Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "google-play",
      "category": "app-stores",
      "name": "Google Play",
      "description": "Google's app store for Android, preinstalled on most Android devices. It distributes apps, games and in-app purchases and requires a Google account to install apps.",
      "website": "https://play.google.com",
      "license": null,
      "platforms": [
        "android",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 4,
      "coverage": 100,
      "summary": "Google Play scores 4 out of 100 (grade F) on the app stores criteria. It partly meets shows trackers and anti-features. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit and no account needed. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/app-stores/google-play/",
      "markdown": "https://privacyratings.com/app-stores/google-play/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Google collects app activity and device data for analytics and advertising, and play.google.com loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://support.google.com/google-ads/answer/6247380?hl=en",
          "note": "Google Play shows paid app ads in search results and on the home page, and Google uses account activity for ad personalization."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 2,
          "answer": "no",
          "evidence": "https://support.google.com/googleplay/answer/2521798?hl=en",
          "note": "A Google account must be added to the device to download apps."
        },
        "tracker_info": {
          "title": "Shows trackers and anti-features",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://support.google.com/googleplay/answer/11416267?hl=en",
          "note": "Listings show a Data safety section, but its contents are self-reported by developers."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:16.509Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "izzyondroid",
      "category": "app-stores",
      "name": "IzzyOnDroid",
      "description": "F-Droid compatible repository of free and open source Android apps, distributing APKs built and signed by their developers after security and library scans, with reproducible build checks.",
      "website": "https://izzyondroid.org",
      "source": "https://codeberg.org/IzzyOnDroid",
      "license": null,
      "platforms": [
        "android",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 73,
      "coverage": 100,
      "summary": "IzzyOnDroid scores 73 out of 100 (grade C) on the app stores criteria. It meets 4 of 6 criteria: no trackers or telemetry, no ads or data sales, no account needed and shows trackers and anti-features. It partly meets open source. It does not meet independent audit.",
      "url": "https://privacyratings.com/app-stores/izzyondroid/",
      "markdown": "https://privacyratings.com/app-stores/izzyondroid/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://codeberg.org/IzzyOnDroid/repo",
          "note": "The website and most repository scripts are public under GPL-2.0 and AGPL-3.0, but not all of the infrastructure is published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://izzyondroid.org/about/security/RepoBrowser/",
          "note": "The repository browser loads no third-party resources or JavaScript."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://izzyondroid.org/",
          "note": "Funded by donations and an NLnet NGI Mobifree grant."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://apt.izzysoft.de/fdroid/",
          "note": "The repository is added to an F-Droid client by URL, and APKs can be downloaded directly, with no account."
        },
        "tracker_info": {
          "title": "Shows trackers and anti-features",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://apt.izzysoft.de/fdroid/index/apk/com.aurora.store",
          "note": "Every app page lists its anti-features, permissions and library scan results."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:17.509Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "neo-store",
      "category": "app-stores",
      "name": "Neo Store",
      "description": "Open source Android client for F-Droid repositories with around a hundred built-in repositories, reproducible build labels and a privacy panel that lists trackers and permissions.",
      "website": "https://github.com/NeoApplications/Neo-Store",
      "source": "https://github.com/NeoApplications/Neo-Store",
      "license": "GPL-3.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "Neo Store scores 85 out of 100 (grade B) on the app stores criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, no account needed and shows trackers and anti-features. It does not meet independent audit.",
      "url": "https://privacyratings.com/app-stores/neo-store/",
      "markdown": "https://privacyratings.com/app-stores/neo-store/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/NeoApplications/Neo-Store/src/branch/master/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.machiav3lli.fdroid/latest/",
          "note": "Exodus Privacy finds no trackers in the app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.machiav3lli.fdroid/latest/",
          "note": "Free volunteer project with no ads or ad libraries."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://codeberg.org/NeoApplications/Neo-Store",
          "note": "Apps are installed from F-Droid repositories with no account."
        },
        "tracker_info": {
          "title": "Shows trackers and anti-features",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://codeberg.org/NeoApplications/Neo-Store/src/branch/master/src/main/res/values/strings.xml",
          "note": "App pages show anti-features and a privacy panel with trackers by category."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:16.587Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "obtainium",
      "category": "app-stores",
      "name": "Obtainium",
      "description": "Open source Android app that installs and updates apps directly from their release pages, such as GitHub, GitLab, Codeberg and F-Droid repositories, and notifies when new releases appear.",
      "website": "https://obtainium.imranr.dev",
      "source": "https://github.com/ImranR98/Obtainium",
      "license": "GPL-3.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 77,
      "coverage": 100,
      "summary": "Obtainium scores 77 out of 100 (grade B) on the app stores criteria. It meets 4 of 6 criteria: open source, no trackers or telemetry, no ads or data sales and no account needed. It does not meet independent audit and shows trackers and anti-features.",
      "url": "https://privacyratings.com/app-stores/obtainium/",
      "markdown": "https://privacyratings.com/app-stores/obtainium/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ImranR98/Obtainium/blob/main/LICENSE.txt",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://obtainium.imranr.dev/",
          "note": "No third-party trackers in the app. The website's self-hosted Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/dev.imranr.obtainium.fdroid/latest/",
          "note": "Free volunteer project with no ads or ad libraries."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://wiki.obtainium.imranr.dev/",
          "note": "Apps are added by release page URL, with no account."
        },
        "tracker_info": {
          "title": "Shows trackers and anti-features",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Obtainium does not show trackers or anti-features for apps."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:17.282Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "breezewiki",
      "category": "proxy-frontends",
      "name": "BreezeWiki",
      "description": "Open source alternative front end for Fandom wikis that removes ads, videos and suggested content. Replacing fandom.com with breezewiki.com in a URL opens the same page, and several independent mirrors exist.",
      "website": "https://breezewiki.com",
      "source": "https://gitdab.com/cadence/breezewiki",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 63,
      "coverage": 100,
      "summary": "BreezeWiki scores 63 out of 100 (grade C) on the private front ends criteria. It meets 4 of 8 criteria: open source, no trackers or telemetry, no ads or data sales and TLS configuration. It does not meet independent audit, transparency report, tells users about requests and security headers. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/proxy-frontends/breezewiki/",
      "markdown": "https://privacyratings.com/proxy-frontends/breezewiki/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitdab.com/cadence/breezewiki/src/branch/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitdab.com/cadence/breezewiki",
          "note": "No telemetry or analytics in the source code, and the site loads no scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://breezewiki.com/",
          "note": "Volunteer project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=breezewiki.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=breezewiki.com",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:17.958Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "freetube",
      "category": "proxy-frontends",
      "name": "FreeTube",
      "description": "Open source desktop YouTube client for Windows, macOS and Linux. It fetches videos with a built-in extractor or an Invidious instance and stores subscriptions and history locally.",
      "website": "https://freetubeapp.io",
      "source": "https://github.com/FreeTubeApp/FreeTube",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "FreeTube scores 65 out of 100 (grade C) on the private front ends criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. Automated tests: Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/proxy-frontends/freetube/",
      "markdown": "https://privacyratings.com/proxy-frontends/freetube/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/FreeTubeApp/FreeTube/blob/development/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://freetubeapp.io/privacy.php",
          "note": "The app sends no data to FreeTube, but the website runs self-hosted Matomo analytics that can be avoided with Do Not Track."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/FreeTubeApp/FreeTube#donate",
          "note": "Volunteer project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:16.962Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "grayjay",
      "category": "proxy-frontends",
      "name": "Grayjay",
      "description": "Video app from FUTO that aggregates YouTube, PeerTube, Twitch and other platforms through plugins into one feed, with local subscriptions and downloads. The source code is public under a non-commercial license.",
      "website": "https://grayjay.app",
      "source": "https://gitlab.futo.org/videostreaming/grayjay",
      "license": null,
      "platforms": [
        "android",
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Grayjay scores 50 out of 100 (grade D) on the private front ends criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/proxy-frontends/grayjay/",
      "markdown": "https://privacyratings.com/proxy-frontends/grayjay/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.futo.org/videostreaming/grayjay/-/blob/master/LICENSE.md",
          "note": "All code is public under the source-available FUTO Source First License, which is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://gitlab.futo.org/videostreaming/grayjay/-/blob/master/app/src/main/java/com/futo/platformplayer/states/StateTelemetry.kt",
          "note": "Release builds send launch telemetry with a random ID, device model and enabled plugins to FUTO, with no setting to turn it off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://grayjay.app/faq.html",
          "note": "Funded by optional one-time license purchases, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:17.533Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "invidious",
      "category": "proxy-frontends",
      "name": "Invidious",
      "description": "Open source alternative front end to YouTube that proxies videos through the instance, so Google does not see the viewer. It works without JavaScript and supports audio-only playback and subscriptions without a Google account.",
      "website": "https://invidious.io",
      "source": "https://github.com/iv-org/invidious",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 63,
      "coverage": 100,
      "summary": "Invidious scores 63 out of 100 (grade C) on the private front ends criteria. It meets 4 of 8 criteria: open source, no trackers or telemetry, no ads or data sales and TLS configuration. It does not meet independent audit, transparency report, tells users about requests and security headers. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/proxy-frontends/invidious/",
      "markdown": "https://privacyratings.com/proxy-frontends/invidious/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/iv-org/invidious/blob/master/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://invidious.io/",
          "note": "The project states it does not track users, and the software contains no analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://invidious.io/donate/",
          "note": "Volunteer project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=invidious.io&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=invidious.io",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:17.695Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "libretube",
      "category": "proxy-frontends",
      "name": "LibreTube",
      "description": "Open source YouTube client for Android that fetches content through Piped instances or locally, without Google services. It supports subscriptions, playlists, downloads and SponsorBlock without a Google account.",
      "website": "https://libretube.dev",
      "source": "https://github.com/libre-tube/LibreTube",
      "license": "GPL-3.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "LibreTube scores 80 out of 100 (grade B) on the private front ends criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/proxy-frontends/libretube/",
      "markdown": "https://privacyratings.com/proxy-frontends/libretube/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/libre-tube/LibreTube/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.github.libretube/latest/",
          "note": "Exodus Privacy finds no trackers in the app, and the website states it uses no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://libretube.dev/",
          "note": "Volunteer project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:17.466Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "materialious",
      "category": "proxy-frontends",
      "name": "Materialious",
      "description": "Open source front end for YouTube and Invidious with a Material Design interface, available for the web, desktop, Android and Android TV. It supports encrypted subscription sync, SponsorBlock and DeArrow.",
      "website": "https://materialio.us",
      "source": "https://github.com/Materialious/Materialious",
      "license": "AGPL-3.0",
      "platforms": [
        "web",
        "windows",
        "macos",
        "linux",
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Materialious scores 80 out of 100 (grade B) on the private front ends criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/proxy-frontends/materialious/",
      "markdown": "https://privacyratings.com/proxy-frontends/materialious/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Materialious/Materialious/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/us.materialio.app/latest/",
          "note": "Exodus Privacy finds no trackers in the Android app, and the project states it has no tracking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://materialio.us/",
          "note": "Volunteer project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:18.432Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "newpipe",
      "category": "proxy-frontends",
      "name": "NewPipe",
      "description": "Open source YouTube client for Android that fetches content without Google APIs or Play Services. It supports background playback, downloads and subscriptions without an account.",
      "website": "https://newpipe.net",
      "source": "https://github.com/TeamNewPipe/NewPipe",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 69,
      "coverage": 100,
      "summary": "NewPipe scores 69 out of 100 (grade C) on the private front ends criteria. It meets 5 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration and security headers. It does not meet independent audit, transparency report and tells users about requests. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/proxy-frontends/newpipe/",
      "markdown": "https://privacyratings.com/proxy-frontends/newpipe/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TeamNewPipe/NewPipe/blob/dev/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://newpipe.net/legal/privacy/",
          "note": "The website sets no cookies and does no tracking, and crash reports are sent only when the user chooses."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://newpipe.net/donate/",
          "note": "Volunteer project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=newpipe.net&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=newpipe.net",
          "note": "Grade A+ (105/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:17.672Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "piped",
      "category": "proxy-frontends",
      "name": "Piped",
      "description": "Open source alternative front end for YouTube that proxies videos through the instance, so Google does not see the viewer. It supports subscriptions, playlists and SponsorBlock without a Google account.",
      "website": "https://piped.video",
      "source": "https://github.com/TeamPiped/Piped",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 63,
      "coverage": 100,
      "summary": "Piped scores 63 out of 100 (grade C) on the private front ends criteria. It meets 4 of 8 criteria: open source, no trackers or telemetry, no ads or data sales and TLS configuration. It does not meet independent audit, transparency report, tells users about requests and security headers. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/proxy-frontends/piped/",
      "markdown": "https://privacyratings.com/proxy-frontends/piped/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TeamPiped/Piped/blob/master/LICENSE",
          "note": "AGPL-3.0, for both the frontend and the backend."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TeamPiped/Piped/blob/master/README.md",
          "note": "The project states it has no tracking, and the frontend contains no analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/TeamPiped/Piped/blob/master/README.md",
          "note": "Volunteer project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=piped.video&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=piped.video",
          "note": "Grade C (55/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:17.554Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "redlib",
      "category": "proxy-frontends",
      "name": "Redlib",
      "description": "Open source alternative front end to Reddit, forked from Libreddit. All requests, including media, are proxied through the server and the pages use no JavaScript.",
      "website": "https://github.com/redlib-org/redlib",
      "source": "https://github.com/redlib-org/redlib",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Redlib scores 80 out of 100 (grade B) on the private front ends criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/proxy-frontends/redlib/",
      "markdown": "https://privacyratings.com/proxy-frontends/redlib/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/redlib-org/redlib/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/redlib-org/redlib#redlib",
          "note": "The project states it has no JavaScript and no tracking, and proxies all requests through the server."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/redlib-org/redlib#redlib",
          "note": "Volunteer project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:41.067Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "rimgo",
      "category": "proxy-frontends",
      "name": "rimgo",
      "description": "Open source alternative front end for Imgur that works without JavaScript and proxies images through the instance. It can be self-hosted, and public instances are run by volunteers.",
      "website": "https://codeberg.org/rimgo/rimgo",
      "source": "https://codeberg.org/rimgo/rimgo",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "rimgo scores 80 out of 100 (grade B) on the private front ends criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/proxy-frontends/rimgo/",
      "markdown": "https://privacyratings.com/proxy-frontends/rimgo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/rimgo/rimgo/src/branch/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/rimgo/rimgo",
          "note": "The project states it has no tracking, and it uses no JavaScript."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://codeberg.org/rimgo/rimgo",
          "note": "Volunteer project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:17.510Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "smarttube",
      "category": "proxy-frontends",
      "name": "SmartTube",
      "description": "Open source YouTube client for Android TV and TV boxes with SponsorBlock, ad-free playback and up to 8K video. It works without Google Play Services.",
      "website": "https://smarttubeapp.github.io",
      "source": "https://github.com/yuliskov/SmartTube",
      "license": "MIT",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "SmartTube scores 50 out of 100 (grade D) on the private front ends criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/proxy-frontends/smarttube/",
      "markdown": "https://privacyratings.com/proxy-frontends/smarttube/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/yuliskov/SmartTube/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/yuliskov/SmartTube/blob/master/smarttubetv/build.gradle",
          "note": "The stable and beta builds include Google Firebase Crashlytics. Only the F-Droid build has no tracking code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/yuliskov/SmartTube/blob/master/PRIVACY.md",
          "note": "Funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:17.564Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "webproxy",
      "category": "proxy-frontends",
      "name": "WebOProxy",
      "description": "Free web proxy run by Devro LABS that routes requests through its servers and the Tor network to reach blocked sites. The service is closed source and funded by advertising.",
      "website": "https://weboproxy.com",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 6,
      "coverage": 100,
      "summary": "WebOProxy scores 6 out of 100 (grade F) on the private front ends criteria. It partly meets TLS configuration. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests and security headers. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/proxy-frontends/webproxy/",
      "markdown": "https://privacyratings.com/proxy-frontends/webproxy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://weboproxy.com/weboproxy-script",
          "note": "Closed source. The proxy code is sold privately on request."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google AdSense, Google Analytics and Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://weboproxy.com/advertising",
          "note": "Funded by display advertising, sponsored links and paid link building."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=weboproxy.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=weboproxy.com",
          "note": "Grade F (0/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:17.627Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "1password",
      "category": "password-managers",
      "name": "1Password",
      "description": "Closed source password manager from AgileBits with end-to-end encrypted sync across desktop, mobile, browser and command-line apps.",
      "website": "https://1password.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "1Password scores 45 out of 100 (grade D) on the password managers criteria. It meets 3 of 11 criteria: tells users about requests, end-to-end encrypted vault and full export. It partly meets no ads or data sales, independent audit, transparency report, TLS configuration and local or self-hosted option. It does not meet open source, no trackers or telemetry and security headers. It is based in Canada: Five Eyes member. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B-.",
      "url": "https://privacyratings.com/password-managers/1password/",
      "markdown": "https://privacyratings.com/password-managers/1password/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://1password.com/legal/privacy",
          "note": "The privacy policy says 1Password and its marketing partners use cookies and tracking technologies on its websites and products for analytics and advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://1password.com/legal/privacy",
          "note": "Funded by subscriptions, but the privacy policy says data shared with marketing partners may count as a sale or sharing of personal information."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.1password.com/security-assessments/",
          "note": "Recent penetration test reports are only available through the 1Password Trust Center. The public full reports are older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://1password.com/legal/law-enforcement",
          "note": "Publishes government request guidelines but no request counts."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://1password.com/legal/law-enforcement",
          "note": "Seeks to notify users before disclosing data unless prohibited by law or where there is risk of harm."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=1password.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=1password.com",
          "note": "Grade B- (65/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://support.1password.com/1password-security/",
          "note": "Vault data is end-to-end encrypted with keys derived from the account password and Secret Key."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.1password.com/export/",
          "note": "Vaults are stored only in the 1Password cloud. Data can be exported."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://support.1password.com/export/",
          "note": "Full export to the JSON-based 1PUX format, or CSV for logins and passwords."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:17.610Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "2of3-by-ente",
      "category": "password-managers",
      "name": "2of3 by Ente",
      "description": "Splits a recovery key, password or other secret into three cards with Shamir secret sharing, so that any two cards recover it. It runs entirely in the browser and includes an offline recovery page.",
      "website": "https://2of3.ente.com",
      "source": "https://github.com/ente/ente/tree/main/web/apps/twoof3",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 73,
      "coverage": 100,
      "summary": "2of3 by Ente scores 73 out of 100 (grade C) on the password managers criteria. It meets 7 of 11 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, end-to-end encrypted vault, local or self-hosted option and full export. It does not meet independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/password-managers/2of3-by-ente/",
      "markdown": "https://privacyratings.com/password-managers/2of3-by-ente/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ente/ente/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ente/ente/blob/main/web/apps/twoof3/package.json",
          "note": "The page loads no third-party scripts and the app has no analytics dependencies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ente.com/privacy/",
          "note": "Free tool from Ente, which is funded by subscriptions and states it does not sell personal information."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=2of3.ente.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=2of3.ente.com",
          "note": "Grade D (35/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://2of3.ente.com/",
          "note": "Secrets are split in the browser and never sent to a server."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://2of3.ente.com/",
          "note": "Cards are printed or downloaded and kept offline, with a standalone recovery page."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://2of3.ente.com/",
          "note": "Cards can be printed or downloaded as images along with an offline recovery page."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:17.631Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "aliasvault",
      "category": "password-managers",
      "name": "AliasVault",
      "description": "Open source, end-to-end encrypted password manager that also generates email aliases and identities and receives mail through its own email server. It can be used in the hosted cloud or self-hosted.",
      "website": "https://www.aliasvault.com",
      "source": "https://github.com/aliasvault/aliasvault",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 75,
      "coverage": 100,
      "summary": "AliasVault scores 75 out of 100 (grade B) on the password managers criteria. It meets 7 of 11 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, end-to-end encrypted vault, local or self-hosted option and full export. It partly meets security headers. It does not meet independent audit, transparency report and tells users about requests. It is based in the Netherlands: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/password-managers/aliasvault/",
      "markdown": "https://privacyratings.com/password-managers/aliasvault/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/aliasvault/aliasvault/blob/main/LICENSE.md",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.aliasvault.com/privacy-policy",
          "note": "No third-party trackers. The website's self-hosted Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.aliasvault.com/pricing",
          "note": "Funded by its founders, community support and planned paid plans, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.aliasvault.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.aliasvault.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.aliasvault.com/privacy-policy",
          "note": "Vault data, including received emails, is end-to-end encrypted with the master password, which is never sent to the server."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.aliasvault.com/installation/",
          "note": "The server can be self-hosted with Docker."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.aliasvault.com/roadmap",
          "note": "Full vault export and import are available."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:19.008Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "apple-passwords",
      "category": "password-managers",
      "name": "Apple Passwords",
      "description": "Apple's password manager, built into iOS, iPadOS and macOS as the Passwords app and synced through iCloud Keychain. It stores passwords, passkeys and verification codes, with an iCloud app for Windows.",
      "website": "https://support.apple.com/guide/passwords/welcome/mac",
      "license": null,
      "platforms": [
        "ios",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 64,
      "coverage": 100,
      "summary": "Apple Passwords scores 64 out of 100 (grade C) on the password managers criteria. It meets 6 of 11 criteria: no ads or data sales, transparency report, tells users about requests, TLS configuration, security headers and end-to-end encrypted vault. It partly meets no trackers or telemetry, local or self-hosted option and full export. It does not meet open source and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/password-managers/apple-passwords/",
      "markdown": "https://privacyratings.com/password-managers/apple-passwords/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/device-analytics/",
          "note": "Device analytics are shared with Apple only with consent, but Apple's websites load first-party analytics by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/en-ww/",
          "note": "The Passwords app has no ads, and Apple states it does not sell or share personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/transparency/",
          "note": "Apple publishes government request counts and outcomes twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/law-enforcement-guidelines-us.pdf",
          "note": "Apple notifies customers when their account information is sought, unless notice is prohibited or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.icloud.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.icloud.com",
          "note": "Grade A+ (130/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://support.apple.com/en-us/102651",
          "note": "Passwords and Keychain are always end-to-end encrypted, and Apple does not have the keys."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.apple.com/guide/passwords/export-passwords-mchl35b12625/mac",
          "note": "Passwords can stay on one device without iCloud sync, but there is no file or self-hosted option. Data can be exported."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://support.apple.com/guide/passwords/export-passwords-mchl35b12625/mac",
          "note": "Passwords can be exported to a CSV file on a Mac. No export is documented for passkeys."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:17.975Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "bitwarden",
      "category": "password-managers",
      "name": "Bitwarden",
      "description": "Open-source, end-to-end encrypted password manager with apps for Windows, macOS, Linux, Android, iOS, the web and browsers, and an option to self-host.",
      "website": "https://bitwarden.com",
      "source": "https://github.com/bitwarden/clients",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web",
        "browser"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": true,
      "pick_reason": "Syncs across desktop, mobile and browser apps and supports sharing with family or a team. End-to-end encrypted, audited every year, and it can be self-hosted.",
      "disclosure": null,
      "grade": "C",
      "score": 73,
      "coverage": 100,
      "summary": "Bitwarden scores 73 out of 100 (grade C) on the password managers criteria. It meets 8 of 11 criteria: open source, no ads or data sales, independent audit, TLS configuration, security headers, end-to-end encrypted vault, local or self-hosted option and full export. It does not meet no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/password-managers/bitwarden/",
      "markdown": "https://privacyratings.com/password-managers/bitwarden/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bitwarden/server/blob/main/LICENSE.txt",
          "note": "All code is public. The apps are GPL-3.0 and the server is AGPL-3.0, and some business features in the same public repositories use the source-available Bitwarden License."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://bitwarden.com/privacy/",
          "note": "The website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://bitwarden.com/pricing/",
          "note": "Funded by paid plans."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://bitwarden.com/assets/5yO7sKgjdwGYg7SXVqD2Vc/4a7ef3cce23d8e929ef3cd8238d3d392/2025_Bitwarden_Core_Application_Security_Report.pdf",
          "note": "Full reports are published yearly, including recent audits by Cure53, Fracture Labs, Unit 42 and ETH Zurich."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=vault.bitwarden.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=vault.bitwarden.com",
          "note": "Grade A+ (110/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://bitwarden.com/help/bitwarden-security-white-paper/",
          "note": "Vault data is encrypted on the device with a key derived from the master password before it is synced."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://bitwarden.com/help/install-on-premise-linux/",
          "note": "The server can be self-hosted."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://bitwarden.com/help/export-your-data/",
          "note": "JSON (plain or encrypted), CSV, and ZIP with attachments."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:03:55.097Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "browserpass",
      "category": "password-managers",
      "name": "Browserpass",
      "description": "Browser extension for pass, the standard Unix password manager. Passwords stay in GPG-encrypted files on your own computer.",
      "website": "https://github.com/browserpass/browserpass-extension",
      "source": "https://github.com/browserpass/browserpass-extension",
      "license": "ISC",
      "platforms": [
        "firefox",
        "chromium",
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": true,
      "pick_reason": "For people who want no password company at all. Every password is a GPG-encrypted file in a folder you control, synced with Git if you like, and Browserpass fills it into the browser.",
      "disclosure": null,
      "grade": "B",
      "score": 88,
      "coverage": 100,
      "summary": "Browserpass scores 88 out of 100 (grade B) on the password managers criteria. It meets 6 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted vault, local or self-hosted option and full export. It does not meet independent audit.",
      "url": "https://privacyratings.com/password-managers/browserpass/",
      "markdown": "https://privacyratings.com/password-managers/browserpass/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/browserpass/browserpass-extension/blob/master/LICENSE",
          "note": "ISC."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/browserpass/browserpass-extension#privacy",
          "note": "Sends no telemetry, and usage metadata stays in local browser storage."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/browserpass/browserpass-extension",
          "note": "Volunteer project with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.passwordstore.org/",
          "note": "Each password is a separate GPG-encrypted file."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.passwordstore.org/",
          "note": "Passwords are stored as files in a local folder that can be synced with git."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.passwordstore.org/",
          "note": "Passwords are ordinary GPG files in a folder, so there is nothing to export."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:41.068Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dashlane",
      "category": "password-managers",
      "name": "Dashlane",
      "description": "Password manager from Dashlane with browser extensions and mobile apps, end-to-end encrypted sync, passkey support and dark web monitoring. The mobile app source code is published under a non-commercial license.",
      "website": "https://www.dashlane.com",
      "source": "https://github.com/Dashlane/android-apps",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "Dashlane scores 45 out of 100 (grade D) on the password managers criteria. It meets 3 of 11 criteria: TLS configuration, end-to-end encrypted vault and full export. It partly meets open source, no ads or data sales, security headers and local or self-hosted option. It does not meet no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/password-managers/dashlane/",
      "markdown": "https://privacyratings.com/password-managers/dashlane/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/Dashlane/android-apps/blob/main/LICENSE.md",
          "note": "The Android and Apple app sources are published under CC BY-NC 4.0, which is not OSI-approved. The server is closed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.dashlane/latest/",
          "note": "The Android app contains Adjust and Sentry, and the privacy policy says the website uses Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.dashlane.com/privacy",
          "note": "Funded by subscriptions, but the privacy policy says Dashlane and third-party advertising partners use personal data for interest-based advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.dashlane.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.dashlane.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.dashlane.com/security",
          "note": "Zero-knowledge design: vault data is encrypted on the device and Dashlane cannot read it."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.dashlane.com/hc/en-us/articles/202625092-Export-your-data-from-Dashlane",
          "note": "Vaults are stored only in the Dashlane cloud. Data can be exported."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://support.dashlane.com/hc/en-us/articles/202625092-Export-your-data-from-Dashlane",
          "note": "Exports to CSV, an encrypted DASH file, or through the Credential Exchange protocol."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "VWO",
            "host": "dev.visualwebsiteoptimizer.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:17.848Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "enpass",
      "category": "password-managers",
      "name": "Enpass",
      "description": "Closed source password manager from Enpass Technologies that stores encrypted vaults on the device and syncs them through the user's own cloud storage, such as iCloud, Dropbox, Google Drive, OneDrive or WebDAV.",
      "website": "https://www.enpass.io",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Enpass scores 50 out of 100 (grade D) on the password managers criteria. It meets 4 of 7 criteria: no ads or data sales, end-to-end encrypted vault, local or self-hosted option and full export. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/password-managers/enpass/",
      "markdown": "https://privacyratings.com/password-managers/enpass/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.enpass.io/privacy-notice/",
          "note": "The privacy notice says the apps collect device and feature usage data, and the website uses Google Analytics and Clearbit."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.enpass.io/pricing/",
          "note": "Funded by paid plans, and the privacy notice says Enpass never sells personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Holds ISO 27001 and SOC 2 Type II attestations, but no audit report is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.enpass.io/security/",
          "note": "Vaults are encrypted on the device with AES-256, and synced cloud storage only holds encrypted copies."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.enpass.io/security/",
          "note": "Vaults are stored on the device and optionally synced through the user's own cloud storage or WebDAV server."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://help.enpass.io/personal/latest/all/importing-from-enpass",
          "note": "Exports vaults to JSON. Passkeys cannot be exported."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js-eu1.hsforms.net",
            "effect": "no"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:19.112Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "google-password-manager",
      "category": "password-managers",
      "name": "Google Password Manager",
      "description": "Password manager built into Chrome, Android and the Google account that saves and syncs passwords and passkeys. Passwords are readable by Google unless on-device encryption is turned on.",
      "website": "https://passwords.google",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 27,
      "coverage": 100,
      "summary": "Google Password Manager scores 27 out of 100 (grade F) on the password managers criteria. It meets 2 of 11 criteria: transparency report and tells users about requests. It partly meets TLS configuration, security headers, local or self-hosted option and full export. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit and end-to-end encrypted vault. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/password-managers/google-password-manager/",
      "markdown": "https://privacyratings.com/password-managers/google-password-manager/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. Chrome's password code is in Chromium, but the Android service and sync servers are not open."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Google collects activity and device data for analytics and advertising across its services."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Google is funded mainly by advertising, and its privacy policy covers using account activity for personalized ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://transparencyreport.google.com/user-data/overview",
          "note": "Google publishes government request counts and outcomes twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://policies.google.com/terms/information-requests",
          "note": "Google emails users before disclosing data to a government agency unless legally prohibited or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=passwords.google.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=passwords.google.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "no",
          "evidence": "https://support.google.com/accounts/answer/11350823?hl=en",
          "note": "By default the encryption key is stored in the Google account and Google can decrypt passwords. Optional on-device encryption keeps the key with the user."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.google.com/chrome/answer/95606?hl=en",
          "note": "Passwords are stored only in the Google account. Data can be exported."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://support.google.com/chrome/answer/95606?hl=en",
          "note": "Passwords can be downloaded as a CSV file. No export is documented for passkeys."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:18.185Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "keepass",
      "category": "password-managers",
      "name": "KeePass",
      "description": "Offline, open source password manager for Windows that stores passwords in an encrypted local database file. It has no built-in cloud sync, and community ports exist for other platforms.",
      "website": "https://keepass.info",
      "source": "https://sourceforge.net/projects/keepass",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 63,
      "coverage": 100,
      "summary": "KeePass scores 63 out of 100 (grade C) on the password managers criteria. It meets 4 of 7 criteria: open source, end-to-end encrypted vault, local or self-hosted option and full export. It partly meets independent audit. It does not meet no trackers or telemetry and no ads or data sales. Automated tests: Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/password-managers/keepass/",
      "markdown": "https://privacyratings.com/password-managers/keepass/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://keepass.info/help/v2/license.html",
          "note": "GPL-2.0 or later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://keepass.info/",
          "note": "The app has no telemetry, but the website loads Google AdSense."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://keepass.info/",
          "note": "The app has no ads, but the website shows Google AdSense ads alongside donation requests."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://interoperable-europe.ec.europa.eu/sites/default/files/inline-files/DLV%20WP6%20-01-%20KeePass%20Code%20Review%20Results%20Report_published.pdf",
          "note": "A full code review by the European Commission EU-FOSSA project is public but older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://keepass.info/help/base/security.html",
          "note": "Local-only: the whole database is encrypted with AES-256 or ChaCha20 using a key derived from the master key."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://keepass.info/help/base/security.html",
          "note": "The database is a local file."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://keepass.info/help/base/importexport.html",
          "note": "Exports to KeePass XML, which includes all fields, and CSV."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:19.028Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "keepassdx",
      "category": "password-managers",
      "name": "KeePassDX",
      "description": "Open source password and passkey manager for Android that stores data in encrypted KeePass (KDB and KDBX) database files. It supports autofill, TOTP and biometric unlock, with no built-in cloud service.",
      "website": "https://www.keepassdx.com",
      "source": "https://github.com/Kunzisoft/KeePassDX",
      "license": "GPL-3.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 88,
      "coverage": 100,
      "summary": "KeePassDX scores 88 out of 100 (grade B) on the password managers criteria. It meets 6 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted vault, local or self-hosted option and full export. It does not meet independent audit.",
      "url": "https://privacyratings.com/password-managers/keepassdx/",
      "markdown": "https://privacyratings.com/password-managers/keepassdx/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Kunzisoft/KeePassDX/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.kunzisoft.keepass.libre/latest/",
          "note": "Exodus Privacy finds no trackers in the app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Kunzisoft/KeePassDX/blob/master/README.md",
          "note": "Funded by donations and an optional Pro version with visual styles, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Kunzisoft/KeePassDX/blob/master/README.md",
          "note": "Local-only: databases are encrypted files using AES, Twofish or ChaCha20 with Argon2 key derivation."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Kunzisoft/KeePassDX/blob/master/README.md",
          "note": "The database is a local file."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/Kunzisoft/KeePassDX/blob/master/README.md",
          "note": "The database is a KDBX file, an open format read by many apps."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:18.095Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "keepassium",
      "category": "password-managers",
      "name": "KeePassium",
      "description": "Open source KeePass-compatible password manager for iOS and macOS from KeePassium Labs. It opens KDBX databases stored locally or in any Files app provider, with AutoFill, TOTP and YubiKey support.",
      "website": "https://keepassium.com",
      "source": "https://github.com/keepassium/KeePassium",
      "license": null,
      "platforms": [
        "ios",
        "macos"
      ],
      "jurisdiction": {
        "code": "LU",
        "name": "Luxembourg",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 100,
      "coverage": 100,
      "summary": "KeePassium scores 100 out of 100 (grade A) on the password managers criteria. It meets 7 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, independent audit, end-to-end encrypted vault, local or self-hosted option and full export. It is based in Luxembourg: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/password-managers/keepassium/",
      "markdown": "https://privacyratings.com/password-managers/keepassium/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/keepassium/KeePassium/blob/master/LICENSE.txt",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://keepassium.com/privacy/app/",
          "note": "No third-party trackers, and the app sends no personal data. The website's Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://keepassium.com/pricing/",
          "note": "Funded by paid Premium and Pro licenses, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://keepassium.com/audit/2024-10-Cure53.pdf",
          "note": "Cure53 audited the app with full source access, and the full report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://keepassium.com/privacy/app/",
          "note": "Local-only: databases are encrypted KeePass files, and the app sends no data to the developer."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://keepassium.com/",
          "note": "Databases are local files or files in the user's own cloud storage."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://support.keepassium.com/kb/compatible-apps/",
          "note": "The database is a KDBX file, an open format read by many apps."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:18.459Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "keepassxc",
      "category": "password-managers",
      "name": "KeePassXC",
      "description": "Open source, offline password manager for Windows, macOS and Linux that stores passwords in an encrypted KeePass (KDBX) database file. It includes browser integration, TOTP, SSH agent and YubiKey support, with no built-in cloud sync.",
      "website": "https://keepassxc.org",
      "source": "https://github.com/keepassxreboot/keepassxc",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 91,
      "coverage": 100,
      "summary": "KeePassXC scores 91 out of 100 (grade A) on the password managers criteria. It meets 6 of 7 criteria: open source, no ads or data sales, independent audit, end-to-end encrypted vault, local or self-hosted option and full export. It partly meets no trackers or telemetry.",
      "url": "https://privacyratings.com/password-managers/keepassxc/",
      "markdown": "https://privacyratings.com/password-managers/keepassxc/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/keepassxreboot/keepassxc/blob/develop/COPYING",
          "note": "GPL-2.0 or GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://keepassxc.org/privacy/",
          "note": "The app sends no data unless the user requests it, but the website uses self-hosted Matomo and Cloudflare Web Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://keepassxc.org/donate/",
          "note": "Volunteer project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://keepassxc.org/assets/pdf/Synacktiv-ANSSI-CSPN-KeePassXC-RTE-v1.3.pdf",
          "note": "Synacktiv evaluated KeePassXC for the French ANSSI CSPN certification, and the full technical report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://keepassxc.org/privacy/",
          "note": "Local-only: the database is an encrypted file on the device, and no data is sent to the developers."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://keepassxc.org/docs/KeePassXC_UserGuide",
          "note": "The database is a local file."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://keepassxc.org/docs/KeePassXC_UserGuide",
          "note": "The database is a KDBX file, an open format read by many apps. CSV, XML and HTML exports are also available."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:18.170Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "keeper",
      "category": "password-managers",
      "name": "Keeper",
      "description": "Closed source password manager from Keeper Security with apps for desktop, mobile and browsers. Records are encrypted on the device with per-record keys, and the company also sells secrets and privileged access management for businesses.",
      "website": "https://www.keepersecurity.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "Keeper scores 45 out of 100 (grade D) on the password managers criteria. It meets 5 of 11 criteria: no ads or data sales, TLS configuration, security headers, end-to-end encrypted vault and full export. It partly meets local or self-hosted option. It does not meet open source, no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/password-managers/keeper/",
      "markdown": "https://privacyratings.com/password-managers/keeper/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.keepersecurity.com/legal/terms-of-use/?s=privacy",
          "note": "The apps have no known trackers, but the website loads Google Analytics, Google Tag Manager, Facebook, Bing and LinkedIn tracking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.keepersecurity.com/pricing/personal-and-family.html",
          "note": "Funded by subscriptions, and the privacy policy says Keeper does not sell or share personal information."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Third-party penetration tests are described, but no audit report is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=keepersecurity.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=keepersecurity.com",
          "note": "Grade A+ (120/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://docs.keeper.io/enterprise-guide/keeper-encryption-model",
          "note": "Records are encrypted on the device with AES-256 keys that Keeper does not hold."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://docs.keeper.io/user-guides/export-and-reports/vault-export",
          "note": "Vaults are stored only in the Keeper cloud. Data can be exported."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.keeper.io/user-guides/export-and-reports/vault-export",
          "note": "Exports to CSV, JSON, PDF and encrypted KeePass files."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "forms.hubspot.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:18.334Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "lastpass",
      "category": "password-managers",
      "name": "LastPass",
      "description": "Closed source password manager from LastPass US LP with browser extensions, desktop and mobile apps. Vaults are encrypted on the device, and a past breach exposed copies of customer vault backups that also held unencrypted website URLs.",
      "website": "https://www.lastpass.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "LastPass scores 45 out of 100 (grade D) on the password managers criteria. It meets 3 of 11 criteria: tells users about requests, TLS configuration and end-to-end encrypted vault. It partly meets no ads or data sales, transparency report, security headers, local or self-hosted option and full export. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/password-managers/lastpass/",
      "markdown": "https://privacyratings.com/password-managers/lastpass/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.lastpass.lpandroid/latest/",
          "note": "The Android app contains Google Firebase Analytics, Crashlytics, Pendo and Segment, and the website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.lastpass.com/legal-center/privacy-notice",
          "note": "Funded by subscriptions, but the privacy notice says third-party cookies for personalized advertising may count as a sale or sharing of personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit report is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.lastpass.com/legal-center/law-enforcement-request-guidelines",
          "note": "Publishes law enforcement request guidelines but no request counts."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.lastpass.com/legal-center/law-enforcement-request-guidelines",
          "note": "Notifies customers before disclosing data unless legally prohibited or there is a risk of harm."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=lastpass.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=lastpass.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.lastpass.com/security/zero-knowledge-security",
          "note": "Vault data is encrypted on the device with a key derived from the master password. Stolen vault backups included unencrypted website URLs."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/lastpass/lastpass-cli/blob/master/lpass.1.txt",
          "note": "Vaults are stored only in the LastPass cloud. Data can be exported."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://github.com/lastpass/lastpass-cli/blob/master/lpass.1.txt",
          "note": "Exports vault items to unencrypted CSV, without attachments."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:39:48.496Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "lesspass",
      "category": "password-managers",
      "name": "LessPass",
      "description": "Stateless password manager that derives each site's password from the site name, login and a master password, so no vault is stored or synced. The hosted profile server is closed to new users, who can self-host one.",
      "website": "https://lesspass.com",
      "source": "https://github.com/lesspass/lesspass",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 71,
      "coverage": 100,
      "summary": "LessPass scores 71 out of 100 (grade C) on the password managers criteria. It meets 6 of 10 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, end-to-end encrypted vault and local or self-hosted option. It does not meet independent audit, transparency report, tells users about requests and security headers. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/password-managers/lesspass/",
      "markdown": "https://privacyratings.com/password-managers/lesspass/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/lesspass/lesspass/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.lesspass.android/latest/",
          "note": "Exodus finds no trackers in the Android app, and the website loads no third-party scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/lesspass",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=lesspass.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=lesspass.com",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/lesspass/lesspass#readme",
          "note": "No vault exists: passwords are generated on the device and never stored or synced."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/lesspass/lesspass#readme",
          "note": "Works without a server, and the optional profile server can be self-hosted."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Passwords are derived on demand and never stored, so there is no vault to export."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:18.281Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nordpass",
      "category": "password-managers",
      "name": "NordPass",
      "description": "Closed source password manager from Nord Security, the company behind NordVPN, with desktop, mobile and browser apps. Vaults are encrypted on the device with XChaCha20 and synced through NordPass servers.",
      "website": "https://nordpass.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "NordPass scores 45 out of 100 (grade D) on the password managers criteria. It meets 4 of 11 criteria: no ads or data sales, TLS configuration, end-to-end encrypted vault and full export. It partly meets independent audit and local or self-hosted option. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and security headers. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/password-managers/nordpass/",
      "markdown": "https://privacyratings.com/password-managers/nordpass/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.nordpass.android.app.password.manager/latest/",
          "note": "The Android app contains AppsFlyer, Google Firebase Analytics, Crashlytics and Sentry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://business.nordsec.com/legal/privacy-policy",
          "note": "Funded by subscriptions, and the privacy policy says Nord does not sell or share personal information."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://nordpass.com/blog/nordpass-business-independent-security-audit/",
          "note": "Cure53 audited the apps, but only a summary is public and it is older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.nordpass.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.nordpass.com",
          "note": "Grade C (55/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://nordpass.com/security/",
          "note": "Zero-knowledge design: vault data is encrypted on the device and NordPass cannot read it."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.nordpass.com/hc/en-us/articles/360007646477-How-to-export-passwords-from-NordPass",
          "note": "Vaults are stored only in the NordPass cloud. Data can be exported."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://support.nordpass.com/hc/en-us/articles/360007646477-How-to-export-passwords-from-NordPass",
          "note": "Exports vault items to a CSV file."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:18.414Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "padloc",
      "category": "password-managers",
      "name": "Padloc",
      "description": "Open source, end-to-end encrypted password manager from MaKleSoft with desktop, mobile, browser and web apps, a hosted service and a self-hostable server. The code has had no updates in several years.",
      "website": "https://padloc.app",
      "source": "https://github.com/padloc/padloc",
      "license": "AGPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 68,
      "coverage": 100,
      "summary": "Padloc scores 68 out of 100 (grade C) on the password managers criteria. It meets 7 of 11 criteria: open source, no ads or data sales, TLS configuration, security headers, end-to-end encrypted vault, local or self-hosted option and full export. It partly meets independent audit. It does not meet no trackers or telemetry, transparency report and tells users about requests. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/password-managers/padloc/",
      "markdown": "https://privacyratings.com/password-managers/padloc/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/padloc/padloc/blob/main/LICENSE",
          "note": "AGPL-3.0 for the apps and server."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://padloc.app/privacy/",
          "note": "The privacy policy says third-party analytics are used on the public website, and the service tracks anonymised app usage data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://padloc.app/",
          "note": "Funded by paid plans, and the privacy policy says personal data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://padloc.app/assets/audit_reports/radically-open-security_2022.pdf",
          "note": "Radically Open Security audited Padloc 4, and the full report is public but older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=web.padloc.app&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=web.padloc.app",
          "note": "Grade A+ (105/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://docs.padloc.app/docs/security/",
          "note": "Vault data is encrypted on the device with keys derived from the master password, and the server cannot decrypt it."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.padloc.app/guides/self-host/",
          "note": "The server can be self-hosted."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.padloc.app/manual/settings/",
          "note": "Exports vaults to CSV or an encrypted Padloc container."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:18.707Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "papervault",
      "category": "password-managers",
      "name": "PaperVault",
      "description": "Encrypts secrets into a printable paper vault and splits the decryption key into several paper key cards with Shamir secret sharing. It runs in the browser, as a standalone offline app or from the command line.",
      "website": "https://papervault.xyz",
      "source": "https://github.com/boazeb/papervault",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 75,
      "coverage": 100,
      "summary": "PaperVault scores 75 out of 100 (grade B) on the password managers criteria. It meets 7 of 11 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, end-to-end encrypted vault, local or self-hosted option and full export. It partly meets security headers. It does not meet independent audit, transparency report and tells users about requests. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/password-managers/papervault/",
      "markdown": "https://privacyratings.com/password-managers/papervault/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/boazeb/papervault/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/boazeb/papervault/blob/main/package.json",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/boazeb/papervault#readme",
          "note": "Free open source tool with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=papervault.xyz&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=papervault.xyz",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/boazeb/papervault#-overview",
          "note": "Local-only: secrets are encrypted in the browser and the key is split into printed shards, with no sync service."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/boazeb/papervault#-self-hosted-web-app-recommended-for-maximum-security",
          "note": "Vaults are kept on paper or local media, and the app can be self-hosted or run offline."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/boazeb/papervault#-quick-start",
          "note": "Vaults and keys are printed or saved to digital media, and any PaperVault instance can unlock them."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:18.427Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "pass",
      "category": "password-managers",
      "name": "Pass",
      "description": "Command-line password manager that stores each password as a GPG-encrypted file in a folder, with optional git for history and syncing. Many third-party clients and extensions exist.",
      "website": "https://www.passwordstore.org",
      "source": "https://git.zx2c4.com/password-store",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 69,
      "coverage": 100,
      "summary": "Pass scores 69 out of 100 (grade C) on the password managers criteria. It meets 5 of 7 criteria: open source, no ads or data sales, end-to-end encrypted vault, local or self-hosted option and full export. It does not meet no trackers or telemetry and independent audit. Automated tests: Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/password-managers/pass/",
      "markdown": "https://privacyratings.com/password-managers/pass/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://git.zx2c4.com/password-store/tree/COPYING",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.passwordstore.org/",
          "note": "The pass tool has no telemetry, but the website loads Google Analytics and the Twitter widgets script."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.passwordstore.org/",
          "note": "Free software with no ads, accounts or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.passwordstore.org/",
          "note": "Local-only: each password is a separate GPG-encrypted file, with no sync service."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.passwordstore.org/",
          "note": "Passwords are stored in a local folder that can be synced with any git server."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.passwordstore.org/",
          "note": "Passwords are ordinary GPG files in a folder that standard tools can read."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:18.846Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "passbolt",
      "category": "password-managers",
      "name": "Passbolt",
      "description": "Open source password manager for teams built on OpenPGP end-to-end encryption, with browser extensions, mobile and desktop apps. It can be self-hosted or used as a hosted cloud service.",
      "website": "https://www.passbolt.com",
      "source": "https://github.com/passbolt/passbolt_api",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "LU",
        "name": "Luxembourg",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 66,
      "coverage": 100,
      "summary": "Passbolt scores 66 out of 100 (grade C) on the password managers criteria. It meets 7 of 11 criteria: no ads or data sales, independent audit, TLS configuration, security headers, end-to-end encrypted vault, local or self-hosted option and full export. It partly meets open source. It does not meet no trackers or telemetry, transparency report and tells users about requests. It is based in Luxembourg: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/password-managers/passbolt/",
      "markdown": "https://privacyratings.com/password-managers/passbolt/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/passbolt/passbolt_api/blob/master/LICENSE.txt",
          "note": "The Community Edition server and apps are AGPL-3.0, but Pro and Cloud features are proprietary."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.passbolt.com/privacy",
          "note": "The website loads Google Tag Manager, and the privacy policy lists Google Analytics, Matomo, Plausible, Google Ads and LinkedIn."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.passbolt.com/pricing/pro",
          "note": "Funded by paid Pro and Cloud plans, and the privacy policy says personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.passbolt.com/docs/files/PBL-13-report.pdf",
          "note": "Full Cure53 and Quarkslab reports are published, including an audit of the version 5 browser extension and API."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.passbolt.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.passbolt.com",
          "note": "Grade A+ (115/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.passbolt.com/security",
          "note": "Secrets are end-to-end encrypted with OpenPGP keys held by each user."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.passbolt.com/docs/hosting/install/",
          "note": "The server can be self-hosted."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.passbolt.com/docs/user/basic-features/browser/export/",
          "note": "All resources can be exported to KDBX, or to CSV when an administrator allows it."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Matomo Cloud",
            "host": "cdn.matomo.cloud",
            "effect": "partial"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:18.960Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "password-safe",
      "category": "password-managers",
      "name": "Password Safe",
      "description": "Open source password manager originally designed by Bruce Schneier that keeps passwords in a Twofish-encrypted local database. Official builds exist for Windows and Linux, with YubiKey support and compatible third-party apps for macOS, Android and iOS.",
      "website": "https://www.pwsafe.org",
      "source": "https://github.com/pwsafe/pwsafe",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 88,
      "coverage": 100,
      "summary": "Password Safe scores 88 out of 100 (grade B) on the password managers criteria. It meets 6 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted vault, local or self-hosted option and full export. It does not meet independent audit. Automated tests: Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/password-managers/password-safe/",
      "markdown": "https://privacyratings.com/password-managers/password-safe/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pwsafe/pwsafe/blob/master/LICENSE",
          "note": "Artistic License 2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pwsafe/pwsafe",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.pwsafe.org/",
          "note": "Volunteer project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pwsafe/pwsafe/blob/master/docs/formatV3.txt",
          "note": "Local-only: the database is encrypted with Twofish using a key derived from the master password."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/pwsafe/pwsafe/blob/master/docs/formatV3.txt",
          "note": "The database is a local file."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/pwsafe/pwsafe/blob/master/help/default/html/export.html",
          "note": "Exports to XML and plain text."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:19.019Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "protonpass",
      "category": "password-managers",
      "name": "Proton Pass",
      "description": "End-to-end encrypted password manager from Proton with apps for desktop, mobile and browsers, built-in email aliases and a TOTP authenticator. The apps are open source.",
      "website": "https://proton.me/pass",
      "source": "https://github.com/protonpass/android-pass",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Proton Pass scores 80 out of 100 (grade B) on the password managers criteria. It meets 7 of 11 criteria: no ads or data sales, independent audit, transparency report, tells users about requests, TLS configuration, end-to-end encrypted vault and full export. It partly meets open source, no trackers or telemetry, security headers and local or self-hosted option. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/password-managers/protonpass/",
      "markdown": "https://privacyratings.com/password-managers/protonpass/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/protonpass/android-pass/blob/main/LICENSE",
          "note": "Apps are GPL-3.0. The server is not open source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://proton.me/support/share-usage-statistics",
          "note": "No third-party analytics, but Proton apps share usage statistics and crash reports by default, and these can be turned off in settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://proton.me/pass/pricing",
          "note": "Funded by paid plans."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://drive.proton.me/urls/T9BGC6B11W#seHd3zMpGo5j",
          "note": "Full report from Recurity Labs covering the browser extensions, mobile and desktop apps and CLI."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://proton.me/legal/transparency",
          "note": "Publishes yearly counts of legal orders received, contested and complied with."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://proton.me/legal/law-enforcement",
          "note": "Users are notified of data requests unless Swiss law or a court order temporarily prohibits it."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=proton.me&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=proton.me",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://proton.me/pass/security",
          "note": "Vault data is end-to-end encrypted on the device before it is synced."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://proton.me/support/pass-export",
          "note": "Vaults are stored only in Proton's cloud. Data can be exported."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://proton.me/support/pass-export",
          "note": "Exports to JSON in a ZIP file, optionally PGP-encrypted, or to CSV."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:19.554Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "psono",
      "category": "password-managers",
      "name": "Psono",
      "description": "Open source password manager for teams and companies from esaqa GmbH, with a web client, browser extensions and mobile apps. Vaults are encrypted on the client, and the server can be self-hosted or used as the psono.pw hosted service.",
      "website": "https://psono.com",
      "source": "https://gitlab.com/esaqa/psono/psono-server",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 55,
      "coverage": 100,
      "summary": "Psono scores 55 out of 100 (grade D) on the password managers criteria. It meets 5 of 11 criteria: no ads or data sales, TLS configuration, security headers, end-to-end encrypted vault and local or self-hosted option. It partly meets open source and full export. It does not meet no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/password-managers/psono/",
      "markdown": "https://privacyratings.com/password-managers/psono/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://gitlab.com/esaqa/psono/psono-server/-/blob/master/LICENSE.md",
          "note": "The clients and Community Edition server are Apache-2.0, but the Enterprise Edition server is not published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://psono.com/privacy-policy",
          "note": "The website uses Google Tag Manager and Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://psono.com/",
          "note": "Funded by paid business plans, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.psono.pw&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.psono.pw",
          "note": "Grade A+ (110/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://doc.psono.com/admin/development/cryptography.html",
          "note": "Vault data is encrypted on the client before it is stored on the server."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://doc.psono.com/admin/installation/install-preparation.html",
          "note": "The server can be self-hosted."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://doc.psono.com/user/other/export.html",
          "note": "Exports secrets and passwords to a file, but files are not included."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:18.546Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "strongbox",
      "category": "password-managers",
      "name": "Strongbox",
      "description": "Open source password manager for iOS and macOS that works with KeePass (KDBX) and Password Safe databases stored locally, in iCloud or in other cloud storage. It supports AutoFill, TOTP, passkeys and YubiKey.",
      "website": "https://strongboxsafe.com",
      "source": "https://github.com/strongbox-password-safe/Strongbox",
      "license": "AGPL-3.0",
      "platforms": [
        "ios",
        "macos"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 88,
      "coverage": 100,
      "summary": "Strongbox scores 88 out of 100 (grade B) on the password managers criteria. It meets 6 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted vault, local or self-hosted option and full export. It does not meet independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/password-managers/strongbox/",
      "markdown": "https://privacyratings.com/password-managers/strongbox/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/strongbox-password-safe/Strongbox/blob/master/LICENSE.md",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://strongboxsafe.com/privacy/",
          "note": "No third-party trackers, and the app uses no analytics. The website's Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://strongboxsafe.com/pricing/",
          "note": "Funded by paid Pro subscriptions and lifetime licenses, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://strongboxsafe.com/privacy/",
          "note": "Local-only: databases are encrypted KeePass or Password Safe files, and the developer has no sync service."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://strongboxsafe.com/privacy/",
          "note": "Databases are local files or files in the user's own cloud storage."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/strongbox-password-safe/Strongbox/blob/master/README.md",
          "note": "Databases are KDBX or Password Safe files, open formats read by many apps."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:18.948Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "vaultwarden",
      "category": "password-managers",
      "name": "Vaultwarden",
      "description": "Open source, lightweight server written in Rust that implements the Bitwarden client API for self-hosting. It works with the official Bitwarden apps and extensions and is not affiliated with Bitwarden.",
      "website": "https://github.com/dani-garcia/vaultwarden",
      "source": "https://github.com/dani-garcia/vaultwarden",
      "license": "AGPL-3.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 88,
      "coverage": 100,
      "summary": "Vaultwarden scores 88 out of 100 (grade B) on the password managers criteria. It meets 6 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted vault, local or self-hosted option and full export. It does not meet independent audit.",
      "url": "https://privacyratings.com/password-managers/vaultwarden/",
      "markdown": "https://privacyratings.com/password-managers/vaultwarden/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dani-garcia/vaultwarden/blob/main/LICENSE.txt",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dani-garcia/vaultwarden",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/dani-garcia/vaultwarden/blob/main/.github/FUNDING.yml",
          "note": "Volunteer project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_vault": {
          "title": "End-to-end encrypted vault",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://bitwarden.com/help/bitwarden-security-white-paper/",
          "note": "Vault data is encrypted by the Bitwarden clients before it reaches the server."
        },
        "self_host_or_local": {
          "title": "Local or self-hosted option",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/dani-garcia/vaultwarden",
          "note": "The server is designed to be self-hosted."
        },
        "export": {
          "title": "Full export",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://bitwarden.com/help/export-your-data/",
          "note": "The Bitwarden clients export to JSON (plain or encrypted), CSV, and ZIP with attachments."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:18.433Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "2fas",
      "category": "two-factor-authentication",
      "name": "2FAS",
      "description": "Open source authenticator app for Android and iOS with a browser extension for filling codes. Backups can be encrypted and synced through the user's Google Drive or iCloud without a 2FAS account.",
      "website": "https://2fas.com",
      "source": "https://github.com/twofas/2fas-android",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "2FAS scores 50 out of 100 (grade D) on the two-factor authentication criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/two-factor-authentication/2fas/",
      "markdown": "https://privacyratings.com/two-factor-authentication/2fas/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/twofas/2fas-android/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.twofasapp/latest/",
          "note": "Exodus finds Google Crashlytics in the Android app, and the privacy policy says Google Analytics is used."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://2fas.com/privacy-policy/",
          "note": "The apps are free and donation-supported, and the privacy policy says personal information is never sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:42.239Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "aegis",
      "category": "two-factor-authentication",
      "name": "Aegis",
      "description": "Free and open source authenticator app for Android that stores codes in an encrypted local vault. It supports encrypted backups, imports from many other authenticator apps and has no internet permission.",
      "website": "https://getaegis.app",
      "source": "https://github.com/beemdevelopment/Aegis",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Aegis scores 80 out of 100 (grade B) on the two-factor authentication criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/two-factor-authentication/aegis/",
      "markdown": "https://privacyratings.com/two-factor-authentication/aegis/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/beemdevelopment/Aegis/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.beemdevelopment.aegis/latest/",
          "note": "Exodus finds no trackers, and the app does not request internet access."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/beemdevelopment/Aegis#readme",
          "note": "Free volunteer project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:41.770Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "authenticator-cc",
      "category": "two-factor-authentication",
      "name": "Authenticator CC",
      "description": "Open source browser extension for Chrome, Firefox and Edge that generates TOTP and HOTP codes. Accounts can be encrypted with a password and backed up to a file or the user's cloud storage.",
      "website": "https://authenticator.cc",
      "source": "https://github.com/Authenticator-Extension/Authenticator",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Authenticator CC scores 80 out of 100 (grade B) on the two-factor authentication criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/two-factor-authentication/authenticator-cc/",
      "markdown": "https://privacyratings.com/two-factor-authentication/authenticator-cc/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Authenticator-Extension/Authenticator/blob/dev/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Authenticator-Extension/Authenticator/blob/dev/package.json",
          "note": "No telemetry or analytics in the source code, and data stays in browser storage unless cloud backup is turned on."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Authenticator-Extension/Authenticator",
          "note": "Free open source project with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:41.573Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "authenticator-gnome",
      "category": "two-factor-authentication",
      "name": "Authenticator GNOME",
      "description": "Open source two-factor code generator for the GNOME desktop, written in Rust. It supports TOTP, HOTP and Steam codes, a GNOME Shell search provider and backups to and from other authenticator apps.",
      "website": "https://apps.gnome.org/Authenticator/",
      "source": "https://gitlab.gnome.org/World/Authenticator",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Authenticator GNOME scores 80 out of 100 (grade B) on the two-factor authentication criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/two-factor-authentication/authenticator-gnome/",
      "markdown": "https://privacyratings.com/two-factor-authentication/authenticator-gnome/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/World/Authenticator/-/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/World/Authenticator",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://apps.gnome.org/Authenticator/",
          "note": "Free volunteer project with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:41.845Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "authenticator",
      "category": "two-factor-authentication",
      "name": "Authenticator",
      "description": "Open source two-factor authentication app for iOS that stores secrets encrypted in the iOS keychain. The app never connects to the internet.",
      "website": "https://mattrubin.me/authenticator/",
      "source": "https://github.com/mattrubin/Authenticator",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Authenticator scores 80 out of 100 (grade B) on the two-factor authentication criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/two-factor-authentication/authenticator/",
      "markdown": "https://privacyratings.com/two-factor-authentication/authenticator/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mattrubin/Authenticator/blob/develop/LICENSE.txt",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mattrubin/Authenticator#readme",
          "note": "The app never connects to the internet, and the website loads no scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mattrubin.me/authenticator/",
          "note": "Free volunteer project with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:41.924Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bitwarden-authenticator",
      "category": "two-factor-authentication",
      "name": "Bitwarden Authenticator",
      "description": "Free, open source authenticator app for iOS and Android from Bitwarden that generates TOTP codes. It works without an account and can optionally sync codes with a Bitwarden password manager vault.",
      "website": "https://bitwarden.com/products/authenticator",
      "source": "https://github.com/bitwarden/ios",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 70,
      "coverage": 100,
      "summary": "Bitwarden Authenticator scores 70 out of 100 (grade C) on the two-factor authentication criteria. It meets 3 of 4 criteria: open source, no ads or data sales and independent audit. It does not meet no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/two-factor-authentication/bitwarden-authenticator/",
      "markdown": "https://privacyratings.com/two-factor-authentication/bitwarden-authenticator/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bitwarden/ios/blob/main/LICENSE.txt",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.bitwarden.authenticator/latest/",
          "note": "Exodus finds Google Crashlytics in the Android app, and the website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://bitwarden.com/pricing/",
          "note": "Free app from Bitwarden, which is funded by paid plans."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://bitwarden.com/assets/718YF2IWeVNARWs6nBgYzS/796a7e97eedc6d569773a1892284d034/2025_Mobile_App_Security_Assessment.pdf",
          "note": "Full report from Unit 42 covering the Bitwarden mobile and authenticator apps."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:42.094Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "chronos-authenticator",
      "category": "two-factor-authentication",
      "name": "Chronos Authenticator",
      "description": "Open source two-factor authentication app for iOS that supports TOTP and HOTP codes. Tokens are encrypted on the device, with optional encrypted iCloud sync and exports.",
      "website": "https://github.com/joeldavidw/Chronos",
      "source": "https://github.com/joeldavidw/Chronos",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Chronos Authenticator scores 80 out of 100 (grade B) on the two-factor authentication criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/two-factor-authentication/chronos-authenticator/",
      "markdown": "https://privacyratings.com/two-factor-authentication/chronos-authenticator/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/joeldavidw/Chronos/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/joeldavidw/Chronos#features",
          "note": "The project states the app has no telemetry and needs no account."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/joeldavidw/Chronos#readme",
          "note": "Free open source app with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:41.860Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ente-auth",
      "category": "two-factor-authentication",
      "name": "Ente Auth",
      "description": "Free, open source TOTP authenticator for mobile, desktop and web. Works fully offline, or with an Ente account to sync codes across devices with end-to-end encrypted backups.",
      "website": "https://ente.com/auth",
      "source": "https://github.com/ente/ente",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 70,
      "coverage": 100,
      "summary": "Ente Auth scores 70 out of 100 (grade C) on the two-factor authentication criteria. It meets 3 of 4 criteria: open source, no ads or data sales and independent audit. It does not meet no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/two-factor-authentication/ente-auth/",
      "markdown": "https://privacyratings.com/two-factor-authentication/ente-auth/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ente/ente/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://ente.com/privacy/",
          "note": "The website loads PostHog analytics, and Exodus finds Sentry crash reporting in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ente.com/privacy/",
          "note": "Free app from Ente, which is funded by subscriptions and states it does not sell personal information."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ente.com/reports/Cure53-Audit-Report-Oct-2025.pdf",
          "note": "Full Cure53 report on the server code and infrastructure shared by Ente Photos and Ente Auth."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "PostHog",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:42.199Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "freeotp-plus",
      "category": "two-factor-authentication",
      "name": "FreeOTP+",
      "description": "Open source fork of FreeOTP for Android that adds backup export and import, search, categories, biometric lock and offline token icons. Generates HOTP and TOTP codes.",
      "website": "https://github.com/helloworld1/FreeOTPPlus",
      "source": "https://github.com/helloworld1/FreeOTPPlus",
      "license": "Apache-2.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "FreeOTP+ scores 80 out of 100 (grade B) on the two-factor authentication criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/two-factor-authentication/freeotp-plus/",
      "markdown": "https://privacyratings.com/two-factor-authentication/freeotp-plus/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/helloworld1/FreeOTPPlus/blob/master/COPYING",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.liberty.android.freeotpplus/latest/",
          "note": "The Exodus report finds no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.liberty.android.freeotpplus/latest/",
          "note": "Free open source app with no ads; the Exodus report finds no advertising libraries."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:18.433Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "freeotp",
      "category": "two-factor-authentication",
      "name": "FreeOTP",
      "description": "Open source two-factor authentication app sponsored by Red Hat that generates HOTP and TOTP codes. Tokens are added by scanning a QR code.",
      "website": "https://freeotp.github.io",
      "source": "https://github.com/freeotp/freeotp-android",
      "license": "Apache-2.0",
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "FreeOTP scores 80 out of 100 (grade B) on the two-factor authentication criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/two-factor-authentication/freeotp/",
      "markdown": "https://privacyratings.com/two-factor-authentication/freeotp/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/freeotp/freeotp-android/blob/master/COPYING",
          "note": "Apache-2.0. The iOS app is in a separate repository under the same license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://freeotp.github.io/privacy.html",
          "note": "The privacy policy states the app collects no data, and the Exodus report finds no trackers. The website loads no scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://freeotp.github.io/privacy.html",
          "note": "Free open source app sponsored by Red Hat, with no ads and no data collection."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:18.551Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "google-authenticator",
      "category": "two-factor-authentication",
      "name": "Google Authenticator",
      "description": "Two-factor authentication app from Google that generates time-based and counter-based one-time codes. Codes can optionally be backed up and synced to a Google Account.",
      "website": "https://support.google.com/accounts/answer/1066447",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Google Authenticator scores 20 out of 100 (grade F) on the two-factor authentication criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/two-factor-authentication/google-authenticator/",
      "markdown": "https://privacyratings.com/two-factor-authentication/google-authenticator/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. The old open source version on GitHub is no longer maintained."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://play.google.com/store/apps/datasafety?id=com.google.android.apps.authenticator2",
          "note": "Exodus finds no third-party trackers, but the Play data safety listing declares required collection of app interactions, crash logs and device IDs for analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://play.google.com/store/apps/datasafety?id=com.google.android.apps.authenticator2",
          "note": "Free app with no ads. The Play data safety listing declares no sharing with third parties and no data use for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:18.865Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "microsoft-authenticator",
      "category": "two-factor-authentication",
      "name": "Microsoft Authenticator",
      "description": "Authenticator app from Microsoft that generates one-time codes for any account and supports push approval, passwordless and passkey sign-in for Microsoft and Entra ID accounts.",
      "website": "https://www.microsoft.com/en-us/security/mobile-authenticator-app",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Microsoft Authenticator scores 20 out of 100 (grade F) on the two-factor authentication criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/two-factor-authentication/microsoft-authenticator/",
      "markdown": "https://privacyratings.com/two-factor-authentication/microsoft-authenticator/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.azure.authenticator/latest/",
          "note": "The Exodus report finds Google Analytics, Google Firebase Analytics and Microsoft App Center Analytics in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://play.google.com/store/apps/datasafety?id=com.azure.authenticator",
          "note": "Free app with no ads. The Play data safety listing declares data use only for app functionality and security, not advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:21.779Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "otp-auth",
      "category": "two-factor-authentication",
      "name": "OTP Auth",
      "description": "Two-factor authentication app for iPhone, iPad, Apple Watch and Mac that generates one-time codes, with optional iCloud sync and encrypted backups.",
      "website": "https://cooperrs.de/otpauth.html",
      "license": null,
      "platforms": [
        "ios",
        "macos"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "OTP Auth scores 50 out of 100 (grade D) on the two-factor authentication criteria. It meets 2 of 4 criteria: no trackers or telemetry and no ads or data sales. It does not meet open source and independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/two-factor-authentication/otp-auth/",
      "markdown": "https://privacyratings.com/two-factor-authentication/otp-auth/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://cooperrs.de/otpauth.html",
          "note": "The app page states no usage data is collected, the privacy policy states account data stays on the device, and the website loads no analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cooperrs.de/otpauth.html",
          "note": "Free app supported by donations through in-app purchases. The app page states no ads are shown."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:18.909Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "proton-authenticator",
      "category": "two-factor-authentication",
      "name": "Proton Authenticator",
      "description": "Free, open source authenticator app from Proton for Android, iOS, macOS, Windows and Linux. It works without an account, and signing in with a Proton account adds end-to-end encrypted sync.",
      "website": "https://proton.me/authenticator",
      "source": "https://github.com/protonpass/android-authenticator",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Proton Authenticator scores 65 out of 100 (grade C) on the two-factor authentication criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law.",
      "url": "https://privacyratings.com/two-factor-authentication/proton-authenticator/",
      "markdown": "https://privacyratings.com/two-factor-authentication/proton-authenticator/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/protonpass/android-authenticator/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://proton.me/support/share-usage-statistics",
          "note": "No third-party analytics, but Proton apps share usage statistics and crash reports by default, and these can be turned off in settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://proton.me/authenticator",
          "note": "Free with no ads. Proton is funded by paid plans."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:42.564Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "stratum",
      "category": "two-factor-authentication",
      "name": "Stratum",
      "description": "Free and open source two-factor authentication app for Android with encrypted backups, icon packs, categories and a Wear OS companion app. It imports from many other authenticator apps.",
      "website": "https://stratumauth.com",
      "source": "https://github.com/stratumauth/app",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Stratum scores 80 out of 100 (grade B) on the two-factor authentication criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/two-factor-authentication/stratum/",
      "markdown": "https://privacyratings.com/two-factor-authentication/stratum/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/stratumauth/app/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://stratumauth.com/privacy",
          "note": "No third-party trackers, and Exodus finds none in the app. The website's Cloudflare Web Analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://stratumauth.com/privacy",
          "note": "Provided at no cost as a GPL-3.0 project, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:00:42.665Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "tofu",
      "category": "two-factor-authentication",
      "name": "Tofu",
      "description": "Open source two-factor authentication app for iOS that generates TOTP and HOTP codes. It works without a network connection.",
      "website": "https://www.tofuauth.com",
      "source": "https://github.com/iKenndac/Tofu",
      "license": "ISC",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Tofu scores 50 out of 100 (grade D) on the two-factor authentication criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/two-factor-authentication/tofu/",
      "markdown": "https://privacyratings.com/two-factor-authentication/tofu/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/iKenndac/Tofu/blob/master/LICENSE",
          "note": "ISC."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.tofuauth.com/",
          "note": "The app needs no network connection, but the website loads an analytics script from okayanalytics.com, a third-party domain now held by a domain reseller."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/iKenndac/Tofu#installation",
          "note": "Free app with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:42.767Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "twilio-authy",
      "category": "two-factor-authentication",
      "name": "Twilio Authy",
      "description": "Two-factor authentication app from Twilio that generates one-time codes and supports push approvals, with encrypted cloud backups tied to a phone number. Available for Android and iOS.",
      "website": "https://www.authy.com",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Twilio Authy scores 20 out of 100 (grade F) on the two-factor authentication criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/two-factor-authentication/twilio-authy/",
      "markdown": "https://privacyratings.com/two-factor-authentication/twilio-authy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.authy.authy/latest/",
          "note": "The Exodus report finds Google Crashlytics and Google Firebase Analytics in the Android app, and the website loads Google Tag Manager, Segment and VWO."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.twilio.com/en-us/legal/privacy",
          "note": "Free app with no ads, run by a paid communications platform. Twilio's privacy notice states it does not sell data to third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "TrustArc",
            "host": "consent.trustarc.com",
            "effect": "none"
          },
          {
            "name": "VWO",
            "host": "dev.visualwebsiteoptimizer.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:18.902Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "yubico-authenticator",
      "category": "two-factor-authentication",
      "name": "Yubico Authenticator",
      "description": "Authenticator app from Yubico that stores OATH one-time password secrets on a YubiKey instead of the phone or computer, and generates codes when the key is connected or tapped.",
      "website": "https://www.yubico.com/products/yubico-authenticator/",
      "source": "https://github.com/Yubico/yubioath-flutter",
      "license": "Apache-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "SE",
        "name": "Sweden",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Yubico Authenticator scores 50 out of 100 (grade D) on the two-factor authentication criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Sweden: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/two-factor-authentication/yubico-authenticator/",
      "markdown": "https://privacyratings.com/two-factor-authentication/yubico-authenticator/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Yubico/yubioath-flutter/blob/main/LICENSE",
          "note": "Apache-2.0. The iOS app is in a separate repository under the same license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.yubico.com/products/yubico-authenticator/",
          "note": "The Android app collects no data and Exodus finds no trackers, but the Yubico website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://play.google.com/store/apps/datasafety?id=com.yubico.yubioath",
          "note": "Free app funded by YubiKey hardware sales, with no ads. The Play data safety listing declares no data collected or shared."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:18.999Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "7-zip",
      "category": "file-encryption",
      "name": "7-Zip",
      "description": "Open source file archiver with its own 7z format that can encrypt 7z and ZIP archives with AES-256, including file names in 7z archives. The full graphical app is for Windows, with a command-line version for Linux and macOS.",
      "website": "https://www.7-zip.org",
      "source": "https://github.com/ip7z/7zip",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "7-Zip scores 80 out of 100 (grade B) on the file encryption criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-encryption/7-zip/",
      "markdown": "https://privacyratings.com/file-encryption/7-zip/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.7-zip.org/license.txt",
          "note": "Mostly LGPL-2.1 with some BSD-licensed code. The optional RAR decompression code carries an extra unRAR license restriction."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ip7z/7zip",
          "note": "No telemetry or analytics in the source code, and the website loads no scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.7-zip.org/",
          "note": "Free software with no registration, payment or ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:19.751Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "aes-crypt",
      "category": "file-encryption",
      "name": "AES Crypt",
      "description": "Cross-platform file encryption tool that encrypts individual files with AES-256 using a password or key file. Available as a desktop app, command-line tool and Android app.",
      "website": "https://www.aescrypt.com",
      "source": "https://github.com/terrapane/aescrypt_cli",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "AES Crypt scores 80 out of 100 (grade B) on the file encryption criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-encryption/aes-crypt/",
      "markdown": "https://privacyratings.com/file-encryption/aes-crypt/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/terrapane/aescrypt_cli/blob/master/LICENSE.md",
          "note": "All code is public, including the command-line, desktop and Android apps, under a source-available commercial license that is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.aescrypt.com/privacy.html",
          "note": "The privacy policy lists no third-party analytics; metrics come from server logs."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.aescrypt.com/license.html",
          "note": "Funded by license sales. The privacy policy states personal information is not sold or shared."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:42.541Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "age",
      "category": "file-encryption",
      "name": "age",
      "description": "Command-line file encryption tool and Go library that uses small explicit keys, has no config options and works with standard Unix pipes.",
      "website": "https://age-encryption.org",
      "source": "https://github.com/FiloSottile/age",
      "license": "BSD-3-Clause",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "age scores 80 out of 100 (grade B) on the file encryption criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-encryption/age/",
      "markdown": "https://privacyratings.com/file-encryption/age/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/FiloSottile/age/blob/main/LICENSE",
          "note": "BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/FiloSottile/age",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/FiloSottile/age/blob/main/LICENSE",
          "note": "Free open source tool with no ads or data collection."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:55.155Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bitlocker",
      "category": "file-encryption",
      "name": "BitLocker",
      "description": "Full-volume encryption built into Windows Pro, Enterprise and Education editions. Protects fixed and removable drives, typically using the device TPM to hold keys.",
      "website": "https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "BitLocker scores 20 out of 100 (grade F) on the file encryption criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/file-encryption/bitlocker/",
      "markdown": "https://privacyratings.com/file-encryption/bitlocker/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/windows/privacy/configure-windows-diagnostic-data-in-your-organization",
          "note": "Part of Windows, which sends required diagnostic data to Microsoft that can only be fully turned off on Enterprise and Education editions."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/",
          "note": "Included with paid Windows editions. The feature shows no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:42.813Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cryptomator",
      "category": "file-encryption",
      "name": "Cryptomator",
      "description": "Client-side encryption for files stored in cloud services. Encrypts each file separately inside a vault so the files can sync individually. Available for desktop, Android and iOS.",
      "website": "https://cryptomator.org",
      "source": "https://github.com/cryptomator/cryptomator",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 75,
      "coverage": 100,
      "summary": "Cryptomator scores 75 out of 100 (grade B) on the file encryption criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry and independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/file-encryption/cryptomator/",
      "markdown": "https://privacyratings.com/file-encryption/cryptomator/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cryptomator/cryptomator/blob/develop/LICENSE.txt",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://cryptomator.org/privacy/",
          "note": "No third-party trackers; the website uses self-hosted first-party analytics and the apps only contact the vendor for update checks."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cryptomator.org/pricing/",
          "note": "Funded by license sales, Hub subscriptions and donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cryptomator.org/audits/2017-11-27%20crypto%20cure53.pdf",
          "note": "Cure53 published a full audit report, but it is older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:42.905Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cryptsetup",
      "category": "file-encryption",
      "name": "CryptSetup",
      "description": "Command-line utility for setting up Linux disk encryption with the dm-crypt kernel module. Supports LUKS, plain dm-crypt, TrueCrypt, VeraCrypt, BitLocker and FileVault2 volumes.",
      "website": "https://gitlab.com/cryptsetup/cryptsetup",
      "source": "https://gitlab.com/cryptsetup/cryptsetup",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "CryptSetup scores 80 out of 100 (grade B) on the file encryption criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-encryption/cryptsetup/",
      "markdown": "https://privacyratings.com/file-encryption/cryptsetup/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/cryptsetup/cryptsetup/-/blob/main/COPYING",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/cryptsetup/cryptsetup",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gitlab.com/cryptsetup/cryptsetup/-/blob/main/COPYING",
          "note": "Free open source tool with no ads or data collection."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:42.666Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "diskcryptor",
      "category": "file-encryption",
      "name": "DiskCryptor",
      "description": "Open source partition and full-disk encryption for Windows, including system drives on UEFI/GPT machines.",
      "website": "https://diskcryptor.org",
      "source": "https://github.com/DavidXanatos/DiskCryptor",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "DiskCryptor scores 30 out of 100 (grade F) on the file encryption criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/file-encryption/diskcryptor/",
      "markdown": "https://privacyratings.com/file-encryption/diskcryptor/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/DavidXanatos/DiskCryptor/blob/master/DCrypt/license.txt",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google AdSense."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://diskcryptor.org",
          "note": "The website shows Google AdSense ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:43.660Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "filevault",
      "category": "file-encryption",
      "name": "FileVault",
      "description": "Full-disk encryption built into macOS that encrypts the startup volume with XTS-AES-128. The recovery key can be kept locally or escrowed with an iCloud account or a device management server.",
      "website": "https://support.apple.com/guide/mac-help/protect-data-on-your-mac-with-filevault-mh11785/mac",
      "license": null,
      "platforms": [
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "FileVault scores 45 out of 100 (grade D) on the file encryption criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets no trackers or telemetry and independent audit. It does not meet open source. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/file-encryption/filevault/",
      "markdown": "https://privacyratings.com/file-encryption/filevault/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/device-analytics/",
          "note": "No third-party trackers in the app, and sharing device analytics with Apple is opt-in. Apple web pages load Apple's own analytics (ac-analytics, sent to metrics.apple.com) by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/en-ww/",
          "note": "Included with macOS, which is paid for through hardware sales. No ads in the feature."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.niap-ccevs.org/products/11448",
          "note": "FileVault is Common Criteria certified against the Full Drive Encryption protection profiles, with certification and validation reports published, but no full security audit report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:20.029Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "gocryptfs",
      "category": "file-encryption",
      "name": "gocryptfs",
      "description": "Open source encrypted overlay filesystem that runs as a FUSE mount and stores each file as a separate encrypted file, suited to cloud-synced folders. Also has a reverse mode for encrypted backups.",
      "website": "https://nuetzlich.net/gocryptfs/",
      "source": "https://github.com/rfjakob/gocryptfs",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 90,
      "coverage": 100,
      "summary": "gocryptfs scores 90 out of 100 (grade A) on the file encryption criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It partly meets independent audit.",
      "url": "https://privacyratings.com/file-encryption/gocryptfs/",
      "markdown": "https://privacyratings.com/file-encryption/gocryptfs/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rfjakob/gocryptfs/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rfjakob/gocryptfs",
          "note": "No telemetry or analytics in the source code. The website loads no third-party scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/rfjakob/gocryptfs",
          "note": "Free volunteer project with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://defuse.ca/audits/gocryptfs.htm",
          "note": "A full audit by Taylor Hornby of Defuse Security is published, but it is older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:19.650Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "kryptor",
      "category": "file-encryption",
      "name": "Kryptor",
      "description": "Open source command-line tool for encrypting and signing files with a passphrase, symmetric key or public keys, using modern primitives with no configuration options.",
      "website": "https://www.kryptor.co.uk",
      "source": "https://github.com/samuel-lucas6/Kryptor",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Kryptor scores 65 out of 100 (grade C) on the file encryption criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-encryption/kryptor/",
      "markdown": "https://privacyratings.com/file-encryption/kryptor/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/samuel-lucas6/Kryptor/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/samuel-lucas6/Kryptor",
          "note": "No telemetry or analytics in the source code. The documentation site is hosted on GitBook, which records visitor page and link-click insights."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/samuel-lucas6/Kryptor",
          "note": "Free volunteer project with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:19.255Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "picocrypt",
      "category": "file-encryption",
      "name": "Picocrypt",
      "description": "Small open source file encryption tool for desktop that uses XChaCha20 and Argon2id, with optional keyfiles, Reed-Solomon error correction and plausible deniability. The original project is archived and no longer developed.",
      "website": "https://github.com/Picocrypt/Picocrypt",
      "source": "https://github.com/Picocrypt/Picocrypt",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 100,
      "coverage": 100,
      "summary": "Picocrypt scores 100 out of 100 (grade A) on the file encryption criteria. It meets 4 of 4 criteria: open source, no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/file-encryption/picocrypt/",
      "markdown": "https://privacyratings.com/file-encryption/picocrypt/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Picocrypt/Picocrypt/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Picocrypt/Picocrypt#readme",
          "note": "The README states the app has no telemetry. The project has no website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Picocrypt/Picocrypt#readme",
          "note": "Free volunteer project with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/Picocrypt/storage/main/Picocrypt.Audit.Report.pdf",
          "note": "Code audit by Radically Open Security, with the full report published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:19.112Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "veracrypt",
      "category": "file-encryption",
      "name": "VeraCrypt",
      "description": "Open source disk encryption for Windows, macOS and Linux. Creates encrypted file containers or encrypts whole partitions and system drives, and supports hidden volumes.",
      "website": "https://veracrypt.io",
      "source": "https://github.com/veracrypt/VeraCrypt",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "JP",
        "name": "Japan",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 90,
      "coverage": 100,
      "summary": "VeraCrypt scores 90 out of 100 (grade A) on the file encryption criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It partly meets independent audit. It is based in Japan: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/file-encryption/veracrypt/",
      "markdown": "https://privacyratings.com/file-encryption/veracrypt/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/veracrypt/VeraCrypt/blob/master/License.txt",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/veracrypt/VeraCrypt",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://veracrypt.io/en/Donation.html",
          "note": "Funded by donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/Studies/Veracrypt/Veracrypt.pdf?__blob=publicationFile",
          "note": "Fraunhofer SIT published a full evaluation for the BSI, but it is older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:43.917Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "flowcrypt",
      "category": "pgp-tools",
      "name": "FlowCrypt",
      "description": "Browser extension for OpenPGP email encryption in Gmail on Chrome, Firefox and other browsers, with companion apps for Android and iOS.",
      "website": "https://flowcrypt.com",
      "source": "https://github.com/FlowCrypt/flowcrypt-browser",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CZ",
        "name": "Czechia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "FlowCrypt scores 45 out of 100 (grade D) on the PGP tools criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source and independent audit. It does not meet no trackers or telemetry. It is based in Czechia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/pgp-tools/flowcrypt/",
      "markdown": "https://privacyratings.com/pgp-tools/flowcrypt/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/FlowCrypt/flowcrypt-browser/blob/master/LICENSE",
          "note": "Source available under a custom license. Not an OSI license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.flowcrypt.email/latest/",
          "note": "The website loads Mouseflow session recording, and Exodus finds ACRA and OpenTelemetry in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://flowcrypt.com/privacy",
          "note": "Funded by enterprise licenses. The privacy policy states personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://flowcrypt.com/assets/documents/FLO-02-report.pdf",
          "note": "Cure53 published full reports on the extension and apps, but they are older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:43.466Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gpg-suite",
      "category": "pgp-tools",
      "name": "GPG Suite",
      "description": "GnuPG distribution for macOS with key management, Finder and system service integration, and GPG Mail, an OpenPGP plugin for Apple Mail that requires a paid support plan.",
      "website": "https://gpgtools.org",
      "source": "https://github.com/GPGTools/GPGTools_Installer",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "AT",
        "name": "Austria",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "GPG Suite scores 65 out of 100 (grade C) on the PGP tools criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in Austria: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/pgp-tools/gpg-suite/",
      "markdown": "https://privacyratings.com/pgp-tools/gpg-suite/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/GPGTools/GPGTools_Installer/blob/dev/LICENSE.txt",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://gpgtools.org/privacy",
          "note": "No third-party trackers; the website uses self-hosted Matomo and the updater contacts the vendor. Crash reports are opt-in."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gpgtools.org/faq",
          "note": "Funded by paid GPG Mail support plans sold through Paddle. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:43.824Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gpg4win",
      "category": "pgp-tools",
      "name": "GPG4Win",
      "description": "GnuPG distribution for Windows that bundles the Kleopatra certificate manager and the GpgOL plugin for Outlook for encrypting and signing files and email.",
      "website": "https://www.gpg4win.org",
      "source": "https://github.com/gpg/gpg4win",
      "license": "GPL-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "GPG4Win scores 80 out of 100 (grade B) on the PGP tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/pgp-tools/gpg4win/",
      "markdown": "https://privacyratings.com/pgp-tools/gpg4win/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gpg/gpg4win/blob/master/COPYING",
          "note": "GPL-2.0 and LGPL-2.1."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gpg4win.org/privacy-policy.html",
          "note": "The website uses no tracking or analytics cookies, and the software has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gpg4win.org/donate.html",
          "note": "Funded by donations and paid support from the developing companies. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:44.656Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kleopatra",
      "category": "pgp-tools",
      "name": "Kleopatra",
      "description": "KDE certificate manager and graphical front end for GnuPG. Manages OpenPGP and X.509 certificates, encrypts, decrypts, signs and verifies files, and retrieves certificates from LDAP servers.",
      "website": "https://apps.kde.org/kleopatra/",
      "source": "https://invent.kde.org/pim/kleopatra",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Kleopatra scores 80 out of 100 (grade B) on the PGP tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/pgp-tools/kleopatra/",
      "markdown": "https://privacyratings.com/pgp-tools/kleopatra/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://invent.kde.org/pim/kleopatra/-/tree/master/LICENSES",
          "note": "GPL-2.0 or later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kde.org/privacypolicy/",
          "note": "No third-party trackers, and the app has no telemetry. KDE websites use self-hosted Matomo with cookies disabled and IP addresses anonymized."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kde.org/donate/",
          "note": "Developed by the KDE community, funded by donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:44.164Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mailvelope",
      "category": "pgp-tools",
      "name": "Mailvelope",
      "description": "Browser extension that adds OpenPGP encryption to webmail services such as Gmail, Outlook.com and many others. Business editions integrate with Google Workspace and Nextcloud.",
      "website": "https://mailvelope.com",
      "source": "https://github.com/mailvelope/mailvelope",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 100,
      "coverage": 100,
      "summary": "Mailvelope scores 100 out of 100 (grade A) on the PGP tools criteria. It meets 4 of 4 criteria: open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/pgp-tools/mailvelope/",
      "markdown": "https://privacyratings.com/pgp-tools/mailvelope/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mailvelope/mailvelope/blob/master/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://mailvelope.com/en/privacy-policy",
          "note": "No third-party trackers. The website's Plausible analytics are cookieless and aggregate-only, and the extension sends usage statistics only with consent."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mailvelope.com/en/privacy-policy",
          "note": "Funded by business subscriptions, donations and grants. The privacy policy states data is not sold and there are no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mailvelope.com/pdf/0xche_mailvelope_report_V3.pdf",
          "note": "Full audit report by 0xche on the browser extension, with retest."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:55.678Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "openkeychain",
      "category": "pgp-tools",
      "name": "OpenKeychain",
      "description": "OpenPGP app for Android that manages keys and encrypts, decrypts and signs messages and files, on its own or through other apps such as K-9 Mail. In maintenance mode: security fixes only, no new features.",
      "website": "https://www.openkeychain.org",
      "source": "https://github.com/open-keychain/open-keychain",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 90,
      "coverage": 100,
      "summary": "OpenKeychain scores 90 out of 100 (grade A) on the PGP tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It partly meets independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/pgp-tools/openkeychain/",
      "markdown": "https://privacyratings.com/pgp-tools/openkeychain/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/open-keychain/open-keychain/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.sufficientlysecure.keychain/latest/",
          "note": "Exodus finds no trackers in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.openkeychain.org",
          "note": "Funded by donations and sponsorship from heylogin. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cure53.de/pentest-report_openkeychain.pdf",
          "note": "Cure53 published a full audit report, but it is older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:44.446Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "pgp-everywhere",
      "category": "pgp-tools",
      "name": "PGP Everywhere",
      "description": "iOS app for encrypting, decrypting and signing text and files with PGP, with a custom keyboard for use inside other apps. It has not received updates for several years.",
      "website": "https://www.pgpeverywhere.com",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "PGP Everywhere scores 50 out of 100 (grade D) on the PGP tools criteria. It meets 2 of 4 criteria: no trackers or telemetry and no ads or data sales. It does not meet open source and independent audit.",
      "url": "https://privacyratings.com/pgp-tools/pgp-everywhere/",
      "markdown": "https://privacyratings.com/pgp-tools/pgp-everywhere/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://apps.apple.com/us/app/pgp-everywhere/id1011677987",
          "note": "The App Store privacy label states the app collects no data, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://apps.apple.com/us/app/pgp-everywhere/id1011677987",
          "note": "Paid app with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:44.383Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "seahorse",
      "category": "pgp-tools",
      "name": "SeaHorse",
      "description": "GNOME app, shown as Passwords and Keys, for managing PGP and SSH keys and the passwords stored in GNOME Keyring.",
      "website": "https://gitlab.gnome.org/GNOME/seahorse",
      "source": "https://gitlab.gnome.org/GNOME/seahorse",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "SeaHorse scores 80 out of 100 (grade B) on the PGP tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/pgp-tools/seahorse/",
      "markdown": "https://privacyratings.com/pgp-tools/seahorse/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/GNOME/seahorse/-/blob/main/COPYING",
          "note": "GPL-2.0 and LGPL-2.1."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/GNOME/seahorse",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://donate.gnome.org/en/",
          "note": "Developed by the GNOME community, funded by donations to the GNOME Foundation. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:44.164Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "1time-io",
      "category": "secret-sharing",
      "name": "1time.io",
      "description": "One-time secret sharing service that encrypts text and files in the browser with AES-256-GCM before upload and deletes them after the first view or expiry. Also offers a CLI, a browser extension and self-hosting.",
      "website": "https://1time.io",
      "source": "https://github.com/shingrus/1time.io",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 59,
      "coverage": 100,
      "summary": "1time.io scores 59 out of 100 (grade D) on the secret sharing criteria. It meets 3 of 8 criteria: open source, no trackers or telemetry and no ads or data sales. It partly meets TLS configuration and security headers. It does not meet independent audit, transparency report and tells users about requests. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/secret-sharing/1time-io/",
      "markdown": "https://privacyratings.com/secret-sharing/1time-io/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/shingrus/1time.io/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://1time.io/privacy/",
          "note": "The privacy policy states no cookies, analytics, tracking scripts or third-party requests."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://1time.io/privacy/",
          "note": "Free service without ads. The privacy policy states no ad networks and no personal data collection."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=1time.io&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=1time.io",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:03:54.417Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "crypt-fyi",
      "category": "secret-sharing",
      "name": "crypt.fyi",
      "description": "Ephemeral secret sharing service that encrypts text and files in the browser before upload, with burn-after-reading, expiry, password and IP restrictions. Offers web, CLI and browser extension clients and can be self-hosted.",
      "website": "https://www.crypt.fyi",
      "source": "https://github.com/osbytes/crypt.fyi",
      "license": "Apache-2.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 69,
      "coverage": 100,
      "summary": "crypt.fyi scores 69 out of 100 (grade C) on the secret sharing criteria. It meets 5 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration and security headers. It does not meet independent audit, transparency report and tells users about requests. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/secret-sharing/crypt-fyi/",
      "markdown": "https://privacyratings.com/secret-sharing/crypt-fyi/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/osbytes/crypt.fyi/blob/main/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.crypt.fyi/privacy",
          "note": "The privacy policy shares data only with hosting providers and user-set webhooks, and the site's Content Security Policy allows no third-party scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.crypt.fyi/privacy",
          "note": "Free open source service without ads. The privacy policy states data is not shared with third parties beyond hosting."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=crypt.fyi&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=crypt.fyi",
          "note": "Grade A+ (110/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:19.372Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hemmelig-app",
      "category": "secret-sharing",
      "name": "Hemmelig.app",
      "description": "Secret sharing service that encrypts text and files in the browser and deletes them after a set number of views or an expiry time. Supports passwords, IP restrictions, webhooks and self-hosting.",
      "website": "https://hemmelig.app",
      "source": "https://github.com/HemmeligOrg/Hemmelig.app",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 59,
      "coverage": 100,
      "summary": "Hemmelig.app scores 59 out of 100 (grade D) on the secret sharing criteria. It meets 4 of 8 criteria: open source, no ads or data sales, TLS configuration and security headers. It partly meets no trackers or telemetry. It does not meet independent audit, transparency report and tells users about requests. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/secret-sharing/hemmelig-app/",
      "markdown": "https://privacyratings.com/secret-sharing/hemmelig-app/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/HemmeligOrg/Hemmelig.app/blob/v7/LICENSE",
          "note": "All code is public under the source-available O'Saasy license, which bans competing hosted offerings and is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://hemmelig.app/privacy",
          "note": "No third-party trackers, but the hosted service records page visits with first-party analytics using hashed visitor IDs; only instance administrators can turn it off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://hemmelig.app/privacy",
          "note": "Free service without ads, supported by donations. The privacy policy lists only the minimal data stored to run the service."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=hemmelig.app&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=hemmelig.app",
          "note": "Grade A+ (135/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:19.710Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "onetime-secret",
      "category": "secret-sharing",
      "name": "Onetime Secret",
      "description": "Secret sharing service that stores a message behind a one-time link and deletes it after it is viewed or expires, with optional passphrases. Offers regional data centers, paid plans with custom domains, and can be self-hosted.",
      "website": "https://onetimesecret.com",
      "source": "https://github.com/onetimesecret/onetimesecret",
      "license": "MIT",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 75,
      "coverage": 100,
      "summary": "Onetime Secret scores 75 out of 100 (grade B) on the secret sharing criteria. It meets 5 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, tells users about requests and TLS configuration. It partly meets transparency report. It does not meet independent audit and security headers. It is based in Canada: Five Eyes member. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/secret-sharing/onetime-secret/",
      "markdown": "https://privacyratings.com/secret-sharing/onetime-secret/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/onetimesecret/onetimesecret/blob/main/LICENSE.txt",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://onetimesecret.com/privacy",
          "note": "The privacy policy states Google Analytics and similar third-party tracking services are not used, and cookies are only for operation and preferences."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://onetimesecret.com/privacy",
          "note": "Funded by paid plans. The privacy policy states no advertising is hosted and personal data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://onetimesecret.com/privacy",
          "note": "The privacy policy describes when data is disclosed to law enforcement, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://onetimesecret.com/privacy",
          "note": "The privacy policy promises reasonable efforts to notify users of disclosures unless prohibited by law or court order, or in exigent circumstances."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=onetimesecret.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=onetimesecret.com",
          "note": "Grade C (55/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:19.414Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "password-pusher",
      "category": "secret-sharing",
      "name": "Password Pusher",
      "description": "Service for sharing passwords, text and files through links that expire after a set number of views or days, with audit logs. Hosted in EU and US regions with paid team plans, and the open source edition can be self-hosted.",
      "website": "https://pwpush.com",
      "source": "https://github.com/pglombardo/PasswordPusher",
      "license": "Apache-2.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 59,
      "coverage": 100,
      "summary": "Password Pusher scores 59 out of 100 (grade D) on the secret sharing criteria. It meets 4 of 8 criteria: no trackers or telemetry, no ads or data sales, TLS configuration and security headers. It partly meets open source. It does not meet independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/secret-sharing/password-pusher/",
      "markdown": "https://privacyratings.com/secret-sharing/password-pusher/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://eu.pwpush.com/security_compliance",
          "note": "The core, including encryption and data handling, is Apache-2.0, but the hosted Solo and Organization editions add closed-source features."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://eu.pwpush.com/privacy",
          "note": "No third-party trackers. The website's Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://eu.pwpush.com/privacy",
          "note": "Funded by paid plans. The privacy policy states personal information is not sold to unrelated third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published. The security page states no penetration test summary is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=eu.pwpush.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=eu.pwpush.com",
          "note": "Grade A+ (110/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:14:29.360Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "privatebin",
      "category": "secret-sharing",
      "name": "PrivateBin",
      "description": "Open source, self-hosted pastebin that encrypts text and files in the browser with AES-256-GCM, so the server never sees the content. Supports expiry, burn after reading, passwords and discussions.",
      "website": "https://privatebin.info",
      "source": "https://github.com/PrivateBin/PrivateBin",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 90,
      "coverage": 100,
      "summary": "PrivateBin scores 90 out of 100 (grade A) on the secret sharing criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It partly meets independent audit.",
      "url": "https://privacyratings.com/secret-sharing/privatebin/",
      "markdown": "https://privacyratings.com/secret-sharing/privatebin/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/PrivateBin/PrivateBin/blob/master/LICENSE.md",
          "note": "Zlib license, with bundled libraries under other OSI licenses."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/PrivateBin/PrivateBin",
          "note": "No telemetry or analytics in the source code, and the project website loads no third-party scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/PrivateBin/PrivateBin",
          "note": "Free volunteer project with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://defuse.ca/audits/zerobin.htm",
          "note": "A full audit by Taylor Hornby covers ZeroBin, the project PrivateBin forked from, and is older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:19.936Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "yopass",
      "category": "secret-sharing",
      "name": "Yopass",
      "description": "Open source secret sharing tool that encrypts messages and files in the browser with OpenPGP and deletes them after one view or an expiry time. Can be self-hosted, and a public instance runs at share.yopass.se.",
      "website": "https://yopass.se",
      "source": "https://github.com/jhaals/yopass",
      "license": "Apache-2.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "SE",
        "name": "Sweden",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Yopass scores 50 out of 100 (grade D) on the secret sharing criteria. It meets 4 of 8 criteria: open source, no ads or data sales, TLS configuration and security headers. It does not meet no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in Sweden: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/secret-sharing/yopass/",
      "markdown": "https://privacyratings.com/secret-sharing/yopass/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jhaals/yopass/blob/master/LICENSE",
          "note": "Apache-2.0. Some business features in the same code base require a paid license key."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://yopass.se/privacy",
          "note": "The privacy policy states the project website uses Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://yopass.se/privacy",
          "note": "Funded by paid business licenses. The privacy policy lists no advertising use of data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=share.yopass.se&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=share.yopass.se",
          "note": "Grade A+ (110/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:19.820Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "10-minute-mail",
      "category": "online-privacy-tools",
      "name": "10 Minute Mail",
      "description": "Generates a disposable email address that expires after ten minutes, for sign-ups where a real address is not wanted.",
      "website": "https://10minutemail.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 13,
      "coverage": 100,
      "summary": "10 Minute Mail scores 13 out of 100 (grade F) on the privacy test tools criteria. It meets 1 of 8 criteria: TLS configuration. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C+.",
      "url": "https://privacyratings.com/online-privacy-tools/10-minute-mail/",
      "markdown": "https://privacyratings.com/online-privacy-tools/10-minute-mail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://10minutemail.com/privacy.html",
          "note": "The privacy policy lists Google Analytics and Google advertising cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://10minutemail.com/privacy.html",
          "note": "The privacy policy states that Google serves ads on the service using cookies."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=10minutemail.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=10minutemail.com",
          "note": "Grade C+ (60/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google DoubleClick",
            "host": "securepubads.g.doubleclick.net",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:19.277Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "am-i-unique",
      "category": "online-privacy-tools",
      "name": "Am I Unique?",
      "description": "Research site that collects a browser fingerprint from device and browser attributes and shows how unique it is compared with other visitors.",
      "website": "https://amiunique.org",
      "source": "https://github.com/DIVERSIFY-project/amiunique",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 34,
      "coverage": 100,
      "summary": "Am I Unique? scores 34 out of 100 (grade F) on the privacy test tools criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It partly meets no trackers or telemetry. It does not meet open source, independent audit, transparency report, tells users about requests and security headers. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/online-privacy-tools/am-i-unique/",
      "markdown": "https://privacyratings.com/online-privacy-tools/am-i-unique/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.amiunique.org/faq",
          "note": "The current version is closed source; only the code of the old version is public under the MIT license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.amiunique.org/privacy-policy",
          "note": "The privacy policy states there are no third-party service providers, but the website runs self-hosted Matomo analytics that is not stated to be cookieless."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.amiunique.org/privacy-policy",
          "note": "A research project run by Inria with no ads; the policy states records are never shared."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=amiunique.org&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=amiunique.org",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:20.403Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "blocked-org",
      "category": "online-privacy-tools",
      "name": "Blocked.org",
      "description": "Open Rights Group tool that checks whether a website is blocked by the filters of UK mobile and broadband Internet service providers.",
      "website": "https://www.blocked.org.uk",
      "source": "https://github.com/OpenRightsGroup/blocked-org-uk",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 66,
      "coverage": 100,
      "summary": "Blocked.org scores 66 out of 100 (grade C) on the privacy test tools criteria. It meets 4 of 8 criteria: open source, no ads or data sales, tells users about requests and TLS configuration. It partly meets no trackers or telemetry and transparency report. It does not meet independent audit and security headers. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/online-privacy-tools/blocked-org/",
      "markdown": "https://privacyratings.com/online-privacy-tools/blocked-org/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/OpenRightsGroup/blocked-org-uk/blob/master/LICENSE-code",
          "note": "Front end is GPL-3.0; the API and backend are published as openrightsgroup/Blocking-Middleware under GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.openrightsgroup.org/privacy-policy/",
          "note": "Self-hosted Matomo analytics is on by default, with an opt-out and Do Not Track support; no third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://action.openrightsgroup.org/make-one-donation-support-blocked",
          "note": "Funded by donations to Open Rights Group, which states it never sells personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.openrightsgroup.org/privacy-policy/",
          "note": "The privacy policy states unwarranted law enforcement requests are refused, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.openrightsgroup.org/privacy-policy/",
          "note": "The privacy policy promises to notify affected users of law enforcement requests unless legally prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.blocked.org.uk&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.blocked.org.uk",
          "note": "Grade F (0/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:19.946Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "browser-leak-test",
      "category": "online-privacy-tools",
      "name": "BrowserLeaks",
      "description": "Collection of browser tests that show which data a browser exposes to websites, including IP address, WebRTC and DNS leaks, TLS details and canvas, WebGL and font fingerprints.",
      "website": "https://browserleaks.com",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 22,
      "coverage": 100,
      "summary": "BrowserLeaks scores 22 out of 100 (grade F) on the privacy test tools criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales and security headers. It does not meet open source, no trackers or telemetry, independent audit, transparency report and tells users about requests. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/online-privacy-tools/browser-leak-test/",
      "markdown": "https://privacyratings.com/online-privacy-tools/browser-leak-test/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://browserleaks.com/",
          "note": "The site notice says third-party analytics may be active; the analytics setting is on by default and can be switched off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://browserleaks.com/settings",
          "note": "Partner attributions and cosmetic ads are shown by default and can be switched off; the site states it collects no personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=browserleaks.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=browserleaks.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:19.757Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cover-your-tracks",
      "category": "online-privacy-tools",
      "name": "Cover Your Tracks",
      "description": "EFF tool, formerly Panopticlick, that tests how well a browser and its extensions block tracking and how unique the browser fingerprint is.",
      "website": "https://coveryourtracks.eff.org",
      "source": "https://github.com/EFForg/cover-your-tracks",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 69,
      "coverage": 100,
      "summary": "Cover Your Tracks scores 69 out of 100 (grade C) on the privacy test tools criteria. It meets 4 of 8 criteria: open source, no trackers or telemetry, no ads or data sales and tells users about requests. It partly meets transparency report and TLS configuration. It does not meet independent audit and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade B-.",
      "url": "https://privacyratings.com/online-privacy-tools/cover-your-tracks/",
      "markdown": "https://privacyratings.com/online-privacy-tools/cover-your-tracks/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/EFForg/cover-your-tracks/blob/master/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://coveryourtracks.eff.org/privacy",
          "note": "The privacy policy states there are no third-party service providers; an optional test loads one real tracker resource to check blocking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://supporters.eff.org/donate/coveryourtracks",
          "note": "Funded by donations to EFF, which states it does not sell visitor information."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.eff.org/policy",
          "note": "EFF's privacy policy states visitor information is shared with government only when compelled by law, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.eff.org/policy",
          "note": "EFF's privacy policy promises to attempt prior notice of legal requests unless prohibited or futile."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=coveryourtracks.eff.org&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=coveryourtracks.eff.org",
          "note": "Grade B- (65/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "B-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:19.948Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "exif-remove",
      "category": "online-privacy-tools",
      "name": "ExifRemove",
      "description": "Removes EXIF, GPS, XMP, IPTC and other metadata from JPEG photos, processing the files in the browser without uploading them.",
      "website": "https://www.exifremove.com",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 16,
      "coverage": 100,
      "summary": "ExifRemove scores 16 out of 100 (grade F) on the privacy test tools criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets security headers. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report and tells users about requests. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/online-privacy-tools/exif-remove/",
      "markdown": "https://privacyratings.com/online-privacy-tools/exif-remove/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.exifremove.com/contact.php",
          "note": "The cleaner page has no third-party scripts, but the contact page loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.exifremove.com/contact.php",
          "note": "The contact page shows Google AdSense ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.exifremove.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.exifremove.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:19.895Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hardenize",
      "category": "online-privacy-tools",
      "name": "Hardenize",
      "description": "Tests the security configuration of a domain, covering DNS, email, HTTPS, TLS, certificates and security headers, as a free public report and a paid monitoring service from Red Sift.",
      "website": "https://www.hardenize.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 31,
      "coverage": 100,
      "summary": "Hardenize scores 31 out of 100 (grade F) on the privacy test tools criteria. It meets 3 of 8 criteria: no ads or data sales, TLS configuration and security headers. It does not meet open source, no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/online-privacy-tools/hardenize/",
      "markdown": "https://privacyratings.com/online-privacy-tools/hardenize/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://redsift.com/legal/privacy-policy",
          "note": "The site sends error reports to Sentry, and the Red Sift privacy policy lists third-party analytics providers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.hardenize.com/pricing",
          "note": "Funded by paid subscriptions; the public report has no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.hardenize.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.hardenize.com",
          "note": "Grade A+ (115/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:06:26.373Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "have-i-been-pwned",
      "category": "online-privacy-tools",
      "name": "Have I Been Pwned",
      "description": "Searches a database of data breaches to show whether an email address, phone number or password has been exposed, and can notify subscribers about new breaches.",
      "website": "https://haveibeenpwned.com",
      "source": "https://github.com/HaveIBeenPwned",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "AU",
        "name": "Australia",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 59,
      "coverage": 100,
      "summary": "Have I Been Pwned scores 59 out of 100 (grade D) on the privacy test tools criteria. It meets 4 of 8 criteria: no trackers or telemetry, no ads or data sales, TLS configuration and security headers. It partly meets open source. It does not meet independent audit, transparency report and tells users about requests. It is based in Australia: Five Eyes member; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/online-privacy-tools/have-i-been-pwned/",
      "markdown": "https://privacyratings.com/online-privacy-tools/have-i-been-pwned/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/HaveIBeenPwned/PwnedPasswordsAzureFunction/blob/main/LICENSE",
          "note": "The Pwned Passwords API, Cloudflare worker and downloader are BSD-3-Clause; the main website and breach search are closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://haveibeenpwned.com/Privacy",
          "note": "The privacy policy states no third-party cookies or tracking pixels are used."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://haveibeenpwned.com/Privacy",
          "note": "Funded by paid subscriptions; the privacy policy states no ads or targeted marketing."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=haveibeenpwned.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=haveibeenpwned.com",
          "note": "Grade A+ (115/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:19.971Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ip-leak-test",
      "category": "online-privacy-tools",
      "name": "ipleak.net",
      "description": "Shows the IP addresses, DNS servers, WebRTC addresses, geolocation and browser details that websites can see, to check whether a VPN or proxy leaks. Run by AirVPN.",
      "website": "https://ipleak.net",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "IT",
        "name": "Italy",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 47,
      "coverage": 100,
      "summary": "ipleak.net scores 47 out of 100 (grade D) on the privacy test tools criteria. It meets 3 of 8 criteria: no trackers or telemetry, no ads or data sales and TLS configuration. It partly meets security headers. It does not meet open source, independent audit, transparency report and tells users about requests. It is based in Italy: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/online-privacy-tools/ip-leak-test/",
      "markdown": "https://privacyratings.com/online-privacy-tools/ip-leak-test/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://airvpn.org/privacy/",
          "note": "The AirVPN privacy policy states its web servers use no third-party add-ons that allow profiling; the Google map loads only on request."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://airvpn.org/buy/",
          "note": "Funded by the paid AirVPN service; the site shows no third-party ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=ipleak.net&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=ipleak.net",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:20.393Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "is-legit",
      "category": "online-privacy-tools",
      "name": "IsLegitSite",
      "description": "Checks a website's reputation, domain age, blocklist status and other signals to estimate whether it is legitimate or a scam before buying from it.",
      "website": "https://www.islegitsite.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "IT",
        "name": "Italy",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 9,
      "coverage": 100,
      "summary": "IsLegitSite scores 9 out of 100 (grade F) on the privacy test tools criteria. It partly meets TLS configuration and security headers. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report and tells users about requests. It is based in Italy: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/online-privacy-tools/is-legit/",
      "markdown": "https://privacyratings.com/online-privacy-tools/is-legit/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.privalicy.com/privacy-policy/22994150/",
          "note": "The home page loads Google AdSense, and the privacy policy lists Google Analytics and advertising cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.privalicy.com/privacy-policy/22994150/",
          "note": "Shows Google AdSense ads, which the privacy policy says are based on visits to other sites."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.islegitsite.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.islegitsite.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Fathom",
            "host": "cdn.usefathom.com",
            "effect": "partial"
          },
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:20.018Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mxtoolbox-mail-headers",
      "category": "online-privacy-tools",
      "name": "MxToolbox Email Header Analyzer",
      "description": "Parses pasted email headers to show the delivery path, relay delays and SPF, DKIM and DMARC results, which helps check a message's authenticity and what outgoing mail reveals.",
      "website": "https://mxtoolbox.com/Public/Tools/EmailHeaders.aspx",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 13,
      "coverage": 100,
      "summary": "MxToolbox Email Header Analyzer scores 13 out of 100 (grade F) on the privacy test tools criteria. It meets 1 of 8 criteria: TLS configuration. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/online-privacy-tools/mxtoolbox-mail-headers/",
      "markdown": "https://privacyratings.com/online-privacy-tools/mxtoolbox-mail-headers/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://mxtoolbox.com/privacy.aspx",
          "note": "The home page loads Google Tag Manager, and the privacy policy lists Google Analytics and other third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://mxtoolbox.com/privacy.aspx",
          "note": "The privacy policy states Google advertising cookies are used for interest-based ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mxtoolbox.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mxtoolbox.com",
          "note": "Grade D- (25/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:11:13.004Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "phish-ly",
      "category": "online-privacy-tools",
      "name": "Phish.ly",
      "description": "Free service from Tines that analyzes a suspicious email forwarded to it, scanning its links with urlscan.io and replying with a report.",
      "website": "https://phish.ly",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "IE",
        "name": "Ireland",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Phish.ly scores 25 out of 100 (grade F) on the privacy test tools criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in Ireland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C-.",
      "url": "https://privacyratings.com/online-privacy-tools/phish-ly/",
      "markdown": "https://privacyratings.com/online-privacy-tools/phish-ly/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://phish.ly/",
          "note": "The home page loads Google Analytics, Google Tag Manager and Leadfeeder."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.tines.com/privacy/",
          "note": "No ads; the tool is run by Tines, whose privacy policy states it does not sell personal information."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=phish.ly&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=phish.ly",
          "note": "Grade C- (45/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:20.921Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "redirect-detective",
      "category": "online-privacy-tools",
      "name": "Redirect Detective",
      "description": "Traces the full redirect chain of a URL, such as a shortened or affiliate link, and shows where it ends without opening it in a browser.",
      "website": "https://redirectdetective.com",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Redirect Detective scores 25 out of 100 (grade F) on the privacy test tools criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/online-privacy-tools/redirect-detective/",
      "markdown": "https://privacyratings.com/online-privacy-tools/redirect-detective/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://redirectdetective.com/",
          "note": "The pages load the Google Analytics ga.js script; no privacy policy is published."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://redirectdetective.com/",
          "note": "The free tool shows no ads and has no accounts."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=redirectdetective.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=redirectdetective.com",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:21.391Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "should-i-remove-it",
      "category": "online-privacy-tools",
      "name": "Should I Remove It?",
      "description": "Database of Windows programs that rates whether each one is safe to remove, based on user uninstall data and what the program does, with an optional desktop scanner app.",
      "website": "https://www.shouldiremoveit.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 6,
      "coverage": 100,
      "summary": "Should I Remove It? scores 6 out of 100 (grade F) on the privacy test tools criteria. It partly meets TLS configuration. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/online-privacy-tools/should-i-remove-it/",
      "markdown": "https://privacyratings.com/online-privacy-tools/should-i-remove-it/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.shouldiremoveit.com/privacy.aspx",
          "note": "The home page loads Google AdSense, Google Tag Manager and Meta Pixel."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.shouldiremoveit.com/privacy.aspx",
          "note": "Ad-supported; the privacy statement says Google uses cookies to serve ads based on prior visits."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.shouldiremoveit.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.shouldiremoveit.com",
          "note": "Grade F (0/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Facebook SDK",
            "host": "connect.facebook.net",
            "effect": "no"
          },
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:20.923Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "site-report",
      "category": "online-privacy-tools",
      "name": "Netcraft Site Report",
      "description": "Netcraft tool that reports what a website runs and where it is hosted, including its hosting provider, IP addresses, registrar, TLS certificates, web technologies and security risk.",
      "website": "https://sitereport.netcraft.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 19,
      "coverage": 100,
      "summary": "Netcraft Site Report scores 19 out of 100 (grade F) on the privacy test tools criteria. It meets 2 of 8 criteria: TLS configuration and security headers. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report and tells users about requests. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/online-privacy-tools/site-report/",
      "markdown": "https://privacyratings.com/online-privacy-tools/site-report/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.netcraft.com/legal/privacy",
          "note": "The Netcraft privacy policy lists Google Analytics, HubSpot, Bing Ads and Facebook cookies on its sites."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.netcraft.com/legal/privacy",
          "note": "The privacy policy states visitor data is used to build audience lists for remarketing ads on Google and Facebook."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=sitereport.netcraft.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=sitereport.netcraft.com",
          "note": "Grade A+ (110/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:21.752Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "virus-total",
      "category": "online-privacy-tools",
      "name": "VirusTotal",
      "description": "Google service that scans files, URLs, domains and IP addresses with many antivirus engines and URL scanners. Submitted files and reports are shared with security partners and premium customers.",
      "website": "https://www.virustotal.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 9,
      "coverage": 100,
      "summary": "VirusTotal scores 9 out of 100 (grade F) on the privacy test tools criteria. It partly meets TLS configuration and security headers. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/online-privacy-tools/virus-total/",
      "markdown": "https://privacyratings.com/online-privacy-tools/virus-total/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.virustotal.com/gui/",
          "note": "The home page loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://docs.virustotal.com/docs/how-it-works",
          "note": "No ads are shown, but submitted files and reports are shared with antivirus partners and made available to paying premium customers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.virustotal.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.virustotal.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:13:47.512Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "xodus",
      "category": "online-privacy-tools",
      "name": "εxodus",
      "description": "Exodus Privacy's report site that analyzes Android apps and lists the trackers and permissions found in each one, with a report for every analyzed app version.",
      "website": "https://reports.exodus-privacy.eu.org/en/",
      "source": "https://github.com/Exodus-Privacy/exodus",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 66,
      "coverage": 100,
      "summary": "εxodus scores 66 out of 100 (grade C) on the privacy test tools criteria. It meets 4 of 8 criteria: open source, no trackers or telemetry, no ads or data sales and TLS configuration. It partly meets security headers. It does not meet independent audit, transparency report and tells users about requests. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/online-privacy-tools/xodus/",
      "markdown": "https://privacyratings.com/online-privacy-tools/xodus/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Exodus-Privacy/exodus/blob/v1/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/",
          "note": "The site loads only self-hosted scripts, with no third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://exodus-privacy.eu.org/en/page/contribute/",
          "note": "Run by a French non-profit association and funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=reports.exodus-privacy.eu.org&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=reports.exodus-privacy.eu.org",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:03:55.725Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "7asecurity",
      "category": "security-audit-firms",
      "name": "7ASecurity",
      "description": "Security firm specialising in mobile, web and cloud penetration tests and code audits, with many published audits of open-source and digital-rights projects funded by OSTIF and the Open Technology Fund.",
      "website": "https://7asecurity.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "IE",
        "name": "Ireland",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 86,
      "coverage": 100,
      "summary": "7ASecurity scores 86 out of 100 (grade B) on the security audit firms criteria. It meets 3 of 4 criteria: publishes full reports, audits open-source projects and public research. It does not meet no trackers on website. It is based in Ireland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/security-audit-firms/7asecurity/",
      "markdown": "https://privacyratings.com/security-audit-firms/7asecurity/index.md",
      "answers": {
        "public_reports": {
          "title": "Publishes full reports",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://7asecurity.com/publications",
          "note": "The publications page links dozens of full public audit reports."
        },
        "open_source_work": {
          "title": "Audits open-source projects",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://7asecurity.com/reports/pentest-report-tor2-RC1.2.pdf",
          "note": "Public reports cover many open-source projects, such as Tor, SecureDrop, K-9 Mail, zlib, Linkerd and conda-forge."
        },
        "public_research": {
          "title": "Public research",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://7asecurity.com/blog/",
          "note": "Publishes a regular blog, free training material and talks."
        },
        "no_trackers": {
          "title": "No trackers on website",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics, Google Tag Manager and Yandex Metrica."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Yandex Metrica",
            "host": "mc.yandex.ru",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:09:28.899Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "assured",
      "category": "security-audit-firms",
      "name": "Assured",
      "description": "Swedish security consultancy in Gothenburg that performs penetration tests, code reviews and infrastructure audits, including published audits of Mullvad VPN and OTF-funded projects.",
      "website": "https://www.assured.se",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "SE",
        "name": "Sweden",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 93,
      "coverage": 100,
      "summary": "Assured scores 93 out of 100 (grade A) on the security audit firms criteria. It meets 3 of 4 criteria: publishes full reports, audits open-source projects and no trackers on website. It partly meets public research. It is based in Sweden: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/security-audit-firms/assured/",
      "markdown": "https://privacyratings.com/security-audit-firms/assured/index.md",
      "answers": {
        "public_reports": {
          "title": "Publishes full reports",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.assured.se/publications",
          "note": "The publications page links many full client reports as PDFs, including Mullvad VPN audits and OTF-sponsored tests."
        },
        "open_source_work": {
          "title": "Audits open-source projects",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.opentech.fund/wp-content/uploads/2024/09/UWA001_Final_Report_September_2024.pdf",
          "note": "Published audits cover open-source projects such as Uwazi, CDR Link and Cinemata for the Open Technology Fund, and Mullvad VPN code."
        },
        "public_research": {
          "title": "Public research",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.assured.se/blog",
          "note": "Publishes occasional technical blog posts and white papers."
        },
        "no_trackers": {
          "title": "No trackers on website",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.assured.se/privacy-policy",
          "note": "No third-party trackers. Umami analytics and Vercel Speed Insights are cookieless and aggregate-only."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:07:13.723Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bishop-fox",
      "category": "security-audit-firms",
      "name": "Bishop Fox",
      "description": "US offensive security firm based in Tempe, Arizona, that provides penetration testing, red teaming and continuous attack surface testing, and develops open-source tools such as Sliver.",
      "website": "https://bishopfox.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 14,
      "coverage": 100,
      "summary": "Bishop Fox scores 14 out of 100 (grade F) on the security audit firms criteria. It meets 1 of 4 criteria: public research. It does not meet publishes full reports, audits open-source projects and no trackers on website. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/security-audit-firms/bishop-fox/",
      "markdown": "https://privacyratings.com/security-audit-firms/bishop-fox/index.md",
      "answers": {
        "public_reports": {
          "title": "Publishes full reports",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The firm does not publish client audit reports."
        },
        "open_source_work": {
          "title": "Audits open-source projects",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No public audits of open-source projects are published."
        },
        "public_research": {
          "title": "Public research",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://bishopfox.com/tools",
          "note": "Publishes regular research, advisories and open-source offensive security tools."
        },
        "no_trackers": {
          "title": "No trackers on website",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Tag Manager."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:07:13.856Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cure53",
      "category": "security-audit-firms",
      "name": "Cure53",
      "description": "Berlin security firm that performs penetration tests and source code audits of web, mobile, browser, VPN and cryptographic software, and publishes many client reports.",
      "website": "https://cure53.de",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": true,
      "pick_reason": "Publishes a large public library of full audit reports, many for open-source and privacy projects, and maintains the DOMPurify sanitizer. Its website uses no cookies or analytics.",
      "disclosure": null,
      "grade": "A",
      "score": 100,
      "coverage": 100,
      "summary": "Cure53 scores 100 out of 100 (grade A) on the security audit firms criteria. It meets 4 of 4 criteria: publishes full reports, audits open-source projects, public research and no trackers on website. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/security-audit-firms/cure53/",
      "markdown": "https://privacyratings.com/security-audit-firms/cure53/index.md",
      "answers": {
        "public_reports": {
          "title": "Publishes full reports",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://cure53.de/#publications-anchor",
          "note": "The publications section links many full client reports as PDFs."
        },
        "open_source_work": {
          "title": "Audits open-source projects",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cure53.de/pentest-report_psiphon-conduit-library.pdf",
          "note": "Published reports cover many open-source projects, such as Psiphon, Mullvad VPN and KeePassium."
        },
        "public_research": {
          "title": "Public research",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/cure53/DOMPurify",
          "note": "Maintains the open-source DOMPurify sanitizer and publishes research papers on browser and web security."
        },
        "no_trackers": {
          "title": "No trackers on website",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://cure53.de/datenschutz.php",
          "note": "The privacy policy states the site uses no cookies and no user analytics, and the tracker test found none."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:07:13.901Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "doyensec",
      "category": "security-audit-firms",
      "name": "Doyensec",
      "description": "Application security firm with offices in San Francisco and San Marino that tests web, mobile, desktop, cloud and Electron applications and spends part of its time on public security research.",
      "website": "https://doyensec.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 86,
      "coverage": 100,
      "summary": "Doyensec scores 86 out of 100 (grade B) on the security audit firms criteria. It meets 3 of 4 criteria: publishes full reports, public research and no trackers on website. It partly meets audits open-source projects. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/security-audit-firms/doyensec/",
      "markdown": "https://privacyratings.com/security-audit-firms/doyensec/index.md",
      "answers": {
        "public_reports": {
          "title": "Publishes full reports",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://doyensec.com/research.html",
          "note": "The research page links more than a dozen full client reports, such as Teleport, Brave Wallet and Apollo Router."
        },
        "open_source_work": {
          "title": "Audits open-source projects",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://doyensec.com/resources/Doyensec_ThinkstCanaryTokensOSS_Report_Q22024_WithRetesting.pdf",
          "note": "Published reports include open-source products such as Teleport, Canary Tokens and SoloKeys firmware, commissioned by their vendors."
        },
        "public_research": {
          "title": "Public research",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://blog.doyensec.com/",
          "note": "Publishes a regular research blog, security advisories and open-source tools."
        },
        "no_trackers": {
          "title": "No trackers on website",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://doyensec.com/",
          "note": "The tracker test found no trackers or analytics on the home page; it loads only Google Fonts and a public script CDN."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:07:13.949Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "include-security",
      "category": "security-audit-firms",
      "name": "Include Security",
      "description": "US application security consultancy based in Brooklyn, New York, that performs penetration tests and source code reviews of web, mobile, cloud and embedded software.",
      "website": "https://includesecurity.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 14,
      "coverage": 100,
      "summary": "Include Security scores 14 out of 100 (grade F) on the security audit firms criteria. It meets 1 of 4 criteria: public research. It does not meet publishes full reports, audits open-source projects and no trackers on website. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C-.",
      "url": "https://privacyratings.com/security-audit-firms/include-security/",
      "markdown": "https://privacyratings.com/security-audit-firms/include-security/index.md",
      "answers": {
        "public_reports": {
          "title": "Publishes full reports",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The firm does not publish client audit reports."
        },
        "open_source_work": {
          "title": "Audits open-source projects",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No public audits of open-source projects are published."
        },
        "public_research": {
          "title": "Public research",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://blog.includesecurity.com/",
          "note": "Publishes a regular research blog on application, mobile and cloud security."
        },
        "no_trackers": {
          "title": "No trackers on website",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads WordPress.com Stats."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "WordPress.com Stats",
            "host": "stats.wp.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:07:14.035Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ioactive",
      "category": "security-audit-firms",
      "name": "IOActive",
      "description": "US security services firm based in Seattle that performs penetration testing, hardware and embedded security assessments and research, with a focus on industrial, transport and IoT systems.",
      "website": "https://www.ioactive.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 14,
      "coverage": 100,
      "summary": "IOActive scores 14 out of 100 (grade F) on the security audit firms criteria. It meets 1 of 4 criteria: public research. It does not meet publishes full reports, audits open-source projects and no trackers on website. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/security-audit-firms/ioactive/",
      "markdown": "https://privacyratings.com/security-audit-firms/ioactive/index.md",
      "answers": {
        "public_reports": {
          "title": "Publishes full reports",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The firm does not publish client audit reports."
        },
        "open_source_work": {
          "title": "Audits open-source projects",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No public audits of open-source projects are published."
        },
        "public_research": {
          "title": "Public research",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.ioactive.com/resources/research/",
          "note": "Publishes regular research papers, vulnerability disclosures and tools."
        },
        "no_trackers": {
          "title": "No trackers on website",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics, Google Tag Manager and LinkedIn Insight."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cookiebot",
            "host": "consent.cookiebot.com",
            "effect": "none"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "snap.licdn.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:07:14.086Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kudelski-security",
      "category": "security-audit-firms",
      "name": "Kudelski Security",
      "description": "Cybersecurity division of the Swiss Kudelski Group that provides managed detection and response, incident response, advisory services and security assessments.",
      "website": "https://kudelskisecurity.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Kudelski Security scores 50 out of 100 (grade D) on the security audit firms criteria. It meets 1 of 4 criteria: public research. It partly meets publishes full reports and audits open-source projects. It does not meet no trackers on website. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/security-audit-firms/kudelski-security/",
      "markdown": "https://privacyratings.com/security-audit-firms/kudelski-security/index.md",
      "answers": {
        "public_reports": {
          "title": "Publishes full reports",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://x41-dsec.de/static/reports/Kudelski-X41-Wire-Report-phase1-20170208.pdf",
          "note": "Some reports are public, such as the joint Wire review with X41 D-Sec, but the firm keeps no list of public reports."
        },
        "open_source_work": {
          "title": "Audits open-source projects",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://x41-dsec.de/static/reports/Kudelski-X41-Wire-Report-phase1-20170208.pdf",
          "note": "Occasional public audits of open-source software, such as the Wire messenger."
        },
        "public_research": {
          "title": "Public research",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://kudelskisecurity.com/research-blog",
          "note": "Publishes regular threat research and vulnerability advisories, and open-source tools on GitHub."
        },
        "no_trackers": {
          "title": "No trackers on website",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads HubSpot, and the privacy notice says the site uses Google Analytics."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:07:14.172Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "least-authority",
      "category": "security-audit-firms",
      "name": "Least Authority",
      "description": "Berlin security consultancy that audits cryptographic protocols, blockchain systems, wallets and privacy software, and develops open-source privacy tools.",
      "website": "https://leastauthority.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 93,
      "coverage": 100,
      "summary": "Least Authority scores 93 out of 100 (grade A) on the security audit firms criteria. It meets 3 of 4 criteria: publishes full reports, audits open-source projects and no trackers on website. It partly meets public research. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/security-audit-firms/least-authority/",
      "markdown": "https://privacyratings.com/security-audit-firms/least-authority/index.md",
      "answers": {
        "public_reports": {
          "title": "Publishes full reports",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://leastauthority.com/security-consulting/published-audits/",
          "note": "The published audits page lists many full client reports each year."
        },
        "open_source_work": {
          "title": "Audits open-source projects",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://leastauthority.com/blog/audit-of-zcash-nu6-1-network-upgrade/",
          "note": "Published audits cover many open-source projects, such as Zcash Zebra for the Zcash Foundation, Holochain and the White Noise Marmot protocol."
        },
        "public_research": {
          "title": "Public research",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://leastauthority.com/community-matters/moonmath-manual/",
          "note": "Publishes the MoonMath Manual on zk-SNARKs and some open-source privacy software, but few advisories."
        },
        "no_trackers": {
          "title": "No trackers on website",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://leastauthority.com/privacy-policy/",
          "note": "No third-party trackers. Self-hosted Matomo runs with cookies disabled and stores only a masked IP address."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:07:14.219Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ncc-group",
      "category": "security-audit-firms",
      "name": "NCC Group",
      "description": "UK cyber security company that provides penetration testing, cryptography reviews, incident response and managed security services.",
      "website": "https://www.nccgroup.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 86,
      "coverage": 100,
      "summary": "NCC Group scores 86 out of 100 (grade B) on the security audit firms criteria. It meets 3 of 4 criteria: publishes full reports, audits open-source projects and public research. It does not meet no trackers on website. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B-.",
      "url": "https://privacyratings.com/security-audit-firms/ncc-group/",
      "markdown": "https://privacyratings.com/security-audit-firms/ncc-group/index.md",
      "answers": {
        "public_reports": {
          "title": "Publishes full reports",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.nccgroup.com/research/",
          "note": "The research section publishes dozens of full public reports, for clients such as WhatsApp, Google, AWS and Zcash."
        },
        "open_source_work": {
          "title": "Audits open-source projects",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.nccgroup.com/research/public-report-ebpf-verifier-code-review/",
          "note": "Public reports cover open-source projects such as the eBPF verifier for the eBPF Foundation, RustCrypto, Ricochet and Zcash Zebra."
        },
        "public_research": {
          "title": "Public research",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.nccgroup.com/research/",
          "note": "Publishes regular research articles, advisories and open-source tools."
        },
        "no_trackers": {
          "title": "No trackers on website",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics and Google Tag Manager."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:07:14.266Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "quarkslab",
      "category": "security-audit-firms",
      "name": "Quarkslab",
      "description": "French security research company that performs audits, reverse engineering and vulnerability research, and develops open-source tools such as LIEF and Triton.",
      "website": "https://www.quarkslab.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 86,
      "coverage": 100,
      "summary": "Quarkslab scores 86 out of 100 (grade B) on the security audit firms criteria. It meets 3 of 4 criteria: publishes full reports, audits open-source projects and public research. It does not meet no trackers on website. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/security-audit-firms/quarkslab/",
      "markdown": "https://privacyratings.com/security-audit-firms/quarkslab/index.md",
      "answers": {
        "public_reports": {
          "title": "Publishes full reports",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://blog.quarkslab.com/tag/audit.html",
          "note": "The blog publishes audit write-ups with full reports for many clients, such as PHP, Bitcoin Core, KubeVirt and Paramiko."
        },
        "open_source_work": {
          "title": "Audits open-source projects",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://blog.quarkslab.com/security-audit-of-php-src.html",
          "note": "Regularly audits open-source projects, many through OSTIF, including php-src, Bitcoin Core, KubeVirt, Notary Project and Paramiko."
        },
        "public_research": {
          "title": "Public research",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://blog.quarkslab.com/",
          "note": "Publishes a regular research blog, advisories and open-source tools."
        },
        "no_trackers": {
          "title": "No trackers on website",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics and Google Tag Manager."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:07:14.324Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "radically-open-security",
      "category": "security-audit-firms",
      "name": "Radically Open Security",
      "description": "Dutch not-for-profit security firm that performs penetration tests and code audits, including for open-source and public-interest projects, and sends most of its profits to the NLnet Foundation.",
      "website": "https://www.radicallyopensecurity.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 93,
      "coverage": 100,
      "summary": "Radically Open Security scores 93 out of 100 (grade A) on the security audit firms criteria. It meets 3 of 4 criteria: publishes full reports, audits open-source projects and no trackers on website. It partly meets public research. It is based in the Netherlands: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/security-audit-firms/radically-open-security/",
      "markdown": "https://privacyratings.com/security-audit-firms/radically-open-security/index.md",
      "answers": {
        "public_reports": {
          "title": "Publishes full reports",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.radicallyopensecurity.com/our-portfolio/",
          "note": "The portfolio links a collection of full public reports hosted on GitHub."
        },
        "open_source_work": {
          "title": "Audits open-source projects",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.radicallyopensecurity.com/our-portfolio/",
          "note": "Public reports include audits of GlobaLeaks, Ushahidi, F-Droid, Tauri and other open-source projects, some funded by the Open Technology Fund."
        },
        "public_research": {
          "title": "Public research",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://github.com/radicallyopensecurity/pentext",
          "note": "Publishes open-source tooling such as the PenText report system and gives occasional talks."
        },
        "no_trackers": {
          "title": "No trackers on website",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/radicallyopensecurity/ros-website/main/ROS_Privacy_Policy__-_V1.0_-_2022.pdf",
          "note": "The privacy policy states the website uses no cookies and does not track or analyze visitors, and the tracker test found none."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:07:14.371Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sec-consult",
      "category": "security-audit-firms",
      "name": "SEC Consult",
      "description": "Austrian cyber security consultancy, part of Atos, that provides penetration testing, red teaming, incident response and security consulting, and runs a vulnerability research lab.",
      "website": "https://sec-consult.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "AT",
        "name": "Austria",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 14,
      "coverage": 100,
      "summary": "SEC Consult scores 14 out of 100 (grade F) on the security audit firms criteria. It meets 1 of 4 criteria: public research. It does not meet publishes full reports, audits open-source projects and no trackers on website. It is based in Austria: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/security-audit-firms/sec-consult/",
      "markdown": "https://privacyratings.com/security-audit-firms/sec-consult/index.md",
      "answers": {
        "public_reports": {
          "title": "Publishes full reports",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The firm does not publish client audit reports."
        },
        "open_source_work": {
          "title": "Audits open-source projects",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No public audits of open-source projects are published."
        },
        "public_research": {
          "title": "Public research",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://sec-consult.com/vulnerability-lab/",
          "note": "The vulnerability lab publishes regular security advisories and research."
        },
        "no_trackers": {
          "title": "No trackers on website",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Tag Manager."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:07:14.418Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "securitum",
      "category": "security-audit-firms",
      "name": "Securitum",
      "description": "Polish penetration testing company in Kraków that tests web, mobile and infrastructure systems and runs the Sekurak security publication and training.",
      "website": "https://securitum.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "PL",
        "name": "Poland",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 86,
      "coverage": 100,
      "summary": "Securitum scores 86 out of 100 (grade B) on the security audit firms criteria. It meets 3 of 4 criteria: publishes full reports, public research and no trackers on website. It partly meets audits open-source projects. It is based in Poland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/security-audit-firms/securitum/",
      "markdown": "https://privacyratings.com/security-audit-firms/securitum/index.md",
      "answers": {
        "public_reports": {
          "title": "Publishes full reports",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://securitum.com/public-reports.html",
          "note": "The public reports page links dozens of full client reports, including Proton VPN, DuckDuckGo VPN and Internxt."
        },
        "open_source_work": {
          "title": "Audits open-source projects",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://securitum.com/public-reports/addy-io-security-audit.pdf",
          "note": "Public reports include audits of open-source products such as addy.io, SimpleLogin and Internxt, commissioned by their vendors; no foundation-funded open-source audit programme is listed."
        },
        "public_research": {
          "title": "Public research",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://securitum.com/pentest-chronicles.html",
          "note": "Publishes regular vulnerability write-ups and CVEs, and runs the Sekurak security publication."
        },
        "no_trackers": {
          "title": "No trackers on website",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://securitum.com/",
          "note": "The tracker test found no trackers or analytics on the home page; it loads only Google Fonts and a public script CDN."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:07:14.468Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "trail-of-bits",
      "category": "security-audit-firms",
      "name": "Trail of Bits",
      "description": "US security research and engineering firm that audits software, cryptography, blockchain and AI systems, and develops open-source security tools such as Slither and Echidna.",
      "website": "https://trailofbits.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 86,
      "coverage": 100,
      "summary": "Trail of Bits scores 86 out of 100 (grade B) on the security audit firms criteria. It meets 3 of 4 criteria: publishes full reports, audits open-source projects and public research. It does not meet no trackers on website. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/security-audit-firms/trail-of-bits/",
      "markdown": "https://privacyratings.com/security-audit-firms/trail-of-bits/index.md",
      "answers": {
        "public_reports": {
          "title": "Publishes full reports",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/trailofbits/publications",
          "note": "The public publications repository lists hundreds of full security review reports."
        },
        "open_source_work": {
          "title": "Audits open-source projects",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/trailofbits/publications/master/reviews/2025-04-ostif-nats-securityreview.pdf",
          "note": "Public reviews include many open-source projects, such as PyPI Warehouse, the Linux kernel release signing process and OSTIF-funded audits like NATS."
        },
        "public_research": {
          "title": "Public research",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://blog.trailofbits.com/",
          "note": "Publishes a regular research blog, conference papers and open-source security tools."
        },
        "no_trackers": {
          "title": "No trackers on website",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads HubSpot and Cloudflare Web Analytics."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:07:14.564Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "x41-d-sec",
      "category": "security-audit-firms",
      "name": "X41 D-Sec",
      "description": "German security firm in Aachen that performs source code audits, penetration tests, fuzzing and red teaming, with many published audits of open-source projects.",
      "website": "https://x41-dsec.de",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 100,
      "coverage": 100,
      "summary": "X41 D-Sec scores 100 out of 100 (grade A) on the security audit firms criteria. It meets 4 of 4 criteria: publishes full reports, audits open-source projects, public research and no trackers on website. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/security-audit-firms/x41-d-sec/",
      "markdown": "https://privacyratings.com/security-audit-firms/x41-d-sec/index.md",
      "answers": {
        "public_reports": {
          "title": "Publishes full reports",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://x41-dsec.de/references/",
          "note": "The references page links around thirty full public audit reports."
        },
        "open_source_work": {
          "title": "Audits open-source projects",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://x41-dsec.de/static/reports/X41-OSTIF-Hickory-DNS-2025-Audit-Report-Public.pdf",
          "note": "Regularly audits open-source projects, many for OSTIF, including Git, Envoy, CRI-O, Hickory DNS and BIND 9."
        },
        "public_research": {
          "title": "Public research",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://x41-dsec.de/news/lab/",
          "note": "Publishes security advisories and research through its lab and blog."
        },
        "no_trackers": {
          "title": "No trackers on website",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://x41-dsec.de/privacy/",
          "note": "The home page loads no third-party scripts, and the privacy policy describes only server log files, with no analytics services."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:07:14.607Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "comp-ai",
      "category": "compliance-automation",
      "name": "Comp AI",
      "description": "Open-source compliance automation platform that helps companies prepare for SOC 2, ISO 27001, HIPAA and GDPR audits by collecting evidence, managing policies and tracking controls. It is offered as a hosted service or can be self-hosted.",
      "website": "https://www.trycomp.ai",
      "source": "https://github.com/trycompai/comp",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": true,
      "pick_reason": "Open-source compliance automation for SOC 2, ISO 27001, HIPAA and GDPR, with evidence collection, policies and control tracking. Most of the code is AGPL-3.0, and it can be self-hosted, so compliance data does not have to live with a closed vendor.",
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "Comp AI scores 38 out of 100 (grade F) on the compliance automation criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets open source, no ads or data sales, independent audit and security headers. It does not meet no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/compliance-automation/comp-ai/",
      "markdown": "https://privacyratings.com/compliance-automation/comp-ai/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/trycompai/comp/blob/main/LICENSE",
          "note": "Open core. Most of the code is AGPL-3.0, but enterprise features in the ee directory need a commercial license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.trycomp.ai/legal/privacy-policy",
          "note": "The website uses Google Analytics, Google Ads and PostHog session recording."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.trycomp.ai/legal/privacy-policy",
          "note": "Paid service with no ads, and personal information is not sold, but Google Ads conversion tracking runs on the website."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://security.trycomp.ai",
          "note": "The trust center lists SOC 2 Type 2 and ISO 27001 compliance, but the reports are only available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.trycomp.ai/legal/privacy-policy",
          "note": "No transparency report or government request policy is published. The privacy policy only says data may be disclosed in response to lawful requests by public authorities."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.trycomp.ai&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.trycomp.ai",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:07:14.657Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "drata",
      "category": "compliance-automation",
      "name": "Drata",
      "description": "Hosted compliance automation platform that monitors controls and collects evidence from connected cloud and business tools for SOC 2, ISO 27001, HIPAA, GDPR and other frameworks, with AI agents for questionnaires and risk management.",
      "website": "https://drata.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 28,
      "coverage": 100,
      "summary": "Drata scores 28 out of 100 (grade F) on the compliance automation criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales, independent audit and security headers. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/compliance-automation/drata/",
      "markdown": "https://privacyratings.com/compliance-automation/drata/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://drata.com/privacy",
          "note": "The privacy notice says advertising partners are allowed to collect information through cookies and tracking technologies on its websites."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://drata.com/privacy",
          "note": "Paid service with no ads, but website data is shared with advertising partners, which may count as a sale or sharing under California law."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://trust.drata.com/",
          "note": "The trust center lists SOC 2 Type 2, ISO/IEC 27001 and penetration test reports, but full reports require requesting access. Only a SOC 3 summary is listed separately."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://drata.com/privacy",
          "note": "No transparency report is published. The privacy notice only says data may be shared in response to lawful requests by law enforcement."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.drata.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.drata.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:07:14.709Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "eramba",
      "category": "compliance-automation",
      "name": "Eramba",
      "description": "Governance, risk and compliance software for managing risks, controls, policies, audits and frameworks such as ISO 27001, SOC 2, NIS2 and GDPR. A free Community edition and a paid Enterprise edition run on premises, and Enterprise is also offered as SaaS.",
      "website": "https://www.eramba.org",
      "license": null,
      "platforms": [
        "linux",
        "web"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Eramba scores 25 out of 100 (grade F) on the compliance automation criteria. It partly meets open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/compliance-automation/eramba/",
      "markdown": "https://privacyratings.com/compliance-automation/eramba/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.eramba.org/faqs",
          "note": "Source available but not open source. The license allows internal use only and forbids modification and redistribution."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Tag Manager and a Google Ads tag."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.eramba.org/",
          "note": "Funded by Enterprise licenses and services with no ads in the software, but the website runs a Google Ads conversion tag."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:41.681Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hyperproof",
      "category": "compliance-automation",
      "name": "Hyperproof",
      "description": "Hosted compliance and risk management platform that maps controls across frameworks such as SOC 2, ISO 27001, NIST and FedRAMP, collects evidence from connected tools and manages audits.",
      "website": "https://hyperproof.io",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 31,
      "coverage": 100,
      "summary": "Hyperproof scores 31 out of 100 (grade F) on the compliance automation criteria. It meets 2 of 8 criteria: TLS configuration and security headers. It partly meets no ads or data sales and independent audit. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/compliance-automation/hyperproof/",
      "markdown": "https://privacyratings.com/compliance-automation/hyperproof/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://hyperproof.io/privacy-policy/",
          "note": "The privacy policy says advertising and analytics partners use cookies, pixels and device identifiers, and the website loads HubSpot, 6sense, ZoomInfo, LinkedIn and Reddit tags."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://hyperproof.io/privacy-policy/",
          "note": "Paid service with no ads, and it says it is not in the business of selling information, but advertising partners use cookies to recognize visitors across services."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://hyperproof.io/security-trust/",
          "note": "States SOC 2 compliance and FedRAMP Moderate authorization for Hyperproof Gov, but the reports are not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://hyperproof.io/privacy-policy/",
          "note": "No transparency report is published. The privacy policy only says information may be shared to comply with legal process or government requests."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=hyperproof.app&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=hyperproof.app",
          "note": "Grade A+ (115/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "G2",
            "host": "tracking.g2crowd.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "snap.licdn.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Ads",
            "host": "bat.bing.com",
            "effect": "no"
          },
          {
            "name": "VWO",
            "host": "dev.visualwebsiteoptimizer.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:31:58.161Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "probo",
      "category": "compliance-automation",
      "name": "Probo",
      "description": "Open-source governance, risk and compliance platform for SOC 2, ISO 27001 and similar programs, covering risks, controls, vendors, access reviews and documents. It can be self-hosted, used as Probo Cloud, or paired with a managed compliance officer service.",
      "website": "https://www.probo.com",
      "source": "https://github.com/getprobo/probo",
      "license": "MIT",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Probo scores 50 out of 100 (grade D) on the compliance automation criteria. It meets 4 of 8 criteria: open source, no ads or data sales, TLS configuration and security headers. It does not meet no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/compliance-automation/probo/",
      "markdown": "https://privacyratings.com/compliance-automation/probo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/getprobo/probo/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.probo.com/cookie-policy",
          "note": "The website uses PostHog Cloud analytics with a one-year cookie."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.probo.com/privacy",
          "note": "Funded by paid plans and services. The privacy policy says personal data is not sold or shared for cross-context behavioral advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.probo.com/privacy",
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=us.probo.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=us.probo.com",
          "note": "Grade A+ (110/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:07:14.812Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "scrut",
      "category": "compliance-automation",
      "name": "Scrut Automation",
      "description": "Hosted governance, risk and compliance platform that monitors cloud and SaaS systems and collects evidence for SOC 2, ISO 27001, GDPR, HIPAA and other frameworks, with vendor risk management and trust center pages.",
      "website": "https://www.scrut.io",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "IN",
        "name": "India",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 34,
      "coverage": 100,
      "summary": "Scrut Automation scores 34 out of 100 (grade F) on the compliance automation criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It partly meets independent audit and security headers. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in India: Not in the Five, Nine or Fourteen Eyes. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/compliance-automation/scrut/",
      "markdown": "https://privacyratings.com/compliance-automation/scrut/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.scrut.io/privacy-policy",
          "note": "The privacy policy describes cookies and web beacons used to analyze visitor behavior, and the website loads HubSpot, Microsoft Clarity and Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.scrut.io/privacy-policy",
          "note": "Paid service with no ads. The privacy policy states that no user or customer data is sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.scrut.io/company/security",
          "note": "States SOC 2 and ISO 27001 audits, but the reports are only available through its trust center."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.scrut.io/privacy-policy",
          "note": "No transparency report is published. The privacy policy only says data may be disclosed in response to legal process such as a search warrant, court order or subpoena."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.scrut.io&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.scrut.io",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hsforms.net",
            "effect": "no"
          },
          {
            "name": "Microsoft Clarity",
            "host": "www.clarity.ms",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:30:31.391Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "secureframe",
      "category": "compliance-automation",
      "name": "Secureframe",
      "description": "Hosted compliance automation platform that integrates with cloud, identity and HR systems to monitor controls and collect evidence for SOC 2, ISO 27001, FedRAMP, CMMC, HIPAA and other frameworks, with AI tools for questionnaires and risk management.",
      "website": "https://secureframe.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 28,
      "coverage": 100,
      "summary": "Secureframe scores 28 out of 100 (grade F) on the compliance automation criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales, independent audit and security headers. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/compliance-automation/secureframe/",
      "markdown": "https://privacyratings.com/compliance-automation/secureframe/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://secureframe.com/privacy",
          "note": "The privacy policy names Google Analytics and describes cross-site tracking for advertising, and the website loads PostHog and HubSpot."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://secureframe.com/privacy",
          "note": "Paid service with no ads, and it says it does not sell data for money, but website activity is used for personalized advertising of its own services on other sites."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://trust.secureframe.com/",
          "note": "The trust center lists SOC 2 Type 2, ISO 27001, FedRAMP 20x and CMMC Level 2 assessments, but the full reports are only available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://secureframe.com/privacy",
          "note": "No transparency report or government request policy is published. The privacy policy only says data may be disclosed in response to lawful requests by public authorities."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.secureframe.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.secureframe.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google DoubleClick",
            "host": "stats.g.doubleclick.net",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:07:14.863Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sprinto",
      "category": "compliance-automation",
      "name": "Sprinto",
      "description": "Hosted compliance automation platform that monitors cloud, identity and SaaS systems and collects evidence for SOC 2, ISO 27001, HIPAA, GDPR and many other frameworks, with vendor risk management and AI governance features.",
      "website": "https://sprinto.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Sprinto scores 25 out of 100 (grade F) on the compliance automation criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales and independent audit. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/compliance-automation/sprinto/",
      "markdown": "https://privacyratings.com/compliance-automation/sprinto/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://sprinto.com/privacy-policy/",
          "note": "The privacy policy says ad networks, analytics providers and marketing providers may track website visitors for cross-context behavioral advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://sprinto.com/privacy-policy/",
          "note": "Paid service with no ads, but website data is shared with ad networks for cross-context behavioral advertising, with an opt-out."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://trust.sprinto.com/",
          "note": "The trust center lists SOC 2 and ISO 27001 compliance, but the reports are only available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://sprinto.com/privacy-policy/",
          "note": "No transparency report or government request policy is published. The privacy policy only lists law enforcement and government authorities as possible recipients."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.sprinto.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.sprinto.com",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:07:14.917Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "strike-graph",
      "category": "compliance-automation",
      "name": "Strike Graph",
      "description": "Hosted compliance platform that builds security programs, collects evidence and runs audits for SOC 2, ISO 27001, HIPAA, CMMC and other frameworks.",
      "website": "https://www.strikegraph.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Strike Graph scores 25 out of 100 (grade F) on the compliance automation criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales and independent audit. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B-.",
      "url": "https://privacyratings.com/compliance-automation/strike-graph/",
      "markdown": "https://privacyratings.com/compliance-automation/strike-graph/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.strikegraph.com/privacy",
          "note": "The privacy policy names Google Analytics and describes advertising identifiers, and the website loads HubSpot and Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.strikegraph.com/privacy",
          "note": "Paid service with no ads in the product, but the privacy policy lists providing advertising to a visitor's browser or device as a use of collected data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.strikegraph.com/blog/strike-graph-achieves-soc-2-type-2",
          "note": "States SOC 2 Type 2 compliance, but no report is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.strikegraph.com/privacy",
          "note": "No transparency report is published. The privacy policy only says information may be disclosed to comply with subpoenas, warrants, court orders or government requests."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=grc.strikegraph.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=grc.strikegraph.com",
          "note": "Grade B- (65/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js-eu1.hsforms.net",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:32:16.656Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "thoropass",
      "category": "compliance-automation",
      "name": "Thoropass",
      "description": "Compliance platform and audit firm that combines compliance automation software with in-house SOC 2, ISO 27001, HITRUST, PCI DSS and other audits, plus penetration testing, in one service. Formerly known as Laika.",
      "website": "https://www.thoropass.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 22,
      "coverage": 100,
      "summary": "Thoropass scores 22 out of 100 (grade F) on the compliance automation criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales and security headers. It does not meet open source, no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/compliance-automation/thoropass/",
      "markdown": "https://privacyratings.com/compliance-automation/thoropass/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.thoropass.com/privacy-policy",
          "note": "The privacy policy names Google Analytics and FullStory, and the website loads HubSpot and Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.thoropass.com/privacy-policy",
          "note": "Paid service with no ads, and it says it does not sell personal information, but advertising partners use website cookies to show Thoropass ads after a visit."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.thoropass.com/privacy-policy",
          "note": "No transparency report or government request policy is published. The privacy policy only says data may be disclosed to law enforcement when legally required."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=login.thoropass.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=login.thoropass.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:21:27.796Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vanta",
      "category": "compliance-automation",
      "name": "Vanta",
      "description": "Hosted compliance automation platform that connects to a company's cloud, identity and HR tools to collect evidence and monitor controls for SOC 2, ISO 27001, HIPAA, GDPR and other frameworks. It also offers vendor risk management and public trust center pages.",
      "website": "https://www.vanta.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 41,
      "coverage": 100,
      "summary": "Vanta scores 41 out of 100 (grade D) on the compliance automation criteria. It meets 2 of 8 criteria: tells users about requests and TLS configuration. It partly meets no ads or data sales, independent audit, transparency report and security headers. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A-.",
      "url": "https://privacyratings.com/compliance-automation/vanta/",
      "markdown": "https://privacyratings.com/compliance-automation/vanta/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.vanta.com/legal/privacy",
          "note": "The website uses Google Tag Manager, Intercom and HubSpot, and the privacy policy says cookie data is shared with ad networks and analytics providers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.vanta.com/legal/privacy",
          "note": "Paid service with no ads, but website cookie data is shared with ad networks to show Vanta ads on other websites."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.vanta.com/company/security",
          "note": "Vanta has a SOC 2 Type II attestation, ISO 27001 certification and yearly penetration tests, but the reports are only available through its trust center."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.vanta.com/legal/privacy",
          "note": "The privacy policy describes how government demands are handled, including redirecting them to the customer, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.vanta.com/legal/privacy",
          "note": "Vanta promises reasonable notice to the customer before a compelled disclosure, unless legally prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.vanta.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.vanta.com",
          "note": "Grade A- (85/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hsforms.net",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:08:14.116Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "big-ass-data-broker-opt-out-list",
      "category": "data-broker-removal",
      "name": "Big Ass Data Broker Opt-Out List",
      "description": "Free, community-maintained guide on GitHub that lists data brokers and people-search sites with instructions for opting out of each, ranked by priority. It is a do-it-yourself guide, not a service, so no personal data is handed to a third party.",
      "website": "https://github.com/yaelwrites/Big-Ass-Data-Broker-Opt-Out-List",
      "source": "https://github.com/yaelwrites/Big-Ass-Data-Broker-Opt-Out-List",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Big Ass Data Broker Opt-Out List scores 80 out of 100 (grade B) on the data broker removal criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/data-broker-removal/big-ass-data-broker-opt-out-list/",
      "markdown": "https://privacyratings.com/data-broker-removal/big-ass-data-broker-opt-out-list/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/yaelwrites/Big-Ass-Data-Broker-Opt-Out-List/blob/master/LICENSE.md",
          "note": "All content is public under CC BY-NC-SA 4.0, a source-available non-commercial license that is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/yaelwrites/Big-Ass-Data-Broker-Opt-Out-List",
          "note": "A plain Markdown document with no scripts, analytics or tracking of its own."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/yaelwrites/Big-Ass-Data-Broker-Opt-Out-List",
          "note": "Free guide supported by optional donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:19.651Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "deleteme",
      "category": "data-broker-removal",
      "name": "DeleteMe",
      "description": "Paid service from Abine that searches data broker and people-search sites for a subscriber's personal information, submits removal requests, and repeats the process through the year with periodic reports. It needs the subscriber's name, addresses and other details to work.",
      "website": "https://joindeleteme.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 28,
      "coverage": 100,
      "summary": "DeleteMe scores 28 out of 100 (grade F) on the data broker removal criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It partly meets security headers. It does not meet open source, no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/data-broker-removal/deleteme/",
      "markdown": "https://privacyratings.com/data-broker-removal/deleteme/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://joindeleteme.com/",
          "note": "The website loads Google Tag Manager through a server-side tagging host, and the privacy center lists advertising and analytics cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://privacy.joindeleteme.com/policies?name=terms-of-service",
          "note": "Funded by subscriptions. The terms state Abine will never sell the personal information users submit, though it must be shared with data brokers to process opt-outs."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": "https://joindeleteme.com/security/",
          "note": "SOC 2 Type 2 compliance is claimed, but no audit report or summary is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=joindeleteme.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=joindeleteme.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Zendesk",
            "host": "static.zdassets.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:19.916Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "easyoptouts",
      "category": "data-broker-removal",
      "name": "EasyOptOuts",
      "description": "Subscription service that automatically submits opt-out requests to people-search and data broker sites for a user and rescans them regularly. It needs the user's name, addresses and other details to work.",
      "website": "https://easyoptouts.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "EasyOptOuts scores 38 out of 100 (grade F) on the data broker removal criteria. It meets 2 of 8 criteria: no trackers or telemetry and no ads or data sales. It partly meets TLS configuration. It does not meet open source, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade C+.",
      "url": "https://privacyratings.com/data-broker-removal/easyoptouts/",
      "markdown": "https://privacyratings.com/data-broker-removal/easyoptouts/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://easyoptouts.com/security",
          "note": "The security page states no third-party analytics or advertising pixels are used, and the privacy policy states no data is shared with ads or analytics platforms."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://easyoptouts.com/security",
          "note": "Funded by subscriptions. The security page states user information is never sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=easyoptouts.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=easyoptouts.com",
          "note": "Grade C+ (60/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "C+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:19.871Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "incogni",
      "category": "data-broker-removal",
      "name": "Incogni",
      "description": "Paid service, part of the same group as Surfshark, that sends removal requests to data brokers and people-search sites on a subscriber's behalf and repeats them regularly. It needs the subscriber's name, addresses and contact details to work.",
      "website": "https://incogni.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "Incogni scores 38 out of 100 (grade F) on the data broker removal criteria. It meets 3 of 8 criteria: no ads or data sales, independent audit and TLS configuration. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/data-broker-removal/incogni/",
      "markdown": "https://privacyratings.com/data-broker-removal/incogni/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://incogni.com/legal/cookie-policy",
          "note": "The cookie policy lists Google Analytics and Google Ads cookies for analytics and marketing, and the website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://incogni.com/legal/privacy-policy",
          "note": "Funded by subscriptions. The privacy policy states customer personal information is not and has never been sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://blog.incogni.com/wp-content/uploads/2025/08/Incogni-ISAE-3000-Report-FInal.pdf",
          "note": "Deloitte published a full ISAE 3000 limited assurance report on data broker removals and on customer data not being sold. It is not a security audit."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=incogni.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=incogni.com",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "www.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:20.095Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "kanary",
      "category": "data-broker-removal",
      "name": "Kanary",
      "description": "Data broker removal service that scans people-search sites, search results and data leaks for a user's personal information and submits removal requests, with a free tier and paid plans. It needs the user's name, locations and other details to work.",
      "website": "https://www.kanary.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 19,
      "coverage": 100,
      "summary": "Kanary scores 19 out of 100 (grade F) on the data broker removal criteria. It meets 1 of 8 criteria: no ads or data sales. It partly meets TLS configuration. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/data-broker-removal/kanary/",
      "markdown": "https://privacyratings.com/data-broker-removal/kanary/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.kanary.com/privacy-and-security",
          "note": "The website loads PostHog Cloud and Framer analytics, and the privacy page states PostHog is used for app analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.kanary.com/privacy-and-security",
          "note": "Funded by subscriptions. The privacy page states Kanary never sells or shares personal information."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published. SOC 2 compliance is claimed, but no report or summary is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.kanary.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.kanary.com",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "PostHog",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:20.286Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "optery",
      "category": "data-broker-removal",
      "name": "Optery",
      "description": "Data broker removal service that scans people-search sites for a user's personal information, shows screenshots of what it finds, and submits opt-out requests. A free tier offers scans and self-service guides, and paid plans automate removals.",
      "website": "https://www.optery.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 22,
      "coverage": 100,
      "summary": "Optery scores 22 out of 100 (grade F) on the data broker removal criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales and security headers. It does not meet open source, no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/data-broker-removal/optery/",
      "markdown": "https://privacyratings.com/data-broker-removal/optery/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.optery.com/privacy-policy/",
          "note": "The website loads Google Analytics and Amplitude, and the privacy policy describes retargeted advertising with vendors such as Google."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.optery.com/privacy-policy/",
          "note": "Funded by subscriptions. The privacy policy states Optery does not sell or rent personal data, though its retargeted advertising with Google may count as sharing under the CCPA."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.optery.com/privacy-policy/",
          "note": "A SOC 2 Type II audit is claimed, but no audit report or summary is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.optery.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.optery.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Amplitude",
            "host": "cdn.amplitude.com",
            "effect": "no"
          },
          {
            "name": "Crisp",
            "host": "client.crisp.chat",
            "effect": "none"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "WordPress.com Stats",
            "host": "stats.wp.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:20.182Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "permission-slip",
      "category": "data-broker-removal",
      "name": "Permission Slip",
      "description": "Mobile app, created by Consumer Reports and now run by DeleteMe, that sends opt-out and deletion requests to companies and data brokers on the user's behalf. Basic requests are free, and a paid tier adds automated data broker removals.",
      "website": "https://joindeleteme.com/permission-slip/",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Permission Slip scores 20 out of 100 (grade F) on the data broker removal criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/data-broker-removal/permission-slip/",
      "markdown": "https://privacyratings.com/data-broker-removal/permission-slip/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://play.google.com/store/apps/datasafety?id=org.consumerreports.permissionslip.production",
          "note": "The Play data safety listing declares required collection of app interactions, crash logs and device IDs for analytics, and the website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://privacy.joindeleteme.com/policies?name=terms-of-service",
          "note": "Funded by subscriptions, with no ads in the app. DeleteMe's terms state it will never sell the personal information users submit."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Zendesk",
            "host": "static.zdassets.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:20.175Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "privacy-bee",
      "category": "data-broker-removal",
      "name": "Privacy Bee",
      "description": "Data broker removal service that scans hundreds of people-search and marketing data sites for a user's personal information and sends removal requests, with a free scan and paid plans. It needs the user's name, addresses and other details to work.",
      "website": "https://privacybee.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 47,
      "coverage": 100,
      "summary": "Privacy Bee scores 47 out of 100 (grade D) on the data broker removal criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It partly meets no trackers or telemetry, transparency report, tells users about requests and security headers. It does not meet open source and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/data-broker-removal/privacy-bee/",
      "markdown": "https://privacyratings.com/data-broker-removal/privacy-bee/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://privacybee.com/privacy-policy/",
          "note": "The privacy policy states no third-party analytics or ad trackers are used, but first-party pageview and marketing measurement runs with consent only where required."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://privacybee.com/privacy-policy/",
          "note": "Funded by subscriptions. The privacy policy states personal data is never sold and not shared for behavioral advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published. SOC 2 certification is claimed, but no report or summary is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://privacybee.com/privacy-policy/",
          "note": "The privacy policy describes when data is disclosed for legal demands and that overbroad requests may be disputed, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://privacybee.com/privacy-policy/",
          "note": "The privacy policy says users will be notified of legal demands when appropriate in the company's judgment, unless prohibited or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=privacybee.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=privacybee.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:20.151Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "1-1-1-1",
      "category": "mobile-security-apps",
      "name": "1.1.1.1",
      "description": "Cloudflare app that sends DNS queries to the 1.1.1.1 resolver over encrypted DNS, with an optional WARP VPN that encrypts all device traffic.",
      "website": "https://one.one.one.one/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "1.1.1.1 scores 20 out of 100 (grade F) on the mobile security apps criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/mobile-security-apps/1-1-1-1/",
      "markdown": "https://privacyratings.com/mobile-security-apps/1-1-1-1/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.cloudflare.onedotonedotonedotone/latest/",
          "note": "The Exodus report finds Google Firebase Analytics and Google Crashlytics in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.cloudflare.com/application/privacypolicy/",
          "note": "Funded by paid WARP+ plans; the app privacy policy states personal information is not sold or rented."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit of the app is published; the KPMG examination covers only the public resolver service."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:44.323Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "afwall",
      "category": "mobile-security-apps",
      "name": "AFWall+",
      "description": "AFWall+ is an iptables front end for rooted Android devices that controls which apps can reach the network over Wi-Fi, mobile data, VPN and LAN.",
      "website": "https://github.com/ukanth/afwall",
      "source": "https://github.com/ukanth/afwall",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "AFWall+ scores 80 out of 100 (grade B) on the mobile security apps criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mobile-security-apps/afwall/",
      "markdown": "https://privacyratings.com/mobile-security-apps/afwall/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ukanth/afwall/blob/beta/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/dev.ukanth.ufirewall/latest/",
          "note": "The Exodus report finds no trackers in the app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/ukanth/afwall",
          "note": "Free app funded by donations and an optional paid unlocker, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:44.324Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "app-manager",
      "category": "mobile-security-apps",
      "name": "App Manager",
      "description": "Open source Android package manager that shows app components, permissions, trackers and signatures, and can block trackers, freeze apps and change permissions, with more control on rooted devices or through ADB.",
      "website": "https://muntashir.dev/AppManager/",
      "source": "https://github.com/MuntashirAkon/AppManager",
      "license": null,
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "App Manager scores 80 out of 100 (grade B) on the mobile security apps criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mobile-security-apps/app-manager/",
      "markdown": "https://privacyratings.com/mobile-security-apps/app-manager/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/MuntashirAkon/AppManager/blob/master/COPYING",
          "note": "GPL-3.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/io.github.muntashirakon.AppManager/latest/",
          "note": "The Exodus report finds no trackers, and the website uses only a language-preference cookie."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/MuntashirAkon/AppManager",
          "note": "Free volunteer project distributed through F-Droid and GitHub, with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:20.177Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "blokada",
      "category": "mobile-security-apps",
      "name": "Blokada",
      "description": "Android and iOS app that blocks ads and trackers in all apps without root. Blokada 5 filters on the device, and Blokada 6 uses a subscription cloud DNS service.",
      "website": "https://blokada.org",
      "source": "https://github.com/blokadaorg/blokada",
      "license": "MPL-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "SE",
        "name": "Sweden",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Blokada scores 65 out of 100 (grade C) on the mobile security apps criteria. It meets 2 of 4 criteria: no trackers or telemetry and no ads or data sales. It partly meets open source. It does not meet independent audit. It is based in Sweden: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/mobile-security-apps/blokada/",
      "markdown": "https://privacyratings.com/mobile-security-apps/blokada/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/blokadaorg/blokada/blob/main/LICENSE",
          "note": "Apps are open source under MPL-2.0; the Blokada Cloud server code used by Blokada 6 is not published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.blokada.sex/latest/",
          "note": "The Exodus reports for Blokada 6 and Blokada 5 find no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://community.blokada.org/t/privacy-policy/6",
          "note": "Funded by subscriptions; the privacy policy limits data sharing to payment and email providers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:44.683Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bouncer",
      "category": "mobile-security-apps",
      "name": "Bouncer",
      "description": "Android app that grants app permissions temporarily and revokes them after the app is closed. It is no longer available on Google Play.",
      "website": "https://samruston.com/",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Bouncer scores 50 out of 100 (grade D) on the mobile security apps criteria. It meets 2 of 4 criteria: no trackers or telemetry and no ads or data sales. It does not meet open source and independent audit.",
      "url": "https://privacyratings.com/mobile-security-apps/bouncer/",
      "markdown": "https://privacyratings.com/mobile-security-apps/bouncer/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://samruston.com/privacy/",
          "note": "The developer's app privacy policy lists no analytics or advertising services."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://samruston.com/privacy/",
          "note": "Sold as a paid app with no ads; the privacy policy lists no advertising services."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:44.708Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "camwings",
      "category": "mobile-security-apps",
      "name": "CamWings",
      "description": "Android app that disables the device cameras system-wide so that apps, including background processes, cannot use them until access is restored.",
      "website": "https://schiffer.tech/camwings-mobile.html",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "CamWings scores 50 out of 100 (grade D) on the mobile security apps criteria. It meets 2 of 4 criteria: no trackers or telemetry and no ads or data sales. It does not meet open source and independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/mobile-security-apps/camwings/",
      "markdown": "https://privacyratings.com/mobile-security-apps/camwings/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://schiffer.tech/software/camwings_m/license.txt",
          "note": "Closed source freeware license that forbids modification."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.schiffertech.camwings/latest/",
          "note": "The Exodus report finds no trackers, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://schiffer.tech/privacy.html",
          "note": "Free app with no ads; the privacy policy lists no advertising or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:45.133Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "exodus",
      "category": "mobile-security-apps",
      "name": "Exodus",
      "description": "Android app that shows which trackers and permissions each installed app has, using reports from the Exodus Privacy database of scanned APKs.",
      "website": "https://exodus-privacy.eu.org/en/page/what/#android-app",
      "source": "https://github.com/Exodus-Privacy/exodus-android-app",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Exodus scores 80 out of 100 (grade B) on the mobile security apps criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/mobile-security-apps/exodus/",
      "markdown": "https://privacyratings.com/mobile-security-apps/exodus/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Exodus-Privacy/exodus-android-app/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://exodus-privacy.eu.org/en/page/privacy-policy/",
          "note": "The privacy policy states the app collects no personal information and contains no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://exodus-privacy.eu.org/en/page/contribute/",
          "note": "Run by a French non-profit funded by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:56.121Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fing-app",
      "category": "mobile-security-apps",
      "name": "Fing App",
      "description": "Network scanner app that lists the devices on a Wi-Fi network and runs security and speed checks. Some features need a paid plan or Fing hardware.",
      "website": "https://www.fing.com/app/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "IE",
        "name": "Ireland",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Fing App scores 0 out of 100 (grade F) on the mobile security apps criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in Ireland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/mobile-security-apps/fing-app/",
      "markdown": "https://privacyratings.com/mobile-security-apps/fing-app/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.overlook.android.fing/latest/",
          "note": "The Exodus report finds six trackers including Google Analytics and Facebook SDKs, and the website loads Google Analytics, Google Tag Manager and Meta Pixel."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.fing.com/fing-privacy-policy/",
          "note": "The privacy policy allows sharing device identifiers and hashed emails with advertising partners for ad targeting."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cookiebot",
            "host": "consentcdn.cookiebot.com",
            "effect": "none"
          },
          {
            "name": "Facebook SDK",
            "host": "connect.facebook.net",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google DoubleClick",
            "host": "googleads.g.doubleclick.net",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Ads",
            "host": "bat.bing.com",
            "effect": "no"
          },
          {
            "name": "TikTok Pixel",
            "host": "analytics.tiktok.com",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "trustpilot.com",
            "effect": "none"
          },
          {
            "name": "WordPress.com Stats",
            "host": "stats.wp.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:45.372Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "greentooth",
      "category": "mobile-security-apps",
      "name": "Greentooth",
      "description": "Android app that turns Bluetooth off automatically after the last connected device disconnects. It is no longer maintained.",
      "website": "https://gitlab.com/nbergman/greentooth",
      "source": "https://gitlab.com/nbergman/greentooth",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Greentooth scores 80 out of 100 (grade B) on the mobile security apps criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mobile-security-apps/greentooth/",
      "markdown": "https://privacyratings.com/mobile-security-apps/greentooth/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/nbergman/greentooth/-/blob/master/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.smilla.greentooth/latest/",
          "note": "The Exodus report finds no trackers in the app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gitlab.com/nbergman/greentooth",
          "note": "Free open-source app with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:44.684Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "insular",
      "category": "mobile-security-apps",
      "name": "Insular",
      "description": "Fully open-source fork of Island that isolates Android apps in a work profile, where they can be cloned, frozen or hidden. Distributed through F-Droid.",
      "website": "https://secure-system.gitlab.io/Insular/",
      "source": "https://gitlab.com/secure-system/Insular",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Insular scores 80 out of 100 (grade B) on the mobile security apps criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mobile-security-apps/insular/",
      "markdown": "https://privacyratings.com/mobile-security-apps/insular/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/secure-system/Insular/-/blob/dev-ci/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.oasisfeng.island.fdroid/latest/",
          "note": "The Exodus report for the F-Droid build finds no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.oasisfeng.island.fdroid/latest/",
          "note": "Free app with no ads; the Exodus report finds no advertising libraries."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:45.304Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "invizible-pro",
      "category": "mobile-security-apps",
      "name": "InviZible Pro",
      "description": "Open source Android app that routes device traffic through Tor, encrypts DNS with DNSCrypt, and gives access to the I2P network, with a per-app firewall. Works with or without root.",
      "website": "https://invizible.net/en/",
      "source": "https://github.com/Gedsh/InviZible",
      "license": "GPL-3.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "InviZible Pro scores 80 out of 100 (grade B) on the mobile security apps criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mobile-security-apps/invizible-pro/",
      "markdown": "https://privacyratings.com/mobile-security-apps/invizible-pro/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Gedsh/InviZible/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://invizible.net/en/privacy/",
          "note": "The privacy policy states the app collects and shares no personal data, and the Exodus report for the Google Play build finds no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://invizible.net/en/donate/",
          "note": "Free app supported by donations, with no ads. The privacy policy states no user data is collected."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:21.659Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "island",
      "category": "mobile-security-apps",
      "name": "Island",
      "description": "Android sandbox that uses a work profile to clone selected apps, isolate them from personal data, and freeze them when not in use.",
      "website": "https://island.oasisfeng.com",
      "source": "https://github.com/oasisfeng/island",
      "license": "Apache-2.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Island scores 50 out of 100 (grade D) on the mobile security apps criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/mobile-security-apps/island/",
      "markdown": "https://privacyratings.com/mobile-security-apps/island/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/oasisfeng/island/blob/master/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.oasisfeng.island/latest/",
          "note": "The Exodus report for the Google Play build finds Google Analytics, Google Firebase Analytics and Google Crashlytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.oasisfeng.island/latest/",
          "note": "Free app with no ads; the Exodus report finds no advertising libraries."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:44.923Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "netguard",
      "category": "mobile-security-apps",
      "name": "NetGuard",
      "description": "A firewall app for Android, which does not require root.",
      "website": "https://netguard.me",
      "source": "https://github.com/M66B/NetGuard",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "NetGuard scores 80 out of 100 (grade B) on the mobile security apps criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mobile-security-apps/netguard/",
      "markdown": "https://privacyratings.com/mobile-security-apps/netguard/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/M66B/NetGuard/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/M66B/NetGuard/blob/master/README.md",
          "note": "The README states the app has no tracking or analytics, and the Exodus report finds no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/M66B/NetGuard/blob/master/README.md",
          "note": "Funded by optional paid pro features, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:45.105Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "orbot",
      "category": "mobile-security-apps",
      "name": "Orbot",
      "description": "Android and iOS app from the Guardian Project that routes app traffic through the Tor network as a VPN or proxy.",
      "website": "https://orbot.app/en/",
      "source": "https://github.com/guardianproject/orbot-android",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Orbot scores 80 out of 100 (grade B) on the mobile security apps criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mobile-security-apps/orbot/",
      "markdown": "https://privacyratings.com/mobile-security-apps/orbot/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/guardianproject/orbot-android/blob/master/LICENSE",
          "note": "BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://orbot.app/en/privacy-policy/",
          "note": "The privacy policy states Orbot collects no activity data and uses no third-party analytics; the Exodus report finds no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://orbot.app/en/donate/",
          "note": "Developed by the Guardian Project, funded by grants and donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:45.764Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "pcapdroid",
      "category": "mobile-security-apps",
      "name": "PCAPdroid",
      "description": "Open source Android app that captures and inspects the network traffic of other apps without root, using a local VPN. It can export PCAP files and decrypt TLS, with optional paid firewall and malware detection features.",
      "website": "https://emanuele-f.github.io/PCAPdroid/",
      "source": "https://github.com/emanuele-f/PCAPdroid",
      "license": "GPL-3.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "PCAPdroid scores 80 out of 100 (grade B) on the mobile security apps criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mobile-security-apps/pcapdroid/",
      "markdown": "https://privacyratings.com/mobile-security-apps/pcapdroid/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/emanuele-f/PCAPdroid/blob/master/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://emanuele-f.github.io/PCAPdroid/privacy",
          "note": "The privacy policy states the app collects no information and processes traffic only on the device, and the Exodus report finds no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://emanuele-f.github.io/PCAPdroid/paid_features",
          "note": "Funded by optional paid features and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:20.971Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "privatelock",
      "category": "mobile-security-apps",
      "name": "PrivateLock",
      "description": "Android app that locks the screen when the accelerometer detects movement above a set threshold.",
      "website": "https://github.com/wesaphzt/privatelock",
      "source": "https://github.com/wesaphzt/privatelock",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "PrivateLock scores 80 out of 100 (grade B) on the mobile security apps criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mobile-security-apps/privatelock/",
      "markdown": "https://privacyratings.com/mobile-security-apps/privatelock/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/wesaphzt/privatelock/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/wesaphzt/privatelock/blob/master/README.md",
          "note": "The README states the app is free from ads and tracking, and the Exodus report finds no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/wesaphzt/privatelock/blob/master/README.md",
          "note": "Free app with no ads, supported by optional donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:45.133Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "rethinkdns-firewall",
      "category": "mobile-security-apps",
      "name": "RethinkDNS & Firewall",
      "description": "Open-source DNS-based content blocker and firewall for Android that does not require root.",
      "website": "https://rethinkdns.com",
      "source": "https://github.com/celzero/rethink-app",
      "license": "Apache-2.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "RethinkDNS & Firewall scores 80 out of 100 (grade B) on the mobile security apps criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mobile-security-apps/rethinkdns-firewall/",
      "markdown": "https://privacyratings.com/mobile-security-apps/rethinkdns-firewall/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/celzero/rethink-app/blob/main/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://rethinkdns.com/privacy",
          "note": "The F-Droid build has no trackers, and Crashlytics crash reporting in the Play Store build is opt-in."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://rethinkdns.com/privacy",
          "note": "The privacy policy states no data is sold and the app has no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:45.314Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "shelter",
      "category": "mobile-security-apps",
      "name": "Shelter",
      "description": "Open source Android app that uses the work profile feature to run cloned or separately installed apps in an isolated space, and can freeze them when they are not in use.",
      "website": "https://gitea.angry.im/PeterCxy/Shelter",
      "source": "https://gitea.angry.im/PeterCxy/Shelter",
      "license": null,
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Shelter scores 80 out of 100 (grade B) on the mobile security apps criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mobile-security-apps/shelter/",
      "markdown": "https://privacyratings.com/mobile-security-apps/shelter/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitea.angry.im/PeterCxy/Shelter/src/branch/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/net.typeblog.shelter/latest/",
          "note": "The Exodus report finds no trackers, and the app does not request internet access."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gitea.angry.im/PeterCxy/Shelter",
          "note": "Free volunteer project distributed through F-Droid, with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:21.955Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "spectre",
      "category": "mobile-security-apps",
      "name": "Spectre",
      "description": "Android app that scans Bluetooth, Wi-Fi, cellular and GNSS signals, with tools for wireless security testing.",
      "website": "https://github.com/thomasbuilds/Spectre",
      "source": "https://github.com/thomasbuilds/Spectre",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Spectre scores 80 out of 100 (grade B) on the mobile security apps criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mobile-security-apps/spectre/",
      "markdown": "https://privacyratings.com/mobile-security-apps/spectre/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/thomasbuilds/Spectre/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/thomasbuilds/Spectre/blob/main/README.md",
          "note": "The README states the app has no ads, trackers or analytics, and the Exodus report finds none."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/thomasbuilds/Spectre/blob/main/README.md",
          "note": "Free, ad-free app supported by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:45.305Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "superfreezz",
      "category": "mobile-security-apps",
      "name": "SuperFreezZ",
      "description": "Android app that freezes all background activity of selected apps.",
      "website": "https://superfreezz.gitlab.io",
      "source": "https://gitlab.com/SuperFreezZ/SuperFreezZ",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "SuperFreezZ scores 80 out of 100 (grade B) on the mobile security apps criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mobile-security-apps/superfreezz/",
      "markdown": "https://privacyratings.com/mobile-security-apps/superfreezz/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/SuperFreezZ/SuperFreezZ/-/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/superfreeze.tool.android/latest/",
          "note": "The Exodus report finds no trackers in the app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gitlab.com/SuperFreezZ/SuperFreezZ",
          "note": "Free app with no ads, supported by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:45.959Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "trackercontrol",
      "category": "mobile-security-apps",
      "name": "TrackerControl",
      "description": "Android app that monitors and blocks tracking connections made by other apps, using a local VPN that needs no root.",
      "website": "https://trackercontrol.org",
      "source": "https://github.com/TrackerControl/tracker-control-android",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "TrackerControl scores 80 out of 100 (grade B) on the mobile security apps criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mobile-security-apps/trackercontrol/",
      "markdown": "https://privacyratings.com/mobile-security-apps/trackercontrol/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TrackerControl/tracker-control-android/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TrackerControl/tracker-control-android/blob/master/README.md",
          "note": "The only library Exodus flags is ACRA, which only shows a dialog for sending crash reports by email."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/TrackerControl/tracker-control-android/blob/master/README.md",
          "note": "Free open-source app with no ads; the README states personal data does not leave the device."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:45.595Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "exifcleaner",
      "category": "metadata-removal",
      "name": "ExifCleaner",
      "description": "Desktop app for Windows, macOS and Linux that removes metadata from images, media files and PDFs, with drag and drop and batch processing. It uses ExifTool.",
      "website": "https://exifcleaner.com",
      "source": "https://github.com/szTheory/exifcleaner",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "ExifCleaner scores 80 out of 100 (grade B) on the metadata removal criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/metadata-removal/exifcleaner/",
      "markdown": "https://privacyratings.com/metadata-removal/exifcleaner/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/szTheory/exifcleaner/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/szTheory/exifcleaner/blob/master/README.md",
          "note": "The README states the app makes no network connections and has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/szTheory/exifcleaner/blob/master/README.md",
          "note": "Free open-source app with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:45.731Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "exiferaser",
      "category": "metadata-removal",
      "name": "ExifEraser",
      "description": "Android app that removes Exif and other metadata from JPEG, PNG and WebP images. The developer considers it in maintenance mode, with bug fixes only.",
      "website": "https://github.com/Tommy-Geenexus/exif-eraser",
      "source": "https://github.com/Tommy-Geenexus/exif-eraser",
      "license": "MIT",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "ExifEraser scores 80 out of 100 (grade B) on the metadata removal criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/metadata-removal/exiferaser/",
      "markdown": "https://privacyratings.com/metadata-removal/exiferaser/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Tommy-Geenexus/exif-eraser/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.none.tom.exiferaser/latest/",
          "note": "Exodus finds no trackers, and the privacy policy states the app collects no user data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Tommy-Geenexus/exif-eraser/blob/main/privacy-policy.md",
          "note": "Free open-source app with no ads; the privacy policy states no user data is collected."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:20.183Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "exiftool",
      "category": "metadata-removal",
      "name": "ExifTool",
      "description": "Cross-platform Perl library and command-line tool by Phil Harvey for reading, writing and removing metadata in images, audio, video and documents.",
      "website": "https://exiftool.org",
      "source": "https://github.com/exiftool/exiftool",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "ExifTool scores 80 out of 100 (grade B) on the metadata removal criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/metadata-removal/exiftool/",
      "markdown": "https://privacyratings.com/metadata-removal/exiftool/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/exiftool/exiftool/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/exiftool/exiftool",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://exiftool.org/#donate",
          "note": "Free software with no ads, supported by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:46.593Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "imageoptim",
      "category": "metadata-removal",
      "name": "ImageOptim",
      "description": "macOS app that compresses images and removes metadata such as EXIF data, comments and color profiles, using drag and drop.",
      "website": "https://imageoptim.com/mac",
      "source": "https://github.com/ImageOptim/ImageOptim",
      "license": "GPL-2.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "ImageOptim scores 80 out of 100 (grade B) on the metadata removal criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/metadata-removal/imageoptim/",
      "markdown": "https://privacyratings.com/metadata-removal/imageoptim/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ImageOptim/ImageOptim/blob/main/LICENSE",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ImageOptim/ImageOptim",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://imageoptim.com/mac",
          "note": "Free open-source app with no ads, supported by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:46.498Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mat2",
      "category": "metadata-removal",
      "name": "mat2",
      "description": "Python library and command-line tool that removes metadata from images, audio, video, office documents, PDFs and archives. Includes a service menu for the Dolphin and Nemo file managers.",
      "website": "https://github.com/jvoisin/mat2",
      "source": "https://github.com/jvoisin/mat2",
      "license": "LGPL-3.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "mat2 scores 80 out of 100 (grade B) on the metadata removal criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/metadata-removal/mat2/",
      "markdown": "https://privacyratings.com/metadata-removal/mat2/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jvoisin/mat2/blob/main/LICENSE",
          "note": "LGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jvoisin/mat2",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/jvoisin/mat2#donations",
          "note": "Free software with no ads; the project directs donations to Tails."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:20.183Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "metadata-cleaner",
      "category": "metadata-removal",
      "name": "Metadata Cleaner",
      "description": "GNOME desktop app for viewing and removing metadata in files, built on the mat2 library. Maintained by a community project after the original author stepped down.",
      "website": "https://gitlab.com/metadatacleaner/metadatacleaner",
      "source": "https://gitlab.com/metadatacleaner/metadatacleaner",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Metadata Cleaner scores 80 out of 100 (grade B) on the metadata removal criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/metadata-removal/metadata-cleaner/",
      "markdown": "https://privacyratings.com/metadata-removal/metadata-cleaner/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/metadatacleaner/metadatacleaner/-/blob/main/LICENSE.md",
          "note": "GPL-3.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/metadatacleaner/metadatacleaner",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gitlab.com/metadatacleaner/metadatacleaner",
          "note": "Free open-source software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:20.183Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "scrambled-exif",
      "category": "metadata-removal",
      "name": "Scrambled Exif",
      "description": "Android app that removes Exif metadata from pictures before they are shared, by acting as an intermediate step in the share menu.",
      "website": "https://gitlab.com/juanitobananas/scrambled-exif",
      "source": "https://gitlab.com/juanitobananas/scrambled-exif",
      "license": null,
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Scrambled Exif scores 80 out of 100 (grade B) on the metadata removal criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/metadata-removal/scrambled-exif/",
      "markdown": "https://privacyratings.com/metadata-removal/scrambled-exif/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/juanitobananas/scrambled-exif/-/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.jarsilio.android.scrambledeggsif/latest/",
          "note": "Exodus finds no trackers, and the privacy policy states the developer collects no personal data; crash reports are only sent by email if the user chooses."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gitlab.com/juanitobananas/scrambled-exif#donating",
          "note": "Free software with no ads, supported by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:20.183Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "dban",
      "category": "data-erasers",
      "name": "DBAN",
      "description": "Darik's Boot and Nuke is a bootable disk image that wipes hard disk drives. It is owned by Blancco, has not been developed since its last release, and does not support SSDs.",
      "website": "https://dban.org",
      "source": "https://sourceforge.net/projects/dban/",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "DBAN scores 50 out of 100 (grade D) on the data erasers criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/data-erasers/dban/",
      "markdown": "https://privacyratings.com/data-erasers/dban/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://sourceforge.net/projects/dban/files/dban/dban-2.3.0/",
          "note": "GPL-2.0; the source archive of the last release is published on SourceForge."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The dban.org home page loads Google Analytics and Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://dban.org/",
          "note": "Free tool with no ads, offered by Blancco alongside its paid erasure products."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:46.388Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dr-fone",
      "category": "data-erasers",
      "name": "Dr.Fone",
      "description": "Wondershare Dr.Fone, a closed-source desktop toolkit for Android and iOS devices whose data eraser wipes a phone connected to a computer.",
      "website": "https://drfone.wondershare.com",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Dr.Fone scores 0 out of 100 (grade F) on the data erasers criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/data-erasers/dr-fone/",
      "markdown": "https://privacyratings.com/data-erasers/dr-fone/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.wondershare.com/privacy.html",
          "note": "The privacy policy lists third-party tracking tools including Google Analytics, Facebook, Criteo and Firebase, and the home page loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.wondershare.com/privacy.html",
          "note": "The privacy policy states that device and usage data are sold or shared for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:46.384Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "eraser",
      "category": "data-erasers",
      "name": "Eraser",
      "description": "Windows tool that removes sensitive data from a hard drive by overwriting it several times with selected patterns.",
      "website": "https://eraser.heidi.ie",
      "source": "https://sourceforge.net/p/eraser/code/",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Eraser scores 80 out of 100 (grade B) on the data erasers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/data-erasers/eraser/",
      "markdown": "https://privacyratings.com/data-erasers/eraser/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://sourceforge.net/projects/eraser/",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://sourceforge.net/p/eraser/code/",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://eraser.heidi.ie/",
          "note": "Free software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:46.851Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nwipe",
      "category": "data-erasers",
      "name": "nwipe",
      "description": "Command-line disk eraser for Linux written in C, with a text-based interface. It is a fork of the dwipe engine from DBAN and is used by ShredOS.",
      "website": "https://github.com/martijnvanbrummelen/nwipe",
      "source": "https://github.com/martijnvanbrummelen/nwipe",
      "license": "GPL-2.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "nwipe scores 80 out of 100 (grade B) on the data erasers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/data-erasers/nwipe/",
      "markdown": "https://privacyratings.com/data-erasers/nwipe/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/martijnvanbrummelen/nwipe/blob/master/COPYING",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/martijnvanbrummelen/nwipe",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/martijnvanbrummelen/nwipe",
          "note": "Free open-source tool with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:46.389Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ow-shredder",
      "category": "data-erasers",
      "name": "OW Shredder",
      "description": "Portable Windows tool that securely erases files, folders and drives, with extra tools to analyse drives and remove leftover file system traces.",
      "website": "https://schiffer.tech/ow-shredder.html",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "OW Shredder scores 50 out of 100 (grade D) on the data erasers criteria. It meets 2 of 4 criteria: no trackers or telemetry and no ads or data sales. It does not meet open source and independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/data-erasers/ow-shredder/",
      "markdown": "https://privacyratings.com/data-erasers/ow-shredder/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://schiffer.tech/software/ow_shredder/license.txt",
          "note": "Closed source freeware."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://schiffer.tech/privacy.html",
          "note": "The privacy policy lists no analytics or third-party tracking, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://schiffer.tech/privacy.html",
          "note": "Free tool with no ads; the privacy policy lists no advertising or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:46.943Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sdelete",
      "category": "data-erasers",
      "name": "SDelete",
      "description": "Microsoft Sysinternals command-line tool for Windows that securely deletes files and cleans free disk space by overwriting data.",
      "website": "https://learn.microsoft.com/en-us/sysinternals/downloads/sdelete",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "SDelete scores 35 out of 100 (grade F) on the data erasers criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets no trackers or telemetry. It does not meet open source and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/data-erasers/sdelete/",
      "markdown": "https://privacyratings.com/data-erasers/sdelete/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "The tool has no documented telemetry, but the Microsoft Learn download site uses first-party analytics cookies under the Microsoft privacy statement."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://learn.microsoft.com/en-us/sysinternals/downloads/sdelete",
          "note": "Free Microsoft utility with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:46.692Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "secure-remove",
      "category": "data-erasers",
      "name": "Secure Remove",
      "description": "Command-line tool that securely removes files, directories and whole disks by overwriting them, for Linux, BSD, macOS and Windows. It has not been updated for several years.",
      "website": "https://srm.sourceforge.net/",
      "source": "https://sourceforge.net/p/srm/srm/",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Secure Remove scores 80 out of 100 (grade B) on the data erasers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/data-erasers/secure-remove/",
      "markdown": "https://privacyratings.com/data-erasers/secure-remove/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://sourceforge.net/projects/srm/",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://sourceforge.net/p/srm/srm/",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://srm.sourceforge.net/",
          "note": "Free open-source tool with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:46.594Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "shred",
      "category": "data-erasers",
      "name": "shred",
      "description": "A CLI utility that overwrites files and devices so their contents are difficult to recover.",
      "website": "https://www.gnu.org/software/coreutils/manual/html_node/shred-invocation.html",
      "source": "https://cgit.git.savannah.gnu.org/cgit/coreutils.git",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "shred scores 80 out of 100 (grade B) on the data erasers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/data-erasers/shred/",
      "markdown": "https://privacyratings.com/data-erasers/shred/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://cgit.git.savannah.gnu.org/cgit/coreutils.git/tree/COPYING",
          "note": "Part of GNU coreutils, GPL-3.0 or later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://cgit.git.savannah.gnu.org/cgit/coreutils.git",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cgit.git.savannah.gnu.org/cgit/coreutils.git",
          "note": "Free software from the GNU Project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:16.595Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "buskill",
      "category": "usb-security",
      "name": "BusKill",
      "description": "Dead man's switch that locks the screen or shuts down a computer when a magnetic USB breakaway cable tethered to the user is pulled out. The open-source app runs on Linux, Windows and macOS, and the cables are sold by the project.",
      "website": "https://www.buskill.in",
      "source": "https://github.com/BusKill/buskill-app",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "BusKill scores 65 out of 100 (grade C) on the USB kill switches and anti-forensics criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/usb-security/buskill/",
      "markdown": "https://privacyratings.com/usb-security/buskill/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/BusKill/buskill-app/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/BusKill/buskill-app",
          "note": "No telemetry or analytics in the app source code, and updates are only checked on request. The website runs a self-hosted heatmap analytics plugin."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.buskill.in/store/",
          "note": "Funded by sales of BusKill cables and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:43.077Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "silk-guardian",
      "category": "usb-security",
      "name": "Silk Guardian",
      "description": "Linux kernel module that, when any USB device is added or removed, can securely delete chosen files and then powers off the computer. It is an anti-forensic kill switch inspired by usbkill.",
      "website": "https://github.com/NateBrune/silk-guardian",
      "source": "https://github.com/NateBrune/silk-guardian",
      "license": "MIT",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Silk Guardian scores 80 out of 100 (grade B) on the USB kill switches and anti-forensics criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/usb-security/silk-guardian/",
      "markdown": "https://privacyratings.com/usb-security/silk-guardian/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/NateBrune/silk-guardian/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/NateBrune/silk-guardian",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/NateBrune/silk-guardian",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:41.441Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "swiftguard",
      "category": "usb-security",
      "name": "swiftGuard",
      "description": "macOS menu bar app that watches USB ports and shuts down or hibernates the Mac when an unknown device is connected or a whitelisted one is removed, with an optional countdown to cancel.",
      "website": "https://github.com/Lennolium/swiftGuard",
      "source": "https://github.com/Lennolium/swiftGuard",
      "license": "GPL-3.0",
      "platforms": [
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "swiftGuard scores 80 out of 100 (grade B) on the USB kill switches and anti-forensics criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/usb-security/swiftguard/",
      "markdown": "https://privacyratings.com/usb-security/swiftguard/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Lennolium/swiftGuard/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Lennolium/swiftGuard",
          "note": "No telemetry or analytics in the source code. An update check against the GitHub API is on by default and can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Lennolium/swiftGuard",
          "note": "Free volunteer project funded by donations, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:41.441Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "usbkill",
      "category": "usb-security",
      "name": "usbkill",
      "description": "Python script that shuts down the computer as soon as a USB device is plugged in or removed, as an anti-forensic kill switch. It runs on Linux, BSD and macOS and has not been updated in years.",
      "website": "https://github.com/hephaest0s/usbkill",
      "source": "https://github.com/hephaest0s/usbkill",
      "license": null,
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "usbkill scores 80 out of 100 (grade B) on the USB kill switches and anti-forensics criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/usb-security/usbkill/",
      "markdown": "https://privacyratings.com/usb-security/usbkill/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hephaest0s/usbkill/blob/master/setup.py",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hephaest0s/usbkill",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/hephaest0s/usbkill",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:41.442Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "avast",
      "category": "anti-malware",
      "name": "Avast",
      "description": "Antivirus and security software from Gen Digital for Windows, macOS, Android and iOS, in free and paid versions. The US FTC fined Avast for selling users' browsing data through its Jumpshot subsidiary.",
      "website": "https://www.avast.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CZ",
        "name": "Czechia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Avast scores 0 out of 100 (grade F) on the anti-malware criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in Czechia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/anti-malware/avast/",
      "markdown": "https://privacyratings.com/anti-malware/avast/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.avast.android.mobilesecurity/latest/",
          "note": "Exodus finds Google AdMob, Facebook Ads, Unity Ads, Firebase Analytics, Singular and Adobe Experience Cloud in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.ftc.gov/news-events/news/press-releases/2024/02/ftc-order-will-ban-avast-selling-browsing-data-advertising-purposes-require-it-pay-165-million-over",
          "note": "The FTC fined Avast and banned it from selling browsing data for advertising after its Jumpshot subsidiary sold users' browsing data; the free mobile apps show personalized third-party ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:56.290Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bitdefender",
      "category": "anti-malware",
      "name": "Bitdefender",
      "description": "Antivirus and security software from Romania for Windows, macOS, Android and iOS, with web protection, a VPN and anti-theft features.",
      "website": "https://www.bitdefender.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "RO",
        "name": "Romania",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Bitdefender scores 20 out of 100 (grade F) on the anti-malware criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in Romania: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/anti-malware/bitdefender/",
      "markdown": "https://privacyratings.com/anti-malware/bitdefender/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.bitdefender.security/latest/",
          "note": "Exodus finds AppsFlyer, Firebase Analytics, Crashlytics and Facebook Login and Share in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.bitdefender.com/en-us/site/view/legal-privacy-policy-for-home-users-solutions",
          "note": "Funded by subscriptions with no ads in the apps; the privacy policy states user data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:56.138Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "clamav",
      "category": "anti-malware",
      "name": "ClamAV",
      "description": "Open-source antivirus engine for detecting viruses, malware and other threats on Linux, macOS and Windows, maintained by Cisco Talos.",
      "website": "https://www.clamav.net",
      "source": "https://github.com/Cisco-Talos/clamav",
      "license": "GPL-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "ClamAV scores 65 out of 100 (grade C) on the anti-malware criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/anti-malware/clamav/",
      "markdown": "https://privacyratings.com/anti-malware/clamav/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Cisco-Talos/clamav/blob/main/COPYING.txt",
          "note": "GPL-2.0 and LGPL-2.1."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/Cisco-Talos/clamav/blob/main/libfreshclam/libfreshclam_internal.c",
          "note": "The freshclam updater sends a random installation ID with OS and CPU details to the update servers unless a private mirror is used."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.clamav.net/about",
          "note": "Free open-source software maintained by Cisco, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:00:47.118Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "eset",
      "category": "anti-malware",
      "name": "ESET",
      "description": "Antivirus and security software from Slovakia for Windows, macOS, Linux and Android, including the NOD32 antivirus engine.",
      "website": "https://www.eset.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android"
      ],
      "jurisdiction": {
        "code": "SK",
        "name": "Slovakia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "ESET scores 20 out of 100 (grade F) on the anti-malware criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in Slovakia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/anti-malware/eset/",
      "markdown": "https://privacyratings.com/anti-malware/eset/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.eset.ems2.gp/latest/",
          "note": "Exodus finds Firebase Analytics and Crashlytics in the Android app, and the website shares data with third-party ad networks."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.eset.com/us/policy-hub/privacy/",
          "note": "Funded by subscriptions with no ads in the apps; the privacy policy states personal information is not sold for money, though website cookies are shared with ad networks."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "www.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:57.113Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kaspersky",
      "category": "anti-malware",
      "name": "Kaspersky",
      "description": "Antivirus and security software from Kaspersky Lab for Windows, macOS, Android and iOS. The US Commerce Department prohibits Kaspersky from selling or updating its antivirus products for US customers.",
      "website": "https://www.kaspersky.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "RU",
        "name": "Russia",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Kaspersky scores 30 out of 100 (grade F) on the anti-malware criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets independent audit. It does not meet open source and no trackers or telemetry. It is based in Russia: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/anti-malware/kaspersky/",
      "markdown": "https://privacyratings.com/anti-malware/kaspersky/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.kms.free/latest/",
          "note": "Exodus finds AppsFlyer, Facebook Analytics, Firebase Analytics, Crashlytics and Huawei Mobile Services in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.kaspersky.com/home-security",
          "note": "Funded by subscriptions, with no ads in the apps."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.kaspersky.com/about/compliance-soc2",
          "note": "A Big Four firm audits the development and release of antivirus databases under SOC 2 Type 2, but the report is only available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:22.508Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "malwarebytes",
      "category": "anti-malware",
      "name": "Malwarebytes",
      "description": "Anti-malware software for Windows, macOS, Android and iOS that detects and removes viruses, ransomware, adware and potentially unwanted programs.",
      "website": "https://www.malwarebytes.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Malwarebytes scores 20 out of 100 (grade F) on the anti-malware criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/anti-malware/malwarebytes/",
      "markdown": "https://privacyratings.com/anti-malware/malwarebytes/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.malwarebytes.antimalware/latest/",
          "note": "Exodus finds Amplitude, AppsFlyer, Firebase Analytics, Crashlytics and Sentry in the Android app, and the privacy policy lists third-party analytics and targeting cookies on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.malwarebytes.com/legal/privacy-policy",
          "note": "Funded by subscriptions with no ads in the apps; the privacy policy states personal data is not sold for money, though website targeting cookies may count as sharing under US state laws."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          },
          {
            "name": "VWO",
            "host": "dev.visualwebsiteoptimizer.com",
            "effect": "no"
          },
          {
            "name": "WordPress.com Stats",
            "host": "stats.wp.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:21.264Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "mcafee",
      "category": "anti-malware",
      "name": "McAfee",
      "description": "Antivirus and online protection suite for Windows, macOS, Android and iOS, with identity monitoring, a VPN and web protection.",
      "website": "https://www.mcafee.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "McAfee scores 10 out of 100 (grade F) on the anti-malware criteria. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/anti-malware/mcafee/",
      "markdown": "https://privacyratings.com/anti-malware/mcafee/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.wsandroid.suite/latest/",
          "note": "Exodus finds Amplitude, AppsFlyer, FullStory, Crashlytics and Split in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.mcafee.com/en-us/consumer-support/policy/legal.html",
          "note": "Funded by subscriptions with no ads in the apps; the privacy notice states personal data is not sold, though it is shared with advertising partners for targeted ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:21.367Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "microsoft-defender-antivirus",
      "category": "anti-malware",
      "name": "Microsoft Defender Antivirus",
      "description": "Antivirus built into Windows that scans for malware, unwanted software and potentially harmful apps, with cloud-delivered protection from Microsoft. It turns on automatically when no other antivirus is installed.",
      "website": "https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-windows",
      "license": null,
      "platforms": [
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Microsoft Defender Antivirus scores 35 out of 100 (grade F) on the anti-malware criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets no trackers or telemetry. It does not meet open source and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/anti-malware/microsoft-defender-antivirus/",
      "markdown": "https://privacyratings.com/anti-malware/microsoft-defender-antivirus/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "Reports on suspected malware and file samples are sent to Microsoft by default; this reporting can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-windows",
          "note": "Included with Windows licenses and shows no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:21.515Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "norton-360",
      "category": "anti-malware",
      "name": "Norton 360",
      "description": "Security suite from Gen Digital that combines antivirus with a firewall, password manager, VPN and dark web monitoring, for Windows, macOS, Android and iOS.",
      "website": "https://us.norton.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Norton 360 scores 10 out of 100 (grade F) on the anti-malware criteria. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/anti-malware/norton-360/",
      "markdown": "https://privacyratings.com/anti-malware/norton-360/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.symantec.mobilesecurity/latest/",
          "note": "Exodus finds Adobe Experience Cloud, Firebase Analytics, Crashlytics and Singular in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://privacy.gendigital.com/en",
          "note": "Funded by subscriptions, but the Gen Digital privacy notice allows sharing account and product data with advertising partners for cross-context advertising, while stating that data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:21.547Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "berty",
      "category": "messengers",
      "name": "Berty",
      "description": "Peer-to-peer, end-to-end encrypted messenger built on IPFS by the French non-profit Berty Technologies. It needs no phone number or email and can exchange messages offline over Bluetooth and local networks.",
      "website": "https://berty.tech",
      "source": "https://github.com/berty/berty",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 89,
      "coverage": 100,
      "summary": "Berty scores 89 out of 100 (grade B) on the messengers criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted by default, no phone number needed, metadata protection and decentralized. It does not meet independent audit. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/messengers/berty/",
      "markdown": "https://privacyratings.com/messengers/berty/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/berty/berty/blob/master/LICENSE-APACHE",
          "note": "Dual-licensed under Apache-2.0 and MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/tech.berty.android/latest/",
          "note": "Exodus finds no trackers in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://berty.tech/about",
          "note": "Developed by a non-profit organization that does not sell a product, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://berty.tech/about",
          "note": "All conversations, including groups, are end-to-end encrypted by default."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://berty.tech/faq",
          "note": "No phone number or email is required; identity is based on public-key cryptography."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://berty.tech/faq",
          "note": "There is no central server, rendezvous points rotate regularly, and users join each group with a group-specific identity."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://berty.tech/faq",
          "note": "Peer to peer over IPFS, with optional offline transports such as Bluetooth; anyone can run a replication node."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Simple Analytics",
            "host": "queue.simpleanalyticscdn.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:21.828Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "briar",
      "category": "messengers",
      "name": "Briar",
      "description": "Peer-to-peer encrypted messenger for Android and desktop that syncs over Tor, Wi-Fi or Bluetooth. Messages, forums and blogs are stored only on users' devices.",
      "website": "https://briarproject.org",
      "source": "https://code.briarproject.org/briar/briar",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 94,
      "coverage": 100,
      "summary": "Briar scores 94 out of 100 (grade A) on the messengers criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted by default, no phone number needed, metadata protection and decentralized. It partly meets independent audit.",
      "url": "https://privacyratings.com/messengers/briar/",
      "markdown": "https://privacyratings.com/messengers/briar/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://code.briarproject.org/briar/briar/-/blob/master/LICENSE.txt",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://briarproject.org/privacy-policy/",
          "note": "The privacy policy states no information is collected about how Briar is used; feedback and crash reports are opt-in."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://briarproject.org/about-us/",
          "note": "Funded by grants and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://briarproject.org/raw/BRP-01-report.pdf",
          "note": "A full Cure53 audit report is public but is older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://briarproject.org/how-it-works/",
          "note": "All communication between devices is end-to-end encrypted."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://briarproject.org/how-it-works/",
          "note": "Accounts are created on the device with a nickname and password, with no phone number or email."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://briarproject.org/how-it-works/",
          "note": "Messages sync directly over Tor, Wi-Fi or Bluetooth, and contact lists are stored only on the device."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://briarproject.org/how-it-works/",
          "note": "Peer to peer with no central server."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:47.560Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "conversations",
      "category": "messengers",
      "name": "Conversations",
      "description": "XMPP (Jabber) client for Android that works with any standard XMPP server, with OMEMO end-to-end encryption on by default for one-to-one and private group chats.",
      "website": "https://conversations.im",
      "source": "https://codeberg.org/iNPUTmice/Conversations",
      "license": null,
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 83,
      "coverage": 100,
      "summary": "Conversations scores 83 out of 100 (grade B) on the messengers criteria. It meets 6 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted by default, no phone number needed and decentralized. It partly meets independent audit. It does not meet metadata protection.",
      "url": "https://privacyratings.com/messengers/conversations/",
      "markdown": "https://privacyratings.com/messengers/conversations/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/iNPUTmice/Conversations/src/branch/master/LICENSE",
          "note": "GPL-3.0, and it works with open-source XMPP servers such as Prosody and ejabberd."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/eu.siacs.conversations/latest/",
          "note": "Exodus finds no trackers in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://play.google.com/store/apps/details?id=eu.siacs.conversations",
          "note": "Sold as a paid app on Google Play and free on F-Droid, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://conversations.im/omemo/audit.pdf",
          "note": "A full cryptographic analysis of OMEMO, including its Conversations implementation, is public but older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/iNPUTmice/Conversations/src/branch/master/README.md",
          "note": "OMEMO end-to-end encryption is on by default for one-to-one and private group chats; public group chats are not encrypted."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://conversations.im",
          "note": "Accounts are XMPP addresses on any server; no phone number is needed."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "The user's XMPP server stores the contact list and sees who talks to whom."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://conversations.im/#xmpp",
          "note": "XMPP is federated, so users on different servers can message each other and anyone can run a server."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:22.630Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "cwtch",
      "category": "messengers",
      "name": "Cwtch",
      "description": "Decentralized, metadata-resistant messenger from the non-profit Open Privacy Research Society. Contacts talk peer to peer over Tor onion services, and optional group chats use untrusted servers that anyone can run.",
      "website": "https://docs.cwtch.im",
      "source": "https://git.openprivacy.ca/cwtch.im/cwtch-ui",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android"
      ],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 89,
      "coverage": 100,
      "summary": "Cwtch scores 89 out of 100 (grade B) on the messengers criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted by default, no phone number needed, metadata protection and decentralized. It does not meet independent audit. It is based in Canada: Five Eyes member.",
      "url": "https://privacyratings.com/messengers/cwtch/",
      "markdown": "https://privacyratings.com/messengers/cwtch/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://git.openprivacy.ca/cwtch.im/cwtch-ui",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/im.cwtch.flwtch/latest/",
          "note": "Exodus finds no trackers in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://openprivacy.ca/donate/",
          "note": "Funded by donations to the non-profit Open Privacy Research Society, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://docs.cwtch.im/",
          "note": "All communication, including groups, is end-to-end encrypted over Tor v3 onion services."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.cwtch.im/",
          "note": "No phone number or account registration is needed; profiles are identified by onion addresses."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.cwtch.im/docs/groups/introduction/",
          "note": "Contacts connect directly over Tor, and group servers are designed to learn as little as possible about contents or metadata."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.cwtch.im/",
          "note": "Peer to peer over Tor, with no central Cwtch service; anyone can host a group server."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:22.105Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "dino",
      "category": "messengers",
      "name": "Dino",
      "description": "Desktop XMPP (Jabber) client for Linux built with GTK, with group chats, file transfers, and voice and video calls. OMEMO end-to-end encryption is on by default for one-to-one and private group chats.",
      "website": "https://dino.im",
      "source": "https://github.com/dino/dino",
      "license": "GPL-3.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 78,
      "coverage": 100,
      "summary": "Dino scores 78 out of 100 (grade B) on the messengers criteria. It meets 6 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted by default, no phone number needed and decentralized. It does not meet independent audit and metadata protection.",
      "url": "https://privacyratings.com/messengers/dino/",
      "markdown": "https://privacyratings.com/messengers/dino/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dino/dino/blob/master/LICENSE",
          "note": "GPL-3.0, and it works with open-source XMPP servers."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dino/dino",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://dino.im/#donate",
          "note": "Free software with no ads, supported by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://dino.im/",
          "note": "OMEMO is the default encryption for one-to-one chats and private group chats, and calls are end-to-end encrypted; public group chats are not encrypted."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://dino.im/",
          "note": "Accounts are XMPP addresses on any server; no phone number is needed."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "The user's XMPP server stores the contact list and sees who talks to whom."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://dino.im/",
          "note": "XMPP is federated, so users on different servers can message each other and anyone can run a server."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:22.616Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "facebook-messenger",
      "category": "messengers",
      "name": "Facebook Messenger",
      "description": "Meta's messaging app for Facebook accounts, with chats, groups, voice and video calls. Personal chats and calls are end-to-end encrypted by default.",
      "website": "https://www.messenger.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 19,
      "coverage": 100,
      "summary": "Facebook Messenger scores 19 out of 100 (grade F) on the messengers criteria. It meets 1 of 8 criteria: no phone number needed. It partly meets end-to-end encrypted by default. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, metadata protection and decentralized. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/messengers/facebook-messenger/",
      "markdown": "https://privacyratings.com/messengers/facebook-messenger/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.facebook.orca/latest/",
          "note": "Exodus finds Google Analytics, Mapbox and Facebook SDK components in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Funded by advertising; Messenger shows ads and Meta uses account activity to personalize ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://about.fb.com/news/2023/12/default-end-to-end-encryption-on-messenger/",
          "note": "Personal chats and calls are end-to-end encrypted by default, but not every chat type is, such as chats with businesses and community chats."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.facebook.com/help/188157731232424",
          "note": "Messenger requires a Facebook account, which can be created with an email address instead of a phone number."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Meta's servers see who talks to whom."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "One central service run by Meta."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:22.222Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "gajim",
      "category": "messengers",
      "name": "Gajim",
      "description": "Desktop XMPP (Jabber) client for Linux, Windows and macOS that works with any standard XMPP server, with group chats, file transfer and optional OMEMO or OpenPGP end-to-end encryption.",
      "website": "https://gajim.org",
      "source": "https://gitlab.com/gajim/gajim",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 69,
      "coverage": 100,
      "summary": "Gajim scores 69 out of 100 (grade C) on the messengers criteria. It meets 5 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, no phone number needed and decentralized. It partly meets end-to-end encrypted by default. It does not meet independent audit and metadata protection.",
      "url": "https://privacyratings.com/messengers/gajim/",
      "markdown": "https://privacyratings.com/messengers/gajim/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/gajim/gajim/-/blob/master/COPYING",
          "note": "GPL-3.0, and it works with open-source XMPP servers."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gajim.org/privacy/",
          "note": "No analytics or telemetry; the app only checks gajim.org for updates, and crash reports are sent only with the user's approval."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gajim.org/#donate",
          "note": "Free software with no ads, supported by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://gitlab.com/gajim/gajim/-/blob/master/src/gajim/gtk/preference/account.py",
          "note": "OMEMO and OpenPGP are supported, but the default encryption setting for new chats is unencrypted."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gajim.org/privacy/",
          "note": "Accounts are XMPP addresses on any server; no phone number is needed."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "no",
          "evidence": "https://gajim.org/privacy/",
          "note": "The user's XMPP server sees contacts, group memberships and who talks to whom."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://gajim.org/privacy/",
          "note": "XMPP is federated, and Gajim connects to any server the user chooses."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:22.568Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "google-messages",
      "category": "messengers",
      "name": "Google Messages",
      "description": "Google's default SMS, MMS and RCS messaging app for Android, with a paired web client. RCS chats between Google Messages users are end-to-end encrypted automatically; SMS and MMS are not.",
      "website": "https://messages.google.com",
      "license": null,
      "platforms": [
        "android",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 17,
      "coverage": 100,
      "summary": "Google Messages scores 17 out of 100 (grade F) on the messengers criteria. It partly meets no trackers or telemetry and end-to-end encrypted by default. It does not meet open source, no ads or data sales, independent audit, no phone number needed, metadata protection and decentralized. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/messengers/google-messages/",
      "markdown": "https://privacyratings.com/messengers/google-messages/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.google.android.apps.messaging/latest/",
          "note": "Exodus finds no third-party trackers, but Google collects app usage and diagnostic data by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "The app shows no ads, but it is provided free by Google, whose privacy policy uses activity across its services to fund and personalize advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://support.google.com/messages/answer/10262381",
          "note": "RCS chats, including groups, are end-to-end encrypted automatically only when all participants use a supporting app; SMS and MMS are never encrypted."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Messages are sent and received with the phone number of the SIM, which is visible to recipients."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Google and carriers see who talks to whom."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "RCS runs through carrier and Google servers that users cannot run themselves."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:22.261Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "imessage",
      "category": "messengers",
      "name": "iMessage",
      "description": "Apple's end-to-end encrypted messaging service built into the Messages app on iPhone, iPad, Mac and other Apple devices, addressed by phone number or Apple Account email.",
      "website": "https://support.apple.com/messages",
      "license": null,
      "platforms": [
        "ios",
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 42,
      "coverage": 100,
      "summary": "iMessage scores 42 out of 100 (grade D) on the messengers criteria. It meets 2 of 8 criteria: no ads or data sales and end-to-end encrypted by default. It partly meets no trackers or telemetry and no phone number needed. It does not meet open source, independent audit, metadata protection and decentralized. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/messengers/imessage/",
      "markdown": "https://privacyratings.com/messengers/imessage/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/device-analytics/",
          "note": "No third-party trackers in the app, and sharing device analytics with Apple is opt-in. Apple web pages load Apple's own analytics (ac-analytics, sent to metrics.apple.com) by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/en-ww/",
          "note": "Funded by Apple device sales, with no ads in Messages; the privacy policy states Apple does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published; Apple has only published commissioned formal analyses of the PQ3 protocol."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://support.apple.com/guide/security/imessage-security-overview-secd9764312f/web",
          "note": "All iMessage chats, including groups, are end-to-end encrypted; iCloud backups of messages are only end-to-end encrypted with Advanced Data Protection, and SMS fallback is not encrypted."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.apple.com/en-us/108647",
          "note": "Creating an Apple Account requires verifying a phone number, but iMessage can be used with an email address so the number is not shown to contacts."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.apple.com/legal/privacy/data/en/messages/",
          "note": "Apple's servers route messages by sender and recipient and may keep the phone numbers and email addresses a user looks up for up to 30 days."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "One central service run by Apple."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:22.274Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "jami",
      "category": "messengers",
      "name": "Jami",
      "description": "Peer-to-peer encrypted messenger from the GNU project for text, audio and video calls, screen sharing and conferences, with apps for desktop and mobile.",
      "website": "https://jami.net",
      "source": "https://github.com/savoirfairelinux/jami-project",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 75,
      "coverage": 100,
      "summary": "Jami scores 75 out of 100 (grade B) on the messengers criteria. It meets 5 of 8 criteria: open source, no ads or data sales, end-to-end encrypted by default, no phone number needed and decentralized. It partly meets no trackers or telemetry and metadata protection. It does not meet independent audit. It is based in Canada: Five Eyes member.",
      "url": "https://privacyratings.com/messengers/jami/",
      "markdown": "https://privacyratings.com/messengers/jami/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/savoirfairelinux/jami-project/blob/master/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://jami.net/privacy-policy/",
          "note": "The apps have no telemetry and Exodus finds no trackers, but the website runs self-hosted Matomo analytics by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://jami.net/privacy-policy/",
          "note": "Free software funded by Savoir-faire Linux and donations, with no ads and no personal data collected."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://jami.net/privacy-policy/",
          "note": "All connections are end-to-end encrypted with perfect forward secrecy."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.jami.net/en_US/user/faq.html",
          "note": "Accounts are key pairs created on the device; no email or phone number is required."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://docs.jami.net/en_US/user/faq.html",
          "note": "No central server holds contact lists, but peers are located through a public DHT that exposes device announcements and IP addresses to other nodes."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://jami.net/privacy-policy/",
          "note": "Peer to peer over a distributed hash table, with optional self-hosted account management servers."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:47.212Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "keybase",
      "category": "messengers",
      "name": "Keybase",
      "description": "End-to-end encrypted chat, group chat and file sharing tied to public-key identity proofs. Owned by Zoom since its acquisition, with little ongoing development.",
      "website": "https://keybase.io",
      "source": "https://github.com/keybase/client",
      "license": "BSD-3-Clause",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 61,
      "coverage": 100,
      "summary": "Keybase scores 61 out of 100 (grade C) on the messengers criteria. It meets 3 of 8 criteria: no ads or data sales, end-to-end encrypted by default and no phone number needed. It partly meets open source, no trackers or telemetry and independent audit. It does not meet metadata protection and decentralized. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/messengers/keybase/",
      "markdown": "https://privacyratings.com/messengers/keybase/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/keybase/client/blob/master/LICENSE",
          "note": "Client apps are BSD-3-Clause; the server is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://keybase.io/docs/privacypolicy",
          "note": "No third-party analytics are listed, but the service collects device and operating system analytics data with no documented opt-out."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://keybase.io/docs/privacypolicy",
          "note": "The privacy policy states Keybase will never run ads or sell user data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://keybase.io/docs-assets/blog/NCC_Group_Keybase_KB2018_Public_Report_2019-02-27_v1.3.pdf",
          "note": "A full NCC Group report is public but is older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://book.keybase.io/docs/chat/crypto",
          "note": "All chats and team chats are end-to-end encrypted with per-device keys."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://keybase.io/docs/privacypolicy",
          "note": "The privacy policy states Keybase never requires a phone number or an email address."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "The central server sees which accounts and teams exchange messages."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "One central service run by Keybase; the server is not published for self-hosting."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:47.515Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "matrix",
      "category": "messengers",
      "name": "Matrix",
      "description": "Open standard and federated network for real-time chat and calls, with end-to-end encryption through the Olm and Megolm protocols. Anyone can run a homeserver, and many clients such as Element support it.",
      "website": "https://matrix.org",
      "source": "https://github.com/matrix-org/matrix-spec",
      "license": "Apache-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 58,
      "coverage": 100,
      "summary": "Matrix scores 58 out of 100 (grade D) on the messengers criteria. It meets 4 of 8 criteria: open source, no ads or data sales, no phone number needed and decentralized. It partly meets independent audit and end-to-end encrypted by default. It does not meet no trackers or telemetry and metadata protection. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/messengers/matrix/",
      "markdown": "https://privacyratings.com/messengers/matrix/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/matrix-org/matrix-spec/blob/main/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://matrix.org/legal/privacy-notice/",
          "note": "The matrix.org homeserver sends account usage analytics to PostHog, and the website uses hosted Plausible analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://matrix.org/support/",
          "note": "The non-profit Matrix.org Foundation is funded by donations and organisational memberships, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://matrix.org/media/Least%20Authority%20-%20Matrix%20vodozemac%20Final%20Audit%20Report.pdf",
          "note": "A full Least Authority audit of the vodozemac encryption library is public but is older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://spec.matrix.org/latest/client-server-api/#end-to-end-encryption",
          "note": "Encryption is an optional room setting in the protocol; major clients enable it for private chats, but public rooms are unencrypted."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://matrix.org/legal/privacy-notice/",
          "note": "No phone number is needed; on the matrix.org homeserver a verified phone number is optional."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Homeservers see room membership, senders and timestamps, and share them with every server in a room."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://spec.matrix.org/latest/",
          "note": "Federated protocol; anyone can run a homeserver."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:00:47.568Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "molly",
      "category": "messengers",
      "name": "Molly",
      "description": "Independent fork of the Signal Android app that connects to the Signal network and adds database encryption with a passphrase, UnifiedPush notifications and a Molly-FOSS build without proprietary Google components.",
      "website": "https://molly.im",
      "source": "https://github.com/mollyim/mollyim-android",
      "license": "AGPL-3.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 78,
      "coverage": 100,
      "summary": "Molly scores 78 out of 100 (grade B) on the messengers criteria. It meets 5 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted by default and metadata protection. It partly meets no phone number needed. It does not meet independent audit and decentralized.",
      "url": "https://privacyratings.com/messengers/molly/",
      "markdown": "https://privacyratings.com/messengers/molly/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mollyim/mollyim-android/blob/main/LICENSE",
          "note": "AGPL-3.0, and it uses the open-source Signal server."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mollyim/mollyim-android",
          "note": "No trackers or analytics; the Molly-FOSS build also removes proprietary Google components such as FCM and Google Maps."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/mollyim",
          "note": "Free software with no ads, funded by donations through Open Collective."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://signal.org/docs/",
          "note": "All messages and calls, including groups, use the Signal Protocol end to end."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.signal.org/hc/en-us/articles/6712070553754-Phone-Number-Privacy-and-Usernames",
          "note": "A phone number is required to register a Signal account, but it is hidden by default and contacts can be reached by username."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://signal.org/blog/sealed-sender/",
          "note": "Uses the Signal network, where sealed sender hides the sender from the server."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Connects to the central Signal service."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:22.511Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "olvid",
      "category": "messengers",
      "name": "Olvid",
      "description": "End-to-end encrypted messenger from France that needs no phone number, email or other personal data; contacts are added by exchanging keys. Certified under the French ANSSI CSPN scheme.",
      "website": "https://www.olvid.io",
      "source": "https://github.com/olvid-io",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 81,
      "coverage": 100,
      "summary": "Olvid scores 81 out of 100 (grade B) on the messengers criteria. It meets 5 of 8 criteria: no trackers or telemetry, no ads or data sales, end-to-end encrypted by default, no phone number needed and metadata protection. It partly meets open source and independent audit. It does not meet decentralized. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/messengers/olvid/",
      "markdown": "https://privacyratings.com/messengers/olvid/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://olvid.io/faq/is-olvid-open-source/",
          "note": "The apps and the message distribution server are AGPL-3.0, but server code for paid enterprise features is not published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.olvid.io/privacy/en/",
          "note": "The privacy policy states Olvid collects no personal data; Exodus only detects the OpenCensus library bundled with Google's API client, and Firebase Analytics is excluded from the build."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.olvid.io/pricing/en/",
          "note": "Free for personal use and funded by paid licences, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.olvid.io/assets/documents/Synacktiv-Olvid-CSPN_Olvid-0.9.2-RTE-v1.2.pdf",
          "note": "Synacktiv's full CSPN evaluation reports are public, but they are older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.olvid.io/technology/en/",
          "note": "All messages, group discussions, calls and metadata are end-to-end encrypted."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.olvid.io/privacy/en/",
          "note": "No phone number, email or other personal data is needed to create a profile."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.olvid.io/technology/en/",
          "note": "Metadata is encrypted end to end and there is no user directory, so the server cannot identify who is talking."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "One central service run by Olvid; the published server code does not federate."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:22.392Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "openpgp",
      "category": "messengers",
      "name": "OpenPGP",
      "description": "Open standard for public-key encryption and signing of messages and files, defined in RFC 9580. It adds end-to-end encryption to existing channels such as email, through implementations like GnuPG.",
      "website": "https://www.openpgp.org",
      "source": "https://gitlab.com/openpgp-wg/rfc4880bis",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 78,
      "coverage": 100,
      "summary": "OpenPGP scores 78 out of 100 (grade B) on the messengers criteria. It meets 5 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, no phone number needed and decentralized. It partly meets end-to-end encrypted by default. It does not meet metadata protection.",
      "url": "https://privacyratings.com/messengers/openpgp/",
      "markdown": "https://privacyratings.com/messengers/openpgp/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.rfc-editor.org/rfc/rfc9580.html",
          "note": "Open IETF standard with open source implementations such as GnuPG (GPL-3.0)."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.gnupg.org/privacy-policy.html",
          "note": "The standard has no telemetry, and the GnuPG reference project states it does not track users or share data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gnupg.org/donate/",
          "note": "The reference implementation GnuPG is funded mainly by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "A standard is not audited as a product; audits cover individual implementations."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.rfc-editor.org/rfc/rfc9580.html",
          "note": "Messages are end-to-end encrypted only when both parties have keys and the sender chooses to encrypt; email is sent in plaintext by default."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.rfc-editor.org/rfc/rfc9580.html",
          "note": "There are no accounts; keys carry a user ID, usually an email address, and no phone number."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Encryption covers the message body only; senders, recipients and subject lines of the carrying channel stay visible."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.rfc-editor.org/rfc/rfc9580.html",
          "note": "No central service; keys are generated locally and messages travel over any channel."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:47.820Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "quiet",
      "category": "messengers",
      "name": "Quiet",
      "description": "Peer-to-peer team chat, similar to Slack, that runs without servers: community members' devices sync messages directly over Tor. The developers warn it is not yet audited.",
      "website": "https://tryquiet.org",
      "source": "https://github.com/TryQuiet/quiet",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 89,
      "coverage": 100,
      "summary": "Quiet scores 89 out of 100 (grade B) on the messengers criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted by default, no phone number needed, metadata protection and decentralized. It does not meet independent audit.",
      "url": "https://privacyratings.com/messengers/quiet/",
      "markdown": "https://privacyratings.com/messengers/quiet/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TryQuiet/quiet/blob/develop/LICENSE.md",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.quietmobile/latest/",
          "note": "Exodus finds no trackers in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/TryQuiet/quiet#donations",
          "note": "Free software with no ads, supported by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": "https://github.com/TryQuiet/quiet",
          "note": "No independent audit is published; the developers state Quiet is not audited."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://tryquiet.org/",
          "note": "All data is encrypted end to end between community members' devices over Tor."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tryquiet.org/",
          "note": "No phone number or email is needed to create or join a community."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tryquiet.org/",
          "note": "There are no servers, and peers connect over Tor onion services, so no third party sees who talks to whom."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://tryquiet.org/",
          "note": "Peer to peer; members' devices sync messages directly with no server."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:22.536Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "ricochet-refresh",
      "category": "messengers",
      "name": "Ricochet Refresh",
      "description": "Desktop instant messenger that runs each user as a Tor onion service and connects contacts peer to peer, hiding identity, IP address and metadata. Maintained by Blueprint for Free Speech.",
      "website": "https://www.ricochetrefresh.net",
      "source": "https://github.com/blueprint-freespeech/ricochet-refresh",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 94,
      "coverage": 100,
      "summary": "Ricochet Refresh scores 94 out of 100 (grade A) on the messengers criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted by default, no phone number needed, metadata protection and decentralized. It partly meets independent audit.",
      "url": "https://privacyratings.com/messengers/ricochet-refresh/",
      "markdown": "https://privacyratings.com/messengers/ricochet-refresh/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/blueprint-freespeech/ricochet-refresh/blob/main/LICENSE",
          "note": "LGPL-2.1 and BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/blueprint-freespeech/ricochet-refresh",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ricochetrefresh.net/",
          "note": "Non-profit project funded by grants such as the NGI Assure Fund, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://public.opentech.fund/documents/ricochet-ncc-audit-2016-01.pdf",
          "note": "A full NCC Group audit of the original Ricochet, which this project forks, is public but is older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.ricochetrefresh.net/",
          "note": "All chats run over end-to-end encrypted Tor onion service connections."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ricochetrefresh.net/",
          "note": "The identity is a Tor onion address generated on the device."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ricochetrefresh.net/",
          "note": "There are no servers, and connections go through Tor circuits so no node knows both sender and recipient."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.ricochetrefresh.net/",
          "note": "Peer to peer over Tor with no servers."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:47.913Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "session",
      "category": "messengers",
      "name": "Session",
      "description": "End-to-end encrypted messenger that uses a random Account ID instead of a phone number and sends messages through onion routing over a decentralized network of community-operated nodes. Stewarded by the Session Technology Foundation in Switzerland.",
      "website": "https://getsession.org",
      "source": "https://github.com/session-foundation",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 94,
      "coverage": 100,
      "summary": "Session scores 94 out of 100 (grade A) on the messengers criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted by default, no phone number needed, metadata protection and decentralized. It partly meets independent audit. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law.",
      "url": "https://privacyratings.com/messengers/session/",
      "markdown": "https://privacyratings.com/messengers/session/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/session-foundation/session-android/blob/dev/LICENSE",
          "note": "The apps are GPL-3.0, and the storage server run by network nodes is MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/network.loki.messenger/latest/",
          "note": "Exodus finds no trackers in the Android app, and the privacy policy states Session stores no information that could be used to track users."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://getsession.org/donate",
          "note": "Funded by donations to the Session Technology Foundation, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://blog.quarkslab.com/resources/2021-05-04_audit-of-session-secure-messaging-application/20-08-Oxen-REP-v1.4.pdf",
          "note": "Quarkslab published a full audit report, but it is older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://getsession.org/faq",
          "note": "One-to-one chats and groups are end-to-end encrypted by default; large public communities are only encrypted in transit to their server."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://getsession.org/faq",
          "note": "No phone number or email is needed; accounts use a randomly generated Account ID."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://getsession.org/whitepaper",
          "note": "Onion requests hide the sender's IP address and no single node knows both origin and destination of a message."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://getsession.org/faq",
          "note": "Messages are stored and relayed by a network of more than a thousand community-operated Session Nodes rather than central servers."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:23.337Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "signal",
      "category": "messengers",
      "name": "Signal",
      "description": "End-to-end encrypted messenger for text, voice and video calls, and groups, built on the Signal Protocol. Run by the non-profit Signal Foundation.",
      "website": "https://signal.org",
      "source": "https://github.com/signalapp/Signal-Server",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 78,
      "coverage": 100,
      "summary": "Signal scores 78 out of 100 (grade B) on the messengers criteria. It meets 5 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted by default and metadata protection. It partly meets no phone number needed. It does not meet independent audit and decentralized. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/messengers/signal/",
      "markdown": "https://privacyratings.com/messengers/signal/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/signalapp/Signal-Server/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.thoughtcrime.securesms/latest/",
          "note": "Exodus finds no trackers in the Android app, and the privacy policy lists no analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://signal.org/donate/",
          "note": "Funded by donations to the non-profit Signal Foundation; the terms state it never sells or monetizes personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published; only academic analyses of the Signal Protocol exist."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://signal.org/docs/",
          "note": "All messages and calls, including groups, use the Signal Protocol end to end."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.signal.org/hc/en-us/articles/6712070553754-Phone-Number-Privacy-and-Usernames",
          "note": "A phone number is required to register, but it is hidden by default and contacts can be reached by username."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://signal.org/blog/sealed-sender/",
          "note": "Sealed sender hides the sender from the server, and contact discovery runs in secure enclaves."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "One central service; the published server code cannot federate with the Signal network."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:47.854Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "simplex",
      "category": "messengers",
      "name": "SimpleX",
      "description": "End-to-end encrypted messenger that has no user identifiers of any kind, not even random ones. Messages pass through relay servers that anyone can run.",
      "website": "https://simplex.chat",
      "source": "https://github.com/simplex-chat/simplex-chat",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 94,
      "coverage": 100,
      "summary": "SimpleX scores 94 out of 100 (grade A) on the messengers criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted by default, no phone number needed, metadata protection and decentralized. It partly meets independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/messengers/simplex/",
      "markdown": "https://privacyratings.com/messengers/simplex/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/simplex-chat/simplex-chat/blob/stable/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://simplex.chat/privacy/",
          "note": "The privacy policy states client apps contain no tracking or analytics code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://simplex.chat/faq/",
          "note": "Funded by venture investment and donations, with no ads; the privacy policy states user data is not sold or monetized."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/simplex-chat/simplex-chat/blob/stable/docs/SimpleX_Design_Review_2024_Summary_Report_12_08_2024.pdf",
          "note": "Trail of Bits reviewed the protocol design, but only a summary report is public; the earlier full audit is older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://simplex.chat/privacy/",
          "note": "All direct and group messages and files are end-to-end encrypted with a quantum-resistant double ratchet."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://simplex.chat/privacy/",
          "note": "No phone number, email or user ID is needed."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://simplex.chat/privacy/",
          "note": "There are no user identifiers; each contact uses separate pairwise message queues, and private routing hides the sender IP from the recipient's server."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://simplex.chat/docs/server.html",
          "note": "Anyone can run SMP and XFTP relay servers, and users on different servers can message each other."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:48.361Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "telegram",
      "category": "messengers",
      "name": "Telegram",
      "description": "Cloud-based messenger with large groups, public channels and bots. Regular chats and groups are stored on Telegram's servers with client-server encryption; only optional one-to-one secret chats are end-to-end encrypted.",
      "website": "https://telegram.org",
      "source": "https://github.com/DrKLO/Telegram",
      "license": "GPL-2.0",
      "platforms": [
        "android",
        "ios",
        "windows",
        "macos",
        "linux",
        "web"
      ],
      "jurisdiction": {
        "code": "AE",
        "name": "United Arab Emirates",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 44,
      "coverage": 100,
      "summary": "Telegram scores 44 out of 100 (grade D) on the messengers criteria. It meets 1 of 8 criteria: no trackers or telemetry. It partly meets open source, no ads or data sales, end-to-end encrypted by default and no phone number needed. It does not meet independent audit, metadata protection and decentralized. It is based in the United Arab Emirates: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/messengers/telegram/",
      "markdown": "https://privacyratings.com/messengers/telegram/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/DrKLO/Telegram/blob/master/LICENSE",
          "note": "The apps are open source (the Android app is GPL-2.0); the server is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.telegram.messenger/latest/",
          "note": "Exodus finds no trackers in the Android app, and the privacy policy states cookies are not used for profiling or advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://telegram.org/privacy#5-6-no-ads-based-on-contents-of-chats-or-contact-lists",
          "note": "Sponsored messages appear in large public channels, bots and search, and by default are based only on the channel topic or search terms rather than user data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://telegram.org/faq#q-so-how-do-you-encrypt-data",
          "note": "Only secret chats, which must be started manually and do not support groups, are end-to-end encrypted; cloud chats and groups use client-server encryption."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://telegram.org/faq#q-who-can-see-my-phone-number",
          "note": "A phone number is required to sign up, but it can be hidden from everyone and contacts can be reached by username."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "The server stores cloud chats and sees who talks to whom."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "One central service; the server code is not published."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:22.967Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "threema",
      "category": "messengers",
      "name": "Threema",
      "description": "Paid end-to-end encrypted messenger from Switzerland that works with a random Threema ID instead of a phone number. The apps are open source; the server is proprietary.",
      "website": "https://threema.com",
      "source": "https://github.com/threema-ch",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 83,
      "coverage": 100,
      "summary": "Threema scores 83 out of 100 (grade B) on the messengers criteria. It meets 5 of 8 criteria: no trackers or telemetry, no ads or data sales, independent audit, end-to-end encrypted by default and no phone number needed. It partly meets open source, metadata protection and decentralized. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law.",
      "url": "https://privacyratings.com/messengers/threema/",
      "markdown": "https://privacyratings.com/messengers/threema/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/threema-ch/threema-android/blob/main/LICENSE.txt",
          "note": "The apps are AGPL-3.0; the server is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://threema.com/en/why-threema/privacy",
          "note": "Threema states it refrains from advertising and tracking users; the website uses only a first-party affiliate cookie."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://threema.com/en/why-threema/privacy",
          "note": "Funded by app purchases and business licenses, with no ads or data trading."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://threema.com/assets/6-resources/audits/3ma-03-report.v3.pdf",
          "note": "Cure53 published a full audit report of the desktop app."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://threema.com/en/why-threema/security",
          "note": "All messages, media, calls and group data are end-to-end encrypted."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://threema.com/en/why-threema/privacy",
          "note": "No phone number or email address is required; accounts use a random Threema ID."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://threema.com/en/why-threema/privacy",
          "note": "Group memberships stay on devices and messages are deleted after delivery, but the server routes messages by sender and recipient ID."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://threema.com/en/products/onprem",
          "note": "Organizations can self-host with Threema OnPrem, but servers do not federate."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:58.004Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "tox-qtox-client",
      "category": "messengers",
      "name": "Tox & qTox client",
      "description": "Peer-to-peer encrypted messaging protocol with no central servers, and qTox, its desktop client for chat, voice, video and file transfer. qTox is now maintained by the TokTok project after the original repository was archived.",
      "website": "https://tox.chat",
      "source": "https://github.com/TokTok/qTox",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 83,
      "coverage": 100,
      "summary": "Tox & qTox client scores 83 out of 100 (grade B) on the messengers criteria. It meets 6 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted by default, no phone number needed and decentralized. It partly meets metadata protection. It does not meet independent audit.",
      "url": "https://privacyratings.com/messengers/tox-qtox-client/",
      "markdown": "https://privacyratings.com/messengers/tox-qtox-client/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TokTok/qTox/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TokTok/qTox",
          "note": "No telemetry or analytics in the source code, and there is no central service to report to."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tox.chat/about.html",
          "note": "Volunteer-run open source project with no company, ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://tox.chat/faq.html",
          "note": "End-to-end encryption with perfect forward secrecy is the default and only mode for all messages."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tox.chat/faq.html",
          "note": "Identity is a Tox ID public key generated on the device."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://tox.chat/faq.html",
          "note": "There are no servers holding contact lists, but Tox does not hide IP addresses from contacts or the public DHT."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://tox.chat/faq.html",
          "note": "Peer to peer over a distributed hash table, with no central servers."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:48.215Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "viber",
      "category": "messengers",
      "name": "Viber",
      "description": "Messenger owned by Rakuten for chats, groups, voice and video calls, communities and channels, tied to a phone number. Private chats, groups and calls are end-to-end encrypted; the app is funded by ads.",
      "website": "https://www.viber.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "LU",
        "name": "Luxembourg",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 22,
      "coverage": 100,
      "summary": "Viber scores 22 out of 100 (grade F) on the messengers criteria. It meets 1 of 8 criteria: end-to-end encrypted by default. It partly meets no phone number needed. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, metadata protection and decentralized. It is based in Luxembourg: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/messengers/viber/",
      "markdown": "https://privacyratings.com/messengers/viber/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.viber.voip/latest/",
          "note": "Exodus finds 21 trackers in the Android app, including Google AdMob, Facebook Ads, AppLovin, Adjust and MixPanel."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.viber.com/en/terms/viber-privacy-policy/",
          "note": "Funded by advertising; the privacy policy describes personalized ads based on Viber activity and data from third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.viber.com/app/uploads/viber-encryption-overview.pdf",
          "note": "One-on-one chats, group chats, calls and media are end-to-end encrypted by default; public communities and channels are not."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.viber.com/en/security/",
          "note": "A phone number is required, but people met in communities or through name search can chat without seeing it."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "The server sees who talks to whom, and the privacy policy lists activity and device data used for advertising."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "One central service run by Rakuten Viber."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Mixpanel",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:57.138Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "whatsapp",
      "category": "messengers",
      "name": "WhatsApp",
      "description": "Messenger owned by Meta for text, voice and video calls, groups and channels, tied to a phone number. Personal chats and calls use the Signal Protocol for end-to-end encryption.",
      "website": "https://www.whatsapp.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "windows",
        "macos",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 22,
      "coverage": 100,
      "summary": "WhatsApp scores 22 out of 100 (grade F) on the messengers criteria. It meets 1 of 8 criteria: end-to-end encrypted by default. It partly meets independent audit. It does not meet open source, no trackers or telemetry, no ads or data sales, no phone number needed, metadata protection and decentralized. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/messengers/whatsapp/",
      "markdown": "https://privacyratings.com/messengers/whatsapp/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.whatsapp.com/legal/privacy-policy",
          "note": "Exodus finds no third-party tracker libraries, but the app collects usage, diagnostic and performance data that cannot be turned off and shares information with other Meta companies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.whatsapp.com/legal/privacy-policy",
          "note": "Ads are shown in Status and Channels, and information is shared with Meta companies, including for marketing."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.nccgroup.com/media/phzpm0qv/_ncc_group_metaplatforms_e008327_report_2023-11-14_v10.pdf",
          "note": "NCC Group published a full review of the key transparency library only; no audit of the app or service is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.whatsapp.com/privacy",
          "note": "Personal messages, group chats and calls are end-to-end encrypted by default; public channels are not."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.whatsapp.com/legal/privacy-policy",
          "note": "A mobile phone number is required to create an account and is shown to contacts."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.whatsapp.com/legal/privacy-policy",
          "note": "The server sees who talks to whom, and the privacy policy lists activity, contacts and connection data that WhatsApp collects."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "One central service run by Meta."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:22.700Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "wire",
      "category": "messengers",
      "name": "Wire",
      "description": "End-to-end encrypted messenger and team collaboration app from Switzerland, with chats, calls and file sharing using Proteus and MLS. Accounts use an email address, and organizations can self-host federated backends.",
      "website": "https://wire.com",
      "source": "https://github.com/wireapp",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "windows",
        "macos",
        "linux",
        "web"
      ],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 61,
      "coverage": 100,
      "summary": "Wire scores 61 out of 100 (grade C) on the messengers criteria. It meets 5 of 8 criteria: open source, no ads or data sales, end-to-end encrypted by default, no phone number needed and decentralized. It does not meet no trackers or telemetry, independent audit and metadata protection. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law.",
      "url": "https://privacyratings.com/messengers/wire/",
      "markdown": "https://privacyratings.com/messengers/wire/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/wireapp/wire-server/blob/develop/LICENSE",
          "note": "The server is AGPL-3.0 and the apps are GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://wire.com/en/privacy-policy",
          "note": "The apps use only opt-in, self-hosted Countly analytics, but the website uses Google Analytics and HubSpot after cookie consent."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://wire.com/en/pricing",
          "note": "Funded by paid team and enterprise plans, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://wire.com/en/security",
          "note": "Messages, calls and files are end-to-end encrypted by default, and encryption cannot be turned off."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://wire-docs.wire.com/download/Wire+Security+Whitepaper.pdf",
          "note": "Accounts can be registered with an email address instead of a phone number."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "no",
          "evidence": "https://wire-docs.wire.com/download/Wire+Privacy+Whitepaper.pdf",
          "note": "The server stores each user's connections and conversation memberships."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.wire.com/latest/understand/federation/index.html",
          "note": "Organizations can run their own Wire backend, and backends can federate with each other."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:57.449Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "xmpp",
      "category": "messengers",
      "name": "XMPP",
      "description": "XMPP, also known as Jabber, is an open standard for federated instant messaging maintained by the XMPP Standards Foundation, with many independent clients and servers.",
      "website": "https://xmpp.org",
      "source": "https://github.com/xsf/xeps",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 78,
      "coverage": 100,
      "summary": "XMPP scores 78 out of 100 (grade B) on the messengers criteria. It meets 5 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, no phone number needed and decentralized. It partly meets end-to-end encrypted by default. It does not meet metadata protection.",
      "url": "https://privacyratings.com/messengers/xmpp/",
      "markdown": "https://privacyratings.com/messengers/xmpp/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://datatracker.ietf.org/doc/html/rfc6120",
          "note": "Open standard (RFC 6120) with many open source clients and servers."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/xsf/xmpp.org",
          "note": "The standard defines no telemetry, and the xmpp.org site loads only its own scripts with no analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://xmpp.org/about/xmpp-standards-foundation/",
          "note": "Maintained by the non-profit XMPP Standards Foundation, funded by sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "A standard is not audited as a product; audits cover individual clients and servers."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee_default": {
          "title": "End-to-end encrypted by default",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://xmpp.org/extensions/xep-0384.html",
          "note": "End-to-end encryption comes from the optional OMEMO extension; some clients enable it by default, but the core protocol does not."
        },
        "no_phone_number": {
          "title": "No phone number needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://datatracker.ietf.org/doc/html/rfc6120",
          "note": "Accounts are addresses of the form user@server; no phone number is involved."
        },
        "metadata_protection": {
          "title": "Metadata protection",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Servers store contact lists and see who talks to whom."
        },
        "decentralized": {
          "title": "Decentralized",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://datatracker.ietf.org/doc/html/rfc6120",
          "note": "Federated; anyone can run a server that talks to other servers."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:48.671Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "campfire",
      "category": "team-chat",
      "name": "Campfire",
      "description": "Self-hosted group chat web app from 37signals with rooms, direct messages, file attachments, search and bot integrations, distributed through ONCE.",
      "website": "https://once.com/campfire",
      "source": "https://github.com/basecamp/once-campfire",
      "license": "MIT",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Campfire scores 80 out of 100 (grade B) on the team chat criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/team-chat/campfire/",
      "markdown": "https://privacyratings.com/team-chat/campfire/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/basecamp/once-campfire/blob/main/MIT-LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/basecamp/once-campfire/blob/main/config/initializers/sentry.rb",
          "note": "No third-party trackers. The once.com website's Plausible analytics are cookieless and aggregate-only, and Sentry error reports are sent only when an administrator sets a DSN."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://once.com/campfire",
          "note": "Free software from 37signals with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:22.852Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "discord",
      "category": "team-chat",
      "name": "Discord",
      "description": "Voice, video and text chat app organized into community servers and channels, with direct messages and screen sharing.",
      "website": "https://discord.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Discord scores 0 out of 100 (grade F) on the team chat criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/team-chat/discord/",
      "markdown": "https://privacyratings.com/team-chat/discord/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.discord/latest/",
          "note": "The Android app contains Google Analytics and crash reporting trackers, and the policy allows sharing data with advertising platforms."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://discord.com/privacy",
          "note": "Partly funded by sponsored content such as Quests, personalized with user data by default; the policy says data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:22.781Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "element",
      "category": "team-chat",
      "name": "Element",
      "description": "Matrix client for web, desktop and mobile with end-to-end encrypted chats, group rooms, file sharing and voice and video calls. Built by Element, which also sells hosted and self-hosted Matrix servers.",
      "website": "https://element.io",
      "source": "https://github.com/element-hq/element-web",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 60,
      "coverage": 100,
      "summary": "Element scores 60 out of 100 (grade C) on the team chat criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets independent audit. It does not meet no trackers or telemetry. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/team-chat/element/",
      "markdown": "https://privacyratings.com/team-chat/element/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/element-hq/element-web/blob/develop/LICENSE-AGPL-3.0",
          "note": "AGPL-3.0 and GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://element.io/legal/privacy",
          "note": "The website loads HubSpot, and the privacy policy lists HubSpot for website analytics and marketing."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://element.io/pricing",
          "note": "Funded by paid hosting and enterprise subscriptions, with no ads; Element commits not to sell personal information."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://matrix.org/media/Least%20Authority%20-%20Matrix%20vodozemac%20Final%20Audit%20Report.pdf",
          "note": "Only the vodozemac encryption library used by Element has a public full audit, and it is older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "HubSpot",
            "host": "js-eu1.hs-scripts.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:57.901Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mattermost",
      "category": "team-chat",
      "name": "Mattermost",
      "description": "Self-hostable team chat with channels, threads, calls and integrations, with desktop, mobile and web apps. Messages are not end-to-end encrypted, and server telemetry is on by default but can be turned off.",
      "website": "https://mattermost.com",
      "source": "https://github.com/mattermost/mattermost",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "Mattermost scores 45 out of 100 (grade D) on the team chat criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source and independent audit. It does not meet no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/team-chat/mattermost/",
      "markdown": "https://privacyratings.com/team-chat/mattermost/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/mattermost/mattermost/blob/master/LICENSE.enterprise",
          "note": "Most code is AGPL-3.0 and Apache-2.0, and some enterprise code is public under the source-available Mattermost Source Available License, but other paid enterprise features are built from a private repository."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://docs.mattermost.com/administration-guide/manage/telemetry",
          "note": "The website loads Google Tag Manager, and server telemetry is on by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mattermost.com/pricing/",
          "note": "Funded by commercial licenses and subscriptions, with no ads in the product."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://trust.mattermost.com/",
          "note": "SOC 2 Type II and other audit reports exist but are available only on request through the trust center."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:48.338Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "microsoft-teams",
      "category": "team-chat",
      "name": "Microsoft Teams",
      "description": "Microsoft's workplace chat and meeting app with channels, direct messages, video calls and file sharing, part of Microsoft 365, with a free tier for personal use.",
      "website": "https://www.microsoft.com/en-us/microsoft-teams/group-chat-software",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Microsoft Teams scores 30 out of 100 (grade F) on the team chat criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/team-chat/microsoft-teams/",
      "markdown": "https://privacyratings.com/team-chat/microsoft-teams/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "Microsoft websites use third-party cookies, including for ads, and Teams sends required diagnostic data by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "Funded by Microsoft 365 subscriptions with no ads in Teams; the privacy statement says chats and video calls are not used to target ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2",
          "note": "Teams is covered by independent SOC 2 Type 2 audits, but the reports are only available to signed-in Microsoft 365 customers."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:23.043Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "nextcloud-talk",
      "category": "team-chat",
      "name": "Nextcloud Talk",
      "description": "Chat, audio and video call app for Nextcloud servers, with group conversations, screen sharing, desktop and mobile clients, and optional federation between servers.",
      "website": "https://nextcloud.com/talk/",
      "source": "https://github.com/nextcloud/spreed",
      "license": "AGPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Nextcloud Talk scores 65 out of 100 (grade C) on the team chat criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/team-chat/nextcloud-talk/",
      "markdown": "https://privacyratings.com/team-chat/nextcloud-talk/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nextcloud/spreed/blob/main/LICENSES/AGPL-3.0-or-later.txt",
          "note": "Server app and clients are AGPL-3.0 or GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": null,
          "note": "No third-party trackers, but the home page loads Matomo Cloud, which can set cookies (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://nextcloud.com/pricing/",
          "note": "Funded by enterprise support subscriptions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Matomo Cloud",
            "host": "cdn.matomo.cloud",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:23.688Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "rocket-chat",
      "category": "team-chat",
      "name": "Rocket.Chat",
      "description": "Self-hostable team chat platform with web, desktop and mobile apps, federation and many integrations. End-to-end encryption is available but off by default, so workspace admins can otherwise read messages.",
      "website": "https://www.rocket.chat",
      "source": "https://github.com/RocketChat/Rocket.Chat",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Rocket.Chat scores 50 out of 100 (grade D) on the team chat criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/team-chat/rocket-chat/",
      "markdown": "https://privacyratings.com/team-chat/rocket-chat/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/RocketChat/Rocket.Chat/blob/develop/LICENSE",
          "note": "All code is public. Most is MIT, and enterprise features in the ee directories use the source-available Rocket.Chat Enterprise license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Tag Manager, HubSpot, Microsoft Clarity and Reddit Pixel (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.rocket.chat/docs/privacy-policy",
          "note": "Funded by paid plans and enterprise licenses; the privacy policy states personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Clarity",
            "host": "www.clarity.ms",
            "effect": "no"
          },
          {
            "name": "Reddit Pixel",
            "host": "www.redditstatic.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:48.610Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "slack",
      "category": "team-chat",
      "name": "Slack",
      "description": "Team messaging app with channels, direct messages, voice and video huddles, file sharing and integrations, owned by Salesforce.",
      "website": "https://slack.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Slack scores 20 out of 100 (grade F) on the team chat criteria. It partly meets no ads or data sales and independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/team-chat/slack/",
      "markdown": "https://privacyratings.com/team-chat/slack/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://slack.com/trust/compliance/cookie-policy",
          "note": "The cookie policy lists third-party cookies such as Google Analytics and advertising pixels on its websites."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://slack.com/trust/privacy/privacy-policy",
          "note": "Funded by subscriptions with no ads in the product, but the policy allows sharing identifiers with third-party advertisers to target Slack ads on other sites."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://a.slack-edge.com/d6e4a4e/marketing/downloads/security/Slack_SOC_3_2025_Report.pdf",
          "note": "Only a SOC 3 summary report is public; the full SOC 2 report is available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:23.025Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "stoat",
      "category": "team-chat",
      "name": "Stoat",
      "description": "Open source chat platform for friends and communities with servers, channels, direct messages and voice chat, formerly named Revolt. The server software can be self-hosted.",
      "website": "https://stoat.chat",
      "source": "https://github.com/stoatchat/stoatchat",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Stoat scores 65 out of 100 (grade C) on the team chat criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/team-chat/stoat/",
      "markdown": "https://privacyratings.com/team-chat/stoat/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/stoatchat/stoatchat/blob/main/LICENSE",
          "note": "Server and apps are AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/stoatchat/for-web/blob/main/packages/client/src/sentry.ts",
          "note": "The official web and Android builds enable Sentry crash reporting by default; no ad or analytics trackers are used."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://stoat.chat/legal/privacy",
          "note": "No ads; the privacy policy states data is never sold to third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:23.471Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "xeres",
      "category": "team-chat",
      "name": "Xeres",
      "description": "A decentralized, encrypted P2P friend-to-friend app for chat, forums, channels, boards, voice calls and anonymous file sharing.",
      "website": "https://xeres.io",
      "source": "https://github.com/zapek/Xeres",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Xeres scores 80 out of 100 (grade B) on the team chat criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/team-chat/xeres/",
      "markdown": "https://privacyratings.com/team-chat/xeres/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/zapek/Xeres/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/zapek/Xeres",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://xeres.io/",
          "note": "Free GPL software developed by an individual, with no ads, accounts or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:49.601Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "zulip",
      "category": "team-chat",
      "name": "Zulip",
      "description": "Open source team chat that organizes conversations into channels and named topics. It can be self-hosted or used as the Zulip Cloud service run by Kandra Labs.",
      "website": "https://zulip.com",
      "source": "https://github.com/zulip/zulip",
      "license": "Apache-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Zulip scores 65 out of 100 (grade C) on the team chat criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/team-chat/zulip/",
      "markdown": "https://privacyratings.com/team-chat/zulip/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/zulip/zulip/blob/main/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://zulip.readthedocs.io/en/latest/production/mobile-push-notifications.html",
          "note": "No third-party trackers were found on the website, but self-hosted servers using the push notification service send usage statistics by default, which admins can turn off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://zulip.com/plans/",
          "note": "Funded by paid Cloud plans and self-hosted support contracts; the privacy policy states personal data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:48.912Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bigbluebutton",
      "category": "video-calls",
      "name": "BigBlueButton",
      "description": "Self-hosted web conferencing system for online classes, with whiteboard, shared notes, breakout rooms, polls and recording, often integrated with learning management systems.",
      "website": "https://bigbluebutton.org",
      "source": "https://github.com/bigbluebutton/bigbluebutton",
      "license": "LGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 47,
      "coverage": 100,
      "summary": "BigBlueButton scores 47 out of 100 (grade D) on the video calls criteria. It meets 4 of 7 criteria: open source, no ads or data sales, join without an account and self-hostable. It does not meet no trackers or telemetry, independent audit and end-to-end encrypted.",
      "url": "https://privacyratings.com/video-calls/bigbluebutton/",
      "markdown": "https://privacyratings.com/video-calls/bigbluebutton/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bigbluebutton/bigbluebutton/blob/v3.0.x-develop/LICENSE",
          "note": "LGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://bigbluebutton.org/privacy-policy/",
          "note": "The bigbluebutton.org website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.bigbluebutton.org/support/faq/",
          "note": "Open source project with no ads, supported by companies that sell hosting and support."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee": {
          "title": "End-to-end encrypted",
          "weight": 3,
          "answer": "no",
          "evidence": "https://docs.bigbluebutton.org/support/faq/",
          "note": "Media is encrypted between each browser and the server with DTLS-SRTP, not end to end."
        },
        "no_account_needed": {
          "title": "Join without an account",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.bigbluebutton.org/development/api/",
          "note": "The server has no user accounts; participants join through links created by a front end such as Greenlight or a learning platform."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.bigbluebutton.org/administration/install/",
          "note": "Official installation guide for Ubuntu servers."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:23.670Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "brave-talk",
      "category": "video-calls",
      "name": "Brave Talk",
      "description": "Browser-based video calling service from Brave, built on Jitsi and run with 8x8. Calls are started from the Brave browser and can be joined from any browser.",
      "website": "https://talk.brave.com",
      "source": "https://github.com/brave/brave-talk",
      "license": "MPL-2.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 60,
      "coverage": 100,
      "summary": "Brave Talk scores 60 out of 100 (grade C) on the video calls criteria. It meets 3 of 7 criteria: no trackers or telemetry, no ads or data sales and join without an account. It partly meets open source and end-to-end encrypted. It does not meet independent audit and self-hostable. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/video-calls/brave-talk/",
      "markdown": "https://privacyratings.com/video-calls/brave-talk/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/brave/brave-talk/blob/main/LICENSE",
          "note": "The web app is MPL-2.0 and built on open source Jitsi, but the hosted 8x8 service setup is not public."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://brave.com/talk/",
          "note": "Brave states the service has no tracking and no data collection linking users to calls."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://brave.com/talk/",
          "note": "Funded by a paid premium tier, with no ads in calls."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee": {
          "title": "End-to-end encrypted",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://brave.com/talk/",
          "note": "Calls use transport encryption by default; Video Bridge Encryption is optional and has limits on call size and phone participants."
        },
        "no_account_needed": {
          "title": "Join without an account",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://brave.com/talk/",
          "note": "Calls can be started and joined without an account or login."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Hosted only; the service runs on 8x8 infrastructure."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:23.181Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "element-call",
      "category": "video-calls",
      "name": "Element Call",
      "description": "Open source group video calling app built on Matrix and LiveKit, usable standalone in the browser at call.element.io or inside Matrix apps such as Element X. It can be self-hosted.",
      "website": "https://call.element.io",
      "source": "https://github.com/element-hq/element-call",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 77,
      "coverage": 100,
      "summary": "Element Call scores 77 out of 100 (grade B) on the video calls criteria. It meets 5 of 7 criteria: open source, no ads or data sales, end-to-end encrypted, join without an account and self-hostable. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/video-calls/element-call/",
      "markdown": "https://privacyratings.com/video-calls/element-call/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/element-hq/element-call/blob/main/LICENSE-AGPL-3.0",
          "note": "AGPL-3.0, with a commercial license option."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://call.element.io/config.json",
          "note": "call.element.io sends Sentry error reports to Element's own server by default; PostHog usage analytics are opt-in."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://element.io/pricing",
          "note": "Funded by Element's paid hosting and enterprise plans, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee": {
          "title": "End-to-end encrypted",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/element-hq/element-call/blob/main/README.md",
          "note": "Calls, including group calls, are end-to-end encrypted with MatrixRTC."
        },
        "no_account_needed": {
          "title": "Join without an account",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/element-hq/element-call/blob/main/docs/self_hosting.md",
          "note": "Unregistered users can join a standalone call from a link by entering a name; a temporary account is created automatically."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/element-hq/element-call/blob/main/docs/self_hosting.md",
          "note": "Official self-hosting guide with a Matrix homeserver and LiveKit."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:23.391Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "facetime",
      "category": "video-calls",
      "name": "FaceTime",
      "description": "Apple's audio and video calling app built into iPhone, iPad, Mac and Apple Vision Pro, supporting group calls and call links that others can join from a web browser.",
      "website": "https://support.apple.com/facetime",
      "license": null,
      "platforms": [
        "macos",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 47,
      "coverage": 100,
      "summary": "FaceTime scores 47 out of 100 (grade D) on the video calls criteria. It meets 2 of 7 criteria: no ads or data sales and end-to-end encrypted. It partly meets no trackers or telemetry and join without an account. It does not meet open source, independent audit and self-hostable. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/video-calls/facetime/",
      "markdown": "https://privacyratings.com/video-calls/facetime/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/device-analytics/",
          "note": "No third-party trackers in the app, and sharing device analytics with Apple is opt-in. Apple web pages load Apple's own analytics (ac-analytics, sent to metrics.apple.com) by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/en-ww/",
          "note": "No ads in FaceTime. Apple states it does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee": {
          "title": "End-to-end encrypted",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://support.apple.com/guide/security/facetime-security-seca331c55cd/web",
          "note": "One-to-one and Group FaceTime calls are end-to-end encrypted."
        },
        "no_account_needed": {
          "title": "Join without an account",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://support.apple.com/en-us/109364",
          "note": "People with a FaceTime link can join from a web browser without an Apple Account; the person creating the link needs an Apple device and account."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Hosted only."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:23.489Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "galene",
      "category": "video-calls",
      "name": "Galène",
      "description": "Lightweight self-hosted videoconference server with a web client, designed for lectures, conferences and meetings, with screen sharing, chat and recording.",
      "website": "https://galene.org",
      "source": "https://github.com/jech/galene",
      "license": "MIT",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 67,
      "coverage": 100,
      "summary": "Galène scores 67 out of 100 (grade C) on the video calls criteria. It meets 5 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, join without an account and self-hostable. It does not meet independent audit and end-to-end encrypted.",
      "url": "https://privacyratings.com/video-calls/galene/",
      "markdown": "https://privacyratings.com/video-calls/galene/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jech/galene/blob/master/LICENCE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jech/galene",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://galene.org/",
          "note": "Free software with no ads, supported by NLnet grants."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee": {
          "title": "End-to-end encrypted",
          "weight": 3,
          "answer": "no",
          "evidence": "https://galene.org/",
          "note": "Traffic is encrypted to and from the server, but not end to end."
        },
        "no_account_needed": {
          "title": "Join without an account",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/jech/galene/blob/master/galene.md",
          "note": "Invitation links allow password-less login, and groups can let anyone join with any name."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/jech/galene/blob/master/galene-install.md",
          "note": "Official installation guide; self-hosting is the only way to run it."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:24.003Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "google-meet",
      "category": "video-calls",
      "name": "Google Meet",
      "description": "Google's video meeting service, part of Google Workspace, used in the browser and in mobile apps with screen sharing, captions and recording.",
      "website": "https://workspace.google.com/products/meet/",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Google Meet scores 20 out of 100 (grade F) on the video calls criteria. It partly meets independent audit, end-to-end encrypted and join without an account. It does not meet open source, no trackers or telemetry, no ads or data sales and self-hostable. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/video-calls/google-meet/",
      "markdown": "https://privacyratings.com/video-calls/google-meet/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Google collects activity data across its services and uses it for analytics and personalized ads."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Free for personal accounts and funded by Google's advertising business, which uses activity data across services."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cloud.google.com/security/compliance/soc-3",
          "note": "Google Workspace, which includes Meet, has third-party SOC 2 audits. Only the SOC 3 summary report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee": {
          "title": "End-to-end encrypted",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://support.google.com/meet/answer/12387251",
          "note": "Meetings use cloud encryption by default; end-to-end or client-side encryption is optional and limited to some calls and accounts."
        },
        "no_account_needed": {
          "title": "Join without an account",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://support.google.com/meet/answer/9303069",
          "note": "Guests can ask to join without a Google account if someone in the meeting admits them; organizers need an account."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Hosted only."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:23.532Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "jitsi",
      "category": "video-calls",
      "name": "Jitsi",
      "description": "Open source video conferencing that runs in the browser without an account, with desktop and mobile apps. It can be self-hosted or used through the free meet.jit.si service run by 8x8.",
      "website": "https://jitsi.org",
      "source": "https://github.com/jitsi/jitsi-meet",
      "license": "Apache-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 53,
      "coverage": 100,
      "summary": "Jitsi scores 53 out of 100 (grade D) on the video calls criteria. It meets 3 of 7 criteria: open source, no ads or data sales and self-hostable. It partly meets end-to-end encrypted and join without an account. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/video-calls/jitsi/",
      "markdown": "https://privacyratings.com/video-calls/jitsi/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jitsi/jitsi-meet/blob/master/LICENSE",
          "note": "Apache-2.0 and MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://meet.jit.si/config.js",
          "note": "The public meet.jit.si service sends usage events to Amplitude analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://jitsi.org/meet-jit-si-privacy/",
          "note": "Developed and funded by 8x8, with no ads; the privacy notice states personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee": {
          "title": "End-to-end encrypted",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://jitsi.org/security/",
          "note": "End-to-end encryption is optional and must be turned on in each meeting."
        },
        "no_account_needed": {
          "title": "Join without an account",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://jitsi.org/security/",
          "note": "On meet.jit.si the person creating the room must sign in; guests join from a link without an account."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://jitsi.github.io/handbook/docs/devops-guide/devops-guide-quickstart/",
          "note": "Official self-hosting guide and Debian packages."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:49.167Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "webex",
      "category": "video-calls",
      "name": "Webex",
      "description": "Cisco's video meeting and team messaging platform with desktop, mobile and browser apps, webinars and calling features.",
      "website": "https://www.webex.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Webex scores 30 out of 100 (grade F) on the video calls criteria. It partly meets no ads or data sales, independent audit, end-to-end encrypted, join without an account and self-hostable. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/video-calls/webex/",
      "markdown": "https://privacyratings.com/video-calls/webex/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.cisco.com/c/en/us/about/legal/privacy-full.html",
          "note": "The Cisco privacy statement describes third-party cookies used for interest-based advertising on its websites."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.cisco.com/c/en/us/about/legal/privacy-full.html",
          "note": "Funded by subscriptions with no ads in meetings, but Cisco works with third parties on interest-based advertising; Cisco states it does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://help.webex.com/en-us/article/pdz31w/Webex-Compliance-and-Certifications",
          "note": "Webex lists ISO 27001 certification, but no audit report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee": {
          "title": "End-to-end encrypted",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://help.webex.com/en-us/article/nsj2xpfb/Schedule-a-Webex-Meeting-with-end-to-end-encryption",
          "note": "End-to-end encryption is available as a separate meeting type that must be chosen by the host or set by an administrator."
        },
        "no_account_needed": {
          "title": "Join without an account",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://help.webex.com/en-us/article/n665eiq/Join-a-Webex-Meeting-for-the-first-time-as-a-guest",
          "note": "Guests can join from a link without an account; hosts need a Webex account."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://help.webex.com/en-us/article/maj0a6/Proxy-Support-for-Hybrid-Data-Security-and-Webex-Video-Mesh",
          "note": "Webex Video Mesh nodes can process meeting media on customer premises, but meetings still depend on the Webex cloud."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:23.788Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "whereby",
      "category": "video-calls",
      "name": "Whereby",
      "description": "Browser-based video meeting service from Norway where hosts create permanent room links that guests open in a browser, with mobile apps and an embeddable video API.",
      "website": "https://whereby.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "NO",
        "name": "Norway",
        "eyes": "Nine Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 33,
      "coverage": 100,
      "summary": "Whereby scores 33 out of 100 (grade F) on the video calls criteria. It meets 1 of 7 criteria: no ads or data sales. It partly meets independent audit, end-to-end encrypted and join without an account. It does not meet open source, no trackers or telemetry and self-hostable. It is based in Norway: Nine Eyes member; EEA member (GDPR).",
      "url": "https://privacyratings.com/video-calls/whereby/",
      "markdown": "https://privacyratings.com/video-calls/whereby/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://whereby.com/information/tos/privacy-policy/",
          "note": "The home page loads Google Tag Manager, and the policy describes an analytics tracking system."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://whereby.com/information/tos/privacy-policy/",
          "note": "Funded by paid subscriptions; the privacy policy says user data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://whereby.com/information/security/",
          "note": "Third-party penetration test summaries are only shared under NDA, and only the ISO 27001 certificate is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee": {
          "title": "End-to-end encrypted",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://whereby.com/information/security/",
          "note": "Small peer-to-peer rooms are end-to-end encrypted; larger rooms routed through servers are not."
        },
        "no_account_needed": {
          "title": "Join without an account",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://support.whereby.com/en/articles/4369346",
          "note": "Guests join from the room link in a browser without an account; room owners need an account."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Hosted only."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Fathom",
            "host": "cdn.usefathom.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:24.195Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "zoom",
      "category": "video-calls",
      "name": "Zoom",
      "description": "Video meeting platform with desktop, mobile and browser apps, screen sharing, chat, recording and webinars.",
      "website": "https://www.zoom.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 23,
      "coverage": 100,
      "summary": "Zoom scores 23 out of 100 (grade F) on the video calls criteria. It partly meets independent audit, end-to-end encrypted, join without an account and self-hostable. It does not meet open source, no trackers or telemetry and no ads or data sales. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/video-calls/zoom/",
      "markdown": "https://privacyratings.com/video-calls/zoom/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.zoom.com/en/trust/privacy/privacy-statement/",
          "note": "The privacy statement describes third-party advertising and analytics cookies shared with marketing partners."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.zoom.com/en/trust/privacy/privacy-statement/",
          "note": "The privacy statement allows targeted advertising through third-party partners and sales of business contact data through one product."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.zoom.com/en/trust/legal-compliance/",
          "note": "Zoom lists SOC 2 Type 2, ISO 27001 and FedRAMP audits, but the reports are not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "e2ee": {
          "title": "End-to-end encrypted",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0065408",
          "note": "End-to-end encryption is optional, off by default and disables features such as cloud recording and the web client."
        },
        "no_account_needed": {
          "title": "Join without an account",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0060732",
          "note": "Participants can join without an account; hosts need a Zoom account."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.zoom.com/en/products/zoom-node/",
          "note": "Zoom Node can keep meeting media on customer servers, but it is managed from and depends on the Zoom cloud."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          },
          {
            "name": "Optimizely",
            "host": "cdn.optimizely.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:23.726Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "beehiiv",
      "category": "newsletters",
      "name": "beehiiv",
      "description": "Newsletter platform for writing, sending and monetizing email newsletters, with websites, paid subscriptions, referral programs and an ad network that places sponsors in newsletters.",
      "website": "https://www.beehiiv.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 13,
      "coverage": 100,
      "summary": "beehiiv scores 13 out of 100 (grade F) on the newsletter platforms criteria. It meets 1 of 8 criteria: TLS configuration. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/newsletters/beehiiv/",
      "markdown": "https://privacyratings.com/newsletters/beehiiv/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.beehiiv.com/privacy",
          "note": "The home page loads Google Tag Manager, HubSpot and TikTok scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.beehiiv.com/privacy",
          "note": "Runs an ad network, and the policy covers sharing data for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.beehiiv.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.beehiiv.com",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          },
          {
            "name": "Meta Pixel",
            "host": "www.facebook.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:25.036Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "buttondown",
      "category": "newsletters",
      "name": "Buttondown",
      "description": "Hosted newsletter service for writing and sending email newsletters in Markdown, with paid subscriptions, archives, custom domains and an API.",
      "website": "https://buttondown.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 28,
      "coverage": 100,
      "summary": "Buttondown scores 28 out of 100 (grade F) on the newsletter platforms criteria. It meets 1 of 8 criteria: no ads or data sales. It partly meets no trackers or telemetry and TLS configuration. It does not meet open source, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade C-.",
      "url": "https://privacyratings.com/newsletters/buttondown/",
      "markdown": "https://privacyratings.com/newsletters/buttondown/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://buttondown.com/legal/privacy",
          "note": "The website uses Seline, a cookieless analytics service, and the policy describes collecting data for internal analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://buttondown.com/pricing",
          "note": "Funded by paid plans, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=buttondown.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=buttondown.com",
          "note": "Grade C- (45/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "C-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:23.897Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "forward-email",
      "category": "newsletters",
      "name": "Forward Email",
      "description": "Email service whose paid plans include outbound SMTP, which can send newsletters and mailing lists from a list tool such as listmonk. Newsletter sending needs approval for each domain. Subscriber lists and campaigns are managed in the separate tool.",
      "website": "https://forwardemail.net",
      "source": "https://github.com/forwardemail/forwardemail.net",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": "Privacy Ratings is maintained by the team behind Forward Email. This entry is scored by the same criteria as every other entry in this category, and changes to it are reviewed under the published conflict-of-interest rules.",
      "grade": "B",
      "score": 84,
      "coverage": 100,
      "summary": "Forward Email scores 84 out of 100 (grade B) on the newsletter platforms criteria. It meets 6 of 8 criteria: open source, no ads or data sales, independent audit, tells users about requests, TLS configuration and security headers. It partly meets no trackers or telemetry and transparency report. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/newsletters/forward-email/",
      "markdown": "https://privacyratings.com/newsletters/forward-email/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/forwardemail/forwardemail.net/blob/master/LICENSE.md",
          "note": "All code is public, including the outbound SMTP servers that run the service. Core mail storage and protocol code is MPL-2.0 and the rest is under the source-available Business Source License 1.1 (BUSL-1.1), which becomes MPL-2.0 four years after each release."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://forwardemail.net/en/privacy#analytics",
          "note": "No third-party analytics. First-party anonymized analytics of page views and service usage is on by default, and Cloudflare Turnstile loads on sign-in and sign-up forms."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/private-business-email",
          "note": "Funded by paid plans. No ads, and the privacy policy states user data is not shared with third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cure53.de/pentest-report_forward-email.pdf",
          "note": "Two independent Cure53 audits of the code and the infrastructure are published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://forwardemail.net/technical-whitepaper.pdf",
          "note": "The technical whitepaper (section 9.3) publishes the government request policy and commits to transparency reports with request counts. A report with counts is not published yet."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://forwardemail.net/technical-whitepaper.pdf",
          "note": "Users are notified of requests when legally allowed, with notice after disclosure when advance notice is prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=forwardemail.net&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=forwardemail.net",
          "note": "Grade A+ (125/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:29:21.626Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "keila",
      "category": "newsletters",
      "name": "Keila",
      "description": "Open source newsletter tool with a visual and Markdown editor, sign-up forms and subscriber segments. It can be self-hosted or used through Keila Cloud, a hosted service run by Keila GmbH in Germany.",
      "website": "https://www.keila.io",
      "source": "https://github.com/pentacent/keila",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 59,
      "coverage": 100,
      "summary": "Keila scores 59 out of 100 (grade D) on the newsletter platforms criteria. It meets 3 of 8 criteria: open source, no ads or data sales and TLS configuration. It partly meets no trackers or telemetry and transparency report. It does not meet independent audit, tells users about requests and security headers. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/newsletters/keila/",
      "markdown": "https://privacyratings.com/newsletters/keila/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pentacent/keila/blob/main/LICENSE.md",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.keila.io/legal/privacy/",
          "note": "The website uses first-party analytics from its own tracking server; newsletter open and click tracking can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.keila.io/legal/privacy/",
          "note": "Funded by paid hosting plans; the policy says data is never rented or sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.keila.io/legal/privacy/",
          "note": "The privacy policy says it only complies with disclosure requests from German authorities, but publishes no request counts."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.keila.io&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.keila.io",
          "note": "Grade D (35/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:24.570Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "kit",
      "category": "newsletters",
      "name": "Kit",
      "description": "Email marketing platform for creators, formerly ConvertKit, with sign-up forms, landing pages, automated email sequences, paid newsletters and digital product sales.",
      "website": "https://kit.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 19,
      "coverage": 100,
      "summary": "Kit scores 19 out of 100 (grade F) on the newsletter platforms criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/newsletters/kit/",
      "markdown": "https://privacyratings.com/newsletters/kit/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://help.kit.com/en/articles/2502687-how-email-open-tracking-works",
          "note": "Emails track opens with images and clicks by default, and a tracking pixel is offered for creators' websites."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://help.kit.com/en/articles/14017264-programmatic-ads-compliance-opt-out-link-and-privacy-policy-requirements",
          "note": "Funded by subscriptions, but creators can add Kit Ads that show personalized ads to subscribers unless they opt out."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=kit.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=kit.com",
          "note": "Grade D (35/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:23.842Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "listmonk",
      "category": "newsletters",
      "name": "listmonk",
      "description": "Self-hosted newsletter and mailing list manager distributed as a single binary with a PostgreSQL database, with a web dashboard, templates, subscriber lists and transactional email API.",
      "website": "https://listmonk.app",
      "source": "https://github.com/knadh/listmonk",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "listmonk scores 80 out of 100 (grade B) on the newsletter platforms criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/newsletters/listmonk/",
      "markdown": "https://privacyratings.com/newsletters/listmonk/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/knadh/listmonk/blob/master/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/knadh/listmonk/blob/master/schema.sql",
          "note": "No telemetry or analytics in the source code, and individual subscriber tracking is off by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://listmonk.app/",
          "note": "Free open source software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:23.894Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "mailchimp",
      "category": "newsletters",
      "name": "Mailchimp",
      "description": "Email marketing platform owned by Intuit for building mailing lists, sending newsletters and automated campaigns, and tracking opens and clicks.",
      "website": "https://mailchimp.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 34,
      "coverage": 100,
      "summary": "Mailchimp scores 34 out of 100 (grade F) on the newsletter platforms criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales, independent audit, transparency report and tells users about requests. It does not meet open source, no trackers or telemetry and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C+.",
      "url": "https://privacyratings.com/newsletters/mailchimp/",
      "markdown": "https://privacyratings.com/newsletters/mailchimp/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.intuit.com/privacy/statement/",
          "note": "The Intuit privacy statement covers advertising cookies, pixels and session-replay tools, and campaigns track opens and clicks by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.intuit.com/privacy/statement/",
          "note": "Funded by subscriptions and states data is not sold, but personal information is shared with advertising networks for targeted ads unless users opt out."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://mailchimp.com/about/security/",
          "note": "SOC 2 and ISO 27001 audits are done, but the reports are only available through the Intuit compliance portal."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://mailchimp.com/legal/service-of-legal-process/",
          "note": "Publishes how it accepts legal process from governments, but no request counts."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://mailchimp.com/legal/service-of-legal-process/",
          "note": "Mailchimp reserves the right to notify customers of legal process, and some customer agreements require notice unless prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mailchimp.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mailchimp.com",
          "note": "Grade C+ (60/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          },
          {
            "name": "Optimizely",
            "host": "cdn.optimizely.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:24.179Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "phplist",
      "category": "newsletters",
      "name": "phpList",
      "description": "Open source newsletter and mailing list manager written in PHP, installed on your own web server. phpList Ltd in the UK also runs a hosted version at phplist.com.",
      "website": "https://www.phplist.org",
      "source": "https://github.com/phpList/phplist3",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 47,
      "coverage": 100,
      "summary": "phpList scores 47 out of 100 (grade D) on the newsletter platforms criteria. It meets 3 of 8 criteria: open source, no ads or data sales and TLS configuration. It partly meets security headers. It does not meet no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/newsletters/phplist/",
      "markdown": "https://privacyratings.com/newsletters/phplist/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/phpList/phplist3/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.phplist.com/privacy",
          "note": "The phplist.com website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.phplist.com/privacy",
          "note": "Funded by hosted plans; the policy says contact lists are never sold, shared or rented."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.phplist.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.phplist.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:24.632Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "substack",
      "category": "newsletters",
      "name": "Substack",
      "description": "Publishing platform for email newsletters, podcasts and video where writers can charge for subscriptions, with a reader app, comments and a social feed called Notes.",
      "website": "https://substack.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Substack scores 25 out of 100 (grade F) on the newsletter platforms criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B-.",
      "url": "https://privacyratings.com/newsletters/substack/",
      "markdown": "https://privacyratings.com/newsletters/substack/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://substack.com/privacy",
          "note": "The cookie list in the privacy policy includes third-party analytics and FullStory session tracking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://substack.com/privacy",
          "note": "Funded by a share of paid subscriptions; the policy says data is not sold or shared for cross-context behavioral advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=substack.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=substack.com",
          "note": "Grade B- (65/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:44:11.066Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "chatwoot",
      "category": "customer-support",
      "name": "Chatwoot",
      "description": "Open source customer support platform with a shared inbox for website chat, email, social media and messaging apps, plus a help center and automations. It can be self-hosted or used through Chatwoot Cloud.",
      "website": "https://www.chatwoot.com",
      "source": "https://github.com/chatwoot/chatwoot",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 53,
      "coverage": 100,
      "summary": "Chatwoot scores 53 out of 100 (grade D) on the customer support and live chat criteria. It meets 3 of 8 criteria: open source, no ads or data sales and TLS configuration. It partly meets no trackers or telemetry. It does not meet independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/customer-support/chatwoot/",
      "markdown": "https://privacyratings.com/customer-support/chatwoot/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/chatwoot/chatwoot/blob/develop/LICENSE",
          "note": "All code is public. Most is MIT, and the enterprise directory in the same repository uses a source-available proprietary license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/chatwoot/chatwoot/blob/develop/lib/chatwoot_hub.rb",
          "note": "Self-hosted instances send usage metrics to Chatwoot by default unless telemetry is disabled; no third-party trackers were found on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.chatwoot.com/privacy-policy",
          "note": "Funded by paid plans; the privacy policy says personal information is not rented or sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.chatwoot.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.chatwoot.com",
          "note": "Grade F (10/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:24.451Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "freescout",
      "category": "customer-support",
      "name": "FreeScout",
      "description": "Self-hosted help desk and shared mailbox written in PHP, with ticketing, customer profiles and optional modules for chat, knowledge base, workflows and more.",
      "website": "https://freescout.net",
      "source": "https://github.com/freescout-help-desk/freescout",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "FreeScout scores 50 out of 100 (grade D) on the customer support and live chat criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/customer-support/freescout/",
      "markdown": "https://privacyratings.com/customer-support/freescout/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/freescout-help-desk/freescout/blob/dist/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://freescout.net/legal/privacy/",
          "note": "The freescout.net privacy policy states that Google Analytics sets analytics cookies on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://freescout.net/modules/",
          "note": "Free software funded by sales of optional paid modules, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Simple Analytics",
            "host": "scripts.simpleanalyticscdn.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:24.431Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "freshdesk",
      "category": "customer-support",
      "name": "Freshdesk",
      "description": "Help desk software from Freshworks with ticketing across email, chat, phone and social channels, a knowledge base, automations and AI assistants.",
      "website": "https://www.freshworks.com/freshdesk/",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 28,
      "coverage": 100,
      "summary": "Freshdesk scores 28 out of 100 (grade F) on the customer support and live chat criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales, independent audit and security headers. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/customer-support/freshdesk/",
      "markdown": "https://privacyratings.com/customer-support/freshdesk/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.freshworks.com/privacy/",
          "note": "The privacy notice describes cookies and pixels used for personalized ads, and sharing of hashed contact details with social media platforms."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.freshworks.com/privacy/",
          "note": "Funded by subscriptions with no ads in the product, but personal data is shared with advertising partners for targeted marketing; it states data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.freshworks.com/security/",
          "note": "SOC 2 and ISO certifications are listed, but the audit reports are only available through the trust center."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.freshworks.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.freshworks.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "LinkedIn Insight",
            "host": "px.ads.linkedin.com",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn-ukwest.onetrust.com",
            "effect": "none"
          },
          {
            "name": "Optimizely",
            "host": "cdn.optimizely.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:24.499Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "help-scout",
      "category": "customer-support",
      "name": "Help Scout",
      "description": "Customer support platform with a shared email inbox, live chat widget, knowledge base and customer profiles, run by Help Scout PBC in the United States.",
      "website": "https://www.helpscout.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 19,
      "coverage": 100,
      "summary": "Help Scout scores 19 out of 100 (grade F) on the customer support and live chat criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets independent audit. It does not meet open source, no trackers or telemetry, no ads or data sales, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C-.",
      "url": "https://privacyratings.com/customer-support/help-scout/",
      "markdown": "https://privacyratings.com/customer-support/help-scout/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.helpscout.com/company/legal/privacy/",
          "note": "The privacy policy describes cookies from third-party analytics and advertising partners used for interest-based ads."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.helpscout.com/company/legal/privacy/",
          "note": "The privacy policy discloses that browsing data and hashed email addresses were sold or shared with advertising partners."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.helpscout.com/company/legal/security/",
          "note": "SOC 2 Type 2 reports and independent penetration test results are only available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.helpscout.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.helpscout.com",
          "note": "Grade C- (45/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:24.788Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "intercom",
      "category": "customer-support",
      "name": "Intercom",
      "description": "Customer service platform with a shared inbox, in-app and website chat messenger, help center, ticketing and the Fin AI agent for answering customer questions.",
      "website": "https://www.intercom.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 41,
      "coverage": 100,
      "summary": "Intercom scores 41 out of 100 (grade D) on the customer support and live chat criteria. It meets 2 of 8 criteria: tells users about requests and TLS configuration. It partly meets no ads or data sales, independent audit, transparency report and security headers. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/customer-support/intercom/",
      "markdown": "https://privacyratings.com/customer-support/intercom/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.intercom.com/legal/privacy",
          "note": "The privacy policy describes cookies and services from advertising partners used for targeted ads and analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.intercom.com/legal/privacy",
          "note": "Funded by subscriptions with no ads in the product, but identifiers and browsing data are shared with advertising partners for targeted ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.intercom.com/security",
          "note": "SOC 2 Type II and ISO 27001 audits are done, but the reports are only provided through the trust center, not published openly."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.intercom.com/legal/law-enforcement-guidelines",
          "note": "Publishes law enforcement guidelines, but no request counts."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.intercom.com/legal/law-enforcement-guidelines",
          "note": "Notifies users before disclosure so they can challenge the request, unless prohibited by law or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.intercom.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.intercom.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:24.933Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "zammad",
      "category": "customer-support",
      "name": "Zammad",
      "description": "Open source help desk and ticketing system that brings email, chat, phone, forms and social media into one web interface. It can be self-hosted, and Zammad GmbH in Germany also offers hosted instances.",
      "website": "https://zammad.org",
      "source": "https://github.com/zammad/zammad",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Zammad scores 65 out of 100 (grade C) on the customer support and live chat criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/customer-support/zammad/",
      "markdown": "https://privacyratings.com/customer-support/zammad/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/zammad/zammad/blob/develop/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://zammad.com/en/company/privacy",
          "note": "The websites use self-hosted Matomo analytics without cookies; the software itself has no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://zammad.com/en/company/privacy",
          "note": "Funded by hosting and support plans; the privacy policy says data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Matomo Cloud",
            "host": "cdn.matomo.cloud",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:25.309Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "zendesk",
      "category": "customer-support",
      "name": "Zendesk",
      "description": "Customer service platform with a shared ticket inbox, live chat, help center, voice support and AI agents for handling customer conversations across channels.",
      "website": "https://www.zendesk.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 41,
      "coverage": 100,
      "summary": "Zendesk scores 41 out of 100 (grade D) on the customer support and live chat criteria. It meets 2 of 8 criteria: transparency report and tells users about requests. It partly meets no ads or data sales, independent audit, TLS configuration and security headers. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/customer-support/zendesk/",
      "markdown": "https://privacyratings.com/customer-support/zendesk/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.zendesk.com/company/agreements-and-terms/privacy-notice/",
          "note": "The privacy notice describes sharing identifiers and browsing data with advertising partners through cookies and tracking technologies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.zendesk.com/company/agreements-and-terms/privacy-notice/",
          "note": "Funded by subscriptions with no ads in the product, but website data is shared with advertising partners unless visitors opt out."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.zendesk.com/trust-center/security-compliance/",
          "note": "SOC 2 and ISO audits are done, but the reports are only available on request through the trust center."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.zendesk.com/hc/en-us/articles/5040336930970-Zendesk-Transparency-Report",
          "note": "Publishes counts of government requests and disclosures about every six months."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://support.zendesk.com/hc/en-us/articles/5040452168090-Government-Data-Request-Policy",
          "note": "Notifies customers before disclosing data unless legally prohibited or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.zendesk.com&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.zendesk.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Zendesk",
            "host": "static.zdassets.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:24.654Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "baresip",
      "category": "voip-clients",
      "name": "Baresip",
      "description": "Portable, modular SIP client with audio and video calling, mainly used from the command line. It supports SRTP, ZRTP and many audio and video codecs.",
      "website": "https://github.com/baresip/baresip",
      "source": "https://github.com/baresip/baresip",
      "license": "BSD-3-Clause",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Baresip scores 80 out of 100 (grade B) on the voice calls criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/voip-clients/baresip/",
      "markdown": "https://privacyratings.com/voip-clients/baresip/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/baresip/baresip/blob/main/LICENSE",
          "note": "Open source under the BSD-3-Clause license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.tutpro.baresip/latest/",
          "note": "No telemetry or analytics in the source code, and the Android build has no known trackers on Exodus."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/baresip/baresip",
          "note": "Free open-source project maintained by volunteers. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:24.632Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "linphone",
      "category": "voip-clients",
      "name": "Linphone",
      "description": "Open source SIP softphone for audio and video calls and instant messaging, with end-to-end encrypted chat and apps for Android, iOS, Windows, macOS and Linux. Developed by Belledonne Communications.",
      "website": "https://www.linphone.org",
      "source": "https://github.com/BelledonneCommunications/linphone-desktop",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Linphone scores 50 out of 100 (grade D) on the voice calls criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/voip-clients/linphone/",
      "markdown": "https://privacyratings.com/voip-clients/linphone/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/BelledonneCommunications/linphone-desktop/blob/master/LICENSE.txt",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.linphone.org/en/privacy-policy/",
          "note": "The website uses Google Analytics cookies, subject to a consent prompt."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.linphone.org/en/privacy-policy/",
          "note": "Funded by commercial licensing and services; the privacy policy states personal data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:50.190Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "microsip",
      "category": "voip-clients",
      "name": "MicroSIP",
      "description": "Lightweight portable SIP softphone for Windows, built on the PJSIP stack, for voice and video calls through any SIP provider.",
      "website": "https://www.microsip.org",
      "source": "https://www.microsip.org/source",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "MicroSIP scores 30 out of 100 (grade F) on the voice calls criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/voip-clients/microsip/",
      "markdown": "https://privacyratings.com/voip-clients/microsip/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.microsip.org/source",
          "note": "GPL-2.0; source archives are published for each release."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.microsip.org/privacy-policy",
          "note": "The website loads Google Tag Manager and uses analytics cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.microsip.org/privacy-policy",
          "note": "The website shows Google AdSense ads and states that advertising helps fund the project; the app itself has no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:49.741Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mumble",
      "category": "voip-clients",
      "name": "Mumble",
      "description": "Open source, low-latency voice chat client and server (Murmur) for groups, with encrypted connections and self-hosted servers.",
      "website": "https://www.mumble.info",
      "source": "https://github.com/mumble-voip/mumble",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Mumble scores 65 out of 100 (grade C) on the voice calls criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/voip-clients/mumble/",
      "markdown": "https://privacyratings.com/voip-clients/mumble/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mumble-voip/mumble/blob/master/LICENSE",
          "note": "BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/mumble-voip/mumble/blob/master/src/mumble/Usage.cpp",
          "note": "No third-party trackers; the client sends first-party usage statistics, which are on by default and can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.mumble.info/about/",
          "note": "Volunteer-run open source project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:49.991Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "spoofcard",
      "category": "voip-clients",
      "name": "SpoofCard",
      "description": "Paid caller ID spoofing service that places calls and texts showing a phone number the user chooses. Closed source, and calls and recordings pass through SpoofCard's servers.",
      "website": "https://www.spoofcard.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "SpoofCard scores 0 out of 100 (grade F) on the voice calls criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/voip-clients/spoofcard/",
      "markdown": "https://privacyratings.com/voip-clients/spoofcard/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.spoofcard.com/privacy",
          "note": "The website loads Google Tag Manager, and the privacy policy describes third-party advertising and analytics cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.spoofcard.com/privacy",
          "note": "Paid service, but the privacy policy reserves the right to sell aggregated or anonymized data and uses third-party advertising cookies."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:50.254Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "zoiper",
      "category": "voip-clients",
      "name": "Zoiper",
      "description": "SIP softphone from Securax in Bulgaria for desktop and mobile, with a free version and a paid Pro licence that adds features.",
      "website": "https://www.zoiper.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "BG",
        "name": "Bulgaria",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Zoiper scores 20 out of 100 (grade F) on the voice calls criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in Bulgaria: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/voip-clients/zoiper/",
      "markdown": "https://privacyratings.com/voip-clients/zoiper/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.zoiper.android.app/latest/",
          "note": "The Android app includes Google Firebase Analytics, and the website uses Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.zoiper.com/en/shop/buy/zoiper5",
          "note": "Funded by paid licences. No ad SDKs are found in the Android app."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Ads",
            "host": "www.googleadservices.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google DoubleClick",
            "host": "googleads.g.doubleclick.net",
            "effect": "no"
          },
          {
            "name": "Meta Pixel",
            "host": "www.facebook.com",
            "effect": "no"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:24.879Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "burner",
      "category": "virtual-phone-numbers",
      "name": "Burner",
      "description": "Second phone number app from Ad Hoc Labs in the United States. Paid subscriptions provide disposable or long-term numbers for calls and texts from a smartphone.",
      "website": "https://www.burnerapp.com",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 16,
      "coverage": 100,
      "summary": "Burner scores 16 out of 100 (grade F) on the virtual phone numbers criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets security headers. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/virtual-phone-numbers/burner/",
      "markdown": "https://privacyratings.com/virtual-phone-numbers/burner/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.adhoclabs.burner/latest/",
          "note": "The Android app includes Adjust, Amplitude, Braze and Facebook SDKs, and the website loads Google and Hotjar scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.adhoclabs.co/privacy-policy",
          "note": "Funded by subscriptions, but the policy allows sharing personal data for targeted advertising and lookalike modeling, with an opt-out."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.burnerapp.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.burnerapp.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Amplitude",
            "host": "cdn.amplitude.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Hotjar",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:24.904Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "crypton-sh",
      "category": "virtual-phone-numbers",
      "name": "Crypton.sh",
      "description": "Phone numbers backed by physical SIM cards hosted in the cloud, for receiving and sending SMS through a web interface, API or Android app, plus eSIM data plans. Stored messages are encrypted with a user key.",
      "website": "https://crypton.sh",
      "source": "https://gitlab.com/rinzler-labs",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 63,
      "coverage": 100,
      "summary": "Crypton.sh scores 63 out of 100 (grade C) on the virtual phone numbers criteria. It meets 3 of 8 criteria: no ads or data sales, transparency report and TLS configuration. It partly meets open source, no trackers or telemetry, tells users about requests and security headers. It does not meet independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/virtual-phone-numbers/crypton-sh/",
      "markdown": "https://privacyratings.com/virtual-phone-numbers/crypton-sh/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://gitlab.com/rinzler-labs/crypton-android-app/-/blob/main/LICENSE",
          "note": "The Android app is GPL-3.0 and the self-hosted BYOD platform is source-available; the main service is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://gitlab.com/rinzler-labs/crypton-android-app/-/blob/main/app/src/main/kotlin/sh/crypton/app/CryptonApplication.kt",
          "note": "No third-party advertising trackers, but store builds of the Android app send crash reports to a self-hosted Bugsink server."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://crypton.sh/privacy",
          "note": "Paid service; the privacy policy states data is not sold or used for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://crypton.sh/transparency",
          "note": "Publishes yearly counts of government and law enforcement requests and whether data was provided."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://crypton.sh/transparency",
          "note": "Affected account IDs are listed in the transparency report for users to check, but there is no promise of direct notice."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=crypton.sh&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=crypton.sh",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Trustpilot",
            "host": "uk.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:22.434Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "google-voice",
      "category": "virtual-phone-numbers",
      "name": "Google Voice",
      "description": "Phone number service from Google that gives a US number for calls, texts and voicemail through web and mobile apps. It is free for personal accounts in the US and paid as part of Google Workspace.",
      "website": "https://voice.google.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "Google Voice scores 38 out of 100 (grade F) on the virtual phone numbers criteria. It meets 3 of 8 criteria: transparency report, tells users about requests and TLS configuration. It partly meets independent audit. It does not meet open source, no trackers or telemetry, no ads or data sales and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B-.",
      "url": "https://privacyratings.com/virtual-phone-numbers/google-voice/",
      "markdown": "https://privacyratings.com/virtual-phone-numbers/google-voice/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "The free personal service is funded by Google, whose business relies on advertising and uses account activity to personalise ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cloud.google.com/security/compliance/soc-3",
          "note": "Google Voice is in scope of Google's SOC 2 and SOC 3 audits. Only the SOC 3 summary is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://transparencyreport.google.com/user-data/overview",
          "note": "Google publishes counts of government requests for user data twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://policies.google.com/terms/information-requests",
          "note": "Google states it notifies users before disclosing their information unless prohibited by law or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=voice.google.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=voice.google.com",
          "note": "Grade B- (65/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:13:47.640Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hushed",
      "category": "virtual-phone-numbers",
      "name": "Hushed",
      "description": "Second phone number app from AffinityClick Inc. in Canada. Paid plans provide numbers in many area codes for calls and texts over Wi-Fi or mobile data.",
      "website": "https://hushed.com",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Hushed scores 25 out of 100 (grade F) on the virtual phone numbers criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in Canada: Five Eyes member. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C-.",
      "url": "https://privacyratings.com/virtual-phone-numbers/hushed/",
      "markdown": "https://privacyratings.com/virtual-phone-numbers/hushed/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.hushed.release/latest/",
          "note": "The Android app includes AppsFlyer, Google Firebase Analytics and Crashlytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://hushed.com/privacy-policy/",
          "note": "Funded by paid plans. The policy states personal information is not rented or sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=hushed.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=hushed.com",
          "note": "Grade C- (45/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cookiebot",
            "host": "consent.cookiebot.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Zendesk",
            "host": "static.zdassets.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:25.045Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "jmp-chat",
      "category": "virtual-phone-numbers",
      "name": "JMP.chat",
      "description": "Paid phone number service for calls, SMS and MMS through an XMPP account, with optional SIP for calls and numbers in the US and Canada. Run by the MBOA Technology Co-operative using open source Soprani.ca software.",
      "website": "https://jmp.chat",
      "source": "https://gitlab.com/ossguy/jmp-register",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 69,
      "coverage": 100,
      "summary": "JMP.chat scores 69 out of 100 (grade C) on the virtual phone numbers criteria. It meets 4 of 8 criteria: open source, no trackers or telemetry, no ads or data sales and TLS configuration. It partly meets transparency report. It does not meet independent audit, tells users about requests and security headers. It is based in Canada: Five Eyes member. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C-.",
      "url": "https://privacyratings.com/virtual-phone-numbers/jmp-chat/",
      "markdown": "https://privacyratings.com/virtual-phone-numbers/jmp-chat/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/ossguy/jmp-register/-/blob/master/COPYING",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://jmp.chat/privacy",
          "note": "The website loads no third-party scripts, and the privacy statement describes no analytics or tracking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://jmp.chat/faq",
          "note": "Funded by monthly subscriptions, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://jmp.chat/privacy",
          "note": "Publishes a law enforcement and data retention statement, but no request counts."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=jmp.chat&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=jmp.chat",
          "note": "Grade C- (45/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:21.097Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "monerosms",
      "category": "virtual-phone-numbers",
      "name": "MoneroSMS",
      "description": "Prepaid US phone numbers for sending and receiving SMS, paid in Monero, with access through a web app, command-line client or API. Operated by VoidNetwork LLC.",
      "website": "https://monerosms.com",
      "source": "https://github.com/EgosOwn/monerosms-client",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 53,
      "coverage": 100,
      "summary": "MoneroSMS scores 53 out of 100 (grade D) on the virtual phone numbers criteria. It meets 3 of 8 criteria: no trackers or telemetry, no ads or data sales and TLS configuration. It partly meets open source. It does not meet independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/virtual-phone-numbers/monerosms/",
      "markdown": "https://privacyratings.com/virtual-phone-numbers/monerosms/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/EgosOwn/monerosms-client/blob/master/LICENSE.txt",
          "note": "GPL-3.0. Only part of the service is published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://api.monerosms.com/tos",
          "note": "The privacy terms list only operational data and server logs, with no analytics, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://api.monerosms.com/tos",
          "note": "Funded by prepaid Monero payments; the terms list no data sales or advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://api.monerosms.com/tos",
          "note": "No transparency report; the terms only state that data is shared to comply with valid legal demands."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=monerosms.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=monerosms.com",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:21.070Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nadanada",
      "category": "virtual-phone-numbers",
      "name": "nadanada",
      "description": "Disposable and rental phone numbers for receiving SMS verification codes, plus eSIM data plans and a WireGuard VPN, bought without an account, email or ID. Formerly known as LNVPN.",
      "website": "https://nadanada.me",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 47,
      "coverage": 100,
      "summary": "nadanada scores 47 out of 100 (grade D) on the virtual phone numbers criteria. It meets 2 of 8 criteria: no trackers or telemetry and no ads or data sales. It partly meets transparency report, TLS configuration and security headers. It does not meet open source, independent audit and tells users about requests. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/virtual-phone-numbers/nadanada/",
      "markdown": "https://privacyratings.com/virtual-phone-numbers/nadanada/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source; an older version of the LNVPN web app was published, but the current code is not public."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://nadanada.me/privacy",
          "note": "The privacy policy states the site uses no cookies and names no analytics providers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://nadanada.me/privacy",
          "note": "Funded by pay-as-you-go purchases, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://nadanada.me/privacy",
          "note": "Publishes a law enforcement request policy and states no court orders or subpoenas have been received, but no request counts over time."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=nadanada.me&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=nadanada.me",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:21.667Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "narayana",
      "category": "virtual-phone-numbers",
      "name": "Narayana",
      "description": "Estonian telecom provider selling physical SIM cards, eSIMs, virtual numbers and SIP calling without KYC, paid by card or cryptocurrency. Registration needs no email or personal details.",
      "website": "https://narayana.im",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "EE",
        "name": "Estonia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "Narayana scores 38 out of 100 (grade F) on the virtual phone numbers criteria. It meets 2 of 8 criteria: no trackers or telemetry and no ads or data sales. It partly meets TLS configuration. It does not meet open source, independent audit, transparency report, tells users about requests and security headers. It is based in Estonia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/virtual-phone-numbers/narayana/",
      "markdown": "https://privacyratings.com/virtual-phone-numbers/narayana/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source; the company publishes some libraries and XMPP clients, but not the telephony service code."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://narayana.im/gdpr.pdf",
          "note": "The privacy policy states no third-party services or cookies are used for tracking, analytics or marketing."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://narayana.im/about/prices",
          "note": "Funded by prepaid service fees, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://narayana.im/gdpr.pdf",
          "note": "No transparency report; the privacy policy only states data may be disclosed when required by law."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=narayana.im&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=narayana.im",
          "note": "Grade F (15/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:23.909Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "pikasim",
      "category": "virtual-phone-numbers",
      "name": "PikaSim",
      "description": "Prepaid eSIM data plans for many countries, plus phone plans and SMS verification numbers, bought without an account, email or ID. Accepts cards and cryptocurrency through a self-hosted BTCPay Server.",
      "website": "https://pikasim.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 53,
      "coverage": 100,
      "summary": "PikaSim scores 53 out of 100 (grade D) on the virtual phone numbers criteria. It meets 3 of 8 criteria: no trackers or telemetry, no ads or data sales and TLS configuration. It partly meets transparency report and security headers. It does not meet open source, independent audit and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/virtual-phone-numbers/pikasim/",
      "markdown": "https://privacyratings.com/virtual-phone-numbers/pikasim/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://pikasim.com/privacy",
          "note": "No third-party trackers. Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://pikasim.com/privacy",
          "note": "Funded by eSIM and phone plan sales; the privacy policy states data is never sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://pikasim.com/canary",
          "note": "Publishes a quarterly warrant canary, but no request counts."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=pikasim.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=pikasim.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:22.011Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "silent-link",
      "category": "virtual-phone-numbers",
      "name": "Silent.link",
      "description": "Prepaid eSIM for mobile data in many countries, with optional US or UK numbers for receiving SMS and activation calls. No personal data is required, and payment is in Bitcoin, Lightning, Monero or other cryptocurrencies.",
      "website": "https://silent.link",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 47,
      "coverage": 100,
      "summary": "Silent.link scores 47 out of 100 (grade D) on the virtual phone numbers criteria. It meets 3 of 8 criteria: no trackers or telemetry, no ads or data sales and TLS configuration. It partly meets security headers. It does not meet open source, independent audit, transparency report and tells users about requests. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/virtual-phone-numbers/silent-link/",
      "markdown": "https://privacyratings.com/virtual-phone-numbers/silent-link/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://silent.link/faq",
          "note": "The FAQ states the service gathers no user data, and the website loads only its own scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://silent.link/faq",
          "note": "Funded by prepaid cryptocurrency payments, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=silent.link&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=silent.link",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:21.883Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "smspool",
      "category": "virtual-phone-numbers",
      "name": "SMSPool",
      "description": "Paid service that rents one-time and longer-term non-VoIP phone numbers in many countries for receiving SMS verification codes. Operated by SMSPool B.V. in the Netherlands.",
      "website": "https://www.smspool.net",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "SMSPool scores 38 out of 100 (grade F) on the virtual phone numbers criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It partly meets no trackers or telemetry and security headers. It does not meet open source, independent audit, transparency report and tells users about requests. It is based in the Netherlands: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/virtual-phone-numbers/smspool/",
      "markdown": "https://privacyratings.com/virtual-phone-numbers/smspool/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.smspool.net/privacy-policy",
          "note": "No advertising trackers. The privacy policy names Cloudflare analytics, which is on by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.smspool.net/privacy-policy",
          "note": "Funded by prepaid purchases; the privacy policy states user information is not sold or shared for marketing."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.smspool.net/privacy-policy",
          "note": "No transparency report; the privacy policy only says law enforcement can request data within reasonable demand."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.smspool.net&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.smspool.net",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:21.854Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "textnow",
      "category": "virtual-phone-numbers",
      "name": "TextNow",
      "description": "Free, ad-supported phone number service from TextNow, Inc. in Waterloo, Canada, offering US and Canadian numbers for calls and texts over Wi-Fi or its mobile network, with paid options to remove ads.",
      "website": "https://www.textnow.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 19,
      "coverage": 100,
      "summary": "TextNow scores 19 out of 100 (grade F) on the virtual phone numbers criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets transparency report. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, tells users about requests and security headers. It is based in Canada: Five Eyes member. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/virtual-phone-numbers/textnow/",
      "markdown": "https://privacyratings.com/virtual-phone-numbers/textnow/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.enflick.android.TextNow/latest/",
          "note": "The Android app includes 19 trackers, among them Google AdMob, Facebook Ads, AppLovin and AppsFlyer."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.enflick.android.TextNow/latest/",
          "note": "The free service is funded by in-app advertising from several ad networks."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://help.textnow.com/hc/en-us/articles/360052815653-Submitting-Orders-Requests-To-TextNow",
          "note": "Law enforcement guidelines explain how legal orders are handled. No request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": "https://help.textnow.com/hc/en-us/articles/360052060674-Non-Disclosure-Requests",
          "note": "The guidelines state users are not notified of law enforcement orders. Only civil requests may be notified."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.textnow.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.textnow.com",
          "note": "Grade C (55/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:25.064Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "aws-end-user-messaging-sms",
      "category": "communications-apis",
      "name": "AWS End User Messaging SMS",
      "description": "Amazon Web Services API for sending SMS, MMS and voice messages, formerly Amazon Pinpoint SMS. Amazon SNS also sends SMS through it.",
      "website": "https://aws.amazon.com/end-user-messaging/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 85,
      "summary": "AWS End User Messaging SMS scores 45 out of 100 (grade D) on the SMS and voice APIs criteria. It meets 5 of 10 criteria: transparency report, tells users about requests, TLS configuration, security headers and EU data location. It partly meets no ads or data sales and independent audit. It does not meet open source and no trackers or telemetry. Still needing evidence: message content deleted or redacted. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A.",
      "url": "https://privacyratings.com/communications-apis/aws-end-user-messaging-sms/",
      "markdown": "https://privacyratings.com/communications-apis/aws-end-user-messaging-sms/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Amplitude, DoubleClick and Marketo scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://aws.amazon.com/compliance/data-privacy-faq/",
          "note": "Customer content is not used for marketing or advertising, but the website loads DoubleClick advertising scripts to promote AWS."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://aws.amazon.com/compliance/soc-faqs/",
          "note": "A SOC 3 summary report is public. The full SOC 2 report is only available to customers through AWS Artifact."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://aws.amazon.com/compliance/data-privacy-faq/",
          "note": "Amazon regularly publishes a report on the types and volume of information requests it receives."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://aws.amazon.com/compliance/data-privacy-faq/",
          "note": "AWS gives customers notice of demands for their content unless legally prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=aws.amazon.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=aws.amazon.com",
          "note": "Grade A (95/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted or redacted",
          "weight": 3,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.aws.amazon.com/general/latest/gr/end-user-messaging.html",
          "note": "Available in several EU regions, including Frankfurt, Ireland, Paris, Milan, Spain and Stockholm."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:29:21.921Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bandwidth",
      "category": "communications-apis",
      "name": "Bandwidth",
      "description": "Communications platform and phone carrier with APIs for SMS, MMS, voice calls, emergency calling and phone numbers.",
      "website": "https://www.bandwidth.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 70,
      "summary": "Bandwidth scores 30 out of 100 (grade F) on the SMS and voice APIs criteria. It meets 2 of 10 criteria: TLS configuration and message content deleted or redacted. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry and security headers. Still needing evidence: independent audit, transparency report, tells users about requests and EU data location. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C+.",
      "url": "https://privacyratings.com/communications-apis/bandwidth/",
      "markdown": "https://privacyratings.com/communications-apis/bandwidth/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Tag Manager, Marketo and VWO."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.bandwidth.com/legal/privacy/",
          "note": "Funded by usage fees, but website identifiers and browsing data are shared with advertising networks for Bandwidth's own targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=bandwidth.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=bandwidth.com",
          "note": "Grade C+ (60/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted or redacted",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://dev.bandwidth.com/docs/messaging/",
          "note": "Text message content is not stored, only metadata. Uploaded media is kept for up to 48 hours."
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          },
          {
            "name": "VWO",
            "host": "dev.visualwebsiteoptimizer.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:31:47.517Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bird",
      "category": "communications-apis",
      "name": "Bird",
      "description": "Communications platform, formerly MessageBird, with APIs for SMS, WhatsApp, email and voice, and marketing and customer support tools.",
      "website": "https://bird.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": null,
      "score": 13,
      "coverage": 30,
      "summary": "Bird is not graded yet: 30% of its criteria have evidence, and 60% is needed. It meets 1 of 10 criteria: TLS configuration. It partly meets security headers. It does not meet open source. Still needing evidence: no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests, message content deleted or redacted and EU data location. It is based in the Netherlands: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/communications-apis/bird/",
      "markdown": "https://privacyratings.com/communications-apis/bird/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=bird.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=bird.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted or redacted",
          "weight": 3,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:44:20.332Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "clicksend",
      "category": "communications-apis",
      "name": "ClickSend",
      "description": "Business messaging service with APIs and a web app for SMS, MMS, voice messages, email and letters.",
      "website": "https://www.clicksend.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "AU",
        "name": "Australia",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": null,
      "score": 5,
      "coverage": 45,
      "summary": "ClickSend is not graded yet: 45% of its criteria have evidence, and 60% is needed. It partly meets TLS configuration. It does not meet open source, no trackers or telemetry and security headers. Still needing evidence: no ads or data sales, independent audit, transparency report, tells users about requests, message content deleted or redacted and EU data location. It is based in Australia: Five Eyes member; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/communications-apis/clicksend/",
      "markdown": "https://privacyratings.com/communications-apis/clicksend/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Tag Manager and a Reddit advertising pixel."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=clicksend.com&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=clicksend.com",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted or redacted",
          "weight": 3,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "widget.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:29:53.333Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "infobip",
      "category": "communications-apis",
      "name": "Infobip",
      "description": "Communications platform with APIs for SMS, WhatsApp, RCS, email, voice calls and phone number verification, plus customer engagement tools.",
      "website": "https://www.infobip.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 15,
      "coverage": 60,
      "summary": "Infobip scores 15 out of 100 (grade F) on the SMS and voice APIs criteria. It partly meets TLS configuration, security headers and message content deleted or redacted. It does not meet open source and no trackers or telemetry. Still needing evidence: no ads or data sales, independent audit, transparency report, tells users about requests and EU data location. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/communications-apis/infobip/",
      "markdown": "https://privacyratings.com/communications-apis/infobip/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Tag Manager, Google Analytics, Amplitude, Microsoft Clarity, HubSpot, Demandbase and DoubleClick, LinkedIn, Reddit and Microsoft Advertising scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=infobip.com&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=infobip.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted or redacted",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.infobip.com/policies/data-retention-notice",
          "note": "Message content is kept for 3 months by default. A shorter retention period can be requested at no charge."
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Amplitude",
            "host": "cdn.eu.amplitude.com",
            "effect": "no"
          },
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:29:53.383Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "plivo",
      "category": "communications-apis",
      "name": "Plivo",
      "description": "Cloud communications platform with APIs for SMS, MMS, WhatsApp, voice calls and phone number verification.",
      "website": "https://www.plivo.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 33,
      "coverage": 70,
      "summary": "Plivo scores 33 out of 100 (grade F) on the SMS and voice APIs criteria. It meets 2 of 10 criteria: TLS configuration and message content deleted or redacted. It partly meets no ads or data sales and security headers. It does not meet open source and no trackers or telemetry. Still needing evidence: independent audit, transparency report, tells users about requests and EU data location. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/communications-apis/plivo/",
      "markdown": "https://privacyratings.com/communications-apis/plivo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Tag Manager, HubSpot and PostHog."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.plivo.com/legal/privacy/",
          "note": "Funded by usage fees, but cookie and pixel data and encrypted email addresses are shared with advertisers for Plivo's own marketing."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=plivo.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=plivo.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted or redacted",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.plivo.com/docs/messaging/api/message/send-a-message",
          "note": "Logging is on by default. The log parameter can turn off logging of message content, phone numbers or both for each message."
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          },
          {
            "name": "PostHog",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:29:53.468Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "signalwire",
      "category": "communications-apis",
      "name": "SignalWire",
      "description": "Communications platform from the team behind FreeSWITCH, with APIs for SMS, voice calls and video.",
      "website": "https://signalwire.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": null,
      "score": 5,
      "coverage": 45,
      "summary": "SignalWire is not graded yet: 45% of its criteria have evidence, and 60% is needed. It partly meets TLS configuration. It does not meet open source, no trackers or telemetry and security headers. Still needing evidence: no ads or data sales, independent audit, transparency report, tells users about requests, message content deleted or redacted and EU data location. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/communications-apis/signalwire/",
      "markdown": "https://privacyratings.com/communications-apis/signalwire/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The hosted service is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Tag Manager and HubSpot."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=signalwire.com&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=signalwire.com",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted or redacted",
          "weight": 3,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:29:53.513Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sinch",
      "category": "communications-apis",
      "name": "Sinch",
      "description": "Communications platform with APIs for SMS, MMS, RCS, WhatsApp, voice calls and phone number verification, with regional endpoints.",
      "website": "https://sinch.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "SE",
        "name": "Sweden",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 65,
      "summary": "Sinch scores 25 out of 100 (grade F) on the SMS and voice APIs criteria. It meets 2 of 10 criteria: TLS configuration and EU data location. It partly meets security headers and message content deleted or redacted. It does not meet open source and no trackers or telemetry. Still needing evidence: no ads or data sales, independent audit, transparency report and tells users about requests. It is based in Sweden: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/communications-apis/sinch/",
      "markdown": "https://privacyratings.com/communications-apis/sinch/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics, Google Tag Manager, HubSpot, LinkedIn Insight, Meta Pixel, Microsoft Clarity and Reddit Pixel (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=sinch.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=sinch.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted or redacted",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://community.sinch.com/t5/SMS/Can-I-send-a-message-and-then-delete-it-from-my-records/ta-p/7106",
          "note": "SMS message logs are kept for 14 days, then depersonalized and archived. Sent messages cannot be deleted on request."
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developers.sinch.com/docs/sms/api-reference/",
          "note": "An EU endpoint serves the SMS API from servers in Ireland and Sweden. Staff and providers outside the EU may have access."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "snap.licdn.com",
            "effect": "no"
          },
          {
            "name": "Meta Pixel",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Microsoft Clarity",
            "host": "www.clarity.ms",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          },
          {
            "name": "Reddit Pixel",
            "host": "www.redditstatic.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:29:53.559Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "telnyx",
      "category": "communications-apis",
      "name": "Telnyx",
      "description": "Communications platform with APIs for SMS, MMS, voice calls, SIP trunking and phone number verification.",
      "website": "https://telnyx.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 70,
      "summary": "Telnyx scores 25 out of 100 (grade F) on the SMS and voice APIs criteria. It meets 1 of 10 criteria: message content deleted or redacted. It partly meets no ads or data sales and TLS configuration. It does not meet open source, no trackers or telemetry and security headers. Still needing evidence: independent audit, transparency report, tells users about requests and EU data location. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade C+.",
      "url": "https://privacyratings.com/communications-apis/telnyx/",
      "markdown": "https://privacyratings.com/communications-apis/telnyx/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Tag Manager and Marketo."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://telnyx.com/privacy-policy",
          "note": "Funded by usage fees and states information is not sold for advertising, but personal data is used for Telnyx's own marketing through Google Ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=telnyx.com&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=telnyx.com",
          "note": "Grade C+ (60/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted or redacted",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://developers.telnyx.com/api-reference/profiles/update-a-messaging-profile",
          "note": "Redaction of message text, media and counterparty numbers can be turned on for each messaging profile."
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "C+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:29:53.641Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "textbelt",
      "category": "communications-apis",
      "name": "Textbelt",
      "description": "SMS API with a paid hosted service and an open-source self-hosted version that sends through carrier email-to-SMS gateways.",
      "website": "https://textbelt.com",
      "source": "https://github.com/typpo/textbelt",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": null,
      "score": 13,
      "coverage": 45,
      "summary": "Textbelt is not graded yet: 45% of its criteria have evidence, and 60% is needed. It partly meets open source and TLS configuration. It does not meet no trackers or telemetry and security headers. Still needing evidence: no ads or data sales, independent audit, transparency report, tells users about requests, message content deleted or redacted and EU data location. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/communications-apis/textbelt/",
      "markdown": "https://privacyratings.com/communications-apis/textbelt/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/typpo/textbelt/blob/master/LICENSE",
          "note": "The self-hosted version is MIT-licensed. It uses a different, free sending method, and the code of the paid hosted service is not public."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads analytics.js with a Google Analytics ID."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=textbelt.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=textbelt.com",
          "note": "Grade D- (25/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted or redacted",
          "weight": 3,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:29:53.690Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "twilio",
      "category": "communications-apis",
      "name": "Twilio",
      "description": "Cloud communications platform with APIs for SMS, MMS, WhatsApp, voice calls, phone number verification and video.",
      "website": "https://www.twilio.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 43,
      "coverage": 100,
      "summary": "Twilio scores 43 out of 100 (grade D) on the SMS and voice APIs criteria. It meets 2 of 10 criteria: transparency report and tells users about requests. It partly meets no ads or data sales, independent audit, TLS configuration, security headers, message content deleted or redacted and EU data location. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/communications-apis/twilio/",
      "markdown": "https://privacyratings.com/communications-apis/twilio/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Tag Manager, Segment, Adobe Launch and VWO."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.twilio.com/en-us/legal/privacy",
          "note": "Funded by usage fees and states data is not sold, but website tracking for targeted advertising counts as sharing under some US state laws."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://security.twilio.com/",
          "note": "SOC 2 and ISO 27001 audits are listed, but reports are only available on request through the Twilio Trust Center."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.twilio.com/en-us/legal/transparency",
          "note": "Publishes annual transparency reports with government request counts, responses and how often users were notified."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.twilio.com/en-us/legal/law-enforcement-guidelines",
          "note": "Uses reasonable efforts to notify customers of requests for their information unless prohibited by law."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=twilio.com&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=twilio.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted or redacted",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://support.twilio.com/hc/en-us/articles/223133687-Deleting-messages-message-media-or-message-bodies",
          "note": "Message bodies are kept until deleted, and can be deleted through the API. Automatic message redaction is only available to Twilio Editions customers."
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.twilio.com/en-us/changelog/data-residency-for-sms--eu--is-now-in-public-beta",
          "note": "Voice and SMS can run in the Ireland (IE1) region. Data residency for SMS in the EU is in beta."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Segment",
            "host": "cdn.segment.com",
            "effect": "no"
          },
          {
            "name": "TrustArc",
            "host": "consent.trustarc.com",
            "effect": "none"
          },
          {
            "name": "VWO",
            "host": "dev.visualwebsiteoptimizer.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:32:53.864Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vonage",
      "category": "communications-apis",
      "name": "Vonage",
      "description": "Communications APIs from Vonage, formerly Nexmo, for SMS, voice calls, video, WhatsApp and phone number verification.",
      "website": "https://www.vonage.com/communications-apis/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 18,
      "coverage": 60,
      "summary": "Vonage scores 18 out of 100 (grade F) on the SMS and voice APIs criteria. It meets 1 of 10 criteria: TLS configuration. It partly meets message content deleted or redacted. It does not meet open source, no trackers or telemetry and security headers. Still needing evidence: no ads or data sales, independent audit, transparency report, tells users about requests and EU data location. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/communications-apis/vonage/",
      "markdown": "https://privacyratings.com/communications-apis/vonage/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Adobe Launch and 6sense scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=vonage.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=vonage.com",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "content_retention": {
          "title": "Message content deleted or redacted",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://developer.vonage.com/en/messaging/sms/message-privacy",
          "note": "Server logs keep message text for up to one month and call detail records for 13 months. Auto-redact removes message text before it is stored, and is turned on by request."
        },
        "eu_data_location": {
          "title": "EU data location",
          "weight": 1,
          "answer": "unknown",
          "evidence": null,
          "note": null
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:30:31.581Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "airvpn",
      "category": "vpns",
      "name": "AirVPN",
      "description": "VPN service run by Air di Paolo Brini in Italy. Accounts need no email address, and the open-source Eddie client supports WireGuard and OpenVPN.",
      "website": "https://airvpn.org",
      "source": "https://github.com/AirVPN/Eddie",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android"
      ],
      "jurisdiction": {
        "code": "IT",
        "name": "Italy",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "AirVPN scores 65 out of 100 (grade C) on the VPN providers criteria. It meets 6 of 12 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, anonymous payment, open-source apps and modern protocols. It partly meets open source, security headers and audited no-logs policy. It does not meet independent audit, transparency report and tells users about requests. It is based in Italy: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/vpns/airvpn/",
      "markdown": "https://privacyratings.com/vpns/airvpn/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/AirVPN/Eddie/blob/master/LICENSE",
          "note": "The Eddie client is open source under GPL-3.0. The server side is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://airvpn.org/privacy/",
          "note": "The privacy notice states no third-party add-ons or tracking cookies are used on the website. The Android app has no known trackers on Exodus."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://airvpn.org/privacy/",
          "note": "Funded by paid plans. The privacy notice states data is not passed to third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=airvpn.org&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=airvpn.org",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_logs_audited": {
          "title": "Audited no-logs policy",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://airvpn.org/privacy/",
          "note": "The privacy notice states traffic and IP addresses are not logged. Not audited."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://airvpn.org/buy/",
          "note": "No email address is required, and Monero and other cryptocurrencies are accepted directly."
        },
        "open_source_clients": {
          "title": "Open-source apps",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://eddie.website/",
          "note": "The Eddie apps for Windows, macOS, Linux and Android are open source under GPL-3.0. There is no iOS app."
        },
        "modern_protocols": {
          "title": "Modern protocols",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://airvpn.org/faq/wireguard/",
          "note": "WireGuard is supported alongside OpenVPN."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:18:13.445Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "azire",
      "category": "vpns",
      "name": "Azire",
      "description": "WireGuard VPN service founded in Stockholm and owned by Malwarebytes, running on servers it owns and operates.",
      "website": "https://www.azirevpn.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 48,
      "coverage": 100,
      "summary": "Azire scores 48 out of 100 (grade D) on the VPN providers criteria. It meets 5 of 12 criteria: no ads or data sales, independent audit, transparency report, audited no-logs policy and modern protocols. It partly meets TLS configuration and security headers. It does not meet open source, no trackers or telemetry, tells users about requests, anonymous payment and open-source apps. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/vpns/azire/",
      "markdown": "https://privacyratings.com/vpns/azire/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. Only a small WireGuard configuration script is published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.malwarebytes.com/legal/privacy-policy",
          "note": "The Malwarebytes privacy policy that covers the service allows mobile analytics software and advertising cookies. The Android app has no known trackers on Exodus."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.azirevpn.com/support/faq",
          "note": "Funded by paid plans. The FAQ states user data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://blog.azirevpn.com/content/files/2026/03/X41-DSec-Audit-AzireVPN-Public.pdf",
          "note": "Full public report from X41 D-Sec covering source code, infrastructure and server hardware."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.azirevpn.com/legal/transparency-report",
          "note": "Yearly counts of data requests, valid requests and data provided, plus a warrant canary."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": "https://www.malwarebytes.com/legal/privacy-policy",
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.azirevpn.com&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.azirevpn.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_logs_audited": {
          "title": "Audited no-logs policy",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://blog.azirevpn.com/content/files/2026/03/X41-DSec-Audit-AzireVPN-Public.pdf",
          "note": "The X41 D-Sec audit found production server images discard log messages. The FAQ states no logs are kept."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.azirevpn.com/support/faq",
          "note": "Email is optional, but payment is only by card, PayPal or SEPA debit. Cash and cryptocurrency are not accepted."
        },
        "open_source_clients": {
          "title": "Open-source apps",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "The Windows, macOS, iOS and Android apps are closed source."
        },
        "modern_protocols": {
          "title": "Modern protocols",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.azirevpn.com/support/faq",
          "note": "WireGuard is the supported protocol."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:23.055Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cyberghost",
      "category": "vpns",
      "name": "CyberGhost VPN",
      "description": "Commercial VPN service from CyberGhost S.R.L. in Romania, a subsidiary of Kape Technologies. Apps support WireGuard, OpenVPN and IKEv2.",
      "website": "https://www.cyberghostvpn.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "RO",
        "name": "Romania",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "CyberGhost VPN scores 50 out of 100 (grade D) on the VPN providers criteria. It meets 5 of 12 criteria: no ads or data sales, independent audit, transparency report, audited no-logs policy and modern protocols. It partly meets TLS configuration and anonymous payment. It does not meet open source, no trackers or telemetry, tells users about requests, security headers and open-source apps. It is based in Romania: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade C-.",
      "url": "https://privacyratings.com/vpns/cyberghost/",
      "markdown": "https://privacyratings.com/vpns/cyberghost/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.cyberghostvpn.com/privacypolicy",
          "note": "The privacy policy lists AppsFlyer, Mouseflow, Google Analytics and VWO, and the Android app includes AppsFlyer, Firebase Analytics and Sentry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.cyberghostvpn.com/privacypolicy",
          "note": "Funded by paid subscriptions. The policy states personal data is not sold, rented or traded."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.cyberghostvpn.com/deloitte-privacy-policy",
          "note": "Full Deloitte ISAE 3000 assurance report on the VPN infrastructure is downloadable."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.cyberghostvpn.com/transparency-report",
          "note": "Quarterly counts of legal requests for user data are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.cyberghostvpn.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.cyberghostvpn.com",
          "note": "Grade C- (45/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_logs_audited": {
          "title": "Audited no-logs policy",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.cyberghostvpn.com/deloitte-privacy-policy",
          "note": "Deloitte Audit Romania examined the server configuration and safeguards against activity logging. The full report is public."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.cyberghostvpn.com/privacypolicy",
          "note": "Bitcoin is accepted, but an email address is needed for the account."
        },
        "open_source_clients": {
          "title": "Open-source apps",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "The apps are closed source."
        },
        "modern_protocols": {
          "title": "Modern protocols",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://support.cyberghostvpn.com/hc/en-us/articles/213983829-Which-VPN-Protocols-Do-You-Support",
          "note": "WireGuard is supported alongside OpenVPN and IKEv2."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "C-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:25.263Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "expressvpn",
      "category": "vpns",
      "name": "ExpressVPN",
      "description": "Commercial VPN service run by Express Technologies Ltd. in the British Virgin Islands, a subsidiary of Kape Technologies. It uses its own open-source Lightway protocol.",
      "website": "https://www.expressvpn.com",
      "source": "https://github.com/expressvpn/lightway",
      "license": "AGPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "VG",
        "name": "British Virgin Islands",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 56,
      "coverage": 100,
      "summary": "ExpressVPN scores 56 out of 100 (grade D) on the VPN providers criteria. It meets 6 of 12 criteria: no ads or data sales, independent audit, transparency report, TLS configuration, audited no-logs policy and modern protocols. It partly meets security headers and anonymous payment. It does not meet open source, no trackers or telemetry, tells users about requests and open-source apps. It is based in the British Virgin Islands: Not in the Five, Nine or Fourteen Eyes. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/vpns/expressvpn/",
      "markdown": "https://privacyratings.com/vpns/expressvpn/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://raw.githubusercontent.com/expressvpn/lightway/main/LICENSE",
          "note": "The apps and servers are closed source. Only the Lightway protocol implementation is published under AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.expressvpn.com/privacy-policy",
          "note": "The privacy policy lists Google Analytics and AppsFlyer, and the Android app includes AppsFlyer and Google Firebase Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.expressvpn.com/privacy-policy",
          "note": "Funded by paid subscriptions. The policy states personal data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cure53.de/pentest-report_expressvpn-lightway_2024.pdf",
          "note": "Full reports are published, including Cure53 on the Lightway protocol and KPMG on the no-logs policy."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.expressvpn.com/trust",
          "note": "Twice-yearly counts of government requests, warrants and DMCA requests are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.expressvpn.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.expressvpn.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_logs_audited": {
          "title": "Audited no-logs policy",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.expressvpn.com/security-audit-reports/kpmg-privacy-policy-2025",
          "note": "KPMG assessed that the TrustedServer design prevents activity and connection logging. The full report is public after accepting KPMG terms."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.expressvpn.com/privacy-policy",
          "note": "Bitcoin is accepted, but an email address is needed for the account."
        },
        "open_source_clients": {
          "title": "Open-source apps",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "The apps are closed source."
        },
        "modern_protocols": {
          "title": "Modern protocols",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.expressvpn.com/lightway",
          "note": "The Lightway protocol, audited by Cure53 and Praetorian, is the default."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:25.254Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "hide-me",
      "category": "vpns",
      "name": "hide.me",
      "description": "VPN service from eVenture Ltd. in Malaysia with a free plan that needs no sign-up and paid plans. Apps support WireGuard, OpenVPN, IKEv2 and SoftEther.",
      "website": "https://hide.me",
      "source": "https://github.com/eventure/hide.client.linux",
      "license": "GPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "MY",
        "name": "Malaysia",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 67,
      "coverage": 100,
      "summary": "hide.me scores 67 out of 100 (grade C) on the VPN providers criteria. It meets 6 of 12 criteria: no ads or data sales, independent audit, transparency report, TLS configuration, audited no-logs policy and modern protocols. It partly meets open source, security headers, anonymous payment and open-source apps. It does not meet no trackers or telemetry and tells users about requests. It is based in Malaysia: Not in the Five, Nine or Fourteen Eyes. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/vpns/hide-me/",
      "markdown": "https://privacyratings.com/vpns/hide-me/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/eventure/hide.client.linux/blob/master/LICENSE.md",
          "note": "Only the Linux command-line client is open source, under GPL-2.0. The other apps and the servers are closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://hide.me/en/privacy",
          "note": "The privacy policy allows third-party analytics cookies, and the Android app includes Sentry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://hide.me/en/free-vpn",
          "note": "Funded by paid plans. The free plan has no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://hide.me/downloads/Securitum_Hide.me_no-log-policy_20240607.pdf",
          "note": "Securitum's no-logs audit report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://hide.me/downloads/hide.me-transparency-report-2025.pdf",
          "note": "Yearly report with counts of legal requests and DMCA complaints."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=hide.me&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=hide.me",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_logs_audited": {
          "title": "Audited no-logs policy",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://hide.me/downloads/Securitum_Hide.me_no-log-policy_20240607.pdf",
          "note": "Securitum verified that no user activity or DNS logs are stored on the VPN servers."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://hide.me/en/pricing",
          "note": "Monero and other cryptocurrencies are accepted, but an email address is needed for paid plans."
        },
        "open_source_clients": {
          "title": "Open-source apps",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/eventure/hide.client.linux",
          "note": "Only the Linux command-line client is open source."
        },
        "modern_protocols": {
          "title": "Modern protocols",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://hide.me/en/wireguard-vpn",
          "note": "WireGuard is supported."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:26.066Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "ivpn",
      "category": "vpns",
      "name": "IVPN",
      "description": "VPN service from Gibraltar with random account IDs, no email at sign-up, cash and Monero payment, and open-source apps.",
      "website": "https://www.ivpn.net",
      "source": "https://github.com/ivpn/desktop-app",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "GI",
        "name": "Gibraltar",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 75,
      "coverage": 100,
      "summary": "IVPN scores 75 out of 100 (grade B) on the VPN providers criteria. It meets 7 of 12 criteria: no ads or data sales, independent audit, transparency report, tells users about requests, anonymous payment, open-source apps and modern protocols. It partly meets open source, no trackers or telemetry, TLS configuration, security headers and audited no-logs policy. It is based in Gibraltar: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/vpns/ivpn/",
      "markdown": "https://privacyratings.com/vpns/ivpn/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/ivpn/desktop-app/blob/master/LICENSE.md",
          "note": "Apps are open source under GPL-3.0. The server side is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.ivpn.net/en/privacy/",
          "note": "Website analytics use self-hosted Matomo, and mobile crash reports go to IVPN servers and can be turned off. No third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ivpn.net/en/pricing/",
          "note": "Funded by paid plans. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cure53.de/pentest-report_IVPN_2024.pdf",
          "note": "Full public Cure53 report on the customer website and servers. Audits are repeated yearly."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ivpn.net/en/transparency-report/",
          "note": "Yearly counts of requests received, valid requests and requests where data was provided."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.ivpn.net/en/legal-process-guidelines/",
          "note": "The legal process guidelines promise to notify users unless notice is prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.ivpn.net&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.ivpn.net",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_logs_audited": {
          "title": "Audited no-logs policy",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://cure53.de/audit-report_ivpn.pdf",
          "note": "The Cure53 no-logs audit is older than three years. Later audits focus on security."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ivpn.net/en/pricing/",
          "note": "No email is needed. Cash, Monero and Bitcoin are accepted."
        },
        "open_source_clients": {
          "title": "Open-source apps",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/ivpn",
          "note": "Android, iOS and desktop apps are open source under GPL-3.0."
        },
        "modern_protocols": {
          "title": "Modern protocols",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.ivpn.net/en/wireguard/",
          "note": "WireGuard is supported, with post-quantum key exchange in the apps."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:22.587Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mozilla-vpn",
      "category": "vpns",
      "name": "Mozilla VPN",
      "description": "VPN service from Mozilla that runs on Mullvad's WireGuard server network. The apps are open source under MPL-2.0 and require a Mozilla account.",
      "website": "https://www.mozilla.org/en-US/products/vpn/",
      "source": "https://github.com/mozilla-mobile/mozilla-vpn-client",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 56,
      "coverage": 100,
      "summary": "Mozilla VPN scores 56 out of 100 (grade D) on the VPN providers criteria. It meets 5 of 12 criteria: no ads or data sales, transparency report, tells users about requests, open-source apps and modern protocols. It partly meets open source, independent audit, TLS configuration, security headers and audited no-logs policy. It does not meet no trackers or telemetry and anonymous payment. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/vpns/mozilla-vpn/",
      "markdown": "https://privacyratings.com/vpns/mozilla-vpn/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/mozilla-mobile/mozilla-vpn-client/blob/main/LICENSE.md",
          "note": "The apps are open source under MPL-2.0. The server network, run by Mullvad, is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.mozilla.org/en-US/privacy/subscription-services/",
          "note": "Campaign and device data is shared with the Adjust attribution service. App interaction data is off by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.mozilla.org/en-US/products/vpn/pricing/",
          "note": "Funded by paid subscriptions. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://blog.mozilla.org/security/files/2023/12/Cure53-Final-Audit-Report.pdf",
          "note": "Full Cure53 report on the client apps is public, but the audit is more than three years old."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.mozilla.org/en-US/about/policy/transparency/",
          "note": "Mozilla publishes counts of government and legal requests, most recently each year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.mozilla.org/en-US/about/policy/transparency/",
          "note": "Mozilla states it notifies affected users of requests unless legally prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.mozilla.org&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.mozilla.org",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_logs_audited": {
          "title": "Audited no-logs policy",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.mozilla.org/en-US/privacy/subscription-services/",
          "note": "The privacy notice states neither Mozilla nor Mullvad keeps logs of network traffic. Not audited for Mozilla VPN."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "A Mozilla account with an email address and payment by card, PayPal, Apple or Google Pay are required."
        },
        "open_source_clients": {
          "title": "Open-source apps",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/mozilla-mobile/mozilla-vpn-client",
          "note": "Apps for Windows, macOS, Linux, Android and iOS are open source."
        },
        "modern_protocols": {
          "title": "Modern protocols",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.mozilla.org/en-US/products/vpn/features/",
          "note": "WireGuard is the protocol used."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:25.354Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "mullvad-vpn",
      "category": "vpns",
      "name": "Mullvad VPN",
      "description": "Flat-priced VPN from Sweden. Accounts are a random number with no email, and payment in cash or Monero is accepted.",
      "website": "https://mullvad.net",
      "source": "https://github.com/mullvad/mullvadvpn-app",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "SE",
        "name": "Sweden",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": true,
      "pick_reason": "No email, no name and no card needed. A stable, flat price, WireGuard on every platform, fully open-source apps, and repeated public audits of both the apps and the server infrastructure.",
      "disclosure": null,
      "grade": "B",
      "score": 79,
      "coverage": 100,
      "summary": "Mullvad VPN scores 79 out of 100 (grade B) on the VPN providers criteria. It meets 8 of 12 criteria: no trackers or telemetry, no ads or data sales, independent audit, TLS configuration, security headers, anonymous payment, open-source apps and modern protocols. It partly meets open source, transparency report and audited no-logs policy. It does not meet tells users about requests. It is based in Sweden: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/vpns/mullvad-vpn/",
      "markdown": "https://privacyratings.com/vpns/mullvad-vpn/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/mullvad/mullvadvpn-app/blob/main/LICENSE.md",
          "note": "All apps are open source under GPL-3.0. Server infrastructure is not fully published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://mullvad.net/en/help/no-logging-data-policy",
          "note": "The policy states no usage data is sent to external analytics. The Android app has no known trackers on Exodus."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mullvad.net/en/pricing",
          "note": "One flat monthly price. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.x41-dsec.de/static/reports/X41-Mullvad-Audit-Public-Report-2026-01-20.pdf",
          "note": "Full public reports are published, including X41 D-Sec on account and payment services and Cure53 on the relay infrastructure."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://mullvad.net/en/help/swedish-legislation",
          "note": "Explains which Swedish laws allow authorities to request data and what can be disclosed. No request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mullvad.net&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mullvad.net",
          "note": "Grade A+ (135/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_logs_audited": {
          "title": "Audited no-logs policy",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.assured.se/publications/Assured_Mullvad_relay_server_audit_report_2022.pdf",
          "note": "The relay audits that checked for logging are older than three years. The no-logging policy is published."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mullvad.net/en/pricing",
          "note": "Accounts are a generated number. Cash, Monero and Bitcoin are accepted."
        },
        "open_source_clients": {
          "title": "Open-source apps",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/mullvad/mullvadvpn-app",
          "note": "Apps for every platform are open source under GPL-3.0."
        },
        "modern_protocols": {
          "title": "Modern protocols",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://mullvad.net/en/help/wireguard-and-mullvad-vpn",
          "note": "WireGuard is the default protocol."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:13:54.823Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nordvpn",
      "category": "vpns",
      "name": "NordVPN",
      "description": "Commercial VPN service from Nord Security, operated by a company in Panama. Apps use the WireGuard-based NordLynx protocol, OpenVPN or the NordWhisper protocol.",
      "website": "https://nordvpn.com",
      "source": "https://github.com/NordSecurity/nordvpn-linux",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "PA",
        "name": "Panama",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 56,
      "coverage": 100,
      "summary": "NordVPN scores 56 out of 100 (grade D) on the VPN providers criteria. It meets 4 of 12 criteria: no ads or data sales, transparency report, TLS configuration and modern protocols. It partly meets open source, independent audit, security headers, audited no-logs policy, anonymous payment and open-source apps. It does not meet no trackers or telemetry and tells users about requests. It is based in Panama: Not in the Five, Nine or Fourteen Eyes. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/vpns/nordvpn/",
      "markdown": "https://privacyratings.com/vpns/nordvpn/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/NordSecurity/nordvpn-linux/blob/main/LICENSE.md",
          "note": "Only the Linux app is open source, under GPL-3.0. The other apps and the servers are closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.nordvpn.android/latest/",
          "note": "The Android app includes AppsFlyer, Google Firebase Analytics and Crashlytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://nordvpn.com/pricing/",
          "note": "Funded by paid subscriptions. No ads in the apps."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://nordvpn.com/blog/nordvpn-no-logs-assurance-engagement-2025/",
          "note": "Deloitte performed a no-logs assurance engagement. The full report is only available to logged-in customers."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://nordvpn.com/blog/nordvpn-introduces-transparency-reports/",
          "note": "Quarterly counts of government inquiries and DMCA requests are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=nordvpn.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=nordvpn.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_logs_audited": {
          "title": "Audited no-logs policy",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://nordvpn.com/blog/nordvpn-no-logs-assurance-engagement-2025/",
          "note": "Deloitte assessed the no-logs policy repeatedly, but the full report is only available to logged-in customers, not publicly."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://nordvpn.com/pricing/",
          "note": "Several cryptocurrencies are accepted, but an email address is needed for the account."
        },
        "open_source_clients": {
          "title": "Open-source apps",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/NordSecurity/nordvpn-linux",
          "note": "Only the Linux app is open source."
        },
        "modern_protocols": {
          "title": "Modern protocols",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://nordvpn.com/blog/nordlynx-protocol-wireguard/",
          "note": "NordLynx, built on WireGuard, is the default protocol."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:25.240Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "nymvpn",
      "category": "vpns",
      "name": "NymVPN",
      "description": "VPN from Nym Technologies SA in Switzerland that runs on a decentralized network of independent nodes. It offers a fast two-hop WireGuard mode and an anonymous mode routed through the Nym mixnet.",
      "website": "https://nym.com",
      "source": "https://github.com/nymtech/nym-vpn-client",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 77,
      "coverage": 100,
      "summary": "NymVPN scores 77 out of 100 (grade B) on the VPN providers criteria. It meets 7 of 12 criteria: open source, no ads or data sales, independent audit, TLS configuration, anonymous payment, open-source apps and modern protocols. It partly meets no trackers or telemetry, transparency report, security headers and audited no-logs policy. It does not meet tells users about requests. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/vpns/nymvpn/",
      "markdown": "https://privacyratings.com/vpns/nymvpn/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nymtech/nym-vpn-client/blob/develop/LICENSE",
          "note": "The apps and the Nym network node software are open source under GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://nym.com/vpn-privacy-statement",
          "note": "App error reports via Sentry and usage statistics are off by default. The website uses self-hosted Matomo analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://nym.com/pricing",
          "note": "Funded by paid subscriptions. The privacy statement rules out selling data to advertisers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cure53.de/audit-report_nym.pdf",
          "note": "Full Cure53 report on the apps, VPN, infrastructure and cryptography is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://nym.com/vpn-privacy-statement",
          "note": "The privacy statement says requests will be challenged and made public. No request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=nym.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=nym.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_logs_audited": {
          "title": "Audited no-logs policy",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://nym.com/vpn-privacy-statement",
          "note": "The privacy statement describes a no-logs design with anonymous credentials. The Cure53 audit is a security audit, not a no-logs assessment."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://nym.com/vpn-privacy-statement",
          "note": "Cash, Monero and Zcash are accepted, and no email is needed with these payment methods."
        },
        "open_source_clients": {
          "title": "Open-source apps",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/nymtech/nym-vpn-client",
          "note": "Apps for Windows, macOS, Linux, Android and iOS are open source."
        },
        "modern_protocols": {
          "title": "Modern protocols",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://nym.com/blog/building-decentralized-wireguard-vpn",
          "note": "The fast mode uses WireGuard across two hops."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:26.593Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "obscura",
      "category": "vpns",
      "name": "Obscura",
      "description": "VPN from Sovereign Engineering Inc. in the United States that sends WireGuard traffic over QUIC through its own relay to Mullvad exit servers, so neither party sees both the user and the traffic. Accounts are a random number.",
      "website": "https://obscura.com",
      "source": "https://github.com/Sovereign-Engineering/obscuravpn-client",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 63,
      "coverage": 100,
      "summary": "Obscura scores 63 out of 100 (grade C) on the VPN providers criteria. It meets 6 of 12 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, anonymous payment, open-source apps and modern protocols. It partly meets open source and audited no-logs policy. It does not meet independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C+.",
      "url": "https://privacyratings.com/vpns/obscura/",
      "markdown": "https://privacyratings.com/vpns/obscura/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/Sovereign-Engineering/obscuravpn-client/blob/main/LICENSE",
          "note": "The client apps are open source under GPL-3.0. The relay servers are not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://obscura.com/legal/",
          "note": "No third-party trackers. Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://obscura.com/pricing/",
          "note": "Funded by paid subscriptions. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=obscura.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=obscura.com",
          "note": "Grade C+ (60/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_logs_audited": {
          "title": "Audited no-logs policy",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://obscura.com/legal/",
          "note": "The policy states IP addresses are not logged or stored, and the two-party relay design limits what each party sees. Not audited."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://obscura.com/",
          "note": "Accounts are a random number with no email, and Monero and Bitcoin over Lightning are accepted."
        },
        "open_source_clients": {
          "title": "Open-source apps",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Sovereign-Engineering/obscuravpn-client",
          "note": "The repository holds the apps for macOS, iOS, Android, Windows and Linux under GPL-3.0."
        },
        "modern_protocols": {
          "title": "Modern protocols",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://obscura.com/",
          "note": "WireGuard is used, carried over QUIC."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:25.549Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "ovpn",
      "category": "vpns",
      "name": "OVPN",
      "description": "VPN service founded in Sweden, now run by OVPN Inc., with WireGuard and OpenVPN on diskless servers, optional ad blocking, and monthly transparency reports.",
      "website": "https://www.ovpn.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 42,
      "coverage": 100,
      "summary": "OVPN scores 42 out of 100 (grade D) on the VPN providers criteria. It meets 4 of 12 criteria: no ads or data sales, transparency report, TLS configuration and modern protocols. It partly meets security headers, audited no-logs policy and anonymous payment. It does not meet open source, no trackers or telemetry, independent audit, tells users about requests and open-source apps. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/vpns/ovpn/",
      "markdown": "https://privacyratings.com/vpns/ovpn/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads PostHog, and the Android app includes Sentry according to Exodus."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ovpn.com/en/pricing",
          "note": "Funded by paid subscriptions. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ovpn.com/en/transparency",
          "note": "Monthly reports list the number of government requests received."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.ovpn.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.ovpn.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_logs_audited": {
          "title": "Audited no-logs policy",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.ovpn.com/en/privacy-notice",
          "note": "A no-logs policy is published but has not been independently audited."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.ovpn.com/hc/en-us/articles/46236278845075-Can-I-make-a-payment-for-my-subscription-anonymously",
          "note": "Email is optional and Bitcoin or Ethereum is accepted. Cash and Monero are not."
        },
        "open_source_clients": {
          "title": "Open-source apps",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "The OVPN apps are closed source."
        },
        "modern_protocols": {
          "title": "Modern protocols",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.ovpn.com/en/wireguard",
          "note": "WireGuard and OpenVPN are supported."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "PostHog",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:23.402Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "party-vpn",
      "category": "vpns",
      "name": "Party VPN",
      "description": "Pay-as-you-go VPN paid for only in cryptocurrency, including Monero. Supports WireGuard and AmneziaWG, and offers a REST API.",
      "website": "https://partyvpn.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 63,
      "coverage": 100,
      "summary": "Party VPN scores 63 out of 100 (grade C) on the VPN providers criteria. It meets 6 of 12 criteria: no trackers or telemetry, no ads or data sales, tells users about requests, TLS configuration, open-source apps and modern protocols. It partly meets transparency report, security headers, audited no-logs policy and anonymous payment. It does not meet open source and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/vpns/party-vpn/",
      "markdown": "https://privacyratings.com/vpns/party-vpn/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. The service uses the separate open-source WireGuard and AmneziaWG apps."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://partyvpn.com/privacy-policy",
          "note": "No third-party trackers. Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://partyvpn.com/privacy-policy",
          "note": "Funded by prepaid usage credits. The policy states personal data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://partyvpn.com/privacy-policy",
          "note": "The privacy policy describes how legal requests are handled. No request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://partyvpn.com/privacy-policy",
          "note": "The privacy policy promises to notify affected users when legally permitted."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=partyvpn.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=partyvpn.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_logs_audited": {
          "title": "Audited no-logs policy",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://partyvpn.com/privacy-policy",
          "note": "A no-logs policy is published but has not been independently audited."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://partyvpn.com/",
          "note": "Only cryptocurrency, including Monero, is accepted, but sign-up requires an email address and name."
        },
        "open_source_clients": {
          "title": "Open-source apps",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://partyvpn.com/help/how-to-set-up-a-vpn/",
          "note": "Connections use the official WireGuard or AmneziaWG apps, which are open source."
        },
        "modern_protocols": {
          "title": "Modern protocols",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://partyvpn.com/help/how-to-set-up-a-vpn/",
          "note": "WireGuard and AmneziaWG are supported."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:23.118Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "private-internet-access",
      "category": "vpns",
      "name": "Private Internet Access",
      "description": "Commercial VPN service from Private Internet Access, Inc. in the United States, a subsidiary of Kape Technologies. The apps are open source and support WireGuard and OpenVPN.",
      "website": "https://www.privateinternetaccess.com",
      "source": "https://github.com/pia-foss/desktop",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 71,
      "coverage": 100,
      "summary": "Private Internet Access scores 71 out of 100 (grade C) on the VPN providers criteria. It meets 7 of 12 criteria: no ads or data sales, independent audit, transparency report, TLS configuration, audited no-logs policy, open-source apps and modern protocols. It partly meets open source, tells users about requests and anonymous payment. It does not meet no trackers or telemetry and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/vpns/private-internet-access/",
      "markdown": "https://privacyratings.com/vpns/private-internet-access/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://raw.githubusercontent.com/pia-foss/desktop/master/LICENSE.txt",
          "note": "The desktop app is GPL-3.0 and the mobile apps are MIT-licensed. The server side is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.privateinternetaccess.com/privacy-policy",
          "note": "The website uses Google Analytics. The Android app has no known trackers on Exodus."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.privateinternetaccess.com/buy-vpn-online",
          "note": "Funded by paid subscriptions. The privacy policy states user data is not shared or sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.privateinternetaccess.com/deloitte-privacy-policy",
          "note": "Full Deloitte ISAE 3000 assurance report on the VPN infrastructure is downloadable after accepting terms."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.privateinternetaccess.com/transparency-report",
          "note": "Counts of government, civil and foreign requests are published regularly."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.privateinternetaccess.com/privacy-policy",
          "note": "The policy says users are given a chance to object to disclosures when possible, without a firm notice promise."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.privateinternetaccess.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.privateinternetaccess.com",
          "note": "Grade F (20/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_logs_audited": {
          "title": "Audited no-logs policy",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.privateinternetaccess.com/deloitte-privacy-policy",
          "note": "Deloitte Audit Romania examined the server configuration and found no data that identifies users or their activity. The full report is public."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.privateinternetaccess.com/privacy-policy",
          "note": "Cryptocurrency is accepted through BitPay, but an email address is needed for the account."
        },
        "open_source_clients": {
          "title": "Open-source apps",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/pia-foss",
          "note": "Apps for Windows, macOS, Linux, Android and iOS are open source."
        },
        "modern_protocols": {
          "title": "Modern protocols",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.privateinternetaccess.com/vpn-features/wireguard",
          "note": "WireGuard is supported alongside OpenVPN."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "widget.trustpilot.com",
            "effect": "none"
          },
          {
            "name": "Zendesk",
            "host": "static.zdassets.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:25.847Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "protonvpn",
      "category": "vpns",
      "name": "Proton VPN",
      "description": "VPN service from Proton in Switzerland with open-source apps on every platform and a free plan without ads.",
      "website": "https://protonvpn.com",
      "source": "https://github.com/ProtonVPN/android-app",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 83,
      "coverage": 100,
      "summary": "Proton VPN scores 83 out of 100 (grade B) on the VPN providers criteria. It meets 8 of 12 criteria: no ads or data sales, independent audit, transparency report, TLS configuration, audited no-logs policy, anonymous payment, open-source apps and modern protocols. It partly meets open source, no trackers or telemetry, tells users about requests and security headers. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/vpns/protonvpn/",
      "markdown": "https://privacyratings.com/vpns/protonvpn/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/ProtonVPN/android-app/blob/master/LICENSE",
          "note": "Apps are open source under GPL-3.0. The server side is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://proton.me/legal/privacy",
          "note": "Website analytics are self-hosted, and the apps send first-party crash reports that can be turned off in settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://protonvpn.com/pricing",
          "note": "Funded by paid plans. The free plan has no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://drive.proton.me/urls/DZVEJZFYHM#FPSKdUEykprb",
          "note": "Full Securitum no-logs audit report, repeated yearly."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://proton.me/legal/transparency",
          "note": "Yearly counts of legal orders received, contested and complied with, including a separate Proton VPN section."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://proton.me/legal/privacy",
          "note": "Swiss law requires authorities to notify subjects of proceedings. Proton does not itself promise notice."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=protonvpn.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=protonvpn.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_logs_audited": {
          "title": "Audited no-logs policy",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://drive.proton.me/urls/DZVEJZFYHM#FPSKdUEykprb",
          "note": "Securitum audits the VPN servers each year and found no activity or connection logging."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://protonvpn.com/support/payment-options",
          "note": "Cash and Bitcoin are accepted, and the privacy policy states no personal information is needed to create an account."
        },
        "open_source_clients": {
          "title": "Open-source apps",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/ProtonVPN",
          "note": "Apps for Windows, macOS, Linux, Android and iOS are open source."
        },
        "modern_protocols": {
          "title": "Modern protocols",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://protonvpn.com/support/wireguard-privacy",
          "note": "WireGuard is supported alongside OpenVPN and the Stealth protocol."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:23.712Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "riseupvpn",
      "category": "vpns",
      "name": "RiseupVPN",
      "description": "Free, donation-funded VPN run by the Riseup collective in the United States. It needs no account and uses the open-source LEAP VPN client with OpenVPN.",
      "website": "https://riseup.net/en/vpn",
      "source": "https://0xacab.org/leap/bitmask-vpn",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 70,
      "coverage": 100,
      "summary": "RiseupVPN scores 70 out of 100 (grade C) on the VPN providers criteria. It meets 5 of 11 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration and open-source apps. It partly meets transparency report, security headers, audited no-logs policy and modern protocols. It does not meet independent audit and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/vpns/riseupvpn/",
      "markdown": "https://privacyratings.com/vpns/riseupvpn/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://0xacab.org/leap/bitmask-vpn/-/raw/main/LICENSE",
          "note": "The LEAP VPN client and provider software are open source under GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://riseup.net/en/privacy-policy",
          "note": "The privacy policy states no third-party cookies or tracking of any kind are used. The Android app has no known trackers on Exodus."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://riseup.net/en/vpn",
          "note": "Entirely funded by user donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://riseup.net/en/canary",
          "note": "A signed warrant canary is updated regularly. No request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=riseup.net&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=riseup.net",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_logs_audited": {
          "title": "Audited no-logs policy",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://riseup.net/en/vpn",
          "note": "Riseup states it does not log VPN users' IP addresses. Not audited."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "The service is free and needs no account or payment."
        },
        "open_source_clients": {
          "title": "Open-source apps",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://0xacab.org/leap/bitmask-vpn",
          "note": "The desktop and Android clients are open source under GPL-3.0."
        },
        "modern_protocols": {
          "title": "Modern protocols",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://0xacab.org/leap/bitmask-vpn",
          "note": "The client uses OpenVPN. WireGuard is not supported."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:26.155Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "surfshark",
      "category": "vpns",
      "name": "Surfshark",
      "description": "Commercial VPN service from Surfshark B.V. in the Netherlands. Apps support WireGuard, OpenVPN and IKEv2.",
      "website": "https://surfshark.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 48,
      "coverage": 100,
      "summary": "Surfshark scores 48 out of 100 (grade D) on the VPN providers criteria. It meets 5 of 12 criteria: no ads or data sales, independent audit, transparency report, TLS configuration and modern protocols. It partly meets audited no-logs policy and anonymous payment. It does not meet open source, no trackers or telemetry, tells users about requests, security headers and open-source apps. It is based in the Netherlands: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C-.",
      "url": "https://privacyratings.com/vpns/surfshark/",
      "markdown": "https://privacyratings.com/vpns/surfshark/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://surfshark.com/privacy",
          "note": "The privacy policy lists Firebase Analytics and AppsFlyer for app analytics and marketing attribution."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://surfshark.com/privacy",
          "note": "Funded by paid subscriptions. The policy states personal data is not sold, rented or traded."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://surfshark.com/media/SurfShark-InfrastructureTestReport_20251217_Public.pdf",
          "note": "Full SecuRing penetration test report on the server infrastructure is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://surfshark.com/transparency-report",
          "note": "Quarterly counts of user data requests by type are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=surfshark.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=surfshark.com",
          "note": "Grade C- (45/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_logs_audited": {
          "title": "Audited no-logs policy",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://surfshark.com/blog/deloitte-nologs-policy-verified-again",
          "note": "Deloitte assessed the no-logs policy, but the full report is only available to logged-in users, not publicly."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.surfshark.com/hc/en-us/articles/360003069034-What-payment-options-do-you-offer",
          "note": "Cryptocurrency is accepted, but an email address is needed for the account."
        },
        "open_source_clients": {
          "title": "Open-source apps",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "The apps are closed source."
        },
        "modern_protocols": {
          "title": "Modern protocols",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://surfshark.com/blog/wireguard-protocol-is-now-live-on-surfshark",
          "note": "WireGuard is supported alongside OpenVPN and IKEv2."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Trustpilot",
            "host": "www.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:26.701Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "tunnelbear",
      "category": "vpns",
      "name": "TunnelBear",
      "description": "VPN service from TunnelBear, based in Canada, with a free plan limited by data and paid unlimited plans. Apps support WireGuard, OpenVPN and IKEv2.",
      "website": "https://www.tunnelbear.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 42,
      "coverage": 100,
      "summary": "TunnelBear scores 42 out of 100 (grade D) on the VPN providers criteria. It meets 4 of 12 criteria: no ads or data sales, independent audit, TLS configuration and modern protocols. It partly meets transparency report, security headers and audited no-logs policy. It does not meet open source, no trackers or telemetry, tells users about requests, anonymous payment and open-source apps. It is based in Canada: Five Eyes member. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/vpns/tunnelbear/",
      "markdown": "https://privacyratings.com/vpns/tunnelbear/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.tunnelbear.com/privacy-policy",
          "note": "The privacy policy lists Google Analytics and Hotjar, and the Android app includes AppsFlyer and Google Firebase Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.tunnelbear.com/privacy-policy",
          "note": "Funded by paid plans, and the free plan has no ads. The policy states personal data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cure53.de/pentest-report_tunnelbear_2023.pdf",
          "note": "Cure53 audits the apps and servers every year, and the full audit report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.tunnelbear.com/privacy-policy",
          "note": "The privacy policy describes what data is disclosed in response to a valid subpoena or warrant. No current request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.tunnelbear.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.tunnelbear.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_logs_audited": {
          "title": "Audited no-logs policy",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.tunnelbear.com/privacy-policy",
          "note": "The policy states IP addresses, DNS queries and activity are not logged. The Cure53 audits are security tests, not a no-logs assessment."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 2,
          "answer": "no",
          "evidence": "https://help.tunnelbear.com/hc/en-us/articles/360059783972-What-payment-platforms-do-you-offer",
          "note": "An email address and payment by card or app store are required. Cryptocurrency is not accepted."
        },
        "open_source_clients": {
          "title": "Open-source apps",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "The apps are closed source."
        },
        "modern_protocols": {
          "title": "Modern protocols",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.tunnelbear.com/features/",
          "note": "WireGuard is supported alongside OpenVPN and IKEv2."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:26.938Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "windscribe",
      "category": "vpns",
      "name": "Windscribe",
      "description": "VPN service from Canada with a limited free plan, open-source apps and browser extensions, and WireGuard, IKEv2 and OpenVPN support.",
      "website": "https://windscribe.com",
      "source": "https://github.com/Windscribe/Desktop-App",
      "license": "GPL-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 81,
      "coverage": 100,
      "summary": "Windscribe scores 81 out of 100 (grade B) on the VPN providers criteria. It meets 8 of 12 criteria: no ads or data sales, independent audit, transparency report, TLS configuration, audited no-logs policy, anonymous payment, open-source apps and modern protocols. It partly meets open source, no trackers or telemetry and security headers. It does not meet tells users about requests. It is based in Canada: Five Eyes member. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/vpns/windscribe/",
      "markdown": "https://privacyratings.com/vpns/windscribe/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/Windscribe/Desktop-App/blob/master/LICENSE",
          "note": "Apps are open source. The server side is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://windscribe.com/privacy",
          "note": "The website uses self-hosted Piwik analytics and no third-party trackers. The Android app has no known trackers on Exodus."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://windscribe.com/ethics",
          "note": "Funded by paid plans. The ethics page rules out targeted advertising and selling user data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://drive.google.com/file/d/1EgNETLVm2oZdGJXZJmFSCDc7Ib72LIOw/view",
          "note": "Full Packetlabs report on the server infrastructure and no-logs configuration."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://windscribe.com/transparency",
          "note": "Live counts of DMCA and law enforcement data requests and how many were complied with."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=windscribe.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=windscribe.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_logs_audited": {
          "title": "Audited no-logs policy",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://drive.google.com/file/d/1EgNETLVm2oZdGJXZJmFSCDc7Ib72LIOw/view",
          "note": "Packetlabs reviewed the no-logs policy on the VPN servers and confirmed the logging issues it found were fixed."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://windscribe.com/knowledge-base/articles/which-cryptocurrencies-do-you-support",
          "note": "Sign-up needs only a username and password. Monero and cash are accepted."
        },
        "open_source_clients": {
          "title": "Open-source apps",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Windscribe",
          "note": "Desktop, Android, iOS and browser extension source code is published."
        },
        "modern_protocols": {
          "title": "Modern protocols",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://windscribe.com/features/flexible-connectivity",
          "note": "WireGuard is supported alongside IKEv2, OpenVPN and Stealth."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:23.413Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "adguard",
      "category": "dns-resolvers",
      "name": "AdGuard",
      "description": "Public DNS resolver from AdGuard that blocks ads, trackers and malicious domains, with open-source server software and DoH, DoT, DoQ and DNSCrypt support.",
      "website": "https://adguard-dns.io",
      "source": "https://github.com/AdguardTeam/AdGuardDNS",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "CY",
        "name": "Cyprus",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 64,
      "coverage": 100,
      "summary": "AdGuard scores 64 out of 100 (grade C) on the DNS resolvers criteria. It meets 5 of 10 criteria: open source, no trackers or telemetry, no ads or data sales, Encrypted DNS and DNSSEC validation. It partly meets no query logs. It does not meet independent audit, transparency report, tells users about requests and security headers. It is based in Cyprus: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/dns-resolvers/adguard/",
      "markdown": "https://privacyratings.com/dns-resolvers/adguard/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/AdguardTeam/AdGuardDNS/blob/master/COPYING",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://adguard-dns.io/en/privacy.html",
          "note": "The policy states processed data is not shared with third parties, and the website loads no third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://adguard-dns.io/en/privacy.html",
          "note": "Funded by paid private DNS plans. The policy states personal data is not sold or shared."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=adguard-dns.io",
          "note": "Grade F (5/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "encrypted_dns": {
          "title": "Encrypted DNS",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://adguard-dns.io/kb/public-dns/overview/",
          "note": "DoH, DoT, DoQ and DNSCrypt are supported."
        },
        "no_query_logs": {
          "title": "No query logs",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://adguard-dns.io/en/privacy.html",
          "note": "The policy states no personal data is processed for public DNS and only an anonymous domain list is kept for 24 hours. Not audited."
        },
        "dnssec_validation": {
          "title": "DNSSEC validation",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://dns.adguard-dns.com/resolve?name=dnssec-failed.org&type=A",
          "note": "A lookup of the deliberately broken dnssec-failed.org domain is rejected as DNSSEC bogus."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:16:55.004Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "applied-privacy-dns",
      "category": "dns-resolvers",
      "name": "Applied Privacy DNS",
      "description": "Public DNS over HTTPS and DNS over TLS resolver run by the Foundation for Applied Privacy, a non-profit association in Vienna. It validates DNSSEC and uses QNAME minimisation.",
      "website": "https://applied-privacy.net/services/dns/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "AT",
        "name": "Austria",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 57,
      "coverage": 100,
      "summary": "Applied Privacy DNS scores 57 out of 100 (grade D) on the DNS resolvers criteria. It meets 5 of 11 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, Encrypted DNS and DNSSEC validation. It partly meets security headers and no query logs. It does not meet open source, independent audit, transparency report and tells users about requests. It is based in Austria: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/dns-resolvers/applied-privacy-dns/",
      "markdown": "https://privacyratings.com/dns-resolvers/applied-privacy-dns/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. The resolver configuration is not published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://applied-privacy.net/privacy-policy/",
          "note": "The website logs requests without IP addresses and uses no third-party analytics. Only the external donation providers are outside its control."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://applied-privacy.net/donate/",
          "note": "Non-profit funded by donations and sponsors. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=applied-privacy.net&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=applied-privacy.net",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "encrypted_dns": {
          "title": "Encrypted DNS",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://applied-privacy.net/services/dns/",
          "note": "DoH and DoT endpoints are both documented."
        },
        "no_query_logs": {
          "title": "No query logs",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://applied-privacy.net/privacy-policy/",
          "note": "The policy states IP addresses and queries are not logged, only aggregated statistics. Not audited."
        },
        "dnssec_validation": {
          "title": "DNSSEC validation",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://applied-privacy.net/services/dns/",
          "note": "The documentation states the resolvers perform DNSSEC validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:28.215Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "blahdns",
      "category": "dns-resolvers",
      "name": "BlahDNS",
      "description": "Hobby ad-blocking DNS resolver run by one person, with servers in Singapore and Germany and support for DoH, DoT, DoQ and DNSCrypt.",
      "website": "https://blahdns.com",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 54,
      "coverage": 100,
      "summary": "BlahDNS scores 54 out of 100 (grade D) on the DNS resolvers criteria. It meets 5 of 11 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, Encrypted DNS and DNSSEC validation. It partly meets no query logs. It does not meet open source, independent audit, transparency report, tells users about requests and security headers. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/dns-resolvers/blahdns/",
      "markdown": "https://privacyratings.com/dns-resolvers/blahdns/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The service setup is not published as source. It runs on open-source Knot Resolver and dnsdist."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://blahdns.com/",
          "note": "No third-party trackers. Cloudflare Web Analytics on the website are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://blahdns.com/",
          "note": "Funded by donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=blahdns.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=blahdns.com",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "encrypted_dns": {
          "title": "Encrypted DNS",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://blahdns.com/",
          "note": "DoH, DoT, DoQ and DNSCrypt are supported."
        },
        "no_query_logs": {
          "title": "No query logs",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://blahdns.com/",
          "note": "The site states no logs are kept. There is no privacy policy or audit."
        },
        "dnssec_validation": {
          "title": "DNSSEC validation",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://blahdns.com/",
          "note": "The site lists DNSSEC support, and the resolver runs Knot Resolver, which validates DNSSEC by default."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:23.279Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "clean-browsing",
      "category": "dns-resolvers",
      "name": "Clean Browsing",
      "description": "DNS filtering service with free family, adult and security filters and paid custom filtering, supporting DoH, DoT and DNSCrypt.",
      "website": "https://cleanbrowsing.org",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 43,
      "coverage": 100,
      "summary": "Clean Browsing scores 43 out of 100 (grade D) on the DNS resolvers criteria. It meets 4 of 11 criteria: no ads or data sales, TLS configuration, Encrypted DNS and DNSSEC validation. It partly meets security headers and no query logs. It does not meet open source, no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/dns-resolvers/clean-browsing/",
      "markdown": "https://privacyratings.com/dns-resolvers/clean-browsing/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics and Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cleanbrowsing.org/privacy",
          "note": "Funded by paid filtering plans. The policy states personal data is never sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published. The privacy policy only says data may be shared to comply with legal process."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=cleanbrowsing.org&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=cleanbrowsing.org",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "encrypted_dns": {
          "title": "Encrypted DNS",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://cleanbrowsing.org/filters/",
          "note": "DoH and DoT endpoints are listed for each free filter."
        },
        "no_query_logs": {
          "title": "No query logs",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://cleanbrowsing.org/privacy",
          "note": "The policy states free DNS queries are not logged with IP addresses, while anonymized aggregate data is kept. Not audited."
        },
        "dnssec_validation": {
          "title": "DNSSEC validation",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://cleanbrowsing.org/learn/what-is-dnssec",
          "note": "The resolvers validate DNSSEC on all queries."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:34.857Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cloudflare",
      "category": "dns-resolvers",
      "name": "Cloudflare",
      "description": "Public DNS resolver from Cloudflare with DNS over HTTPS and TLS, DNSSEC validation, and privacy commitments examined by KPMG.",
      "website": "https://one.one.one.one",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 72,
      "coverage": 100,
      "summary": "Cloudflare scores 72 out of 100 (grade C) on the DNS resolvers criteria. It meets 8 of 11 criteria: no ads or data sales, independent audit, transparency report, tells users about requests, TLS configuration, Encrypted DNS, no query logs and DNSSEC validation. It partly meets security headers. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/dns-resolvers/cloudflare/",
      "markdown": "https://privacyratings.com/dns-resolvers/cloudflare/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.cloudflare.onedotonedotonedotone/latest/",
          "note": "The 1.1.1.1 Android app includes Google Firebase Analytics and Crashlytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://developers.cloudflare.com/1.1.1.1/privacy/public-dns-resolver/",
          "note": "Cloudflare commits not to sell resolver data or use it to target ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cf-assets.www.cloudflare.com/slt3lc6tev37/7tcP0k0xUM8iDCacah9ARy/5c6b296e2fc24813368f6e2b4e58fd3a/Cloudflare_1.1.1.1_Examination_Report.pdf",
          "note": "Full KPMG examination report on the resolver's privacy controls."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.cloudflare.com/transparency/",
          "note": "Semi-annual reports with counts of legal requests and responses."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://cf-assets.www.cloudflare.com/slt3lc6tev37/zItVXCvbb4LZpYG4Uh10R/7b27bba39755f0a4344acb946977704d/2H_2025_Cloudflare_s_Transparency_Report_Legal-v2.pdf",
          "note": "The transparency report states customers are notified of legal requests unless legally prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=one.one.one.one&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=one.one.one.one",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "encrypted_dns": {
          "title": "Encrypted DNS",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://developers.cloudflare.com/1.1.1.1/encryption/",
          "note": "DoH and DoT are supported."
        },
        "no_query_logs": {
          "title": "No query logs",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://cf-assets.www.cloudflare.com/slt3lc6tev37/7tcP0k0xUM8iDCacah9ARy/5c6b296e2fc24813368f6e2b4e58fd3a/Cloudflare_1.1.1.1_Examination_Report.pdf",
          "note": "Source IPs are truncated and deleted within 25 hours, confirmed by the KPMG examination."
        },
        "dnssec_validation": {
          "title": "DNSSEC validation",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developers.cloudflare.com/1.1.1.1/faq/",
          "note": "1.1.1.1 validates DNSSEC on every query."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:23.499Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "control-d",
      "category": "dns-resolvers",
      "name": "Control D",
      "description": "DNS resolver service from ControlD Inc. in Canada, founded by the team behind Windscribe. It offers free filtering resolvers and paid plans with custom rules, over legacy DNS, DoH, DoT and DNS over QUIC.",
      "website": "https://controld.com",
      "source": "https://github.com/Control-D-Inc/ctrld",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 63,
      "coverage": 100,
      "summary": "Control D scores 63 out of 100 (grade C) on the DNS resolvers criteria. It meets 5 of 11 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, Encrypted DNS and DNSSEC validation. It partly meets open source, security headers and no query logs. It does not meet independent audit, transparency report and tells users about requests. It is based in Canada: Five Eyes member. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/dns-resolvers/control-d/",
      "markdown": "https://privacyratings.com/dns-resolvers/control-d/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/Control-D-Inc/ctrld/blob/main/LICENSE",
          "note": "The ctrld client is open source under the MIT license. The resolver service is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://controld.com/free-dns",
          "note": "The site states no third-party tracking or analytics services are used on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://controld.com/pricing",
          "note": "Funded by paid plans. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=controld.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=controld.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "encrypted_dns": {
          "title": "Encrypted DNS",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://docs.controld.com/docs/free-dns",
          "note": "The free resolvers are listed with DoH, DoT and DNS over QUIC endpoints."
        },
        "no_query_logs": {
          "title": "No query logs",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://controld.com/free-dns",
          "note": "The free resolvers are stated to keep no browsing history, timestamps or logs. Not audited."
        },
        "dnssec_validation": {
          "title": "DNSSEC validation",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.controld.com/docs/disable-dnssec-option",
          "note": "DNSSEC validation is on by default and can be turned off per profile."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:26.935Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "digitale-gesellschaft-dns",
      "category": "dns-resolvers",
      "name": "Digitale Gesellschaft DNS",
      "description": "Public DoH and DoT resolver run by Digitale Gesellschaft, a Swiss non-profit digital rights association. It validates DNSSEC, uses no blocklists and publishes its live configuration.",
      "website": "https://www.digitale-gesellschaft.ch/dns/",
      "source": "https://github.com/DigitaleGesellschaft/DNS-Resolver",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 67,
      "coverage": 100,
      "summary": "Digitale Gesellschaft DNS scores 67 out of 100 (grade C) on the DNS resolvers criteria. It meets 5 of 11 criteria: no trackers or telemetry, no ads or data sales, transparency report, Encrypted DNS and DNSSEC validation. It partly meets open source, TLS configuration, security headers and no query logs. It does not meet independent audit and tells users about requests. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/dns-resolvers/digitale-gesellschaft-dns/",
      "markdown": "https://privacyratings.com/dns-resolvers/digitale-gesellschaft-dns/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/DigitaleGesellschaft/DNS-Resolver",
          "note": "The live resolver configuration is published, but the repository has no license file."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://res4.digitale-gesellschaft.ch/",
          "note": "The resolver privacy notice rules out logging IP addresses or domain names, and the website loads only first-party scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.digitale-gesellschaft.ch/uber-uns/mitgliedschaft-und-spenden/",
          "note": "Non-profit association funded by memberships and donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.digitale-gesellschaft.ch/dns/dot-and-doh-transparency-report-2025/",
          "note": "Yearly report with counts of law enforcement requests and blocked domains."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.digitale-gesellschaft.ch&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.digitale-gesellschaft.ch",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "encrypted_dns": {
          "title": "Encrypted DNS",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.digitale-gesellschaft.ch/dns/",
          "note": "DoH and DoT endpoints are both documented."
        },
        "no_query_logs": {
          "title": "No query logs",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://res4.digitale-gesellschaft.ch/",
          "note": "The privacy notice states IP addresses and domain names are not logged, only query statistics. Not audited."
        },
        "dnssec_validation": {
          "title": "DNSSEC validation",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.digitale-gesellschaft.ch/dns/",
          "note": "The service page states DNSSEC is validated."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:33.215Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "dns-sb",
      "category": "dns-resolvers",
      "name": "DNS.SB",
      "description": "Free public DNS resolver operated by xTom GmbH in Germany on an anycast network. It supports DoH and DoT, validates DNSSEC and does not send EDNS Client Subnet.",
      "website": "https://dns.sb",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "DNS.SB scores 65 out of 100 (grade C) on the DNS resolvers criteria. It meets 6 of 11 criteria: no trackers or telemetry, no ads or data sales, transparency report, TLS configuration, Encrypted DNS and DNSSEC validation. It partly meets security headers and no query logs. It does not meet open source, independent audit and tells users about requests. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/dns-resolvers/dns-sb/",
      "markdown": "https://privacyratings.com/dns-resolvers/dns-sb/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. The resolver software stack is not disclosed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://dns.sb/privacy/",
          "note": "No third-party trackers. The website's self-hosted Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://dns.sb/sponsors/",
          "note": "Funded by xTom and sponsors. The privacy policy rules out selling personal information."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://dns.sb/report/",
          "note": "Yearly reports with counts of government and law enforcement requests."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=dns.sb&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=dns.sb",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "encrypted_dns": {
          "title": "Encrypted DNS",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://dns.sb/faq/",
          "note": "DoH and DoT are both supported."
        },
        "no_query_logs": {
          "title": "No query logs",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://dns.sb/privacy/",
          "note": "The policy states queries, IP addresses and timestamps are not logged. Not audited."
        },
        "dnssec_validation": {
          "title": "DNSSEC validation",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://dns.sb/faq/",
          "note": "The FAQ states DNS.SB is a DNSSEC-validating resolver."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:27.267Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "dns4eu",
      "category": "dns-resolvers",
      "name": "DNS4EU",
      "description": "Public DNS resolver co-funded by the European Union and operated by a consortium led by Whalebone in the Czech Republic. It offers protective, child-safe, ad-blocking and unfiltered variants over DoH and DoT.",
      "website": "https://joindns4.eu",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CZ",
        "name": "Czechia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 41,
      "coverage": 100,
      "summary": "DNS4EU scores 41 out of 100 (grade D) on the DNS resolvers criteria. It meets 4 of 11 criteria: no ads or data sales, TLS configuration, Encrypted DNS and DNSSEC validation. It partly meets no query logs. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in Czechia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C-.",
      "url": "https://privacyratings.com/dns-resolvers/dns4eu/",
      "markdown": "https://privacyratings.com/dns-resolvers/dns4eu/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://joindns4.eu/privacy-policy",
          "note": "The website loads Google Tag Manager and HubSpot."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://legal-documents-dns4eu.s3.fr-par.scw.cloud/DNS4EU-Public-DNS-Resolver-policy-2025.pdf",
          "note": "Co-funded by the European Union. The resolver policy rules out selling or transferring IP addresses or user identifiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.joindns4.eu&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.joindns4.eu",
          "note": "Grade C- (45/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "encrypted_dns": {
          "title": "Encrypted DNS",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://joindns4.eu/for-public",
          "note": "DoH and DoT endpoints are listed for each resolver variant."
        },
        "no_query_logs": {
          "title": "No query logs",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://legal-documents-dns4eu.s3.fr-par.scw.cloud/DNS4EU-Public-DNS-Resolver-policy-2025.pdf",
          "note": "Client IP addresses are anonymised with a keyed hash on the resolver before logging. Not audited."
        },
        "dnssec_validation": {
          "title": "DNSSEC validation",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://protective.joindns4.eu/dns-query?dns=AAABAAABAAAAAAABDWRuc3NlYy1mYWlsZWQDb3JnAAABAAEAACkQAAAAgAAAAA",
          "note": "A test query for the deliberately broken dnssec-failed.org returns SERVFAIL, showing validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:28.441Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "google-public-dns",
      "category": "dns-resolvers",
      "name": "Google Public DNS",
      "description": "Free public DNS resolver run by Google at 8.8.8.8 and 8.8.4.4 that validates DNSSEC and supports DNS over HTTPS and DNS over TLS.",
      "website": "https://developers.google.com/speed/public-dns",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "Google Public DNS scores 45 out of 100 (grade D) on the DNS resolvers criteria. It meets 5 of 10 criteria: transparency report, tells users about requests, security headers, Encrypted DNS and DNSSEC validation. It partly meets no query logs. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/dns-resolvers/google-public-dns/",
      "markdown": "https://privacyratings.com/dns-resolvers/google-public-dns/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://developers.google.com/speed/public-dns",
          "note": "The documentation website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://developers.google.com/speed/public-dns/privacy",
          "note": "Free service funded by Google's advertising business. The privacy page states DNS logs are not combined with other Google data for ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://transparencyreport.google.com/user-data/overview",
          "note": "Google publishes counts of government requests for user data twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://policies.google.com/terms/information-requests",
          "note": "Google states it notifies users before disclosing their information unless prohibited by law or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Could not test: No endpoint could be graded"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=dns.google",
          "note": "Grade A+ (100/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "encrypted_dns": {
          "title": "Encrypted DNS",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://developers.google.com/speed/public-dns/docs/secure-transports",
          "note": "DNS over HTTPS and DNS over TLS are both supported."
        },
        "no_query_logs": {
          "title": "No query logs",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://developers.google.com/speed/public-dns/privacy",
          "note": "Temporary logs with full IP addresses are kept for 24 to 48 hours. Sampled permanent logs keep only city or region. Not audited."
        },
        "dnssec_validation": {
          "title": "DNSSEC validation",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developers.google.com/speed/public-dns/faq",
          "note": "Google Public DNS is a validating resolver for all DNSSEC-signed zones."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:52.571Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "libredns",
      "category": "dns-resolvers",
      "name": "LibreDNS",
      "description": "Public encrypted DNS resolver run by the volunteer LibreOps collective, with DoH and DoT endpoints and an optional ad-blocking endpoint.",
      "website": "https://libredns.gr",
      "source": "https://gitlab.com/libreops/libredns/libredns-cfg",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "GR",
        "name": "Greece",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "LibreDNS scores 65 out of 100 (grade C) on the DNS resolvers criteria. It meets 5 of 11 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration and Encrypted DNS. It partly meets security headers and no query logs. It does not meet independent audit, transparency report, tells users about requests and DNSSEC validation. It is based in Greece: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/dns-resolvers/libredns/",
      "markdown": "https://privacyratings.com/dns-resolvers/libredns/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/libreops/libredns/libredns-cfg/-/blob/main/LICENSE",
          "note": "The server deployment scripts are published under AGPL-3.0 and run open-source DNS software."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/libreops/libredns/libredns.gr",
          "note": "The website source is public and loads no analytics or third-party scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/libreops",
          "note": "Run by volunteers and funded by donations through Open Collective. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=libredns.gr&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=libredns.gr",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "encrypted_dns": {
          "title": "Encrypted DNS",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://libredns.gr/",
          "note": "DoH and DoT endpoints are both documented."
        },
        "no_query_logs": {
          "title": "No query logs",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://libredns.gr/",
          "note": "The site states logging is disabled for the DNS daemon. Not audited."
        },
        "dnssec_validation": {
          "title": "DNSSEC validation",
          "weight": 1,
          "answer": "no",
          "evidence": "https://doh.libredns.gr/dns-query?dns=AAABAAABAAAAAAABDWRuc3NlYy1mYWlsZWQDb3JnAAABAAEAACkQAAAAgAAAAA",
          "note": "A test query for the deliberately broken dnssec-failed.org resolves normally, so DNSSEC is not validated."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:30.086Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "mullvad-dns",
      "category": "dns-resolvers",
      "name": "Mullvad DNS",
      "description": "Free encrypted DNS resolver from Mullvad with optional ad, tracker and malware blocking. Mullvad has announced it is shutting the public service down.",
      "website": "https://mullvad.net/en/help/dns-over-https-and-dns-over-tls",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "SE",
        "name": "Sweden",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 63,
      "coverage": 100,
      "summary": "Mullvad DNS scores 63 out of 100 (grade C) on the DNS resolvers criteria. It meets 6 of 11 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, security headers, Encrypted DNS and DNSSEC validation. It partly meets transparency report and no query logs. It does not meet open source, independent audit and tells users about requests. It is based in Sweden: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/dns-resolvers/mullvad-dns/",
      "markdown": "https://privacyratings.com/dns-resolvers/mullvad-dns/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The resolver setup is not published. Only the blocklists and Apple configuration profiles are on GitHub."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://mullvad.net/en/help/no-logging-data-policy",
          "note": "The policy states no usage data is sent to external analytics. There is no app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mullvad.net/en/help/dns-over-https-and-dns-over-tls",
          "note": "Free service funded by Mullvad VPN subscriptions. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit of the DNS service is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://mullvad.net/en/help/swedish-legislation",
          "note": "Explains which Swedish laws allow authorities to request data and what can be disclosed. No request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mullvad.net&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mullvad.net",
          "note": "Grade A+ (135/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "encrypted_dns": {
          "title": "Encrypted DNS",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://mullvad.net/en/help/dns-over-https-and-dns-over-tls",
          "note": "DoH and DoT are supported."
        },
        "no_query_logs": {
          "title": "No query logs",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://mullvad.net/en/help/no-logging-data-policy",
          "note": "The no-logging policy states DNS requests are not logged. The DNS service has not been audited."
        },
        "dnssec_validation": {
          "title": "DNSSEC validation",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://mullvad.net/en/help/dns-over-https-and-dns-over-tls",
          "note": "Tested: queries for domains with broken DNSSEC signatures return SERVFAIL, and succeed only with checking disabled."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:24.431Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nextdns",
      "category": "dns-resolvers",
      "name": "NextDNS",
      "description": "Configurable DNS resolver that blocks ads, trackers and malicious domains, with optional parental controls and per-user query logs.",
      "website": "https://nextdns.io",
      "source": "https://github.com/nextdns/nextdns",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 61,
      "coverage": 100,
      "summary": "NextDNS scores 61 out of 100 (grade C) on the DNS resolvers criteria. It meets 5 of 11 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, Encrypted DNS and DNSSEC validation. It partly meets open source and no query logs. It does not meet independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/dns-resolvers/nextdns/",
      "markdown": "https://privacyratings.com/dns-resolvers/nextdns/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/nextdns/nextdns/blob/master/LICENSE",
          "note": "Only the client is open source. The resolver service is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/io.nextdns.NextDNS/latest/",
          "note": "The Android app has no known trackers on Exodus, and the policy states user data is never shared."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://nextdns.io/privacy",
          "note": "Funded by paid plans. The policy states data is never sold or shared."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=nextdns.io&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=nextdns.io",
          "note": "Grade C (55/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "encrypted_dns": {
          "title": "Encrypted DNS",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://nextdns.io/",
          "note": "DoH and DoT are supported."
        },
        "no_query_logs": {
          "title": "No query logs",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://nextdns.io/privacy",
          "note": "Queries are discarded unless the user turns on logging, with retention chosen by the user. Not audited."
        },
        "dnssec_validation": {
          "title": "DNSSEC validation",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://nextdns.io/",
          "note": "DNS answers are validated with DNSSEC automatically."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:23.845Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "opendns",
      "category": "dns-resolvers",
      "name": "OpenDNS",
      "description": "Public DNS resolver from Cisco at 208.67.222.222 and 208.67.220.220, with optional content filtering and a free home account for managing filters.",
      "website": "https://www.opendns.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 37,
      "coverage": 100,
      "summary": "OpenDNS scores 37 out of 100 (grade F) on the DNS resolvers criteria. It meets 4 of 11 criteria: no ads or data sales, transparency report, tells users about requests and DNSSEC validation. It partly meets TLS configuration and Encrypted DNS. It does not meet open source, no trackers or telemetry, independent audit, security headers and no query logs. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/dns-resolvers/opendns/",
      "markdown": "https://privacyratings.com/dns-resolvers/opendns/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.opendns.com/privacy-policy/",
          "note": "The Cisco privacy statement used by the site allows third-party advertising and analytics cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.opendns.com/privacy-policy/",
          "note": "The free service is backed by Cisco's paid security products. Cisco states it does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.cisco.com/c/en/us/about/trust-center/transparency.html",
          "note": "Cisco publishes counts of law enforcement and national security requests twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.cisco.com/c/dam/en_us/about/doing_business/trust-center/docs/cisco-principled-approach-to-government-requests-for-data.pdf",
          "note": "Cisco states it notifies customers before producing data to a government unless the law prohibits it."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.opendns.com&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.opendns.com",
          "note": "Grade D- (25/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "encrypted_dns": {
          "title": "Encrypted DNS",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://doh.opendns.com/dns-query?dns=AAABAAABAAAAAAAAB2V4YW1wbGUDY29tAAABAAE",
          "note": "DNS over HTTPS answers at doh.opendns.com. No current documentation for DNS over TLS is published."
        },
        "no_query_logs": {
          "title": "No query logs",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.opendns.com/privacy-policy/",
          "note": "No policy states that queries are kept without IP addresses. The Cisco privacy statement allows retention as long as business needs require."
        },
        "dnssec_validation": {
          "title": "DNSSEC validation",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://doh.opendns.com/dns-query?dns=AAABAAABAAAAAAAACGRuc3NlYy1mYWlsZWQDb3JnAAABAAE",
          "note": "A test query for the deliberately broken dnssec-failed.org returns SERVFAIL, showing validation."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:30.965Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "opennic",
      "category": "dns-resolvers",
      "name": "OpenNIC",
      "description": "Volunteer-run alternative DNS root with public resolvers that answer for both ICANN domains and OpenNIC's own top-level domains such as .libre and .oss.",
      "website": "https://opennic.org",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 41,
      "coverage": 100,
      "summary": "OpenNIC scores 41 out of 100 (grade D) on the DNS resolvers criteria. It meets 1 of 11 criteria: no ads or data sales. It partly meets open source, no trackers or telemetry, TLS configuration, Encrypted DNS, no query logs and DNSSEC validation. It does not meet independent audit, transparency report, tells users about requests and security headers. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/dns-resolvers/opennic/",
      "markdown": "https://privacyratings.com/dns-resolvers/opennic/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/OpenNIC",
          "note": "Project tooling is published on GitHub, but each volunteer resolver runs its own setup."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://opennic.org/privacy/",
          "note": "The website uses self-hosted Matomo analytics. No third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opennic.org/",
          "note": "Run by volunteers and funded by donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=opennic.org&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=opennic.org",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "encrypted_dns": {
          "title": "Encrypted DNS",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://wiki.opennic.org/opennic/setup/listserver",
          "note": "Some volunteer servers offer DoH or DoT, but support varies by server."
        },
        "no_query_logs": {
          "title": "No query logs",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://wiki.opennic.org/opennic/setup/listserver",
          "note": "Each volunteer server sets its own log policy, and some keep no logs or anonymized logs. Not audited."
        },
        "dnssec_validation": {
          "title": "DNSSEC validation",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://wiki.opennic.org/opennic/dnssec",
          "note": "Server operators may enable DNSSEC validation, but it is not required."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:23.776Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "quad9",
      "category": "dns-resolvers",
      "name": "Quad9",
      "description": "Public DNS resolver run by the Swiss non-profit Quad9 Foundation that blocks known malicious domains and validates DNSSEC.",
      "website": "https://quad9.net",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Quad9 scores 65 out of 100 (grade C) on the DNS resolvers criteria. It meets 6 of 11 criteria: no trackers or telemetry, no ads or data sales, transparency report, TLS configuration, Encrypted DNS and DNSSEC validation. It partly meets security headers and no query logs. It does not meet open source, independent audit and tells users about requests. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/dns-resolvers/quad9/",
      "markdown": "https://privacyratings.com/dns-resolvers/quad9/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. The resolver configuration and threat-blocking system are not published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://quad9.net/privacy/website-policy/",
          "note": "The website policy states no cookies, web beacons or tracking pixels are used."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://quad9.net/privacy/policy/",
          "note": "Non-profit funded by donations and sponsors. The policy states identifying data is not shared or sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://quad9.net/about/transparency-report/",
          "note": "Yearly summaries of law enforcement requests, updated quarterly."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=quad9.net&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=quad9.net",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "encrypted_dns": {
          "title": "Encrypted DNS",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://quad9.net/service/service-addresses-and-features/",
          "note": "DoH and DoT endpoints are listed for each service."
        },
        "no_query_logs": {
          "title": "No query logs",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://quad9.net/privacy/policy/",
          "note": "The policy states user IP addresses are not stored with queries. Not audited."
        },
        "dnssec_validation": {
          "title": "DNSSEC validation",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://quad9.net/service/service-addresses-and-features/",
          "note": "DNSSEC validation is enabled on the recommended resolver addresses."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:24.265Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "unbound",
      "category": "dns-resolvers",
      "name": "Unbound",
      "description": "Validating, recursive and caching DNS resolver from NLnet Labs for running your own resolver, with DNS over TLS and DNS over HTTPS support.",
      "website": "https://nlnetlabs.nl/projects/unbound/about/",
      "source": "https://github.com/NLnetLabs/unbound",
      "license": "BSD-3-Clause",
      "platforms": [],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "Unbound scores 85 out of 100 (grade B) on the DNS resolvers criteria. It meets 5 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, Encrypted DNS and DNSSEC validation. It partly meets independent audit and no query logs. It is based in the Netherlands: Nine Eyes member; EU member (GDPR). Automated tests: Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/dns-resolvers/unbound/",
      "markdown": "https://privacyratings.com/dns-resolvers/unbound/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/NLnetLabs/unbound/blob/master/LICENSE",
          "note": "BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/NLnetLabs/unbound",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://nlnetlabs.nl/about/",
          "note": "Developed by a non-profit foundation funded by donations and support contracts. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://ostif.org/wp-content/uploads/2019/12/X41-Unbound-Security-Audit-2019-Final-Report.pdf",
          "note": "The full X41 D-Sec audit report is older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "encrypted_dns": {
          "title": "Encrypted DNS",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://nlnetlabs.nl/projects/unbound/about/",
          "note": "DNS over TLS and DNS over HTTPS are supported."
        },
        "no_query_logs": {
          "title": "No query logs",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://unbound.docs.nlnetlabs.nl/en/latest/manpages/unbound.conf.html",
          "note": "Query logging is off by default and controlled by whoever runs the resolver. Not audited."
        },
        "dnssec_validation": {
          "title": "DNSSEC validation",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://nlnetlabs.nl/projects/unbound/about/",
          "note": "Unbound is a validating resolver."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:26.412Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "uncensoreddns",
      "category": "dns-resolvers",
      "name": "UncensoredDNS",
      "description": "Free public DNS resolver in Denmark, run by an individual, that does not apply censorship filters. It offers anycast and unicast servers over plain DNS, DoT and DoH.",
      "website": "https://blog.uncensoreddns.org",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DK",
        "name": "Denmark",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 61,
      "coverage": 100,
      "summary": "UncensoredDNS scores 61 out of 100 (grade C) on the DNS resolvers criteria. It meets 5 of 11 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, Encrypted DNS and DNSSEC validation. It partly meets transparency report, security headers and no query logs. It does not meet open source, independent audit and tells users about requests. It is based in Denmark: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/dns-resolvers/uncensoreddns/",
      "markdown": "https://privacyratings.com/dns-resolvers/uncensoreddns/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. The server configuration is not published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://blog.uncensoreddns.org/faq/",
          "note": "The FAQ states nothing about users is logged, and the website loads no third-party scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://blog.uncensoreddns.org/faq/",
          "note": "Paid for by the operator, with sponsored hosting for anycast nodes. The FAQ states data is never sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://blog.uncensoreddns.org/faq/",
          "note": "The FAQ states the operator has never been contacted by authorities, and that this will change if it happens. No request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=blog.uncensoreddns.org&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=blog.uncensoreddns.org",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "encrypted_dns": {
          "title": "Encrypted DNS",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://blog.uncensoreddns.org/dns-servers/",
          "note": "Both servers listen for DoT on port 853 and DoH on port 443."
        },
        "no_query_logs": {
          "title": "No query logs",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://blog.uncensoreddns.org/faq/",
          "note": "The FAQ states nothing is logged except total query counts. Not audited."
        },
        "dnssec_validation": {
          "title": "DNSSEC validation",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://anycast.uncensoreddns.org/dns-query?dns=AAABAAABAAAAAAABDWRuc3NlYy1mYWlsZWQDb3JnAAABAAEAACkQAAAAgAAAAA",
          "note": "A test query for the deliberately broken dnssec-failed.org returns SERVFAIL, showing validation."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:33.610Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "amazon-route-53",
      "category": "dns-hosting",
      "name": "Amazon Route 53",
      "description": "Authoritative DNS hosting and domain registration service from Amazon Web Services, with health checks, routing policies and pay-per-use pricing.",
      "website": "https://aws.amazon.com/route53/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 52,
      "coverage": 100,
      "summary": "Amazon Route 53 scores 52 out of 100 (grade D) on the DNS hosting criteria. It meets 6 of 11 criteria: transparency report, tells users about requests, TLS configuration, security headers, API access and two-factor login. It partly meets independent audit and DNSSEC. It does not meet open source, no trackers or telemetry and no ads or data sales. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/dns-hosting/amazon-route-53/",
      "markdown": "https://privacyratings.com/dns-hosting/amazon-route-53/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://aws.amazon.com/legal/cookies/",
          "note": "AWS websites set cookies from third parties including The Trade Desk, Oracle BlueKai and LinkedIn."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://aws.amazon.com/privacy/",
          "note": "The privacy notice says cookies and identifiers are used to advertise to visitors on third-party websites."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://d1.awsstatic.com/onedam/marketing-channels/website/aws/en_US/whitepapers/compliance/AWS_SOC3_Report.pdf",
          "note": "Only the SOC 3 summary report is public; SOC 1 and SOC 2 reports are available to customers in AWS Artifact."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://d1.awsstatic.com/onedam/marketing-channels/website/aws/en_US/security/pdfs/Amazon_Government_Request_Report_H1_2026.pdf",
          "note": "Semi-annual reports with counts of government requests to Amazon and AWS and how they were answered."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.amazon.com/gp/help/customer/display.html?nodeId=GYSDRGWQ2C2CRYEF",
          "note": "Amazon notifies customers before disclosing content unless prohibited or there is clear indication of illegal conduct."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=console.aws.amazon.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=console.aws.amazon.com",
          "note": "Grade A+ (105/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "dnssec": {
          "title": "DNSSEC",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/dns-configuring-dnssec.html",
          "note": "DNSSEC signing is supported but needs a customer-managed AWS KMS key for the key-signing key."
        },
        "api_access": {
          "title": "API access",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.aws.amazon.com/Route53/latest/APIReference/Welcome.html",
          "note": "Every AWS account can manage hosted zones and records through the Route 53 API."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa.html",
          "note": "Passkeys, security keys and authenticator apps are supported."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:34.099Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "bunny-dns",
      "category": "dns-hosting",
      "name": "Bunny DNS",
      "description": "Authoritative DNS hosting from the Slovenian CDN provider bunny.net, with DNSSEC, scriptable DNS records, health-check failover and usage-based pricing.",
      "website": "https://bunny.net/dns/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "SI",
        "name": "Slovenia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 43,
      "coverage": 100,
      "summary": "Bunny DNS scores 43 out of 100 (grade D) on the DNS hosting criteria. It meets 4 of 11 criteria: no ads or data sales, DNSSEC, API access and two-factor login. It partly meets TLS configuration and security headers. It does not meet open source, no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in Slovenia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/dns-hosting/bunny-dns/",
      "markdown": "https://privacyratings.com/dns-hosting/bunny-dns/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads PostHog analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://bunny.net/pricing/dns/",
          "note": "Funded by usage-based DNS pricing. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=dash.bunny.net&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=dash.bunny.net",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "dnssec": {
          "title": "DNSSEC",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://bunny.net/docs/dns/dnssec",
          "note": "DNSSEC is enabled on a zone's Security tab with automatic key management. The DS record is added at the registrar."
        },
        "api_access": {
          "title": "API access",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://bunny.net/docs/api-reference/core/dns-zone/add-dns-zone",
          "note": "Zones and records are managed through the bunny.net API on every account."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://bunny.net/docs/account/two-factor-authentication",
          "note": "Authenticator apps (TOTP) are supported."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cookiebot",
            "host": "consent.cookiebot.com",
            "effect": "none"
          },
          {
            "name": "PostHog",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "widget.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:42:09.590Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "cloudflare-dns",
      "category": "dns-hosting",
      "name": "Cloudflare DNS",
      "description": "Authoritative DNS hosting on Cloudflare's anycast network with a free plan, DNSSEC, an API and security-key login.",
      "website": "https://www.cloudflare.com/products/dns/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": true,
      "pick_reason": "Free on every plan, one of the fastest DNS networks, a complete API, and hardware security key login. DNSSEC is automatic when the domain is also registered with Cloudflare Registrar.",
      "disclosure": null,
      "grade": "C",
      "score": 66,
      "coverage": 100,
      "summary": "Cloudflare DNS scores 66 out of 100 (grade C) on the DNS hosting criteria. It meets 7 of 11 criteria: no ads or data sales, transparency report, tells users about requests, TLS configuration, DNSSEC, API access and two-factor login. It partly meets independent audit and security headers. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/dns-hosting/cloudflare-dns/",
      "markdown": "https://privacyratings.com/dns-hosting/cloudflare-dns/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The DNS service is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.cloudflare.com/plans/",
          "note": "Funded by paid plans. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://developers.cloudflare.com/fundamentals/reference/policies-compliances/compliance-docs/",
          "note": "SOC 2, ISO 27001 and PCI reports exist but are only available to account administrators in the dashboard."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.cloudflare.com/transparency/",
          "note": "Semi-annual reports with counts of legal requests and responses."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://cf-assets.www.cloudflare.com/slt3lc6tev37/zItVXCvbb4LZpYG4Uh10R/7b27bba39755f0a4344acb946977704d/2H_2025_Cloudflare_s_Transparency_Report_Legal-v2.pdf",
          "note": "The transparency report states customers are notified of legal requests unless legally prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=dash.cloudflare.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=dash.cloudflare.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "dnssec": {
          "title": "DNSSEC",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://developers.cloudflare.com/dns/dnssec/",
          "note": "Enabled with one click. The DS record is added automatically for Cloudflare Registrar domains and manually at other registrars."
        },
        "api_access": {
          "title": "API access",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developers.cloudflare.com/api/",
          "note": "The DNS API is available on every plan, including the free plan."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://developers.cloudflare.com/fundamentals/user-profiles/2fa/",
          "note": "Security keys and authenticator apps."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:03:55.152Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cloudns",
      "category": "dns-hosting",
      "name": "ClouDNS",
      "description": "Managed DNS hosting from Bulgaria with a free plan and paid plans adding anycast, DNSSEC, GeoDNS, DDoS protection, secondary DNS and failover.",
      "website": "https://www.cloudns.net",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "BG",
        "name": "Bulgaria",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 36,
      "coverage": 100,
      "summary": "ClouDNS scores 36 out of 100 (grade F) on the DNS hosting criteria. It meets 3 of 11 criteria: TLS configuration, DNSSEC and two-factor login. It partly meets security headers and API access. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report and tells users about requests. It is based in Bulgaria: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/dns-hosting/cloudns/",
      "markdown": "https://privacyratings.com/dns-hosting/cloudns/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics and Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.cloudns.net/privacy-policy/",
          "note": "Personal data is not sold, but optional advertising cookies are used on the website."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.cloudns.net&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.cloudns.net",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "dnssec": {
          "title": "DNSSEC",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.cloudns.net/dnssec/",
          "note": "Activated with one button in the zone's control panel on paid plans. The DS record is added at the registrar."
        },
        "api_access": {
          "title": "API access",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.cloudns.net/premium/",
          "note": "The HTTP API is only included in paid plans."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.cloudns.net/wiki/article/201/",
          "note": "TOTP authenticator apps are supported."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "www.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:35.863Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "desec",
      "category": "dns-hosting",
      "name": "deSEC",
      "description": "Free authoritative DNS hosting from the Berlin non-profit deSEC e.V., with automatic DNSSEC signing, a full REST API and open-source software.",
      "website": "https://desec.io",
      "source": "https://github.com/desec-io/desec-stack",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 77,
      "coverage": 100,
      "summary": "deSEC scores 77 out of 100 (grade B) on the DNS hosting criteria. It meets 8 of 11 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, security headers, DNSSEC, API access and two-factor login. It does not meet independent audit, transparency report and tells users about requests. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/dns-hosting/desec/",
      "markdown": "https://privacyratings.com/dns-hosting/desec/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/desec-io/desec-stack/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://desec.io/privacy-policy",
          "note": "The privacy policy states no tracking, behavioral analytics or externally hosted dependencies are used."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://desec.io/about",
          "note": "Run by a non-profit association funded by donations and grants. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=desec.io&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=desec.io",
          "note": "Grade A+ (105/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "dnssec": {
          "title": "DNSSEC",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://desec.io/",
          "note": "Every hosted zone is signed with DNSSEC automatically. The DS record is added at the registrar."
        },
        "api_access": {
          "title": "API access",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://desec.readthedocs.io/en/latest/",
          "note": "All records are managed through the REST API, which every free account can use."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://desec.io/",
          "note": "TOTP authenticator apps are supported for login."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:24.266Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dnsimple",
      "category": "dns-hosting",
      "name": "DNSimple",
      "description": "Paid managed DNS hosting and domain registrar with DNSSEC, secondary DNS, an API, a CLI and a Terraform provider.",
      "website": "https://dnsimple.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 52,
      "coverage": 100,
      "summary": "DNSimple scores 52 out of 100 (grade D) on the DNS hosting criteria. It meets 5 of 11 criteria: tells users about requests, TLS configuration, DNSSEC, API access and two-factor login. It partly meets no ads or data sales, transparency report and security headers. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/dns-hosting/dnsimple/",
      "markdown": "https://privacyratings.com/dns-hosting/dnsimple/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://dnsimple.com/privacy",
          "note": "The privacy policy says third-party tracking technologies may be used for interest-based advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://dnsimple.com/privacy",
          "note": "The privacy policy says data is released only when required by law or properly served legal process. No request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://dnsimple.com/privacy",
          "note": "The privacy policy says users are notified of legal process for their data when possible and legally permissible."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=dnsimple.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=dnsimple.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "dnssec": {
          "title": "DNSSEC",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://support.dnsimple.com/articles/dnssec/",
          "note": "DNSSEC is included on every plan and turned on per domain with automatic key rotation. The DS record is added at the registrar."
        },
        "api_access": {
          "title": "API access",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://dnsimple.com/pricing",
          "note": "Full API access is included on every plan."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.dnsimple.com/articles/multi-factor-authentication/",
          "note": "Authenticator apps (TOTP) and WebAuthn security keys are supported."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:39:09.116Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "hetzner-dns",
      "category": "dns-hosting",
      "name": "Hetzner DNS",
      "description": "Free authoritative DNS hosting from the German provider Hetzner, managed in the Hetzner Console and through the Hetzner Cloud API.",
      "website": "https://www.hetzner.com/dns/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 43,
      "coverage": 100,
      "summary": "Hetzner DNS scores 43 out of 100 (grade D) on the DNS hosting criteria. It meets 4 of 11 criteria: no ads or data sales, TLS configuration, API access and two-factor login. It partly meets no trackers or telemetry and independent audit. It does not meet open source, transparency report, tells users about requests, security headers and DNSSEC. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/dns-hosting/hetzner-dns/",
      "markdown": "https://privacyratings.com/dns-hosting/hetzner-dns/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.hetzner.com/legal/privacy-policy/",
          "note": "No third-party trackers, but website analytics use Matomo with cookies after consent."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.hetzner.com/dns/",
          "note": "Funded by Hetzner's paid hosting. DNS management is free and carries no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://files.hetzner.com/docs/BSI-C52020Typ2_Testat_2026_EN.pdf",
          "note": "Only a one-page summary of the BSI C5 Type 2 audit and an ISO 27001 certificate are public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=console.hetzner.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=console.hetzner.com",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "dnssec": {
          "title": "DNSSEC",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.hetzner.com/dns/",
          "note": "The product FAQ states Hetzner Console does not support DNSSEC."
        },
        "api_access": {
          "title": "API access",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.hetzner.cloud/reference/cloud",
          "note": "Zones and records are managed through the free Hetzner Cloud API."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.hetzner.com/general/security-and-identify/two-factor-authentication/",
          "note": "Two-factor login is supported, including YubiKey security keys."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:36.824Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "hurricane-electric-free-dns",
      "category": "dns-hosting",
      "name": "Hurricane Electric Free DNS",
      "description": "Free authoritative DNS hosting from the US network operator Hurricane Electric, with forward and reverse zones, secondary DNS and dynamic DNS updates.",
      "website": "https://dns.he.net",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Hurricane Electric Free DNS scores 25 out of 100 (grade F) on the DNS hosting criteria. It meets 1 of 11 criteria: no ads or data sales. It partly meets no trackers or telemetry, transparency report and TLS configuration. It does not meet open source, independent audit, tells users about requests, security headers, DNSSEC, API access and two-factor login. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/dns-hosting/hurricane-electric-free-dns/",
      "markdown": "https://privacyratings.com/dns-hosting/hurricane-electric-free-dns/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://he.net/privacy.html",
          "note": "No third-party trackers were found, but a first-party cookie records where visitors come from."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://he.net/privacy.html",
          "note": "Free service from a network operator funded by paid transit and hosting. The privacy policy says personal data is not disclosed to third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://he.net/privacy.html",
          "note": "The privacy policy says user information is disclosed only to comply with law or valid legal process. No request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=dns.he.net&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=dns.he.net",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "dnssec": {
          "title": "DNSSEC",
          "weight": 3,
          "answer": "no",
          "evidence": "https://dns.he.net",
          "note": "DNSSEC signing is not offered or listed among the service's features."
        },
        "api_access": {
          "title": "API access",
          "weight": 1,
          "answer": "no",
          "evidence": "https://dns.he.net",
          "note": "No API for managing zones. Only a dynamic DNS update endpoint for records marked as dynamic."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "no",
          "evidence": "https://dns.he.net",
          "note": "No two-factor login is documented; the login form asks only for a username and password."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:41:15.207Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "luadns",
      "category": "dns-hosting",
      "name": "LuaDNS",
      "description": "Anycast DNS hosting from Romania with DNSSEC, a REST API and git integration that builds zones from BIND or Lua files, with a free plan and paid plans.",
      "website": "https://www.luadns.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "RO",
        "name": "Romania",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 52,
      "coverage": 100,
      "summary": "LuaDNS scores 52 out of 100 (grade D) on the DNS hosting criteria. It meets 5 of 11 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, DNSSEC and API access. It partly meets security headers. It does not meet open source, independent audit, transparency report, tells users about requests and two-factor login. It is based in Romania: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/dns-hosting/luadns/",
      "markdown": "https://privacyratings.com/dns-hosting/luadns/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.luadns.com/privacy.html",
          "note": "The privacy policy says cookies are used only for authentication and authorization."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.luadns.com/pricing.html",
          "note": "Funded by paid plans. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.luadns.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.luadns.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "dnssec": {
          "title": "DNSSEC",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.luadns.com/help.html",
          "note": "Enabled from the zone settings page with automatic key generation and CDS/CDNSKEY records. The DS record is added at the registrar."
        },
        "api_access": {
          "title": "API access",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.luadns.com/pricing.html",
          "note": "The REST API is included in every package, including the free plan."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "no",
          "evidence": "https://app.luadns.com/login",
          "note": "No two-factor login is documented; the login form asks only for an email and password."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:52.762Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "cloudflare-registrar",
      "category": "domain-registrars",
      "name": "Cloudflare Registrar",
      "description": "Domain registrar that charges registry cost with no markup, with free WHOIS redaction, transfer lock and one-click DNSSEC.",
      "website": "https://www.cloudflare.com/domains/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": true,
      "pick_reason": "Registry cost with no markup on registration or renewal, free WHOIS redaction, security-key login, and automatic DNSSEC with Cloudflare DNS.",
      "disclosure": null,
      "grade": "C",
      "score": 66,
      "coverage": 100,
      "summary": "Cloudflare Registrar scores 66 out of 100 (grade C) on the domain registrars criteria. It meets 8 of 12 criteria: no ads or data sales, transparency report, tells users about requests, TLS configuration, Free WHOIS privacy, honest renewal pricing, two-factor login and transfer and registry lock. It partly meets independent audit and security headers. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/domain-registrars/cloudflare-registrar/",
      "markdown": "https://privacyratings.com/domain-registrars/cloudflare-registrar/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.cloudflare.com/domains/",
          "note": "Registrations are sold at cost, and the business is funded by paid Cloudflare plans. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://developers.cloudflare.com/fundamentals/reference/policies-compliances/compliance-docs/",
          "note": "SOC 2, ISO 27001 and PCI reports exist but are only available to account administrators in the dashboard."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.cloudflare.com/transparency/",
          "note": "Semi-annual reports with counts of legal requests and responses."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://cf-assets.www.cloudflare.com/slt3lc6tev37/zItVXCvbb4LZpYG4Uh10R/7b27bba39755f0a4344acb946977704d/2H_2025_Cloudflare_s_Transparency_Report_Legal-v2.pdf",
          "note": "The transparency report states customers are notified of legal requests unless legally prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=dash.cloudflare.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=dash.cloudflare.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "free_whois_privacy": {
          "title": "Free WHOIS privacy",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.cloudflare.com/domains/",
          "note": "WHOIS redaction is free and on by default."
        },
        "at_cost_renewals": {
          "title": "Honest renewal pricing",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.cloudflare.com/domains/",
          "note": "Registration, transfer and renewal are priced at registry and ICANN cost."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://developers.cloudflare.com/fundamentals/user-profiles/2fa/",
          "note": "Security keys and authenticator apps are supported."
        },
        "registry_lock": {
          "title": "Transfer and registry lock",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.cloudflare.com/domains/",
          "note": "Domains are locked against transfer by default. Registry lock is available for Enterprise customers."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:24.262Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dynadot",
      "category": "domain-registrars",
      "name": "Dynadot",
      "description": "California-based domain registrar with free WHOIS privacy on eligible extensions, two-factor login and optional registry lock.",
      "website": "https://www.dynadot.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Dynadot scores 30 out of 100 (grade F) on the domain registrars criteria. It meets 2 of 12 criteria: two-factor login and transfer and registry lock. It partly meets no ads or data sales, TLS configuration, Free WHOIS privacy and honest renewal pricing. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/domain-registrars/dynadot/",
      "markdown": "https://privacyratings.com/domain-registrars/dynadot/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.dynadot.com/terms-of-use",
          "note": "Funded by domain sales, but new domains show a default parked page with third-party ads until nameservers are set."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.dynadot.com&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.dynadot.com",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "free_whois_privacy": {
          "title": "Free WHOIS privacy",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.dynadot.com/domain/security",
          "note": "Free, but only on eligible extensions."
        },
        "at_cost_renewals": {
          "title": "Honest renewal pricing",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.dynadot.com/domain/xyz",
          "note": "Standard registration and renewal prices match, but first-year sale prices on some extensions renew at a much higher rate."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.dynadot.com/help/question/two-step-verification",
          "note": "Authenticator apps, SMS and security keys are supported."
        },
        "registry_lock": {
          "title": "Transfer and registry lock",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.dynadot.com/domain/security",
          "note": "Domains are locked by default, and registry lock is available as an option."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "www.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:24.584Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gandi",
      "category": "domain-registrars",
      "name": "Gandi",
      "description": "French domain registrar and hosting provider with free WHOIS privacy on most extensions, TOTP and security-key login, and a yearly transparency report.",
      "website": "https://www.gandi.net/en",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "Gandi scores 45 out of 100 (grade D) on the domain registrars criteria. It meets 3 of 12 criteria: no ads or data sales, transparency report and two-factor login. It partly meets independent audit, TLS configuration, security headers, Free WHOIS privacy and transfer and registry lock. It does not meet open source, no trackers or telemetry, tells users about requests and honest renewal pricing. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/domain-registrars/gandi/",
      "markdown": "https://privacyratings.com/domain-registrars/gandi/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.gandi.net/en/contracts/privacy-policy",
          "note": "The privacy policy lists AT Internet audience-measurement cookies, which can be opted out of."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.gandi.net/en/domain/tld/com",
          "note": "Funded by paid domain and hosting services. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.gandi.net/en",
          "note": "The site states an ISO 27001 and ISO 22301 certification by BSI. No audit report is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.gandi.net/en/digital-service-act-transparency-report",
          "note": "Yearly reports with counts of information requests from authorities and content notices."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.gandi.net&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.gandi.net",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "free_whois_privacy": {
          "title": "Free WHOIS privacy",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://docs.gandi.net/en/domain_names/common_operations/whois_privacy.html",
          "note": "Free and on by default, but some extensions do not support the anonymized contact option."
        },
        "at_cost_renewals": {
          "title": "Honest renewal pricing",
          "weight": 1,
          "answer": "no",
          "evidence": "https://www.gandi.net/en/domain/tld/com",
          "note": "A .com registers for about 11 EUR but renews for about 32 EUR per year."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.gandi.net/en/account_management/security/totp.html",
          "note": "TOTP apps and security keys are supported."
        },
        "registry_lock": {
          "title": "Transfer and registry lock",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://docs.gandi.net/en/domain_names/transfer_out/transfer_lock.html",
          "note": "Transfer lock is available on most extensions. Registry lock is not offered to regular accounts."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Trustpilot",
            "host": "www.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:03:36.878Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "godaddy",
      "category": "domain-registrars",
      "name": "GoDaddy",
      "description": "US domain registrar and web hosting company offering domain registration, website building, hosting and business email.",
      "website": "https://www.godaddy.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 36,
      "coverage": 100,
      "summary": "GoDaddy scores 36 out of 100 (grade F) on the domain registrars criteria. It meets 3 of 12 criteria: TLS configuration, Free WHOIS privacy and two-factor login. It partly meets transparency report, tells users about requests and transfer and registry lock. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, security headers and honest renewal pricing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/domain-registrars/godaddy/",
      "markdown": "https://privacyratings.com/domain-registrars/godaddy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.godaddy.com/legal/agreements/privacy-policy",
          "note": "The privacy policy says Google Analytics and identifiers for personalized advertising are used."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.godaddy.com/legal/agreements/privacy-policy",
          "note": "Personal data is shared with marketers and advertisers for personalized advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.godaddy.com/legal/agreements/subpoena-policy",
          "note": "A subpoena policy explains how legal requests are handled. No request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.godaddy.com/legal/agreements/subpoena-policy",
          "note": "Customers are notified of valid civil subpoenas; no notice policy is published for law enforcement requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.godaddy.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.godaddy.com",
          "note": "Grade F (10/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "free_whois_privacy": {
          "title": "Free WHOIS privacy",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.godaddy.com/domains",
          "note": "Domain WHOIS privacy protection is included free with domain registrations."
        },
        "at_cost_renewals": {
          "title": "Honest renewal pricing",
          "weight": 1,
          "answer": "no",
          "evidence": "https://www.godaddy.com/domains",
          "note": "A .com costs a few dollars in the first year for new customers and renews at about eight times that price."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.godaddy.com/help/enable-an-identity-verification-method-for-your-godaddy-account-42665",
          "note": "Authenticator apps, passkeys and security keys are supported, as well as SMS."
        },
        "registry_lock": {
          "title": "Transfer and registry lock",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.godaddy.com/domains",
          "note": "Registrar transfer lock is on by default. No registry lock service is documented for regular domains."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:52.867Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "hover",
      "category": "domain-registrars",
      "name": "Hover",
      "description": "Canadian domain registrar owned by Tucows, offering domain registration with free WHOIS privacy on supported extensions and email hosting.",
      "website": "https://www.hover.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 36,
      "coverage": 100,
      "summary": "Hover scores 36 out of 100 (grade F) on the domain registrars criteria. It meets 2 of 12 criteria: TLS configuration and two-factor login. It partly meets transparency report, tells users about requests, security headers, Free WHOIS privacy, honest renewal pricing and transfer and registry lock. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in Canada: Five Eyes member. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/domain-registrars/hover/",
      "markdown": "https://privacyratings.com/domain-registrars/hover/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.hover.com/privacy",
          "note": "The home page loads Google Tag Manager, and the privacy policy lists Google Analytics and Hotjar."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.hover.com/privacy",
          "note": "The privacy policy lists Facebook Ads, Google Ads, LinkedIn Ads and Microsoft Ads among the services used, though registration data is never sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.hover.com/privacy",
          "note": "The privacy policy says law enforcement and court requests are evaluated case by case. No request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.hover.com/privacy",
          "note": "The privacy policy says users may be notified of requests depending on the circumstances."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.hover.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.hover.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "free_whois_privacy": {
          "title": "Free WHOIS privacy",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.hover.com/support/solutions/articles/201000064738-domain-whois-privacy",
          "note": "Free and on by default, but not available for every extension."
        },
        "at_cost_renewals": {
          "title": "Honest renewal pricing",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.hover.com/domain-pricing",
          "note": "Many extensions, including .com, renew at the registration price, but some such as .org and .me have first-year discounts."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.hover.com/support/solutions/articles/201000064727-hover-security-standards-and-best-practices",
          "note": "Two-step sign in uses an authenticator app, with email codes as the default."
        },
        "registry_lock": {
          "title": "Transfer and registry lock",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://support.hover.com/support/solutions/articles/201000064727-hover-security-standards-and-best-practices",
          "note": "Transfer lock is supported on every domain that allows it. No registry lock service is documented."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:52.921Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "inwx",
      "category": "domain-registrars",
      "name": "INWX",
      "description": "German domain registrar with a large selection of European extensions, flat renewal pricing, authenticator-app login and optional registry lock.",
      "website": "https://www.inwx.com/en",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "INWX scores 50 out of 100 (grade D) on the domain registrars criteria. It meets 5 of 12 criteria: no ads or data sales, TLS configuration, honest renewal pricing, two-factor login and transfer and registry lock. It partly meets no trackers or telemetry, security headers and Free WHOIS privacy. It does not meet open source, independent audit, transparency report and tells users about requests. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/domain-registrars/inwx/",
      "markdown": "https://privacyratings.com/domain-registrars/inwx/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.inwx.com/en/aboutus/dataprotection",
          "note": "The website uses self-hosted Matomo analytics. No third-party trackers are listed."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.inwx.com/en/domain/pricelist",
          "note": "Funded by paid domain and hosting services. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.inwx.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.inwx.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "free_whois_privacy": {
          "title": "Free WHOIS privacy",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.inwx.com/en/offer/whoisprivacy",
          "note": "WHOIS privacy is a paid option on supported extensions."
        },
        "at_cost_renewals": {
          "title": "Honest renewal pricing",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.inwx.com/en/domain/pricelist",
          "note": "The price list shows the same price for registration and renewal on most extensions."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kb.inwx.com/en-us/5-customer-details/70-what-is-the-mobile-tan-service-and-how-can-i-activate-it",
          "note": "Login codes from an authenticator app are supported."
        },
        "registry_lock": {
          "title": "Transfer and registry lock",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.inwx.com/en/offer/registrylock",
          "note": "Domains stay transfer-locked until an outgoing transfer is prepared, and registry lock is available for a fee."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:35.198Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ionos",
      "category": "domain-registrars",
      "name": "IONOS",
      "description": "Web hosting company and domain registrar, part of the German IONOS Group, offering domains, website builders, hosting, email and cloud servers. The ionos.com site is run by IONOS Inc. in the US.",
      "website": "https://www.ionos.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "IONOS scores 30 out of 100 (grade F) on the domain registrars criteria. It meets 1 of 12 criteria: two-factor login. It partly meets transparency report, tells users about requests, TLS configuration, security headers, Free WHOIS privacy and transfer and registry lock. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit and honest renewal pricing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/domain-registrars/ionos/",
      "markdown": "https://privacyratings.com/domain-registrars/ionos/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.ionos.com/terms-gtc/privacy-policy/",
          "note": "The privacy policy lists Google Analytics, Mouseflow and HubSpot on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.ionos.com/terms-gtc/privacy-policy/",
          "note": "Hashed customer data is shared with Meta, Google, TikTok, LinkedIn and Reddit for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ionos.com/terms-gtc/subpoena-policy/",
          "note": "A subpoena policy explains how legal requests are handled. No request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.ionos.com/terms-gtc/subpoena-policy/",
          "note": "IONOS reserves the right to notify customers before answering civil subpoenas, with no firm promise."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.ionos.com&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.ionos.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "free_whois_privacy": {
          "title": "Free WHOIS privacy",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ionos.com/help/domains/domain-rights-and-ownership/changes-to-domain-privacy-whois-privacy-through-nis2/",
          "note": "The private registration service was discontinued. Data of individual registrants is withheld from public WHOIS, but company contacts are published."
        },
        "at_cost_renewals": {
          "title": "Honest renewal pricing",
          "weight": 1,
          "answer": "no",
          "evidence": "https://www.ionos.com/domains/domain-names",
          "note": "A .com is offered at 1 dollar for the first year against a regular price of about 20 dollars."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ionos.com/help/my-account/access-passwords/logging-into-ionos-how-to-sign-in-correctly/",
          "note": "Two-factor authentication can be activated for the IONOS account."
        },
        "registry_lock": {
          "title": "Transfer and registry lock",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.ionos.com/help/domains/glossary-important-terms-and-topics-explained/domain-transfer-locks/",
          "note": "Generic domains have a transfer lock by default. No registry lock service is documented."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:52.983Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "joker-com",
      "category": "domain-registrars",
      "name": "Joker.com",
      "description": "German domain registrar run by CSL GmbH, offering hundreds of domain extensions, free DNS hosting with DNSSEC, and optional paid WHOIS privacy.",
      "website": "https://joker.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "Joker.com scores 45 out of 100 (grade D) on the domain registrars criteria. It meets 3 of 12 criteria: no ads or data sales, TLS configuration and two-factor login. It partly meets no trackers or telemetry, security headers, Free WHOIS privacy, honest renewal pricing and transfer and registry lock. It does not meet open source, independent audit, transparency report and tells users about requests. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/domain-registrars/joker-com/",
      "markdown": "https://privacyratings.com/domain-registrars/joker-com/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://joker.com",
          "note": "No third-party trackers were found, but the website loads a self-hosted Matomo tracker by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://joker.com/domain/prices",
          "note": "Funded by paid domain registrations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=joker.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=joker.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "free_whois_privacy": {
          "title": "Free WHOIS privacy",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://joker.com/faq/books/jokercom-faq-en/page/privacy-services",
          "note": "WHOIS privacy is a paid add-on, available for most gTLDs."
        },
        "at_cost_renewals": {
          "title": "Honest renewal pricing",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://joker.com/domain/prices",
          "note": "Renewals cost more than first-year registration for many extensions, with .com renewing about a third higher."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://joker.com/faq/books/jokercom-faq-en/page/what-is-two-factor-authentication",
          "note": "TOTP authenticator apps are supported."
        },
        "registry_lock": {
          "title": "Transfer and registry lock",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://joker.com/faq/books/jokercom-faq-en/page/domain-management-section",
          "note": "Domains can be locked against unauthorized transfers. No registry lock service is documented."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:53.036Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "namecheap",
      "category": "domain-registrars",
      "name": "Namecheap",
      "description": "Large US domain registrar with free WHOIS privacy on eligible extensions and TOTP or security-key login.",
      "website": "https://www.namecheap.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 39,
      "coverage": 100,
      "summary": "Namecheap scores 39 out of 100 (grade F) on the domain registrars criteria. It meets 3 of 12 criteria: no ads or data sales, TLS configuration and two-factor login. It partly meets tells users about requests, security headers, Free WHOIS privacy and transfer and registry lock. It does not meet open source, no trackers or telemetry, independent audit, transparency report and honest renewal pricing. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/domain-registrars/namecheap/",
      "markdown": "https://privacyratings.com/domain-registrars/namecheap/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.namecheap.com/legal/general/privacy-policy/",
          "note": "The privacy policy allows cookies from partners and tracking companies and sharing pseudonymous data with analytics partners."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.namecheap.com/legal/general/privacy-policy/",
          "note": "Funded by paid domain and hosting services. The policy states personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.namecheap.com/legal/general/privacy-policy/",
          "note": "The policy says Namecheap may take reasonable steps to notify users of legal process where permitted, with no firm commitment."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.namecheap.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.namecheap.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "free_whois_privacy": {
          "title": "Free WHOIS privacy",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.namecheap.com/security/domain-privacy-service/",
          "note": "Free for life on eligible extensions, but not available for about 40, including .us, .uk, .de and .eu."
        },
        "at_cost_renewals": {
          "title": "Honest renewal pricing",
          "weight": 1,
          "answer": "no",
          "evidence": "https://www.namecheap.com/domains/",
          "note": "First-year sale prices renew much higher, for example a .com at about 11 USD renews at about 18 USD."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.namecheap.com/security/totp-two-factor-authentication/",
          "note": "TOTP apps and U2F security keys are supported."
        },
        "registry_lock": {
          "title": "Transfer and registry lock",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.namecheap.com/domains/transfer/",
          "note": "Domains are locked at the registrar against transfers. No registry lock service is published."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:35.281Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "namesilo",
      "category": "domain-registrars",
      "name": "NameSilo",
      "description": "US domain registrar with flat renewal pricing and free WHOIS privacy, email forwarding and DNS on every domain.",
      "website": "https://www.namesilo.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 48,
      "coverage": 100,
      "summary": "NameSilo scores 48 out of 100 (grade D) on the domain registrars criteria. It meets 5 of 12 criteria: no ads or data sales, tells users about requests, TLS configuration, honest renewal pricing and two-factor login. It partly meets transparency report, Free WHOIS privacy and transfer and registry lock. It does not meet open source, no trackers or telemetry, independent audit and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C+.",
      "url": "https://privacyratings.com/domain-registrars/namesilo/",
      "markdown": "https://privacyratings.com/domain-registrars/namesilo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.namesilo.com/support/v2/articles/general-terms/privacy-policy",
          "note": "The privacy policy says Google Analytics is used on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.namesilo.com/pricing",
          "note": "Funded by domain sales, with add-ons included free. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.namesilo.com/support/v2/articles/general-terms/privacy-policy",
          "note": "The privacy policy explains that data is disclosed in response to legal process such as subpoenas. No request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.namesilo.com/support/v2/articles/general-terms/privacy-policy",
          "note": "The privacy policy says customers are notified of required disclosures to the extent legally permitted."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.namesilo.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.namesilo.com",
          "note": "Grade C+ (60/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "free_whois_privacy": {
          "title": "Free WHOIS privacy",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.namesilo.com/support/v2/articles/domain-manager/whois-privacy",
          "note": "Free on all domains that allow it, but not available for .us, .in, .tickets or .ca."
        },
        "at_cost_renewals": {
          "title": "Honest renewal pricing",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.namesilo.com/pricing",
          "note": "Renewal prices match registration prices for common extensions."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.namesilo.com/support/v2/articles/account-options/2-factor-authentification",
          "note": "Authenticator apps (TOTP) are supported."
        },
        "registry_lock": {
          "title": "Transfer and registry lock",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.namesilo.com/support/v2/articles/domain-manager/domain-locking-unlocking",
          "note": "All domains are locked by default. No registry lock service is documented."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:53.102Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "njalla",
      "category": "domain-registrars",
      "name": "Njalla",
      "description": "Domain service run by njalla.srl in Costa Rica. Njalla registers domains in its own name and grants customers full usage rights, and accepts cryptocurrency.",
      "website": "https://njal.la/domains/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CR",
        "name": "Costa Rica",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 57,
      "coverage": 100,
      "summary": "Njalla scores 57 out of 100 (grade D) on the domain registrars criteria. It meets 6 of 12 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, Free WHOIS privacy, honest renewal pricing and two-factor login. It partly meets security headers. It does not meet open source, independent audit, transparency report, tells users about requests and transfer and registry lock. It is based in Costa Rica: Not in the Five, Nine or Fourteen Eyes. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/domain-registrars/njalla/",
      "markdown": "https://privacyratings.com/domain-registrars/njalla/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://njal.la/tos/",
          "note": "The terms say no data is collected beyond the email or XMPP address and password, and the website loads only its own scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://njal.la/pricing/",
          "note": "Funded by paid domain registrations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=njal.la&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=njal.la",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "free_whois_privacy": {
          "title": "Free WHOIS privacy",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://njal.la/faq/",
          "note": "Njalla owns every domain on the customer's behalf, so the customer's details never appear in WHOIS, at no extra cost."
        },
        "at_cost_renewals": {
          "title": "Honest renewal pricing",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://njal.la/pricing/",
          "note": "Each extension has one flat yearly price for registration and renewal."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://njal.la/static/CACHE/js/njalla.84ac836b6fcb.js",
          "note": "The site code supports TOTP one-time passwords and WebAuthn security keys for login."
        },
        "registry_lock": {
          "title": "Transfer and registry lock",
          "weight": 1,
          "answer": "no",
          "evidence": "https://njal.la/faq/",
          "note": "Neither a transfer lock setting nor a registry lock service is documented."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:53.157Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "orange-website",
      "category": "domain-registrars",
      "name": "Orange Website",
      "description": "Icelandic hosting company that also registers domains, asks only for an email address at sign-up and accepts Bitcoin.",
      "website": "https://orangewebsite.com/domains/domain-price-list",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "IS",
        "name": "Iceland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Orange Website scores 50 out of 100 (grade D) on the domain registrars criteria. It meets 6 of 12 criteria: no ads or data sales, tells users about requests, TLS configuration, Free WHOIS privacy, honest renewal pricing and two-factor login. It partly meets transparency report. It does not meet open source, no trackers or telemetry, independent audit, security headers and transfer and registry lock. It is based in Iceland: Not in the Five, Nine or Fourteen Eyes; EEA member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/domain-registrars/orange-website/",
      "markdown": "https://privacyratings.com/domain-registrars/orange-website/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://orangewebsite.com/domains/domain-price-list",
          "note": "Funded by paid hosting and domain services. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://orangewebsite.com/docs/privacy-policy.php",
          "note": "The privacy policy states data is released only on a valid Icelandic court order. No request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://orangewebsite.com/pages/faq",
          "note": "The FAQ states clients are informed every time a third party contacts the company about them."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.orangewebsite.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.orangewebsite.com",
          "note": "Grade F (0/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "free_whois_privacy": {
          "title": "Free WHOIS privacy",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://orangewebsite.com/domains/domain-price-list",
          "note": "Private WHOIS is listed among the features included with every domain."
        },
        "at_cost_renewals": {
          "title": "Honest renewal pricing",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://orangewebsite.com/domains/domain-price-list",
          "note": "One flat yearly price per extension, with no separate first-year discount."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://orangewebsite.com/company/secure-hosting",
          "note": "Two-factor authentication is available for the client area."
        },
        "registry_lock": {
          "title": "Transfer and registry lock",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No transfer lock or registry lock option is documented."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:35.327Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "porkbun",
      "category": "domain-registrars",
      "name": "Porkbun",
      "description": "US domain registrar with free WHOIS privacy on most extensions, authenticator-app and security-key login, and an API.",
      "website": "https://porkbun.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 27,
      "coverage": 100,
      "summary": "Porkbun scores 27 out of 100 (grade F) on the domain registrars criteria. It meets 1 of 12 criteria: two-factor login. It partly meets no ads or data sales, TLS configuration, Free WHOIS privacy, honest renewal pricing and transfer and registry lock. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/domain-registrars/porkbun/",
      "markdown": "https://privacyratings.com/domain-registrars/porkbun/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics, Google Tag Manager, LinkedIn Insight, Meta Pixel and Reddit Pixel (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://porkbun.com/legal/agreement/privacy_policy",
          "note": "The privacy policy states personal data is shared with advertising partners for personalized ads, which may count as a sale."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=porkbun.com&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=porkbun.com",
          "note": "Grade F (0/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "free_whois_privacy": {
          "title": "Free WHOIS privacy",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://porkbun.com/products/whois_privacy",
          "note": "Free, but some registries (for example .us, .eu, .de, .uk) do not allow it."
        },
        "at_cost_renewals": {
          "title": "Honest renewal pricing",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://porkbun.com/products/domains",
          "note": "Many extensions, including .com, renew at the registration price, but first-year sale prices renew higher."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kb.porkbun.com/article/19-how-to-enable-two-factor-authentication",
          "note": "Authenticator apps and WebAuthn security keys are supported."
        },
        "registry_lock": {
          "title": "Transfer and registry lock",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://kb.porkbun.com/article/173-how-to-use-domain-management",
          "note": "Domains are transfer-locked and must be unlocked before transfer. No registry lock service is documented."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "snap.licdn.com",
            "effect": "no"
          },
          {
            "name": "Meta Pixel",
            "host": "www.facebook.com",
            "effect": "no"
          },
          {
            "name": "Reddit Pixel",
            "host": "www.redditstatic.com",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "widget.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:35.418Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "spaceship",
      "category": "domain-registrars",
      "name": "Spaceship",
      "description": "US domain registrar from the team behind Namecheap, offering domain registration with free WHOIS privacy, hosting, email and a domain marketplace.",
      "website": "https://www.spaceship.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 41,
      "coverage": 100,
      "summary": "Spaceship scores 41 out of 100 (grade D) on the domain registrars criteria. It meets 2 of 12 criteria: TLS configuration and two-factor login. It partly meets no ads or data sales, transparency report, tells users about requests, security headers, Free WHOIS privacy, honest renewal pricing and transfer and registry lock. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/domain-registrars/spaceship/",
      "markdown": "https://privacyratings.com/domain-registrars/spaceship/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.spaceship.com/legal/privacy-policy/",
          "note": "The privacy policy says Google Analytics and remarketing pixels are used."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.spaceship.com/legal/privacy-policy/",
          "note": "Pseudonymous data is shared with advertising partners for remarketing, though personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.spaceship.com/legal/spaceship-court-order-subpoena-policy/",
          "note": "A court order and subpoena policy explains how legal requests are handled. No request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.spaceship.com/legal/spaceship-court-order-subpoena-policy/",
          "note": "The policy says customers may be notified of criminal subpoenas, decided case by case."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.spaceship.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.spaceship.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "free_whois_privacy": {
          "title": "Free WHOIS privacy",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.spaceship.com/domains/domain-name-privacy/",
          "note": "Free for life on nearly all domains, but not every extension supports it."
        },
        "at_cost_renewals": {
          "title": "Honest renewal pricing",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.spaceship.com/domains/",
          "note": "A .com renews slightly higher than its first-year price."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.spaceship.com/security/",
          "note": "Two-step verification is required at every account login."
        },
        "registry_lock": {
          "title": "Transfer and registry lock",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.spaceship.com/legal/domain-registration-agreement/",
          "note": "Domains can be protected with a registrar lock. No registry lock service is documented."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:53.221Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "squarespace-domains",
      "category": "domain-registrars",
      "name": "Squarespace Domains",
      "description": "Domain registrar run by the website builder Squarespace, which took over Google Domains customers. Registrations include WHOIS privacy on eligible domains, DNSSEC and SSL.",
      "website": "https://domains.squarespace.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 27,
      "coverage": 100,
      "summary": "Squarespace Domains scores 27 out of 100 (grade F) on the domain registrars criteria. It meets 2 of 12 criteria: TLS configuration and two-factor login. It partly meets Free WHOIS privacy, honest renewal pricing and transfer and registry lock. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/domain-registrars/squarespace-domains/",
      "markdown": "https://privacyratings.com/domain-registrars/squarespace-domains/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.squarespace.com/privacy",
          "note": "The privacy policy says interactions with third-party services are analyzed to tailor advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=domains.squarespace.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=domains.squarespace.com",
          "note": "Grade F (0/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "free_whois_privacy": {
          "title": "Free WHOIS privacy",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.squarespace.com/hc/en-us/articles/205812438-Whois-privacy",
          "note": "Free on eligible domains, but most ccTLDs do not allow it."
        },
        "at_cost_renewals": {
          "title": "Honest renewal pricing",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://support.squarespace.com/hc/en-us/articles/206541787-Free-Squarespace-domain-offer",
          "note": "Domains renew at the standard annual TLD price, so first-year offers and discounts renew higher."
        },
        "two_factor": {
          "title": "Two-factor login",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.squarespace.com/hc/en-us/articles/360000044827-Protect-your-account-with-two-factor-authentication",
          "note": "Authenticator apps, passkeys and hardware security keys are supported, as well as SMS in some countries."
        },
        "registry_lock": {
          "title": "Transfer and registry lock",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://support.squarespace.com/hc/en-us/articles/360034059332-Domain-locks",
          "note": "A transfer lock is enabled by default. No registry lock service is documented."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "TrustArc",
            "host": "consent.trustarc.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:53.321Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "1984",
      "category": "server-hosting",
      "name": "1984",
      "description": "Icelandic provider of web hosting, VPS, email and free DNS, running on its own network (AS44925) and hardware. Accepts Bitcoin and Monero.",
      "website": "https://1984.hosting",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "IS",
        "name": "Iceland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 43,
      "coverage": 100,
      "summary": "1984 scores 43 out of 100 (grade D) on the server hosting criteria. It meets 3 of 12 criteria: no ads or data sales, TLS configuration and anonymous payment. It partly meets no trackers or telemetry, independent audit and transparency report. It does not meet open source, tells users about requests, security headers, mail-friendly (port 25), Reverse DNS and IPv6. It is based in Iceland: Not in the Five, Nine or Fourteen Eyes; EEA member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/server-hosting/1984/",
      "markdown": "https://privacyratings.com/server-hosting/1984/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://1984.hosting/GDPR/",
          "note": "No third-party trackers; the website runs self-hosted Matomo analytics by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://1984.hosting/tos/",
          "note": "Funded by paid hosting, and the terms say customer information is not provided to third parties for marketing."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://1984.hosting/static/files/1984-hosting-iso-27001-certificate-is-834168-2026-en.pdf",
          "note": "Only the ISO 27001 certificate from BSI is public, not the audit report."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://1984.hosting/tos/",
          "note": "The terms say access information is released only under a valid court order, and court documents from contested cases are published, but no request counts."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=1984.hosting&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=1984.hosting",
          "note": "Grade C (55/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "no",
          "evidence": "https://1984.hosting/product/vps/",
          "note": "Not documented. The VPS page and FAQ do not say whether outbound port 25 is open."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "no",
          "evidence": "https://1984.hosting/product/vps/",
          "note": "Not documented. The VPS page and FAQ do not mention reverse DNS."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "no",
          "evidence": "https://1984.hosting/product/vps/",
          "note": "Not documented. The VPS page and FAQ do not mention IPv6."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://1984.hosting/faq/#faq-payment-methods",
          "note": "Bitcoin and Monero are accepted."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:35.461Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "amazon-web-services",
      "category": "server-hosting",
      "name": "Amazon Web Services",
      "description": "Cloud computing platform from Amazon offering virtual servers (EC2), storage, databases and hundreds of other services in regions worldwide.",
      "website": "https://aws.amazon.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "Amazon Web Services scores 45 out of 100 (grade D) on the server hosting criteria. It meets 5 of 12 criteria: transparency report, tells users about requests, TLS configuration, security headers and IPv6. It partly meets independent audit, mail-friendly (port 25) and Reverse DNS. It does not meet open source, no trackers or telemetry, no ads or data sales and anonymous payment. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/server-hosting/amazon-web-services/",
      "markdown": "https://privacyratings.com/server-hosting/amazon-web-services/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://aws.amazon.com/legal/cookies/",
          "note": "AWS websites set cookies from third parties including The Trade Desk, Oracle BlueKai and LinkedIn."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://aws.amazon.com/privacy/",
          "note": "The privacy notice says cookies and identifiers are used to advertise to visitors on third-party websites."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://d1.awsstatic.com/onedam/marketing-channels/website/aws/en_US/whitepapers/compliance/AWS_SOC3_Report.pdf",
          "note": "Only the SOC 3 summary report is public; SOC 1 and SOC 2 reports are available to customers in AWS Artifact."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://d1.awsstatic.com/onedam/marketing-channels/website/aws/en_US/security/pdfs/Amazon_Government_Request_Report_H1_2026.pdf",
          "note": "Semi-annual reports with counts of government requests to Amazon and AWS and how they were answered."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.amazon.com/gp/help/customer/display.html?nodeId=GYSDRGWQ2C2CRYEF",
          "note": "Amazon notifies customers before disclosing content unless prohibited or there is clear indication of illegal conduct."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=console.aws.amazon.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=console.aws.amazon.com",
          "note": "Grade A+ (105/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-resource-limits.html",
          "note": "Outbound port 25 to public addresses is blocked by default, and customers can request removal of the restriction."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/elastic-ip-addresses-eip.html",
          "note": "Reverse DNS can be set for Elastic IP addresses, which are IPv4 only."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://aws.amazon.com/vpc/pricing/",
          "note": "IPv6 addresses can be assigned to instances, and only public IPv4 addresses carry an hourly charge."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "no",
          "evidence": "https://repost.aws/knowledge-center/accepted-payment-methods",
          "note": "Payment is by card or direct debit. Cryptocurrency is not accepted."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:53.375Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "bunker",
      "category": "server-hosting",
      "name": "Bunker",
      "description": "French cloud from France Nuage SAS offering virtual machines, managed open-source apps, PostgreSQL and S3-compatible storage in its own datacenters in France.",
      "website": "https://getbunker.net",
      "source": "https://github.com/France-Nuage/plateforme",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Bunker scores 40 out of 100 (grade D) on the server hosting criteria. It meets 2 of 12 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry, TLS configuration and security headers. It does not meet independent audit, transparency report, tells users about requests, mail-friendly (port 25), Reverse DNS, IPv6 and anonymous payment. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/server-hosting/bunker/",
      "markdown": "https://privacyratings.com/server-hosting/bunker/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/France-Nuage/plateforme/blob/master/LICENCE",
          "note": "All platform code is public, including the control plane, agents and console, under the source-available Server Side Public License (SSPL-1.0), which is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://getbunker.net/legal/privacy-policy",
          "note": "No third-party trackers; first-party Matomo analytics run by default in CNIL exemption mode."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://getbunker.net/legal/privacy-policy",
          "note": "Funded by paid subscriptions, with no advertising or data sales described in the privacy policy."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": "https://getbunker.net/legal/security-compliance",
          "note": "Security measures are self-assessed and not certified or audited by a third party."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or dedicated government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=getbunker.net&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=getbunker.net",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "no",
          "evidence": "https://getbunker.net/documentation/ressources/faq",
          "note": "Not documented. The documentation does not say whether outbound port 25 is open."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "no",
          "evidence": "https://getbunker.net/documentation/ressources/faq",
          "note": "Not documented. The documentation does not mention reverse DNS."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "no",
          "evidence": "https://getbunker.net/documentation/ressources/faq",
          "note": "Not documented. The documentation does not mention IPv6."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "no",
          "evidence": "https://getbunker.net/documentation/ressources/faq",
          "note": "Payment is by credit card, bank transfer or SEPA direct debit."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:35.512Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "buyvm",
      "category": "server-hosting",
      "name": "BuyVM",
      "description": "VPS provider owned by Cloudzy, offering KVM slices, storage VPS, block storage and anycast IP addresses in Las Vegas, New York and Luxembourg.",
      "website": "https://buyvm.net",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "AE",
        "name": "United Arab Emirates",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "BuyVM scores 38 out of 100 (grade F) on the server hosting criteria. It meets 4 of 12 criteria: no ads or data sales, Reverse DNS, IPv6 and anonymous payment. It partly meets transparency report, TLS configuration and mail-friendly (port 25). It does not meet open source, no trackers or telemetry, independent audit, tells users about requests and security headers. It is based in the United Arab Emirates: Not in the Five, Nine or Fourteen Eyes. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/server-hosting/buyvm/",
      "markdown": "https://privacyratings.com/server-hosting/buyvm/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics, Google Tag Manager and Tawk.to."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://buyvm.net/privacy-policy/",
          "note": "Funded by paid hosting, and the privacy policy says client information is never shared with third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://buyvm.net/privacy-policy/",
          "note": "The privacy policy says client information is released to law enforcement only under a court order. No request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=my.frantech.ca&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=my.frantech.ca",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://wiki.buyvm.net/doku.php/faq",
          "note": "SMTP ports are the only blocked ports and can be unblocked through a support ticket."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://buyvm.net/features/",
          "note": "Reverse DNS is set in the control panel."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://buyvm.net/features/",
          "note": "IPv6 addresses are assigned from the control panel as part of the service."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://buyvm.net/terms-of-service/",
          "note": "Cryptocurrency payments are accepted through the CoinPayments gateway."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Tawk.to",
            "host": "embed.tawk.to",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "www.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:53.428Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "contabo",
      "category": "server-hosting",
      "name": "Contabo",
      "description": "German provider of VPS, cloud and dedicated servers. Outgoing mail on port 25 is limited to about 25 messages per minute.",
      "website": "https://contabo.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Contabo scores 35 out of 100 (grade F) on the server hosting criteria. It meets 5 of 12 criteria: no ads or data sales, TLS configuration, mail-friendly (port 25), Reverse DNS and IPv6. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests, security headers and anonymous payment. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/server-hosting/contabo/",
      "markdown": "https://privacyratings.com/server-hosting/contabo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://contabo.com/en/legal/privacy/",
          "note": "The privacy policy lists Microsoft Clarity, Google Tag Manager, Varify and affiliate tracking from AWIN."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://contabo.com/en/legal/privacy/",
          "note": "Funded by paid hosting; the privacy policy does not describe advertising or selling data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=contabo.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=contabo.com",
          "note": "Grade C (55/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://help.contabo.com/en/support/solutions/articles/103000280507-is-there-a-limit-to-how-many-emails-can-be-sent-from-my-server-",
          "note": "Mail can be sent directly, limited to about 25 messages per minute."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://help.contabo.com/en/support/solutions/articles/103000336144-dns-and-rdns-managment-with-contabo",
          "note": "PTR records for IPv4 and IPv6 are set in the customer panel."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://help.contabo.com/en/support/solutions/articles/103000270487-how-can-i-use-ipv6-on-my-server-",
          "note": "Servers come with an IPv6 range alongside the IPv4 address."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "no",
          "evidence": "https://help.contabo.com/en/support/solutions/articles/103000226600-how-do-i-update-my-payment-methods-",
          "note": "Cryptocurrency payments are not accepted."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:35.635Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dartnode",
      "category": "server-hosting",
      "name": "DartNode",
      "description": "US provider of VPS and dedicated servers, run by Snaju Inc in Houston on its own network (AS399646) and hardware.",
      "website": "https://dartnode.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "DartNode scores 30 out of 100 (grade F) on the server hosting criteria. It meets 3 of 12 criteria: no ads or data sales, IPv6 and anonymous payment. It partly meets TLS configuration, mail-friendly (port 25) and Reverse DNS. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/server-hosting/dartnode/",
      "markdown": "https://privacyratings.com/server-hosting/dartnode/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://dartnode.com/legal/privacy",
          "note": "The privacy policy lists third-party analytics providers for the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://dartnode.com/legal/privacy",
          "note": "Funded by paid hosting, and the privacy policy says personal information is not sold, rented or leased."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or dedicated government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=dartnode.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=dartnode.com",
          "note": "Grade C (55/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://help.dartnode.com/faq/can-i-send-smtp-traffic-using-my-vps",
          "note": "The help center says SMTP may not be available and is blocked for blacklisted IPs, with support handling SMTP requests."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://help.dartnode.com/networking/configure-reverse-dns",
          "note": "PTR records are set in the client panel; IPv6 support is not documented."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://dartnode.com/vps",
          "note": "All VPS plans include IPv4 and IPv6."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://dartnode.com/legal/tos",
          "note": "Cryptocurrency is accepted, though identity verification can be required at any time."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:35.685Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "datapacket",
      "category": "server-hosting",
      "name": "DataPacket",
      "description": "Dedicated servers, IP transit and bandwidth on its own global network, from DataCamp Limited in London.",
      "website": "https://www.datapacket.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": true,
      "pick_reason": "Dedicated hardware on its own network, open port 25, configurable reverse DNS and native IPv6. Suited to running mail servers without sharing hardware with other customers.",
      "disclosure": null,
      "grade": "D",
      "score": 43,
      "coverage": 100,
      "summary": "DataPacket scores 43 out of 100 (grade D) on the server hosting criteria. It meets 5 of 12 criteria: tells users about requests, TLS configuration, mail-friendly (port 25), Reverse DNS and IPv6. It partly meets no ads or data sales, transparency report and security headers. It does not meet open source, no trackers or telemetry, independent audit and anonymous payment. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/server-hosting/datapacket/",
      "markdown": "https://privacyratings.com/server-hosting/datapacket/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.datapacket.com/privacy-policy",
          "note": "The privacy policy says partners collect usage statistics and cookies are used for ads and traffic analysis."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.datapacket.com/privacy-policy",
          "note": "Funded by paid hosting, but the privacy policy says cookies are used to personalise ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.datapacket.com/dsa-policy",
          "note": "The DSA policy explains how authority orders are handled, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.datapacket.com/terms-and-conditions",
          "note": "The terms say customers are notified of disclosures to authorities where legally permitted."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.datapacket.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.datapacket.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/forwardemail/awesome-mail-server-providers#vps-and-dedicated-mail-server-provider-comparison-table",
          "note": "Open by default."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://api.datapacket.com/",
          "note": "PTR records for IPv4 and IPv6 addresses can be set through the API (setReverseDnsRecord). IPv6 PTR records on DataPacket addresses resolve publicly, for example 2a02:6ea0:d71e::2 to mx1.forwardemail.net."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.datapacket.com/faq",
          "note": "IPv6 addresses are assigned free of charge on request."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "no",
          "evidence": "https://www.datapacket.com/faq",
          "note": "Payment is by credit card or wire transfer."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:03:55.779Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "digitalocean",
      "category": "server-hosting",
      "name": "DigitalOcean",
      "description": "US cloud provider offering virtual machines (Droplets), Kubernetes, managed databases and object storage.",
      "website": "https://www.digitalocean.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 48,
      "coverage": 100,
      "summary": "DigitalOcean scores 48 out of 100 (grade D) on the server hosting criteria. It meets 5 of 12 criteria: transparency report, tells users about requests, TLS configuration, Reverse DNS and IPv6. It partly meets no ads or data sales, independent audit and anonymous payment. It does not meet open source, no trackers or telemetry, security headers and mail-friendly (port 25). It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/server-hosting/digitalocean/",
      "markdown": "https://privacyratings.com/server-hosting/digitalocean/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Amplitude (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.digitalocean.com/legal/privacy-policy",
          "note": "The privacy policy lets third-party advertising partners collect data on its services to show targeted ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.digitalocean.com/trust/certification-reports",
          "note": "SOC 2 Type II and SOC 3 reports from an independent auditor are only available to customers after sign-in."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.digitalocean.com/legal/transparency-report",
          "note": "Publishes request counts and outcomes twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.digitalocean.com/legal/law-enforcement-guidelines",
          "note": "Notifies users of legal process for their account unless prohibited by law or court order."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.digitalocean.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.digitalocean.com",
          "note": "Grade C (55/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "no",
          "evidence": "https://docs.digitalocean.com/support/why-is-smtp-blocked/",
          "note": "SMTP ports are blocked on all Droplets, with no documented way to open them."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.digitalocean.com/products/networking/dns/how-to/manage-records/",
          "note": "PTR records for IPv4 and the first IPv6 address are set from the Droplet name."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.digitalocean.com/products/networking/ipv6/",
          "note": "Each Droplet can enable 16 IPv6 addresses at no extra cost."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://docs.digitalocean.com/platform/billing/manage-payment-methods/",
          "note": "Stablecoin payment is offered to some customers, and every account needs a verified payment method."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Amplitude",
            "host": "cdn.amplitude.com",
            "effect": "no"
          },
          {
            "name": "TrustArc",
            "host": "consent.trustarc.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:35.803Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "exoscale",
      "category": "server-hosting",
      "name": "Exoscale",
      "description": "Swiss cloud provider, part of the A1 Group, offering compute instances, GPUs, managed Kubernetes, object storage and databases in European zones.",
      "website": "https://www.exoscale.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Exoscale scores 65 out of 100 (grade C) on the server hosting criteria. It meets 6 of 12 criteria: no trackers or telemetry, no ads or data sales, tells users about requests, TLS configuration, mail-friendly (port 25) and IPv6. It partly meets independent audit, transparency report, security headers and Reverse DNS. It does not meet open source and anonymous payment. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/server-hosting/exoscale/",
      "markdown": "https://privacyratings.com/server-hosting/exoscale/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.exoscale.com/privacy/",
          "note": "No third-party trackers. Website analytics run in a cookieless mode and measure visits anonymously."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.exoscale.com/privacy/",
          "note": "Funded by paid cloud services, and the privacy policy says personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.exoscale.com/compliance/bsi-c5/",
          "note": "Exoscale holds a BSI C5 Type 2 attestation and ISO 27001 certification, but the reports are not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.exoscale.com/abuse/",
          "note": "The abuse page says foreign authorities must use judicial assistance with Switzerland. No request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.exoscale.com/terms/",
          "note": "The terms promise prior notice of compelled disclosure to government authorities, to the extent legally permitted."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=portal.exoscale.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=portal.exoscale.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://community.exoscale.com/product/networking/security-group/overview/",
          "note": "Security groups allow all outgoing traffic by default, and no SMTP restriction is documented."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://community.exoscale.com/reference/api/compute/reverse-dns/",
          "note": "PTR records for instance public IPs and Elastic IPs are set through the API; IPv6 reverse DNS is not documented."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.exoscale.com/pricing/",
          "note": "Every instance includes a free public IPv4 and IPv6 address."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "no",
          "evidence": "https://community.exoscale.com/platform/billing/",
          "note": "Payment is by credit card or PayPal. Cryptocurrency is not accepted."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:53.508Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "google-cloud",
      "category": "server-hosting",
      "name": "Google Cloud",
      "description": "Cloud computing platform from Google offering virtual machines (Compute Engine), Kubernetes, storage, databases and data analytics services.",
      "website": "https://cloud.google.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Google Cloud scores 50 out of 100 (grade D) on the server hosting criteria. It meets 6 of 12 criteria: no ads or data sales, transparency report, tells users about requests, security headers, Reverse DNS and IPv6. It partly meets independent audit and TLS configuration. It does not meet open source, no trackers or telemetry, mail-friendly (port 25) and anonymous payment. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/server-hosting/google-cloud/",
      "markdown": "https://privacyratings.com/server-hosting/google-cloud/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cloud.google.com/terms/cloud-privacy-notice",
          "note": "Funded by paid usage. The Cloud Privacy Notice says Service Data is not sold or shared with third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cloud.google.com/security/compliance/soc-3",
          "note": "Only the SOC 3 summary report is public; SOC 2 and ISO audit reports are available to customers."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://transparencyreport.google.com/user-data/overview",
          "note": "Google publishes semi-annual counts of government requests for user data, with a separate section for Enterprise Cloud customers."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://policies.google.com/terms/information-requests",
          "note": "Google emails the account, or its administrator, before disclosing data unless prohibited by law or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=console.cloud.google.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=console.cloud.google.com",
          "note": "Grade A+ (110/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "no",
          "evidence": "https://docs.cloud.google.com/compute/docs/tutorials/sending-mail",
          "note": "Connections to external destinations on port 25 are blocked, and no process to request an exception is documented."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.cloud.google.com/compute/docs/instances/create-ptr-record",
          "note": "PTR records for external IPv4 and IPv6 addresses are set on the VM's network interface."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://cloud.google.com/vpc/network-pricing",
          "note": "External IPv6 addresses assigned to VM instances are not charged."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "no",
          "evidence": "https://docs.cloud.google.com/billing/docs/how-to/payment-methods",
          "note": "Payment is by credit card or bank account. Cryptocurrency is not accepted."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:53.676Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "hetzner",
      "category": "server-hosting",
      "name": "Hetzner",
      "description": "German provider of cloud servers, dedicated servers and storage, with its own datacenters in Germany and Finland and cloud locations in the US and Singapore.",
      "website": "https://www.hetzner.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 48,
      "coverage": 100,
      "summary": "Hetzner scores 48 out of 100 (grade D) on the server hosting criteria. It meets 4 of 12 criteria: no ads or data sales, TLS configuration, Reverse DNS and IPv6. It partly meets no trackers or telemetry, independent audit, security headers and mail-friendly (port 25). It does not meet open source, transparency report, tells users about requests and anonymous payment. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/server-hosting/hetzner/",
      "markdown": "https://privacyratings.com/server-hosting/hetzner/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.hetzner.com/legal/privacy-policy/",
          "note": "No third-party trackers, but website analytics use Matomo with cookies after consent."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.hetzner.com/legal/privacy-policy/",
          "note": "Funded by paid hosting, and the privacy policy says data is not passed to third parties unless specified."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://files.hetzner.com/docs/BSI-C52020Typ2_Testat_2026_EN.pdf",
          "note": "Only a one-page summary of the BSI C5 Type 2 audit and an ISO 27001 certificate are public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.hetzner.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.hetzner.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://docs.hetzner.com/cloud/servers/faq/",
          "note": "Ports 25 and 465 are blocked on cloud servers by default and can be unblocked on request after the first paid invoice."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.hetzner.com/cloud/servers/cloud-server-rdns/",
          "note": "rDNS entries for IPv4 and IPv6 are set in the Hetzner Console."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.hetzner.com/cloud/servers/primary-ips/overview/",
          "note": "Primary IPv6 addresses are free."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "no",
          "evidence": "https://docs.hetzner.com/general/billing-and-account-management/billing-at-hetzner/payment-overview/",
          "note": "Cryptocurrency is not accepted."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:35.849Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hostinger",
      "category": "server-hosting",
      "name": "Hostinger",
      "description": "Lithuanian provider of web hosting, VPS and website building services. Port 25 is open on VPS plans, limited to 5 messages per minute.",
      "website": "https://www.hostinger.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "LT",
        "name": "Lithuania",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Hostinger scores 30 out of 100 (grade F) on the server hosting criteria. It meets 5 of 12 criteria: TLS configuration, mail-friendly (port 25), Reverse DNS, IPv6 and anonymous payment. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests and security headers. It is based in Lithuania: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/server-hosting/hostinger/",
      "markdown": "https://privacyratings.com/server-hosting/hostinger/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Amplitude and Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.hostinger.com/legal/privacy-policy",
          "note": "The privacy policy describes targeted advertising with Facebook, Google and other ad tools."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or dedicated government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.hostinger.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.hostinger.com",
          "note": "Grade F (0/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.hostinger.com/support/7854530-is-smtp-port-25-blocked-on-hostinger-vps/",
          "note": "Port 25 is not blocked, with a limit of 5 messages per minute."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.hostinger.com/support/4805528-how-to-setup-reverse-dns-on-vps/",
          "note": "PTR records for the IPv4 and IPv6 addresses are set in the VPS settings."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.hostinger.com/support/4805528-how-to-setup-reverse-dns-on-vps/",
          "note": "Each VPS has an IPv6 address alongside its IPv4 address."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.hostinger.com/payments",
          "note": "A range of cryptocurrencies is accepted."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Amplitude",
            "host": "cdn.amplitude.com",
            "effect": "no"
          },
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:35.910Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "infomaniak",
      "category": "server-hosting",
      "name": "Infomaniak",
      "description": "Swiss provider of web hosting, VPS and OpenStack public cloud, running its own datacenters and network (AS29222).",
      "website": "https://www.infomaniak.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "Infomaniak scores 45 out of 100 (grade D) on the server hosting criteria. It meets 4 of 12 criteria: no ads or data sales, TLS configuration, Reverse DNS and IPv6. It partly meets no trackers or telemetry, independent audit and mail-friendly (port 25). It does not meet open source, transparency report, tells users about requests, security headers and anonymous payment. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade D+.",
      "url": "https://privacyratings.com/server-hosting/infomaniak/",
      "markdown": "https://privacyratings.com/server-hosting/infomaniak/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.infomaniak.com/en/legal/confidentiality-policy",
          "note": "Website analytics use self-hosted Matomo, and it and ad measurement tools load only with consent."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.infomaniak.com/en/legal/confidentiality-policy",
          "note": "Funded by paid services, and customer data is not used for commercial purposes."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.infomaniak.com/documents/iso/27001_1EN.pdf",
          "note": "Only the ISO 27001 certificate is public, not the audit report."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or dedicated government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.infomaniak.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.infomaniak.com",
          "note": "Grade D+ (40/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.infomaniak.com/en/support/faq/2822/manage-the-cloud-vps-vps-lite-firewall",
          "note": "Outgoing port 25 is blocked by default and opened on justified request for Cloud VPS."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.infomaniak.com/en/support/faq/2012/create-a-ptr-record-for-cloud-vps-vps-lite",
          "note": "PTR records for the IPv4 and IPv6 addresses are set in the Infomaniak Manager."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.infomaniak.com/en/hosting/vps-cloud",
          "note": "Each Cloud VPS includes a dedicated IPv6 address."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "no",
          "evidence": "https://www.infomaniak.com/en/support/faq/1385/pay-for-renew-a-product-manually",
          "note": "Payment is by card, PayPal, Twint or bank transfer, with no cryptocurrency option."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "D+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:16:54.076Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "linode",
      "category": "server-hosting",
      "name": "Akamai Cloud (Linode)",
      "description": "Cloud computing platform from Akamai, formerly Linode, offering virtual machines, Kubernetes, object storage and managed databases.",
      "website": "https://www.linode.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Akamai Cloud (Linode) scores 40 out of 100 (grade D) on the server hosting criteria. It meets 4 of 12 criteria: transparency report, TLS configuration, Reverse DNS and IPv6. It partly meets no ads or data sales, security headers and mail-friendly (port 25). It does not meet open source, no trackers or telemetry, independent audit, tells users about requests and anonymous payment. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/server-hosting/linode/",
      "markdown": "https://privacyratings.com/server-hosting/linode/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.akamai.com/legal/manage-cookie-preferences",
          "note": "Akamai websites use analytics and targeting cookies from LinkedIn, Google DoubleClick, Amazon and others."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.akamai.com/legal/manage-cookie-preferences",
          "note": "Targeting cookies let advertising partners build interest profiles of visitors."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.akamai.com/legal/eu-digital-services-act",
          "note": "Publishes DSA transparency reports with counts of orders from EU authorities; requests from other countries are not reported."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.linode.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.linode.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://techdocs.akamai.com/cloud-computing/docs/send-email",
          "note": "SMTP ports are restricted on some new accounts and opened on request to support."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://techdocs.akamai.com/cloud-computing/docs/configure-rdns-reverse-dns-on-a-compute-instance",
          "note": "rDNS for IPv4 and IPv6 addresses is set in Cloud Manager."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://techdocs.akamai.com/cloud-computing/docs/an-overview-of-ipv6-on-linode",
          "note": "Every Linode is created with an IPv6 address."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "no",
          "evidence": "https://techdocs.akamai.com/cloud-computing/docs/manage-payment-methods",
          "note": "Payment is by card, Google Pay or PayPal only."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:35.958Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "microsoft-azure",
      "category": "server-hosting",
      "name": "Microsoft Azure",
      "description": "Cloud computing platform from Microsoft offering virtual machines, Kubernetes, storage, databases and AI services in regions worldwide.",
      "website": "https://azure.microsoft.com/en-us",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Microsoft Azure scores 40 out of 100 (grade D) on the server hosting criteria. It meets 4 of 12 criteria: transparency report, tells users about requests, TLS configuration and IPv6. It partly meets independent audit, security headers and Reverse DNS. It does not meet open source, no trackers or telemetry, no ads or data sales, mail-friendly (port 25) and anonymous payment. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/server-hosting/microsoft-azure/",
      "markdown": "https://privacyratings.com/server-hosting/microsoft-azure/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "Microsoft sites use third-party cookies, including social media and advertising cookies and analytics providers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "The privacy statement describes advertising cookies from partners such as LinkedIn and Xandr used to tailor ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-3",
          "note": "Only the SOC 3 summary report is public; full SOC 2 and ISO audit reports are in the Service Trust Portal for customers."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Semi-annual reports with counts of law enforcement requests for consumer and enterprise customer data."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Microsoft gives enterprise customers prior notice of third-party requests for their data, except where prohibited by law."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=portal.azure.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=portal.azure.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-network/troubleshoot-outbound-smtp-connectivity",
          "note": "Outbound port 25 is blocked on pay-as-you-go and most other subscription types; it is open only on Enterprise Agreement and MCA-E subscriptions."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://learn.microsoft.com/en-us/azure/dns/dns-reverse-dns-for-azure-services",
          "note": "Reverse DNS is set through PowerShell or the CLI and only for public IPv4 addresses."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://learn.microsoft.com/en-us/azure/virtual-network/ip-services/ipv6-overview",
          "note": "There is no charge for public IPv6 addresses or prefixes."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/azure/cost-management-billing/manage/change-credit-card",
          "note": "Payment is by card or invoice. Cryptocurrency is not accepted."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:53.731Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "netcup",
      "category": "server-hosting",
      "name": "netcup",
      "description": "German hosting provider offering virtual and root servers, web hosting, managed servers and domains, with datacenters in Germany, Austria, the Netherlands, the US and Singapore.",
      "website": "https://www.netcup.com/en",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "netcup scores 30 out of 100 (grade F) on the server hosting criteria. It meets 2 of 12 criteria: Reverse DNS and IPv6. It partly meets no ads or data sales, independent audit, TLS configuration, security headers and mail-friendly (port 25). It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and anonymous payment. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/server-hosting/netcup/",
      "markdown": "https://privacyratings.com/server-hosting/netcup/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.netcup.com/en/contact/data-privacy",
          "note": "The privacy policy describes retargeting tags, pixels and cookies from advertising platforms and social networks."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.netcup.com/en/contact/data-privacy",
          "note": "Website usage data is shared with advertising networks for retargeting."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.netcup.com/en",
          "note": "netcup states annual ISO 27001 and ISO 27701 certification, but no audit report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.customercontrolpanel.de&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.customercontrolpanel.de",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.netcup.com/en/helpcenter/documentation/server/firewall",
          "note": "A default firewall policy blocks SMTP, and customers can delete it themselves in the Server Control Panel."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.netcup.com/en/helpcenter/documentation/server/network-server",
          "note": "Reverse DNS for IPv4 and IPv6 addresses is set in the Server Control Panel."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.netcup.com/en/helpcenter/documentation/server/network-configuration",
          "note": "VPS plans include a static IPv4 address and a /64 IPv6 subnet by default."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "no",
          "evidence": "https://www.netcup.com/en/helpcenter/documentation/general/payment-methods",
          "note": "Payment is by bank transfer, PayPal, card or SEPA direct debit. Cryptocurrency is not accepted."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:53.787Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "njalla",
      "category": "server-hosting",
      "name": "Njalla",
      "description": "Provider of VPS, domains and VPN run by njalla.srl in Costa Rica, with servers in Sweden. Accounts need only an email or XMPP address, and crypto payments are accepted.",
      "website": "https://njal.la/servers/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CR",
        "name": "Costa Rica",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 48,
      "coverage": 100,
      "summary": "Njalla scores 48 out of 100 (grade D) on the server hosting criteria. It meets 5 of 12 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, IPv6 and anonymous payment. It partly meets security headers. It does not meet open source, independent audit, transparency report, tells users about requests, mail-friendly (port 25) and Reverse DNS. It is based in Costa Rica: Not in the Five, Nine or Fourteen Eyes. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/server-hosting/njalla/",
      "markdown": "https://privacyratings.com/server-hosting/njalla/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://njal.la/tos/",
          "note": "The terms say no data is collected beyond the email or XMPP address and password, and the website loads only its own scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://njal.la/tos/",
          "note": "Funded by paid services, with data collection limited to account login details."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or dedicated government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=njal.la&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=njal.la",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "no",
          "evidence": "https://njal.la/servers/",
          "note": "Outgoing SMTP is blocked on all servers."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "no",
          "evidence": "https://njal.la/servers/",
          "note": "Not documented. The servers page and FAQ do not mention reverse DNS."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://njal.la/pricing/",
          "note": "Every server includes one IPv4 and one IPv6 address."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://njal.la/faq/",
          "note": "Bitcoin, Litecoin, Monero and Ethereum are accepted."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:36.004Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ovhcloud",
      "category": "server-hosting",
      "name": "OVHcloud",
      "description": "French provider of VPS, dedicated servers and public cloud, running its own datacenters in Europe, North America and Asia-Pacific.",
      "website": "https://www.ovhcloud.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 44,
      "coverage": 100,
      "summary": "OVHcloud scores 44 out of 100 (grade D) on the server hosting criteria. It meets 5 of 11 criteria: transparency report, tells users about requests, mail-friendly (port 25), Reverse DNS and IPv6. It partly meets no ads or data sales and independent audit. It does not meet open source, no trackers or telemetry, security headers and anonymous payment. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: Mozilla HTTP Observatory grade C-.",
      "url": "https://privacyratings.com/server-hosting/ovhcloud/",
      "markdown": "https://privacyratings.com/server-hosting/ovhcloud/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.ovhcloud.com/en/terms-and-conditions/cookies-policy/",
          "note": "The websites load Piano Analytics without consent and use Commanders Act and advertising cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ovhcloud.com/en/terms-and-conditions/cookies-policy/",
          "note": "Funded by paid hosting; targeted advertising cookies are set only with consent."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://us.ovhcloud.com/sites/default/files/external_files/ovhcloud-us-soc3-report-2025.pdf",
          "note": "Only a SOC 3 summary report is public; full SOC 2 and ISO audit reports are not."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://corporate.ovhcloud.com/en/trusted-cloud/ethics-compliance/",
          "note": "Publishes yearly DSA transparency reports with counts of orders from EU authorities."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://us.ovhcloud.com/legal/faqs/legal-law-enforcement/",
          "note": "The law enforcement FAQ promises to notify customers of requests unless prohibited by law."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.ovhcloud.com",
          "note": "Grade C- (45/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.ovhcloud.com/en/guides/bare-metal-cloud/dedicated-servers/antispam-best-practices",
          "note": "Port 25 is open and only blocked when the anti-spam system detects spam."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.ovhcloud.com/en/guides/bare-metal-cloud/virtual-private-servers/configuring-reverse-dns",
          "note": "Reverse DNS for IPv4 and IPv6 is set in the Control Panel."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.ovhcloud.com/en/guides/bare-metal-cloud/virtual-private-servers/configure-ipv6",
          "note": "Every VPS is delivered with an IPv6 address."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "no",
          "evidence": "https://docs.ovhcloud.com/en/guides/account-and-service-management/managing-billing-payments-and-services/manage-payment-methods",
          "note": "Payment methods are cards, PayPal and SEPA direct debit, with no cryptocurrency option."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "C-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:17:29.628Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "racknerd",
      "category": "server-hosting",
      "name": "RackNerd",
      "description": "US provider of budget KVM VPS, dedicated and shared hosting in many North American and European datacenters.",
      "website": "https://www.racknerd.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 33,
      "coverage": 100,
      "summary": "RackNerd scores 33 out of 100 (grade F) on the server hosting criteria. It meets 4 of 12 criteria: no ads or data sales, mail-friendly (port 25), IPv6 and anonymous payment. It partly meets TLS configuration and Reverse DNS. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/server-hosting/racknerd/",
      "markdown": "https://privacyratings.com/server-hosting/racknerd/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics, Google Tag Manager and Tawk.to (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.racknerd.com/privacy-policy",
          "note": "Funded by paid hosting, and the privacy policy says personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.racknerd.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.racknerd.com",
          "note": "Grade F (0/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/forwardemail/awesome-mail-server-providers#vps-and-dedicated-mail-server-provider-comparison-table",
          "note": "Open by default."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://blog.racknerd.com/racknerds-vps-control-panel-video-tutorial-guide/",
          "note": "rDNS can be set in the VPS control panel; IPv6 rDNS is not documented."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://my.racknerd.com/index.php?rp=/knowledgebase/25/Do-you-provide-IPv6-.html",
          "note": "Native IPv6 is allocated free on request in some locations."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://my.racknerd.com/index.php?rp=/knowledgebase/7/What-payment-methods-do-you-accept.html",
          "note": "Bitcoin, Litecoin, Ethereum and stablecoins are accepted."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Tawk.to",
            "host": "embed.tawk.to",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:36.055Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "rarecloud",
      "category": "server-hosting",
      "name": "RareCloud",
      "description": "Romanian provider of KVM VPS, OpenStack cloud VMs, managed Kubernetes and web hosting, with datacenters in Europe, the US and Asia.",
      "website": "https://rarecloud.io",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "RO",
        "name": "Romania",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 33,
      "coverage": 100,
      "summary": "RareCloud scores 33 out of 100 (grade F) on the server hosting criteria. It meets 4 of 12 criteria: TLS configuration, mail-friendly (port 25), IPv6 and anonymous payment. It partly meets no ads or data sales and Reverse DNS. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in Romania: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/server-hosting/rarecloud/",
      "markdown": "https://privacyratings.com/server-hosting/rarecloud/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://rarecloud.io/tos/#cookie-policy",
          "note": "The cookie policy lists Google Tag Manager, Google Analytics, Meta Pixel, Google Ads and Tawk.to."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://rarecloud.io/tos/#cookie-policy",
          "note": "Funded by paid hosting; Meta and Google remarketing cookies are set only with consent."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=rarecloud.io&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=rarecloud.io",
          "note": "Grade C (55/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/forwardemail/awesome-mail-server-providers#vps-and-dedicated-mail-server-provider-comparison-table",
          "note": "Open by default."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://console.rarecloud.io/llms.txt",
          "note": "PTR records can be set through the API for a cloud VM's primary IPv4 address only."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/forwardemail/awesome-mail-server-providers#vps-and-dedicated-mail-server-provider-comparison-table",
          "note": null
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://console.rarecloud.io/llms.txt",
          "note": "Cryptocurrency payment is accepted."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:36.103Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "scaleway",
      "category": "server-hosting",
      "name": "Scaleway",
      "description": "French cloud provider, part of the Iliad group, offering virtual instances, bare-metal servers, Kubernetes, storage and AI infrastructure in European datacenters.",
      "website": "https://www.scaleway.com/en/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Scaleway scores 30 out of 100 (grade F) on the server hosting criteria. It meets 3 of 12 criteria: TLS configuration, Reverse DNS and IPv6. It partly meets independent audit, security headers and mail-friendly (port 25). It does not meet open source, no trackers or telemetry, no ads or data sales, transparency report, tells users about requests and anonymous payment. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/server-hosting/scaleway/",
      "markdown": "https://privacyratings.com/server-hosting/scaleway/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.scaleway.com/en/cookie/",
          "note": "The cookie policy lists Hotjar, HubSpot, LinkedIn and Google Ads cookies, loaded after consent."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.scaleway.com/en/cookie/",
          "note": "Optional marketing and advertising personalization cookies are used, though the privacy policy says personal data is not resold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.scaleway.com/en/security-and-compliance/",
          "note": "Scaleway states ISO/IEC 27001 and HDS certification, but no audit report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=console.scaleway.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=console.scaleway.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.scaleway.com/en/docs/instances/how-to/send-emails-from-your-instance/",
          "note": "SMTP ports are blocked by default and can be opened in the console after identity verification."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.scaleway.com/en/docs/instances/how-to/configure-reverse-dns/",
          "note": "Reverse DNS for flexible IPv4 and IPv6 addresses is set in the console or through the IPAM API."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.scaleway.com/en/docs/ipam/reference-content/understanding-ip-billing/",
          "note": "Flexible IPv6 addresses are generally free, while IPv4 addresses are billed."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "no",
          "evidence": "https://www.scaleway.com/en/docs/billing/faq/",
          "note": "Payment is by card or SEPA direct debit. Cryptocurrency is not accepted."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:54.221Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "ultahost",
      "category": "server-hosting",
      "name": "UltaHost",
      "description": "Provider of shared hosting, VPS, VDS and dedicated servers, headquartered in Delaware with offices in the UK, Turkey and Dubai.",
      "website": "https://ultahost.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "UltaHost scores 38 out of 100 (grade F) on the server hosting criteria. It meets 4 of 12 criteria: tells users about requests, Reverse DNS, IPv6 and anonymous payment. It partly meets no ads or data sales, transparency report, TLS configuration and mail-friendly (port 25). It does not meet open source, no trackers or telemetry, independent audit and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/server-hosting/ultahost/",
      "markdown": "https://privacyratings.com/server-hosting/ultahost/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics, Google Tag Manager and Hotjar (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://ultahost.com/privacy-policy",
          "note": "The privacy policy says cookies are used to provide personalised advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://ultahost.com/court-order-subpoena-policy",
          "note": "A court order and subpoena policy is published, but no request counts."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://ultahost.com/court-order-subpoena-policy",
          "note": "Customers are generally notified of legal requests unless notice is prohibited or would risk safety."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=ultahost.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=ultahost.com",
          "note": "Grade F (10/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://ultahost.com/anti-spam-policy",
          "note": "Port 25 is open by default only on annual VPS plans; other plans must request it."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/forwardemail/awesome-mail-server-providers#vps-and-dedicated-mail-server-provider-comparison-table",
          "note": null
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://ultahost.com/vps-hosting",
          "note": "VPS plans include several dedicated IPv6 addresses."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://ultahost.com/payments",
          "note": "Bitcoin and other cryptocurrencies are accepted."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Hotjar",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:36.163Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "upcloud",
      "category": "server-hosting",
      "name": "UpCloud",
      "description": "Finnish cloud provider offering virtual servers, GPU servers, managed Kubernetes, databases and object storage in datacenters in Europe, North America, Asia and Australia.",
      "website": "https://upcloud.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "FI",
        "name": "Finland",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 53,
      "coverage": 100,
      "summary": "UpCloud scores 53 out of 100 (grade D) on the server hosting criteria. It meets 6 of 12 criteria: no ads or data sales, tells users about requests, TLS configuration, security headers, Reverse DNS and IPv6. It partly meets independent audit, transparency report and mail-friendly (port 25). It does not meet open source, no trackers or telemetry and anonymous payment. It is based in Finland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/server-hosting/upcloud/",
      "markdown": "https://privacyratings.com/server-hosting/upcloud/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://upcloud.com/privacy-notice/",
          "note": "Funded by paid hosting, and the privacy notice says personal data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://upcloud.com/media/upcloud_iso27001_2026.pdf",
          "note": "Only the ISO 27001 certificate is public, not the audit report."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://upcloud.com/privacy-notice/",
          "note": "The privacy notice says data is disclosed only in response to lawful requests or legal process. No request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://upcloud.com/privacy-notice/",
          "note": "The privacy notice says customers are informed in advance of disclosures to authorities where possible."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=hub.upcloud.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=hub.upcloud.com",
          "note": "Grade A+ (105/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://upcloud.com/docs/getting-started/free-trial/",
          "note": "Port 25 is blocked by default on all accounts, and non-trial customers can ask support to unblock it."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://upcloud.com/docs/products/networking/dns/",
          "note": "Reverse DNS for every IP address can be changed in the control panel or through the API at no cost."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://upcloud.com/docs/products/networking/public-network/",
          "note": "Every cloud server gets one IPv4 and one IPv6 address by default."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "no",
          "evidence": "https://upcloud.com/docs/getting-started/billing/payment-methods/",
          "note": "Payment is by card, PayPal, Apple Pay or Google Pay. Cryptocurrency is not accepted."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:54.354Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "vultr",
      "category": "server-hosting",
      "name": "Vultr",
      "description": "US cloud provider of virtual machines, bare metal servers and GPUs in many locations worldwide.",
      "website": "https://www.vultr.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "Vultr scores 38 out of 100 (grade F) on the server hosting criteria. It meets 4 of 12 criteria: TLS configuration, Reverse DNS, IPv6 and anonymous payment. It partly meets no ads or data sales, independent audit and mail-friendly (port 25). It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C+.",
      "url": "https://privacyratings.com/server-hosting/vultr/",
      "markdown": "https://privacyratings.com/server-hosting/vultr/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.vultr.com/legal/privacy/",
          "note": "The privacy policy lists Google Analytics and third-party targeting cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.vultr.com/legal/privacy/",
          "note": "Information is shared with third-party advertising partners for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.vultr.com/legal/compliance/",
          "note": "SOC 2 and ISO 27001 audit documents are only available to customers in the control panel."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.vultr.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.vultr.com",
          "note": "Grade C+ (60/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "port_25": {
          "title": "Mail-friendly (port 25)",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://docs.vultr.com/support/products/compute/why-is-smtp-blocked",
          "note": "Port 25 is blocked by default, and unblocking is reviewed case by case on request."
        },
        "reverse_dns": {
          "title": "Reverse DNS",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.vultr.com/support/products/network/how-do-i-configure-reverse-dns-for-my-vultr-instance",
          "note": "Reverse DNS for IPv4 and IPv6 is set in the Vultr Console."
        },
        "ipv6": {
          "title": "IPv6",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.vultr.com/products/compute/instances/cloud-compute/networking/ipv6",
          "note": "IPv6 can be enabled on Cloud Compute instances."
        },
        "anonymous_payment": {
          "title": "Anonymous payment",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.vultr.com/support/platform/billing/what-payment-methods-do-you-accept",
          "note": "Bitcoin and other cryptocurrencies are accepted through BitPay."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:36.221Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "caprover",
      "category": "app-hosting",
      "name": "CapRover",
      "description": "Open-source, self-hosted platform for deploying apps and databases on Docker Swarm, with nginx load balancing, Let's Encrypt certificates, a web dashboard and one-click apps.",
      "website": "https://caprover.com",
      "source": "https://github.com/caprover/caprover",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "CapRover scores 50 out of 100 (grade D) on the app hosting platforms criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/app-hosting/caprover/",
      "markdown": "https://privacyratings.com/app-hosting/caprover/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/caprover/caprover/blob/master/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/caprover/caprover/blob/master/src/user/events/emitter/AnalyticsLogger.ts",
          "note": "The website uses Google Analytics, and instances send usage events to CapRover's analytics server unless CAPROVER_DISABLE_ANALYTICS or DO_NOT_TRACK is set."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/caprover",
          "note": "Free open-source project funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:41.651Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cloudflare-workers",
      "category": "app-hosting",
      "name": "Cloudflare Workers",
      "description": "Serverless platform that runs JavaScript, TypeScript, Python and WebAssembly on Cloudflare's global network, and hosts static sites and full-stack apps, including those formerly on Cloudflare Pages.",
      "website": "https://www.cloudflare.com/products/workers/",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 47,
      "coverage": 100,
      "summary": "Cloudflare Workers scores 47 out of 100 (grade D) on the app hosting platforms criteria. It meets 3 of 8 criteria: transparency report, tells users about requests and TLS configuration. It partly meets no ads or data sales, independent audit and security headers. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/app-hosting/cloudflare-workers/",
      "markdown": "https://privacyratings.com/app-hosting/cloudflare-workers/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The platform is closed source. The workerd runtime and the Wrangler CLI are open source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.cloudflare.com/privacypolicy/",
          "note": "The website loads Google Tag Manager and Intercom, and the privacy policy describes advertising cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.cloudflare.com/privacypolicy/",
          "note": "Funded by paid plans and does not sell personal information, but marketing and advertising partners receive website data to advertise Cloudflare's services."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://developers.cloudflare.com/fundamentals/reference/policies-compliances/compliance-docs/",
          "note": "SOC 2, ISO 27001 and PCI reports exist but are only available to account administrators in the dashboard."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.cloudflare.com/transparency/",
          "note": "Semi-annual reports with counts of legal requests and responses."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://cf-assets.www.cloudflare.com/slt3lc6tev37/zItVXCvbb4LZpYG4Uh10R/7b27bba39755f0a4344acb946977704d/2H_2025_Cloudflare_s_Transparency_Report_Legal-v2.pdf",
          "note": "The transparency report states customers are notified of legal requests unless legally prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=dash.cloudflare.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=dash.cloudflare.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:08:14.286Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "coolify",
      "category": "app-hosting",
      "name": "Coolify",
      "description": "Open-source, self-hosted platform for deploying apps, databases and one-click services to your own servers over SSH. A paid hosted Coolify Cloud dashboard is also available.",
      "website": "https://coolify.io",
      "source": "https://github.com/coollabsio/coolify",
      "license": "Apache-2.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "HU",
        "name": "Hungary",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Coolify scores 65 out of 100 (grade C) on the app hosting platforms criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in Hungary: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/app-hosting/coolify/",
      "markdown": "https://privacyratings.com/app-hosting/coolify/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/coollabsio/coolify/blob/main/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/coollabsio/coolify/blob/main/app/Console/Commands/Init.php",
          "note": "Self-hosted instances send an anonymous installation ping by default, which can be turned off in settings. Coolify Cloud loads Plausible analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://coolify.io/pricing",
          "note": "Funded by Coolify Cloud subscriptions and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:42.083Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "deno-deploy",
      "category": "app-hosting",
      "name": "Deno Deploy",
      "description": "Serverless hosting from Deno Land for JavaScript and TypeScript apps, running on the Deno runtime with deploys from Git or the command line.",
      "website": "https://deno.com/deploy",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 22,
      "coverage": 100,
      "summary": "Deno Deploy scores 22 out of 100 (grade F) on the app hosting platforms criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales and security headers. It does not meet open source, no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/app-hosting/deno-deploy/",
      "markdown": "https://privacyratings.com/app-hosting/deno-deploy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The platform is closed source. The Deno runtime it runs on is open source under the MIT license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://docs.deno.com/deploy/privacy_policy/",
          "note": "The privacy policy says Google Analytics is used and advertising networks may collect information across sites."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://docs.deno.com/deploy/privacy_policy/",
          "note": "Funded by paid plans and does not sell personal information, but advertising networks may collect data on its sites."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=console.deno.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=console.deno.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "PostHog",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:10:24.907Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dokku",
      "category": "app-hosting",
      "name": "Dokku",
      "description": "Open-source, self-hosted platform that deploys apps to your own server with git push, using Heroku-compatible buildpacks or Dockerfiles.",
      "website": "https://dokku.com",
      "source": "https://github.com/dokku/dokku",
      "license": "MIT",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Dokku scores 80 out of 100 (grade B) on the app hosting platforms criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/app-hosting/dokku/",
      "markdown": "https://privacyratings.com/app-hosting/dokku/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dokku/dokku/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dokku/dokku",
          "note": "No telemetry or analytics in the source code, and no trackers on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/dokku",
          "note": "Funded by donations, sponsors and the paid Dokku Pro add-on, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:42.094Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dokploy",
      "category": "app-hosting",
      "name": "Dokploy",
      "description": "Self-hosted platform for deploying apps and databases with Docker, Docker Swarm and Traefik, managed from a web dashboard. A hosted Dokploy Cloud is also available.",
      "website": "https://dokploy.com",
      "source": "https://github.com/Dokploy/dokploy",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Dokploy scores 50 out of 100 (grade D) on the app hosting platforms criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/app-hosting/dokploy/",
      "markdown": "https://privacyratings.com/app-hosting/dokploy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Dokploy/dokploy/blob/canary/LICENSE.MD",
          "note": "All code is public. Most is Apache-2.0, and enterprise features such as SSO and audit logs in the proprietary folders use the source-available Dokploy Source Available License."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://dokploy.com/privacy",
          "note": "The website and docs use Google Analytics, and Dokploy Cloud uses HubSpot and Google Tag Manager. The self-hosted version loads no analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://dokploy.com/privacy",
          "note": "Funded by Dokploy Cloud and enterprise licenses, and the privacy policy says personal data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js-eu1.hs-scripts.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:42.246Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fly-io",
      "category": "app-hosting",
      "name": "Fly.io",
      "description": "Platform that runs apps as lightweight virtual machines on its own hardware in regions around the world, deployed with the flyctl command-line tool.",
      "website": "https://fly.io",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "Fly.io scores 38 out of 100 (grade F) on the app hosting platforms criteria. It meets 2 of 8 criteria: tells users about requests and TLS configuration. It partly meets no ads or data sales, independent audit and transparency report. It does not meet open source, no trackers or telemetry and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/app-hosting/fly-io/",
      "markdown": "https://privacyratings.com/app-hosting/fly-io/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. The flyctl command-line tool is open source, but the platform is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://fly.io/legal/privacy-policy/",
          "note": "Marketing and documentation pages use Google Analytics and PostHog; the dashboard does not."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://fly.io/legal/privacy-policy/",
          "note": "Funded by paid usage with no ads or data sales, but Google conversion measurement is used for its own advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://fly.io/security/",
          "note": "A SOC 2 Type 2 attestation and third-party penetration tests exist, but reports are only available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://fly.io/legal/privacy-policy/",
          "note": "The privacy statement describes how compelled disclosure requests are handled, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://fly.io/legal/privacy-policy/",
          "note": "The privacy statement says users are notified of disclosures of their information unless prohibited by law or court order."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=fly.io&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=fly.io",
          "note": "Grade C (55/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:10:54.347Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "github-pages",
      "category": "app-hosting",
      "name": "GitHub Pages",
      "description": "Static website hosting from GitHub repositories, with custom domains, HTTPS, and builds through GitHub Actions or Jekyll.",
      "website": "https://pages.github.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "GitHub Pages scores 50 out of 100 (grade D) on the app hosting platforms criteria. It meets 4 of 8 criteria: transparency report, tells users about requests, TLS configuration and security headers. It partly meets no ads or data sales and independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/app-hosting/github-pages/",
      "markdown": "https://privacyratings.com/app-hosting/github-pages/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. The Jekyll generator and the Pages GitHub Actions are open source, but the GitHub service is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement",
          "note": "The GitHub privacy statement allows third-party cookies for interest-based advertising on its marketing pages."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement",
          "note": "Funded by subscriptions, but the privacy statement says third-party cookies may gather data for interest-based advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://docs.github.com/en/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/accessing-compliance-reports-for-your-organization",
          "note": "SOC reports and ISO/IEC 27001 certification are only available to organization owners in account settings."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://transparencycenter.github.com/",
          "note": "GitHub publishes a transparency report with counts of requests for user information, disclosures and takedowns."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.github.com/en/site-policy/other-site-policies/guidelines-for-legal-requests-of-user-data",
          "note": "Policy is to notify affected users about requests for their account information unless prohibited by law or court order."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=github.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=github.com",
          "note": "Grade A+ (115/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:10:25.181Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "heroku",
      "category": "app-hosting",
      "name": "Heroku",
      "description": "Platform as a service owned by Salesforce that runs apps in managed containers called dynos, with Git-based deploys, add-ons, and managed Postgres and Key-Value Store.",
      "website": "https://www.heroku.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Heroku scores 50 out of 100 (grade D) on the app hosting platforms criteria. It meets 4 of 8 criteria: transparency report, tells users about requests, TLS configuration and security headers. It partly meets no ads or data sales and independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/app-hosting/heroku/",
      "markdown": "https://privacyratings.com/app-hosting/heroku/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. Buildpacks and the Heroku CLI are open source, but the platform is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.salesforce.com/company/legal/privacy/",
          "note": "The website loads Google Tag Manager, and the Salesforce privacy statement covers cookies used for tailored advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.salesforce.com/company/legal/privacy/",
          "note": "Funded by paid plans, but the Salesforce privacy statement allows sharing data for advertising on non-Salesforce sites to promote its services."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.heroku.com/compliance/",
          "note": "SOC 1, 2 and 3 reports and ISO 27001 certification exist, but full reports are only available to customers."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.salesforce.com/en-us/wp-content/uploads/sites/4/documents/legal/H2-2025-Transparency-Report.pdf",
          "note": "Salesforce, which owns Heroku, publishes semi-annual transparency reports with counts of government requests."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.salesforce.com/en-us/wp-content/uploads/sites/4/documents/legal/H2-2025-Transparency-Report.pdf",
          "note": "Salesforce notifies customers of legally binding requests for their data unless prohibited by law."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=dashboard.heroku.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=dashboard.heroku.com",
          "note": "Grade A+ (100/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "WordPress.com Stats",
            "host": "stats.wp.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:10:25.363Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kamal",
      "category": "app-hosting",
      "name": "Kamal",
      "description": "Open-source command-line tool from 37signals that deploys containerized web apps to your own servers over SSH, with zero-downtime deploys through kamal-proxy.",
      "website": "https://kamal-deploy.org",
      "source": "https://github.com/basecamp/kamal",
      "license": "MIT",
      "platforms": [
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Kamal scores 80 out of 100 (grade B) on the app hosting platforms criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/app-hosting/kamal/",
      "markdown": "https://privacyratings.com/app-hosting/kamal/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/basecamp/kamal/blob/main/MIT-LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/basecamp/kamal",
          "note": "No third-party trackers, and the source code has no telemetry. The kamal-deploy.org website's Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kamal-deploy.org",
          "note": "Free MIT-licensed tool developed by 37signals, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:42.809Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "koyeb",
      "category": "app-hosting",
      "name": "Koyeb",
      "description": "Serverless platform for deploying apps, APIs, databases and GPU workloads from Git or Docker images in regions around the world.",
      "website": "https://www.koyeb.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 28,
      "coverage": 100,
      "summary": "Koyeb scores 28 out of 100 (grade F) on the app hosting platforms criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It partly meets security headers. It does not meet open source, no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/app-hosting/koyeb/",
      "markdown": "https://privacyratings.com/app-hosting/koyeb/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. The Koyeb CLI is open source, but the platform is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads PostHog analytics, and no privacy policy describing its tracking is published."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.koyeb.com/pricing",
          "note": "Funded by paid plans and usage, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.koyeb.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.koyeb.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:11:50.927Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "netlify",
      "category": "app-hosting",
      "name": "Netlify",
      "description": "Platform for building and deploying websites and web apps from Git, with a global CDN, serverless and edge functions, forms and deploy previews.",
      "website": "https://www.netlify.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 34,
      "coverage": 100,
      "summary": "Netlify scores 34 out of 100 (grade F) on the app hosting platforms criteria. It meets 2 of 8 criteria: tells users about requests and TLS configuration. It partly meets independent audit, transparency report and security headers. It does not meet open source, no trackers or telemetry and no ads or data sales. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/app-hosting/netlify/",
      "markdown": "https://privacyratings.com/app-hosting/netlify/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. The Netlify CLI is open source, but the platform is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.netlify.com/privacy/",
          "note": "The website loads Google Tag Manager, HubSpot and DoubleClick, and the privacy statement describes interest-based advertising cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.netlify.com/privacy/",
          "note": "The privacy statement says it uses services that deliver interest-based ads and may transfer personal information to business partners for their use."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.netlify.com/security/",
          "note": "SOC 2 Type 2 reports are only available to Enterprise customers; the ISO 27001 certificate is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.netlify.com/pdf/netlify-dpa.pdf",
          "note": "The data processing addendum sets out how public authority requests are handled, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.netlify.com/pdf/netlify-dpa.pdf",
          "note": "The data processing addendum promises to notify customers of public authority requests unless legally prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.netlify.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.netlify.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hsforms.net",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:10:38.223Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "northflank",
      "category": "app-hosting",
      "name": "Northflank",
      "description": "Platform for deploying services, jobs, databases and GPU workloads on Northflank's cloud or in a customer's own cloud account, built on Kubernetes.",
      "website": "https://northflank.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 28,
      "coverage": 100,
      "summary": "Northflank scores 28 out of 100 (grade F) on the app hosting platforms criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales, independent audit and security headers. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/app-hosting/northflank/",
      "markdown": "https://privacyratings.com/app-hosting/northflank/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://northflank.com/legal/privacy",
          "note": "The website loads PostHog and Sentry, and the privacy policy lists ad networks and analytics providers among recipients of personal data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://northflank.com/legal/privacy",
          "note": "Funded by paid plans and does not sell data, but the privacy policy lists ad networks and advertising providers among recipients."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://northflank.com/security",
          "note": "A SOC 2 Type 2 report exists but is only available on request through the trust center."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.northflank.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.northflank.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:12:33.770Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "railway",
      "category": "app-hosting",
      "name": "Railway",
      "description": "Cloud platform for deploying apps, databases and services from Git repositories or Docker images, with usage-based billing.",
      "website": "https://railway.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 36,
      "coverage": 100,
      "summary": "Railway scores 36 out of 100 (grade F) on the app hosting platforms criteria. It meets 2 of 7 criteria: no ads or data sales and tells users about requests. It partly meets independent audit and transparency report. It does not meet open source, no trackers or telemetry and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/app-hosting/railway/",
      "markdown": "https://privacyratings.com/app-hosting/railway/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. The Railway CLI and the Railpack builder are open source, but the platform is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://railway.com/legal/privacy",
          "note": "The privacy policy describes third-party analytics providers, advertising measurement cookies and session replay."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://railway.com/legal/privacy",
          "note": "Funded by paid usage, and the privacy policy says personal data is not sold, shared or used for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://docs.railway.com/enterprise/compliance",
          "note": "Only the SOC 3 summary is public; the SOC 2 Type II report is available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://railway.com/legal/dpa",
          "note": "The data processing addendum describes how government requests are handled, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://railway.com/legal/dpa",
          "note": "The data processing addendum promises reasonable notice to customers of compelled disclosure unless legally prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=railway.com",
          "note": "Grade D- (25/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:13:54.676Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "render",
      "category": "app-hosting",
      "name": "Render",
      "description": "Cloud platform for hosting web services, static sites, background workers, cron jobs and managed Postgres and Key Value databases, deployed from Git or container images.",
      "website": "https://render.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 29,
      "coverage": 100,
      "summary": "Render scores 29 out of 100 (grade F) on the app hosting platforms criteria. It meets 1 of 7 criteria: tells users about requests. It partly meets no ads or data sales, independent audit and transparency report. It does not meet open source, no trackers or telemetry and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/app-hosting/render/",
      "markdown": "https://privacyratings.com/app-hosting/render/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://render.com/privacy",
          "note": "The website loads Google Tag Manager, and the privacy policy lists web analytics data shared with advertising partners."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://render.com/privacy",
          "note": "Funded by paid plans, but the privacy policy says device and analytics data is shared with advertising partners for targeted advertising of its services."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://render.com/security",
          "note": "SOC 2 Type 2 and ISO 27001 reports are only available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://render.com/dpa",
          "note": "The data processing addendum describes how government requests are handled, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://render.com/dpa",
          "note": "The data processing addendum promises reasonable notice to customers of compelled disclosure unless legally prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=dashboard.render.com",
          "note": "Grade D- (25/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:14:13.308Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vercel",
      "category": "app-hosting",
      "name": "Vercel",
      "description": "Cloud platform for deploying frontend and full-stack web apps from Git, with serverless and edge functions and a global CDN. Made by the company behind Next.js.",
      "website": "https://vercel.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 28,
      "coverage": 100,
      "summary": "Vercel scores 28 out of 100 (grade F) on the app hosting platforms criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales, independent audit and security headers. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/app-hosting/vercel/",
      "markdown": "https://privacyratings.com/app-hosting/vercel/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. The Vercel CLI and the Next.js framework are open source, but the platform is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://vercel.com/legal/privacy-policy",
          "note": "The privacy policy describes third-party cookies and tracking technologies for targeted advertising and analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://vercel.com/legal/privacy-policy",
          "note": "Funded by paid plans, but the privacy policy says data is shared with third-party advertising networks to advertise Vercel's services."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://vercel.com/security",
          "note": "SOC 2 Type 2 and ISO 27001 reports are only available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=vercel.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=vercel.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:11:51.172Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "atlassian-statuspage",
      "category": "status-pages",
      "name": "Atlassian Statuspage",
      "description": "Hosted status pages from Atlassian.",
      "website": "https://www.atlassian.com/software/statuspage",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 19,
      "coverage": 100,
      "summary": "Atlassian Statuspage scores 19 out of 100 (grade F) on the status pages and uptime monitoring criteria. It meets 1 of 7 criteria: public uptime history. It partly meets no ads or data sales and independent audit. It does not meet open source, no trackers or telemetry, runs on your own infrastructure and no visitor tracking.",
      "url": "https://privacyratings.com/status-pages/atlassian-statuspage/",
      "markdown": "https://privacyratings.com/status-pages/atlassian-statuspage/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.atlassian.com/legal/privacy-policy",
          "note": "The privacy policy says advertising and analytics partners use cookies, pixels and other tracking technologies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.atlassian.com/legal/privacy-policy",
          "note": "The privacy policy describes personalised advertising based on user activity."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.atlassian.com/trust/compliance/resources/soc2",
          "note": "Statuspage is covered by SOC 2 audits, but reports are only available under NDA."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "self_hosted": {
          "title": "Runs on your own infrastructure",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Hosted by the vendor only."
        },
        "no_visitor_tracking": {
          "title": "No visitor tracking",
          "weight": 2,
          "answer": "no",
          "evidence": "https://status.atlassian.com",
          "note": "Hosted status pages load Google reCAPTCHA Enterprise for the subscribe form, and owners can add their own analytics."
        },
        "history": {
          "title": "Public uptime history",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.githubstatus.com/history",
          "note": "Status pages show uptime bars and past incident history."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google reCAPTCHA",
            "host": "www.recaptcha.net",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:50.131Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "better-stack",
      "category": "status-pages",
      "name": "Better Stack",
      "description": "Hosted uptime monitoring, incident management and status pages.",
      "website": "https://betterstack.com",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 31,
      "coverage": 100,
      "summary": "Better Stack scores 31 out of 100 (grade F) on the status pages and uptime monitoring criteria. It meets 2 of 7 criteria: no visitor tracking and public uptime history. It partly meets no ads or data sales and independent audit. It does not meet open source, no trackers or telemetry and runs on your own infrastructure.",
      "url": "https://privacyratings.com/status-pages/better-stack/",
      "markdown": "https://privacyratings.com/status-pages/better-stack/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Facebook SDK, Google DoubleClick, Google Tag Manager, HubSpot, LinkedIn Insight, Meta Pixel, Microsoft Ads, Reddit Pixel and X (Twitter) Pixel (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://betterstack.com/privacy",
          "note": "The website sets cookies for personalised ads through advertising networks."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://betterstack.com/security",
          "note": "A SOC 2 Type 2 report and pen test reports are only shared on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "self_hosted": {
          "title": "Runs on your own infrastructure",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Hosted by the vendor only."
        },
        "no_visitor_tracking": {
          "title": "No visitor tracking",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://status.plausible.io",
          "note": "Hosted status pages load no third-party analytics by default; owners can add their own tracking."
        },
        "history": {
          "title": "Public uptime history",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://status.betterstack.com",
          "note": "Status pages show uptime history and past incidents."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Facebook SDK",
            "host": "connect.facebook.net",
            "effect": "no"
          },
          {
            "name": "Google DoubleClick",
            "host": "googleads.g.doubleclick.net",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hsforms.net",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "snap.licdn.com",
            "effect": "no"
          },
          {
            "name": "Meta Pixel",
            "host": "www.facebook.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Ads",
            "host": "bat.bing.com",
            "effect": "no"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          },
          {
            "name": "Reddit Pixel",
            "host": "www.redditstatic.com",
            "effect": "no"
          },
          {
            "name": "X (Twitter) Pixel",
            "host": "static.ads-twitter.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:50.288Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cachet",
      "category": "status-pages",
      "name": "Cachet",
      "description": "Self-hosted status page system written in PHP.",
      "website": "https://cachethq.io",
      "source": "https://github.com/cachethq/cachet",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 78,
      "coverage": 100,
      "summary": "Cachet scores 78 out of 100 (grade B) on the status pages and uptime monitoring criteria. It meets 5 of 7 criteria: open source, no ads or data sales, runs on your own infrastructure, no visitor tracking and public uptime history. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/status-pages/cachet/",
      "markdown": "https://privacyratings.com/status-pages/cachet/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cachethq/cachet/blob/3.x/LICENSE.md",
          "note": "All code is public under the custom Cachet License, a source-available license that is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/cachethq/core/blob/main/config/cachet.php",
          "note": "The Cachet Beacon sends anonymous usage data to cachethq.io by default and can be turned off with CACHET_BEACON."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/cachethq/cachet/blob/3.x/.github/FUNDING.yml",
          "note": "Free software funded through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "self_hosted": {
          "title": "Runs on your own infrastructure",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cachethq/cachet#readme",
          "note": null
        },
        "no_visitor_tracking": {
          "title": "No visitor tracking",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/cachethq/core/blob/main/resources/views/components/cachet.blade.php",
          "note": "The status page template loads no third-party scripts; owners can add their own header code."
        },
        "history": {
          "title": "Public uptime history",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://demo.cachethq.io",
          "note": "Status pages show past incidents and metric graphs."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Fathom",
            "host": "cdn.usefathom.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:00:50.763Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cstate",
      "category": "status-pages",
      "name": "cState",
      "description": "Static status page theme for the Hugo site generator. Incidents are written as Markdown files and the page can be hosted on any static host.",
      "website": "https://cstate.uncascade.com",
      "source": "https://github.com/cstate/cstate",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 84,
      "coverage": 100,
      "summary": "cState scores 84 out of 100 (grade B) on the status pages and uptime monitoring criteria. It meets 5 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, runs on your own infrastructure and no visitor tracking. It partly meets public uptime history. It does not meet independent audit.",
      "url": "https://privacyratings.com/status-pages/cstate/",
      "markdown": "https://privacyratings.com/status-pages/cstate/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cstate/cstate/blob/master/LICENSE.md",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cstate/cstate/blob/master/layouts/partials/js.html",
          "note": "No telemetry in the source code. Google Analytics loads only if the site owner adds a tracking ID."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/cstate/cstate/blob/master/.github/FUNDING.yml",
          "note": "Free software funded through GitHub Sponsors and PayPal donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "self_hosted": {
          "title": "Runs on your own infrastructure",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cstate/cstate#readme",
          "note": "Builds a static site with Hugo that can be hosted anywhere without a vendor account."
        },
        "no_visitor_tracking": {
          "title": "No visitor tracking",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/cstate/cstate/blob/master/layouts/partials/js.html",
          "note": "No trackers by default; Google Analytics is added only when the owner configures it. The default theme loads Google Fonts."
        },
        "history": {
          "title": "Public uptime history",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://cstate.mnts.lt",
          "note": "Shows current status and past incidents, but no response times or uptime measurements."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:28.579Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "gatus",
      "category": "status-pages",
      "name": "Gatus",
      "description": "Self-hosted health dashboard and status page configured with a single YAML file.",
      "website": "https://gatus.io",
      "source": "https://github.com/TwiN/gatus",
      "license": "Apache-2.0",
      "platforms": [
        "docker",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 88,
      "coverage": 100,
      "summary": "Gatus scores 88 out of 100 (grade B) on the status pages and uptime monitoring criteria. It meets 6 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, runs on your own infrastructure, no visitor tracking and public uptime history. It does not meet independent audit.",
      "url": "https://privacyratings.com/status-pages/gatus/",
      "markdown": "https://privacyratings.com/status-pages/gatus/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TwiN/gatus/blob/master/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TwiN/gatus",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/TwiN/gatus/blob/master/.github/FUNDING.yml",
          "note": "Free software funded through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "self_hosted": {
          "title": "Runs on your own infrastructure",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TwiN/gatus#readme",
          "note": null
        },
        "no_visitor_tracking": {
          "title": "No visitor tracking",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/TwiN/gatus/blob/master/web/static/index.html",
          "note": "The status page loads only its own scripts and styles."
        },
        "history": {
          "title": "Public uptime history",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://status.twin.sh",
          "note": "Status pages show uptime, response time charts and recent events."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:00:50.575Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "healthchecks-io",
      "category": "status-pages",
      "name": "Healthchecks.io",
      "description": "Cron job and scheduled task monitoring service that alerts when expected pings stop arriving, with public status badges. The software is open source and can be self-hosted.",
      "website": "https://healthchecks.io",
      "source": "https://github.com/healthchecks/healthchecks",
      "license": "BSD-3-Clause",
      "platforms": [
        "web",
        "linux"
      ],
      "jurisdiction": {
        "code": "LV",
        "name": "Latvia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 84,
      "coverage": 100,
      "summary": "Healthchecks.io scores 84 out of 100 (grade B) on the status pages and uptime monitoring criteria. It meets 5 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, runs on your own infrastructure and no visitor tracking. It partly meets public uptime history. It does not meet independent audit. It is based in Latvia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/status-pages/healthchecks-io/",
      "markdown": "https://privacyratings.com/status-pages/healthchecks-io/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/healthchecks/healthchecks/blob/master/LICENSE",
          "note": "BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/healthchecks/healthchecks",
          "note": "No telemetry or analytics in the source code, and the privacy policy lists no third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://healthchecks.io/pricing/",
          "note": "Funded by paid plans. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "self_hosted": {
          "title": "Runs on your own infrastructure",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://healthchecks.io/docs/self_hosted/",
          "note": "The open-source Django app can run on your own server without a vendor account."
        },
        "no_visitor_tracking": {
          "title": "No visitor tracking",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://healthchecks.io/docs/badges/",
          "note": "Public status badges are plain images with no third-party trackers."
        },
        "history": {
          "title": "Public uptime history",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://healthchecks.io/docs/badges/",
          "note": "Public badges show only current status; ping history is visible only inside the account."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:28.936Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "instatus",
      "category": "status-pages",
      "name": "Instatus",
      "description": "Hosted status pages.",
      "website": "https://instatus.com",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 31,
      "coverage": 100,
      "summary": "Instatus scores 31 out of 100 (grade F) on the status pages and uptime monitoring criteria. It meets 3 of 7 criteria: no ads or data sales, no visitor tracking and public uptime history. It does not meet open source, no trackers or telemetry, independent audit and runs on your own infrastructure.",
      "url": "https://privacyratings.com/status-pages/instatus/",
      "markdown": "https://privacyratings.com/status-pages/instatus/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://instatus.com/policies/privacy",
          "note": "Funded by subscriptions, and the privacy policy says personal information is never sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "self_hosted": {
          "title": "Runs on your own infrastructure",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Hosted by the vendor only."
        },
        "no_visitor_tracking": {
          "title": "No visitor tracking",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://status.instatus.com",
          "note": "Hosted status pages load no third-party trackers by default; owners can add their own scripts."
        },
        "history": {
          "title": "Public uptime history",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://status.instatus.com/history/1",
          "note": "Status pages show uptime and past incident history."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:50.618Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kener",
      "category": "status-pages",
      "name": "Kener",
      "description": "Self-hosted status page and uptime monitor built with SvelteKit, with incident management, badges and embeddable status widgets.",
      "website": "https://kener.ing",
      "source": "https://github.com/rajnandan1/kener",
      "license": "MIT",
      "platforms": [
        "linux",
        "windows",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 88,
      "coverage": 100,
      "summary": "Kener scores 88 out of 100 (grade B) on the status pages and uptime monitoring criteria. It meets 6 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, runs on your own infrastructure, no visitor tracking and public uptime history. It does not meet independent audit.",
      "url": "https://privacyratings.com/status-pages/kener/",
      "markdown": "https://privacyratings.com/status-pages/kener/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rajnandan1/kener/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rajnandan1/kener/blob/main/src/lib/server/db/seedSiteData.ts",
          "note": "No telemetry in the source code. Analytics providers are only loaded if the site owner adds an ID."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/rajnandan1/kener/blob/main/.github/FUNDING.yml",
          "note": "Free software funded through GitHub Sponsors and Buy Me a Coffee, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "self_hosted": {
          "title": "Runs on your own infrastructure",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kener.ing/docs",
          "note": "Runs on your own server with Node.js or Docker, without a vendor account."
        },
        "no_visitor_tracking": {
          "title": "No visitor tracking",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/rajnandan1/kener/blob/main/src/lib/server/db/seedSiteData.ts",
          "note": "Status pages load no analytics unless the owner configures Google Analytics, Amplitude, Mixpanel or another provider."
        },
        "history": {
          "title": "Public uptime history",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://kener.ing",
          "note": "Status pages show daily uptime bars, response times and incident history."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:28.968Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "oneuptime",
      "category": "status-pages",
      "name": "OneUptime",
      "description": "Open-source observability platform with uptime monitoring, status pages, incident management, on-call alerts, logs and traces, available as a hosted service or self-hosted.",
      "website": "https://oneuptime.com",
      "source": "https://github.com/OneUptime/oneuptime",
      "license": null,
      "platforms": [
        "web",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 63,
      "coverage": 100,
      "summary": "OneUptime scores 63 out of 100 (grade C) on the status pages and uptime monitoring criteria. It meets 4 of 7 criteria: open source, no ads or data sales, runs on your own infrastructure and public uptime history. It partly meets no visitor tracking. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/status-pages/oneuptime/",
      "markdown": "https://privacyratings.com/status-pages/oneuptime/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/OneUptime/oneuptime/blob/master/LICENSE",
          "note": "All code is public. Most is Apache-2.0, and the ee/ directory of enterprise features in the same repository uses a source-available proprietary license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Tag Manager and PostHog."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://oneuptime.com/legal/privacy",
          "note": "Funded by paid plans, and the privacy policy says personal information is not sold or shared for behavioral advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "self_hosted": {
          "title": "Runs on your own infrastructure",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://oneuptime.com/docs/en/installation/docker-compose",
          "note": "Can be installed on your own server with Docker Compose or Helm, without a vendor account."
        },
        "no_visitor_tracking": {
          "title": "No visitor tracking",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/OneUptime/oneuptime/blob/master/config.example.env",
          "note": "Hosted status pages on oneuptime.com load Google Tag Manager, while self-hosted installs never load it."
        },
        "history": {
          "title": "Public uptime history",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://status.oneuptime.com",
          "note": "Status pages show uptime history bars and past incidents."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "PostHog",
            "host": "eu.posthog.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:28.905Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "pingdom",
      "category": "status-pages",
      "name": "Pingdom",
      "description": "Hosted website uptime, page speed and transaction monitoring from SolarWinds, with real user monitoring and public status pages.",
      "website": "https://www.pingdom.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 13,
      "coverage": 100,
      "summary": "Pingdom scores 13 out of 100 (grade F) on the status pages and uptime monitoring criteria. It meets 1 of 7 criteria: public uptime history. It partly meets independent audit. It does not meet open source, no trackers or telemetry, no ads or data sales, runs on your own infrastructure and no visitor tracking. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/status-pages/pingdom/",
      "markdown": "https://privacyratings.com/status-pages/pingdom/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Optimizely and the X (Twitter) pixel."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.solarwinds.com/legal/privacy",
          "note": "The SolarWinds privacy policy says personal data, including purchased data, is used for tailored advertising on third-party websites."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.solarwinds.com/trust-center",
          "note": "SolarWinds shares SOC 2 and ISO 27001 reports only on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "self_hosted": {
          "title": "Runs on your own infrastructure",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Hosted by the vendor only."
        },
        "no_visitor_tracking": {
          "title": "No visitor tracking",
          "weight": 2,
          "answer": "no",
          "evidence": "https://status.pingdom.com",
          "note": "Pingdom's own public status page loads Google Analytics and Google Tag Manager."
        },
        "history": {
          "title": "Public uptime history",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://documentation.solarwinds.com/en/success_center/pingdom/content/topics/public-status-page.htm",
          "note": "Public status pages share uptime check reports, with a page per check."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Optimizely",
            "host": "cdn.optimizely.com",
            "effect": "no"
          },
          {
            "name": "X (Twitter) Pixel",
            "host": "static.ads-twitter.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:29.095Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "statping-ng",
      "category": "status-pages",
      "name": "Statping-ng",
      "description": "Self-hosted status page and monitoring server written in Go, a community fork of Statping that supports MySQL, Postgres and SQLite.",
      "website": "https://statping-ng.github.io",
      "source": "https://github.com/statping-ng/statping-ng",
      "license": "GPL-3.0",
      "platforms": [
        "linux",
        "windows",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 72,
      "coverage": 100,
      "summary": "Statping-ng scores 72 out of 100 (grade C) on the status pages and uptime monitoring criteria. It meets 4 of 7 criteria: open source, no ads or data sales, runs on your own infrastructure and public uptime history. It partly meets no trackers or telemetry and no visitor tracking. It does not meet independent audit.",
      "url": "https://privacyratings.com/status-pages/statping-ng/",
      "markdown": "https://privacyratings.com/status-pages/statping-ng/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/statping-ng/statping-ng/blob/dev/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/statping-ng/statping-ng/blob/dev/utils/log.go",
          "note": "Error reports are sent to the project's Sentry server when enabled, and the setup form turns them on by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/statping-ng/statping-ng/blob/dev/LICENSE",
          "note": "Free software with no ads or paid tier."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "self_hosted": {
          "title": "Runs on your own infrastructure",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/statping-ng/statping-ng#readme",
          "note": "Runs on your own server or in Docker with no vendor account."
        },
        "no_visitor_tracking": {
          "title": "No visitor tracking",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/statping-ng/statping-ng/blob/dev/frontend/src/API.js",
          "note": "The status page loads Sentry error reporting in visitors' browsers when error reports are enabled; it can be turned off in settings."
        },
        "history": {
          "title": "Public uptime history",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/statping-ng/statping-ng/blob/dev/frontend/src/components/Index/IncidentsBlock.vue",
          "note": "Status pages show response-time charts, uptime and incident updates for each service."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:29.070Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "upptime",
      "category": "status-pages",
      "name": "Upptime",
      "description": "Uptime monitor and status page that runs entirely in your own GitHub repository, using GitHub Actions, Issues and Pages.",
      "website": "https://github.com/upptime/upptime",
      "source": "https://github.com/upptime/upptime",
      "license": "MIT",
      "platforms": [
        "github"
      ],
      "jurisdiction": null,
      "pick": true,
      "pick_reason": "No server to run, no vendor account and no tracking scripts. Checks run in GitHub Actions, incidents are GitHub issues, and the status page and response-time history are published with GitHub Pages.",
      "disclosure": "The Forward Email team, which maintains this site, contributes code to Upptime. This entry is scored by the same criteria as every other status page tool.",
      "grade": "B",
      "score": 78,
      "coverage": 100,
      "summary": "Upptime scores 78 out of 100 (grade B) on the status pages and uptime monitoring criteria. It meets 5 of 7 criteria: open source, no ads or data sales, runs on your own infrastructure, no visitor tracking and public uptime history. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/status-pages/upptime/",
      "markdown": "https://privacyratings.com/status-pages/upptime/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/upptime/upptime/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://status.forwardemail.net",
          "note": "Status pages generated by Upptime load no trackers, as on status.forwardemail.net. The separate documentation site upptime.js.org uses Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/upptime/upptime",
          "note": "Free MIT-licensed software with no ads or paid tier."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "self_hosted": {
          "title": "Runs on your own infrastructure",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://upptime.js.org/docs/get-started",
          "note": "Runs in your own repository."
        },
        "no_visitor_tracking": {
          "title": "No visitor tracking",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/upptime/status-page/blob/master/src/template.html",
          "note": "The generated status page loads no third-party trackers; it reads data from the GitHub API."
        },
        "history": {
          "title": "Public uptime history",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://demo.upptime.js.org",
          "note": "Response time graphs and incident history."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:50.563Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "uptime-kuma",
      "category": "status-pages",
      "name": "Uptime Kuma",
      "description": "Self-hosted uptime monitor with status pages and dozens of notification options.",
      "website": "https://uptime.kuma.pet",
      "source": "https://github.com/louislam/uptime-kuma",
      "license": "MIT",
      "platforms": [
        "docker",
        "linux",
        "windows",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 88,
      "coverage": 100,
      "summary": "Uptime Kuma scores 88 out of 100 (grade B) on the status pages and uptime monitoring criteria. It meets 6 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, runs on your own infrastructure, no visitor tracking and public uptime history. It does not meet independent audit.",
      "url": "https://privacyratings.com/status-pages/uptime-kuma/",
      "markdown": "https://privacyratings.com/status-pages/uptime-kuma/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/louislam/uptime-kuma/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/louislam/uptime-kuma",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/louislam/uptime-kuma/blob/master/.github/FUNDING.yml",
          "note": "Free software funded through GitHub Sponsors and Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "self_hosted": {
          "title": "Runs on your own infrastructure",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/louislam/uptime-kuma#readme",
          "note": null
        },
        "no_visitor_tracking": {
          "title": "No visitor tracking",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/louislam/uptime-kuma/blob/master/server/analytics/analytics.js",
          "note": "Status pages load no analytics unless the owner configures Google Analytics, Umami, Plausible, Matomo or Rybbit."
        },
        "history": {
          "title": "Public uptime history",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/louislam/uptime-kuma/blob/master/src/pages/StatusPage.vue",
          "note": "Status pages show uptime bars and a past incidents section."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:00:51.077Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "uptimerobot",
      "category": "status-pages",
      "name": "UptimeRobot",
      "description": "Hosted uptime monitoring with public status pages.",
      "website": "https://uptimerobot.com",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "UptimeRobot scores 25 out of 100 (grade F) on the status pages and uptime monitoring criteria. It meets 1 of 7 criteria: public uptime history. It partly meets no ads or data sales, independent audit and no visitor tracking. It does not meet open source, no trackers or telemetry and runs on your own infrastructure.",
      "url": "https://privacyratings.com/status-pages/uptimerobot/",
      "markdown": "https://privacyratings.com/status-pages/uptimerobot/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Criteo and Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://uptimerobot.com/privacy/",
          "note": "The privacy policy lists Google Ads and Facebook Ads for remarketing and serving relevant advertisements."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://uptimerobot.com/security/",
          "note": "A SOC 2 audit was completed, but the report is only shared with customers on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "self_hosted": {
          "title": "Runs on your own infrastructure",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Hosted by the vendor only."
        },
        "no_visitor_tracking": {
          "title": "No visitor tracking",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://status.uptimerobot.com",
          "note": "Public status pages include Google Tag Manager, which loads only after the visitor consents to cookies."
        },
        "history": {
          "title": "Public uptime history",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://status.uptimerobot.com",
          "note": "Status pages show uptime percentages, response times and incident history."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Cookiebot",
            "host": "consent.cookiebot.com",
            "effect": "none"
          },
          {
            "name": "Criteo",
            "host": "gum.criteo.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Intercom",
            "host": "widget.intercom.io",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:51.468Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dnscrypt-proxy-2",
      "category": "dns-clients",
      "name": "DNScrypt-proxy 2",
      "description": "DNS proxy supporting encrypted DNS protocols including DNSCrypt v2, DNS-over-HTTPS, Oblivious DoH and Anonymized DNSCrypt.",
      "website": "https://dnscrypt.info",
      "source": "https://github.com/DNSCrypt/dnscrypt-proxy",
      "license": "ISC",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "DNScrypt-proxy 2 scores 80 out of 100 (grade B) on the DNS clients criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/dns-clients/dnscrypt-proxy-2/",
      "markdown": "https://privacyratings.com/dns-clients/dnscrypt-proxy-2/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/DNSCrypt/dnscrypt-proxy/blob/master/LICENSE",
          "note": "ISC."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/DNSCrypt/dnscrypt-proxy",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/DNSCrypt/dnscrypt-proxy/blob/master/LICENSE",
          "note": "Free ISC-licensed software with no ads or paid tier."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:53.932Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nebulo",
      "category": "dns-clients",
      "name": "Nebulo",
      "description": "Android DNS changer that sends queries over DNS-over-HTTPS or DNS-over-TLS without root, using Android's VPN interface by default.",
      "website": "https://play.google.com/store/apps/details?id=com.frostnerd.smokescreen",
      "source": "https://github.com/Ch4t4r/Nebulo",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Nebulo scores 50 out of 100 (grade D) on the DNS clients criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/dns-clients/nebulo/",
      "markdown": "https://privacyratings.com/dns-clients/nebulo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Ch4t4r/Nebulo/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.frostnerd.smokescreen/latest/",
          "note": "Exodus finds the Sentry crash reporting SDK in the app, and the website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.frostnerd.smokescreen/latest/",
          "note": "Free app with no advertising SDKs or in-app purchases."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:51.078Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "stubby",
      "category": "dns-clients",
      "name": "Stubby",
      "description": "Local DNS privacy stub resolver that encrypts DNS queries from a desktop or laptop to DNS-over-TLS resolvers.",
      "website": "https://dnsprivacy.org/dns_privacy_daemon_-_stubby/",
      "source": "https://github.com/getdnsapi/stubby",
      "license": "BSD-3-Clause",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Stubby scores 80 out of 100 (grade B) on the DNS clients criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/dns-clients/stubby/",
      "markdown": "https://privacyratings.com/dns-clients/stubby/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/getdnsapi/stubby/blob/develop/COPYING",
          "note": "BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/getdnsapi/stubby",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://dnsprivacy.org/dns_privacy_daemon_-_stubby/",
          "note": "Free software developed with grant funding from NLnet, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:51.964Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bunkerweb",
      "category": "firewalls",
      "name": "BunkerWeb",
      "description": "Open-source web application firewall (WAF) built on NGINX that sits in front of web services as a reverse proxy and blocks common attacks, with secure defaults.",
      "website": "https://www.bunkerweb.io",
      "source": "https://github.com/bunkerity/bunkerweb",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "BunkerWeb scores 50 out of 100 (grade D) on the firewalls criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/firewalls/bunkerweb/",
      "markdown": "https://privacyratings.com/firewalls/bunkerweb/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bunkerity/bunkerweb/blob/master/LICENSE.md",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://docs.bunkerweb.io/latest/features/",
          "note": "The website loads the Brevo marketing SDK and Google reCAPTCHA, and the software sends anonymous usage reports by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.bunkerweb.io/pricing-plan/",
          "note": "Funded by paid PRO and Enterprise plans, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:54.558Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "glasswire",
      "category": "firewalls",
      "name": "GlassWire",
      "description": "Network monitor and firewall for Windows and Android that shows which apps use the network, alerts on new connections and can block apps from going online.",
      "website": "https://www.glasswire.com",
      "license": null,
      "platforms": [
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "GlassWire scores 20 out of 100 (grade F) on the firewalls criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/firewalls/glasswire/",
      "markdown": "https://privacyratings.com/firewalls/glasswire/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.glasswire.com/privacy/",
          "note": "The website loads Google Tag Manager and Facebook scripts, and the privacy policy mentions advertising networks and analytics providers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.glasswire.com/pricing/",
          "note": "Free version with paid Premium plans; the privacy policy states personal data is not sold or rented."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:29.168Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "gufw",
      "category": "firewalls",
      "name": "Gufw",
      "description": "Graphical interface for ufw (Uncomplicated Firewall) on Linux, for managing firewall rules, profiles and per-application allow or deny rules.",
      "website": "https://costales.github.io/projects/gufw/",
      "source": "https://github.com/costales/gufw",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Gufw scores 50 out of 100 (grade D) on the firewalls criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/firewalls/gufw/",
      "markdown": "https://privacyratings.com/firewalls/gufw/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/costales/gufw/blob/master/COPYING.GPL3",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://costales.github.io/projects/gufw/",
          "note": "The app has no telemetry, but the project website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/costales/gufw",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:53.362Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "little-snitch",
      "category": "firewalls",
      "name": "Little Snitch",
      "description": "Application firewall for macOS that alerts on outgoing connections and lets users allow or deny network access per app and per server, with a map of connections.",
      "website": "https://obdev.at/products/littlesnitch/index.html",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "AT",
        "name": "Austria",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Little Snitch scores 35 out of 100 (grade F) on the firewalls criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets no trackers or telemetry. It does not meet open source and independent audit. It is based in Austria: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/firewalls/little-snitch/",
      "markdown": "https://privacyratings.com/firewalls/little-snitch/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://obdev.at/privacy/index.html",
          "note": "No third-party trackers on the website; the automatic update check sends version and system details used for anonymous statistics and can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://obdev.at/products/littlesnitch/order.html",
          "note": "Funded by paid licenses, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:54.547Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "lockdown",
      "category": "firewalls",
      "name": "Lockdown",
      "description": "Open-source firewall app for iPhone, iPad and Mac that blocks connections to tracking, ad and malware domains on the device, with custom block lists.",
      "website": "https://lockdownprivacy.com",
      "source": "https://github.com/confirmedcode/Lockdown-iOS",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Lockdown scores 80 out of 100 (grade B) on the firewalls criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/firewalls/lockdown/",
      "markdown": "https://privacyratings.com/firewalls/lockdown/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/confirmedcode/Lockdown-iOS/blob/main/LICENSE.md",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://lockdownprivacy.com/privacy",
          "note": "The privacy policy states the firewall uses no third-party analytics or trackers and sends no data to Lockdown servers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://lockdownprivacy.com/privacy",
          "note": "Funded by paid VPN subscriptions; the firewall shows no ads and collects no data to sell."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published; the earlier OpenAudit site is offline."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:54.280Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "lulu",
      "category": "firewalls",
      "name": "LuLu",
      "description": "Free, open-source firewall for macOS that blocks unknown outgoing connections and asks the user to allow or deny each new one.",
      "website": "https://objective-see.org/products/lulu.html",
      "source": "https://github.com/objective-see/LuLu",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "LuLu scores 80 out of 100 (grade B) on the firewalls criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/firewalls/lulu/",
      "markdown": "https://privacyratings.com/firewalls/lulu/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/objective-see/LuLu/blob/master/LICENSE.md",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/objective-see/LuLu",
          "note": "No telemetry or analytics in the source code, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://objective-see.org/support.html",
          "note": "Free tool from a non-profit foundation funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:54.661Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "opensnitch",
      "category": "firewalls",
      "name": "OpenSnitch",
      "description": "Application firewall for Linux that shows outgoing connections from each program and lets users allow or deny them with per-app rules.",
      "website": "https://github.com/evilsocket/opensnitch",
      "source": "https://github.com/evilsocket/opensnitch",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "OpenSnitch scores 80 out of 100 (grade B) on the firewalls criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/firewalls/opensnitch/",
      "markdown": "https://privacyratings.com/firewalls/opensnitch/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/evilsocket/opensnitch/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/evilsocket/opensnitch",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/evilsocket/opensnitch",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:54.547Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "opnsense",
      "category": "firewalls",
      "name": "OPNSense",
      "description": "Open-source firewall and routing platform based on FreeBSD, with a web interface, VPN, intrusion detection and plugin support.",
      "website": "https://opnsense.org",
      "source": "https://github.com/opnsense/core",
      "license": "BSD-2-Clause",
      "platforms": [],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 70,
      "coverage": 100,
      "summary": "OPNSense scores 70 out of 100 (grade C) on the firewalls criteria. It meets 3 of 4 criteria: open source, no ads or data sales and independent audit. It does not meet no trackers or telemetry. It is based in the Netherlands: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/firewalls/opnsense/",
      "markdown": "https://privacyratings.com/firewalls/opnsense/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/opnsense/core/blob/master/LICENSE",
          "note": "BSD-2-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics and Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://shop.opnsense.com/product/opnsense-business-edition/",
          "note": "Funded by Deciso through the paid Business Edition, hardware and support, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.opnsense.org/_downloads/1192d82f5a5746287dca94a67976345a/BE26.4-STIC_OPNSENSE_IAD-2604-ETR-v1.0.pdf",
          "note": "Full STIC evaluation technical report by jtsec for the Business Edition, which shares the open-source code base."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:55.604Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "portmaster",
      "category": "firewalls",
      "name": "Portmaster",
      "description": "Application firewall for Windows and Linux that monitors and blocks network connections per app, with DNS filtering, tracker blocklists and an optional paid multi-hop network (SPN).",
      "website": "https://safing.io",
      "source": "https://github.com/safing/portmaster",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "linux"
      ],
      "jurisdiction": {
        "code": "AT",
        "name": "Austria",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Portmaster scores 80 out of 100 (grade B) on the firewalls criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Austria: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/firewalls/portmaster/",
      "markdown": "https://privacyratings.com/firewalls/portmaster/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/safing/portmaster/blob/development/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://safing.io/privacy/",
          "note": "No third-party trackers, and the app contacts Safing only for updates, support and SPN login. The website's self-hosted Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://safing.io/pricing/",
          "note": "Free core app funded by paid Plus and Pro plans, and the privacy policy states personal data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:29.437Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "radio-silence",
      "category": "firewalls",
      "name": "Radio Silence",
      "description": "Paid network monitor and outbound firewall for macOS that lists every app's connections and blocks chosen apps from reaching the internet.",
      "website": "https://radiosilenceapp.com",
      "license": null,
      "platforms": [
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Radio Silence scores 50 out of 100 (grade D) on the firewalls criteria. It meets 2 of 4 criteria: no trackers or telemetry and no ads or data sales. It does not meet open source and independent audit.",
      "url": "https://privacyratings.com/firewalls/radio-silence/",
      "markdown": "https://privacyratings.com/firewalls/radio-silence/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://radiosilenceapp.com/privacy",
          "note": "No third-party trackers, and the app sends no usage data. The website's Simple Analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://radiosilenceapp.com/buy",
          "note": "Funded by one-time license sales, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Simple Analytics",
            "host": "scripts.simpleanalyticscdn.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:30.032Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "shorewall",
      "category": "firewalls",
      "name": "Shorewall",
      "description": "Configuration tool for the Linux Netfilter firewall that generates iptables rules from high-level zone and policy files. Development has ended and it is no longer maintained.",
      "website": "https://shorewall.org",
      "source": "https://gitlab.com/shorewall/code",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Shorewall scores 80 out of 100 (grade B) on the firewalls criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/firewalls/shorewall/",
      "markdown": "https://privacyratings.com/firewalls/shorewall/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/shorewall/code",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/shorewall/code",
          "note": "No telemetry or analytics in the source code, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://shorewall.org/",
          "note": "Free volunteer project with no ads; the site asks for donations to a scholarship fund."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:55.087Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "simplewall",
      "category": "firewalls",
      "name": "simplewall",
      "description": "Windows tool that configures the Windows Filtering Platform (WFP) to allow or block network access per application, with a rules editor and built-in blocklists.",
      "website": "https://github.com/henrypp/simplewall",
      "source": "https://github.com/henrypp/simplewall",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "simplewall scores 80 out of 100 (grade B) on the firewalls criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/firewalls/simplewall/",
      "markdown": "https://privacyratings.com/firewalls/simplewall/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/henrypp/simplewall/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/henrypp/simplewall",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/henrypp/simplewall#donate",
          "note": "Free tool funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:54.662Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "tinywall",
      "category": "firewalls",
      "name": "TinyWall",
      "description": "Lightweight firewall for Windows that builds on Windows Filtering Platform, blocking all traffic by default and allowing apps through a whitelist without popups.",
      "website": "https://tinywall.pados.hu",
      "source": "https://github.com/pylorak/TinyWall",
      "license": "GPL-3.0",
      "platforms": [
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "TinyWall scores 80 out of 100 (grade B) on the firewalls criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/firewalls/tinywall/",
      "markdown": "https://privacyratings.com/firewalls/tinywall/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pylorak/TinyWall/blob/master/LICENSE.txt",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://tinywall.pados.hu/",
          "note": "The project states there is no data collection or telemetry, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tinywall.pados.hu/",
          "note": "Free software with no ads, supported by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:30.418Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "uncomplicated-firewall",
      "category": "firewalls",
      "name": "Uncomplicated Firewall",
      "description": "Command-line front end for managing Netfilter firewall rules on Linux, the default firewall tool on Ubuntu, with simple commands for allowing and denying traffic.",
      "website": "https://launchpad.net/ufw",
      "source": "https://git.launchpad.net/ufw",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Uncomplicated Firewall scores 80 out of 100 (grade B) on the firewalls criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/firewalls/uncomplicated-firewall/",
      "markdown": "https://privacyratings.com/firewalls/uncomplicated-firewall/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://git.launchpad.net/ufw/tree/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://git.launchpad.net/ufw",
          "note": "No telemetry or analytics in the source code, and the Launchpad project page loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://launchpad.net/ufw",
          "note": "Free software maintained within Ubuntu, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:54.662Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "windows-firewall-control",
      "category": "firewalls",
      "name": "Windows Firewall Control",
      "description": "Freeware front end for the built-in Windows Firewall that adds filtering profiles, notifications for blocked outbound connections and easier rule management.",
      "website": "https://www.binisoft.org/wfc",
      "license": null,
      "platforms": [
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Windows Firewall Control scores 20 out of 100 (grade F) on the firewalls criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/firewalls/windows-firewall-control/",
      "markdown": "https://privacyratings.com/firewalls/windows-firewall-control/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.malwarebytes.com/legal/privacy-policy",
          "note": "The website loads no trackers, but the app is covered by the Malwarebytes privacy policy, which allows default product usage data collection and third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.binisoft.org/faq",
          "note": "Freeware from Malwarebytes with no ads, and the Malwarebytes privacy policy states personal data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:30.077Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "easylist",
      "category": "blocklists",
      "name": "EasyList",
      "description": "Filter lists for ad blockers, maintained by volunteers. EasyList removes ads and EasyPrivacy removes tracking scripts, with extra lists for cookie notices, social widgets and annoyances.",
      "website": "https://easylist.to",
      "source": "https://github.com/easylist/easylist",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "EasyList scores 80 out of 100 (grade B) on the blocklists criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/blocklists/easylist/",
      "markdown": "https://privacyratings.com/blocklists/easylist/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://easylist.to/pages/licence.html",
          "note": "Dual licensed GPL-3.0 and CC BY-SA 3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/easylist/easylist",
          "note": "The lists are plain filter files with no telemetry, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://easylist.to/",
          "note": "Free lists maintained by volunteers, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:00:55.091Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hosts-by-stevenblack",
      "category": "blocklists",
      "name": "Hosts by StevenBlack",
      "description": "Consolidated hosts file that merges several curated sources to block ads and malware, with optional extensions for fake news, gambling, adult content and social media.",
      "website": "https://github.com/StevenBlack/hosts",
      "source": "https://github.com/StevenBlack/hosts",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Hosts by StevenBlack scores 80 out of 100 (grade B) on the blocklists criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/blocklists/hosts-by-stevenblack/",
      "markdown": "https://privacyratings.com/blocklists/hosts-by-stevenblack/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/StevenBlack/hosts/blob/master/license.txt",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/StevenBlack/hosts",
          "note": "The list is a plain hosts file with no telemetry, and it is published on GitHub."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/StevenBlack/hosts",
          "note": "Free community-maintained list, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:55.087Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "iblocklist",
      "category": "blocklists",
      "name": "I-Blocklist",
      "description": "Service that distributes IP address blocklists from several providers in P2P, DAT and CIDR formats for peer-to-peer clients and firewalls, with free and subscription lists.",
      "website": "https://www.iblocklist.com",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "I-Blocklist scores 20 out of 100 (grade F) on the blocklists criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/blocklists/iblocklist/",
      "markdown": "https://privacyratings.com/blocklists/iblocklist/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.iblocklist.com/tos",
          "note": "Lists are provided under a personal-use license in the terms of service, not an open license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.iblocklist.com/",
          "note": "The website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.iblocklist.com/subscribe",
          "note": "Funded by paid subscriptions, with no ads on the site."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:55.301Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "no-google",
      "category": "blocklists",
      "name": "No Google",
      "description": "Blocklist of Google domains for Pi-hole and other DNS blockers, with separate category lists such as YouTube, Firebase, fonts and DoubleClick.",
      "website": "https://github.com/nickspaargaren/no-google",
      "source": "https://github.com/nickspaargaren/no-google",
      "license": "Unlicense",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "No Google scores 80 out of 100 (grade B) on the blocklists criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/blocklists/no-google/",
      "markdown": "https://privacyratings.com/blocklists/no-google/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nickspaargaren/no-google/blob/master/LICENSE",
          "note": "Unlicense."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nickspaargaren/no-google",
          "note": "The list is a plain domain file with no telemetry, and it is published on GitHub."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/nickspaargaren/no-google",
          "note": "Free volunteer-maintained list, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:55.091Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "someonewhocares-hosts",
      "category": "blocklists",
      "name": "Someonewhocares Hosts",
      "description": "Hosts file maintained by Dan Pollock that blocks ad, tracking, spyware and malware domains, with a 0.0.0.0 variant.",
      "website": "https://someonewhocares.org/hosts",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Someonewhocares Hosts scores 40 out of 100 (grade D) on the blocklists criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/blocklists/someonewhocares-hosts/",
      "markdown": "https://privacyratings.com/blocklists/someonewhocares-hosts/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://someonewhocares.org/hosts/hosts",
          "note": "The whole hosts file is public, under source-available terms that allow copying and sharing for non-commercial use with attribution, which is not an OSI-approved license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics and Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://someonewhocares.org/hosts/hosts",
          "note": "The list carries a sponsor credit for AdGuard; no ad network or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:55.774Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hyphanet",
      "category": "anonymity-networks",
      "name": "Hyphanet",
      "description": "Peer-to-peer network for censorship-resistant publishing and communication, formerly called Freenet, with a distributed data store and an optional friend-to-friend mode. The Freenet name now belongs to a separate project.",
      "website": "https://www.hyphanet.org/",
      "source": "https://github.com/hyphanet/fred",
      "license": "GPL-2.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Hyphanet scores 80 out of 100 (grade B) on the anonymity networks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/anonymity-networks/hyphanet/",
      "markdown": "https://privacyratings.com/anonymity-networks/hyphanet/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hyphanet/fred/blob/next/LICENSE",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.hyphanet.org/pages/download.html#privacy-policy",
          "note": "The privacy policy states the program sends no information unless the user requests it, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.hyphanet.org/pages/about.html",
          "note": "Volunteer-run free software with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:55.550Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "i2p",
      "category": "anonymity-networks",
      "name": "I2P",
      "description": "Anonymous overlay network that routes traffic through encrypted, unidirectional tunnels between peers, used mainly for hidden services, messaging and file sharing inside the network.",
      "website": "https://i2p.net/",
      "source": "https://i2pgit.org/I2P_Developers/i2p.i2p",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "I2P scores 80 out of 100 (grade B) on the anonymity networks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/anonymity-networks/i2p/",
      "markdown": "https://privacyratings.com/anonymity-networks/i2p/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://i2pgit.org/I2P_Developers/i2p.i2p/-/blob/master/LICENSE.txt",
          "note": "Free licenses listed per component (mostly public domain, BSD, GPL and MIT)."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://i2p.net/en/privacy/",
          "note": "The router has no telemetry, and the privacy policy states the website uses no third-party tracking and shares no data with advertisers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://i2p.net/en/financial-support/",
          "note": "Funded by donations, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:58.228Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "lokinet",
      "category": "anonymity-networks",
      "name": "Lokinet",
      "description": "Onion-routed anonymity network that runs over a decentralized set of staked service nodes, tunneling any IP traffic and hosting private .loki services.",
      "website": "https://lokinet.org",
      "source": "https://github.com/oxen-io/lokinet",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "linux"
      ],
      "jurisdiction": {
        "code": "AU",
        "name": "Australia",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Lokinet scores 80 out of 100 (grade B) on the anonymity networks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Australia: Five Eyes member; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/anonymity-networks/lokinet/",
      "markdown": "https://privacyratings.com/anonymity-networks/lokinet/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/oxen-io/lokinet/blob/dev/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://lokinet.org/privacy-policy",
          "note": "The privacy policy states the app stores no identifying information and the website uses no tracking cookies; the site loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://lokinet.org/privacy-policy",
          "note": "Free software from a non-profit foundation, with no ads and a policy of not sharing user information."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:30.309Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "nym",
      "category": "anonymity-networks",
      "name": "Nym",
      "description": "Decentralized mixnet that routes packets through layers of mix nodes with timing delays and cover traffic to hide metadata, used mainly through the NymVPN app.",
      "website": "https://nym.com/mixnet",
      "source": "https://github.com/nymtech/nym",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "Nym scores 85 out of 100 (grade B) on the anonymity networks criteria. It meets 3 of 4 criteria: open source, no ads or data sales and independent audit. It partly meets no trackers or telemetry. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law.",
      "url": "https://privacyratings.com/anonymity-networks/nym/",
      "markdown": "https://privacyratings.com/anonymity-networks/nym/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nymtech/nym/tree/develop/LICENSES",
          "note": "Applications are GPL-3.0 and libraries Apache-2.0 or MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://nym.com/anonymous-stats",
          "note": "No third-party trackers, but the website uses self-hosted Matomo and NymVPN sends optional anonymous usage statistics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://nym.com/pricing",
          "note": "Funded by NymVPN subscriptions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cure53.de/audit-report_nym.pdf",
          "note": "Full Cure53 report covering the apps, backend, VPN infrastructure and cryptography."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:30.861Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "tor",
      "category": "anonymity-networks",
      "name": "Tor",
      "description": "Anonymity network that routes traffic through three volunteer-run relays with layered encryption, used through Tor Browser and other apps to hide location, resist tracking and bypass censorship.",
      "website": "https://www.torproject.org",
      "source": "https://gitlab.torproject.org/tpo/core/tor",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 100,
      "coverage": 100,
      "summary": "Tor scores 100 out of 100 (grade A) on the anonymity networks criteria. It meets 4 of 4 criteria: open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/anonymity-networks/tor/",
      "markdown": "https://privacyratings.com/anonymity-networks/tor/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.torproject.org/about/history/",
          "note": "BSD-3-Clause. Source releases are published at dist.torproject.org. The Tor GitLab now requires sign-in to view files."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.torproject.org/about/privacy_policy/",
          "note": "The privacy policy states the software has no tracking, telemetry or analytics, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.torproject.org/about/supporters/",
          "note": "Funded by donations and grants to a non-profit, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://7asecurity.com/reports/pentest-report-tor2-RC1.2.pdf",
          "note": "Full 7ASecurity penetration test report covering Tor core code changes and network tools; Cure53 also published a full report on Tor Browser apps and tools."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:56.031Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "yggdrasil",
      "category": "anonymity-networks",
      "name": "Yggdrasil",
      "description": "Experimental decentralized mesh network that gives each node an IPv6 address and routes end-to-end encrypted traffic between peers; the project states it does not aim to provide anonymity.",
      "website": "https://yggdrasil-network.github.io",
      "source": "https://github.com/yggdrasil-network/yggdrasil-go",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Yggdrasil scores 80 out of 100 (grade B) on the anonymity networks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/anonymity-networks/yggdrasil/",
      "markdown": "https://privacyratings.com/anonymity-networks/yggdrasil/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/yggdrasil-network/yggdrasil-go/blob/develop/LICENSE",
          "note": "LGPL-3.0 with a linking exception."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/yggdrasil-network/yggdrasil-go",
          "note": "No telemetry or analytics in the source code, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/yggdrasil-network/yggdrasil-go",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:30.143Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "lantern",
      "category": "proxies",
      "name": "Lantern",
      "description": "Censorship circumvention app and VPN that routes traffic through Lantern's proxy network with obfuscated protocols, offering a free tier and paid Pro plans.",
      "website": "https://lantern.io",
      "source": "https://github.com/getlantern/lantern",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 15,
      "coverage": 100,
      "summary": "Lantern scores 15 out of 100 (grade F) on the proxies criteria. It partly meets open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/proxies/lantern/",
      "markdown": "https://privacyratings.com/proxies/lantern/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/getlantern/lantern/blob/main/LICENSE",
          "note": "The apps are GPL-3.0, but store builds bundle proprietary advertising and crash reporting SDKs."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.getlantern.lantern/latest/",
          "note": "The Android app contains Google AdMob and Sentry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.getlantern.lantern/latest/",
          "note": "The Android app bundles the Google AdMob advertising SDK, though the privacy policy states data is not sold or shared with advertisers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:30.325Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "outline",
      "category": "proxies",
      "name": "Outline",
      "description": "Tool for setting up a personal Shadowsocks-based VPN server on a cloud provider and sharing access keys, with a manager app for servers and client apps for users.",
      "website": "https://getoutline.org",
      "source": "https://github.com/OutlineFoundation/outline-apps",
      "license": "Apache-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 70,
      "coverage": 100,
      "summary": "Outline scores 70 out of 100 (grade C) on the proxies criteria. It meets 3 of 4 criteria: open source, no ads or data sales and independent audit. It does not meet no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/proxies/outline/",
      "markdown": "https://privacyratings.com/proxies/outline/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/OutlineFoundation/outline-apps/blob/master/LICENSE",
          "note": "Apache-2.0 for the apps and the server."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://getoutline.org/policies/data-collection/",
          "note": "The website loads Google Analytics, and the apps send crash reports to Sentry; usage metrics are opt-in."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://getoutline.org/faq/",
          "note": "Free software maintained by a non-profit foundation, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://getoutline.org/reports/cure53-report-SDK-2024.pdf",
          "note": "Full Cure53 report on the Outline SDK; older full reports from Radically Open Security and Cure53 are also published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:30.270Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "privoxy",
      "category": "proxies",
      "name": "Privoxy",
      "description": "Non-caching web proxy that filters web pages and HTTP headers to remove ads and trackers, with configurable access control and support for chaining to Tor.",
      "website": "https://www.privoxy.org",
      "source": "https://www.privoxy.org/gitweb/?p=privoxy.git;a=summary",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Privoxy scores 80 out of 100 (grade B) on the proxies criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/proxies/privoxy/",
      "markdown": "https://privacyratings.com/proxies/privoxy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.privoxy.org/user-manual/copyright.html",
          "note": "GPL-2.0 or later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.privoxy.org/sf-download-mirror/Sources/",
          "note": "No telemetry or analytics in the source code, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.privoxy.org/faq/general.html#DONATE",
          "note": "Funded by donations, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:56.449Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "psiphon",
      "category": "proxies",
      "name": "Psiphon",
      "description": "Censorship circumvention tool that connects through a network of Psiphon servers using several obfuscated transport protocols, switching automatically when one is blocked.",
      "website": "https://psiphon.ca",
      "source": "https://github.com/Psiphon-Labs/psiphon-tunnel-core",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 15,
      "coverage": 100,
      "summary": "Psiphon scores 15 out of 100 (grade F) on the proxies criteria. It partly meets open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit. It is based in Canada: Five Eyes member.",
      "url": "https://privacyratings.com/proxies/psiphon/",
      "markdown": "https://privacyratings.com/proxies/psiphon/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/Psiphon-Labs/psiphon-tunnel-core/blob/master/LICENSE",
          "note": "The tunnel core and apps are mostly GPL-3.0, but store builds bundle proprietary advertising SDKs."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.psiphon3.subscription/latest/",
          "note": "The Android app contains Google AdMob, and the website uses Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://psiphon.ca/en/privacy.html",
          "note": "The free service is supported by advertising partners that may serve ads based on usage data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:30.438Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "shadowsocks",
      "category": "proxies",
      "name": "Shadowsocks",
      "description": "Encrypted SOCKS5-based proxy protocol designed to bypass internet censorship, with open-source server and client implementations for desktop and mobile platforms.",
      "website": "https://shadowsocks.org",
      "source": "https://github.com/shadowsocks/shadowsocks-rust",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Shadowsocks scores 50 out of 100 (grade D) on the proxies criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/proxies/shadowsocks/",
      "markdown": "https://privacyratings.com/proxies/shadowsocks/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/shadowsocks/shadowsocks-rust/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics and Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/shadowsocks/shadowsocks-rust",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:56.196Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sing-box",
      "category": "proxies",
      "name": "sing-box",
      "description": "Universal proxy platform that supports Shadowsocks, VLESS, Trojan, Hysteria 2, WireGuard and other protocols with rule-based routing, available as a command-line core and official graphical clients.",
      "website": "https://sing-box.sagernet.org",
      "source": "https://github.com/SagerNet/sing-box",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "sing-box scores 80 out of 100 (grade B) on the proxies criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/proxies/sing-box/",
      "markdown": "https://privacyratings.com/proxies/sing-box/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/SagerNet/sing-box/blob/testing/LICENSE",
          "note": "GPL-3.0-or-later, with an added restriction on use of the project name."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://sing-box.sagernet.org/clients/privacy/",
          "note": "The privacy policy states the software and official clients do not collect or share personal data, and Exodus finds no trackers in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://sing-box.sagernet.org/sponsors/",
          "note": "Free project supported by sponsors, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:30.480Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "v2ray",
      "category": "proxies",
      "name": "V2Ray",
      "description": "Proxy platform maintained by the V2Fly community that supports VMess, VLESS, Shadowsocks, Trojan and other protocols with configurable routing, used as a server and client core for censorship circumvention.",
      "website": "https://www.v2fly.org",
      "source": "https://github.com/v2fly/v2ray-core",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "V2Ray scores 80 out of 100 (grade B) on the proxies criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/proxies/v2ray/",
      "markdown": "https://privacyratings.com/proxies/v2ray/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/v2fly/v2ray-core/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/v2fly/v2ray-core",
          "note": "No telemetry or analytics in the source code, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/v2fly/v2ray-core",
          "note": "Free community project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:30.506Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "xray",
      "category": "proxies",
      "name": "Xray",
      "description": "Proxy core forked from V2Ray by Project X, adding the XTLS, VLESS and REALITY transports for censorship circumvention; runs as a server or client and powers many third-party apps.",
      "website": "https://github.com/XTLS/Xray-core",
      "source": "https://github.com/XTLS/Xray-core",
      "license": "MPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Xray scores 80 out of 100 (grade B) on the proxies criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/proxies/xray/",
      "markdown": "https://privacyratings.com/proxies/xray/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/XTLS/Xray-core/blob/main/LICENSE",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/XTLS/Xray-core",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/XTLS/Xray-core",
          "note": "Free community project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:30.418Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "blocky",
      "category": "self-hosted-network-security",
      "name": "Blocky",
      "description": "Self-hosted DNS proxy and ad blocker for local networks, with per-client blocklists, conditional forwarding, caching and support for encrypted upstream DNS such as DoH and DoT.",
      "website": "https://0xerr0r.github.io/blocky/",
      "source": "https://github.com/0xERR0R/blocky",
      "license": "Apache-2.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Blocky scores 80 out of 100 (grade B) on the self-hosted network security criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/self-hosted-network-security/blocky/",
      "markdown": "https://privacyratings.com/self-hosted-network-security/blocky/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/0xERR0R/blocky/blob/main/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://0xerr0r.github.io/blocky/latest/",
          "note": "The documentation states Blocky collects no user data, telemetry or statistics, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://0xerr0r.github.io/blocky/latest/",
          "note": "Free volunteer project supported by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:30.516Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "e2guardian",
      "category": "self-hosted-network-security",
      "name": "E2Guardian",
      "description": "Web content filtering proxy for Linux and BSD that blocks sites by phrase, URL, file type and MIME type, running as an explicit or transparent proxy or an ICAP server.",
      "website": "https://github.com/e2guardian/e2guardian",
      "source": "https://github.com/e2guardian/e2guardian",
      "license": "GPL-2.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "E2Guardian scores 80 out of 100 (grade B) on the self-hosted network security criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/self-hosted-network-security/e2guardian/",
      "markdown": "https://privacyratings.com/self-hosted-network-security/e2guardian/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/e2guardian/e2guardian/blob/v5.5/COPYING",
          "note": "GPL-2.0 and LGPL-2.1."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/e2guardian/e2guardian",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/e2guardian/e2guardian",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:56.034Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ipfire",
      "category": "self-hosted-network-security",
      "name": "IPFire",
      "description": "Linux-based firewall distribution for routers and gateways, with a web interface, intrusion prevention, VPN support and add-on packages.",
      "website": "https://www.ipfire.org",
      "source": "https://git.ipfire.org/?p=ipfire-2.x.git;a=summary",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "IPFire scores 80 out of 100 (grade B) on the self-hosted network security criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/self-hosted-network-security/ipfire/",
      "markdown": "https://privacyratings.com/self-hosted-network-security/ipfire/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://git.ipfire.org/?p=ipfire-2.x.git;a=blob;f=doc/COPYING;hb=HEAD",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://git.ipfire.org/?p=ipfire-2.x.git;a=blob;f=html/cgi-bin/fireinfo.cgi;hb=HEAD",
          "note": "The fireinfo hardware statistics service is off until the user enables it, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ipfire.org/about",
          "note": "Funded by donations and Lightning Wire Labs hardware sales, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:57.165Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "openvpn",
      "category": "self-hosted-network-security",
      "name": "OpenVPN",
      "description": "Open-source VPN daemon that uses TLS for key exchange and runs over UDP or TCP, widely used for self-hosted site-to-site and remote-access VPNs.",
      "website": "https://openvpn.net/community/",
      "source": "https://github.com/OpenVPN/openvpn",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 60,
      "coverage": 100,
      "summary": "OpenVPN scores 60 out of 100 (grade C) on the self-hosted network security criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets independent audit. It does not meet no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/self-hosted-network-security/openvpn/",
      "markdown": "https://privacyratings.com/self-hosted-network-security/openvpn/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/OpenVPN/openvpn/blob/master/COPYING",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://openvpn.net/privacy-policy/",
          "note": "The website loads Google Analytics, Microsoft Clarity, HubSpot and LinkedIn trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://openvpn.net/access-server/pricing/",
          "note": "Free community software supported by OpenVPN Inc.'s paid business products, with no ads in the software."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://ostif.org/wp-content/uploads/2017/05/OpenVPN1.2final.pdf",
          "note": "Full Quarkslab report on OpenVPN 2.4.0, older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Clarity",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:30.710Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "pf-sense",
      "category": "self-hosted-network-security",
      "name": "pfSense",
      "description": "FreeBSD-based firewall and router distribution from Netgate with a web interface, VPN and package system, available as the open-source Community Edition and the closed pfSense Plus.",
      "website": "https://www.pfsense.org",
      "source": "https://github.com/pfsense/pfsense",
      "license": "Apache-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "pfSense scores 35 out of 100 (grade F) on the self-hosted network security criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/self-hosted-network-security/pf-sense/",
      "markdown": "https://privacyratings.com/self-hosted-network-security/pf-sense/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.netgate.com/pfsense-plus-software/software-types",
          "note": "pfSense CE is Apache-2.0, but pfSense Plus, the edition Netgate ships and develops first, is closed source under a commercial EULA."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.netgate.com/pfsense-plus-software",
          "note": "Funded by Netgate hardware, pfSense Plus licenses and support, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:56.506Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "pi-hole",
      "category": "self-hosted-network-security",
      "name": "Pi-hole",
      "description": "Self-hosted DNS sinkhole that blocks ads, trackers and malware domains for every device on a network, with a web interface for query logs and blocklist management.",
      "website": "https://pi-hole.net",
      "source": "https://github.com/pi-hole/pi-hole",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Pi-hole scores 80 out of 100 (grade B) on the self-hosted network security criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/self-hosted-network-security/pi-hole/",
      "markdown": "https://privacyratings.com/self-hosted-network-security/pi-hole/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pi-hole/pi-hole/blob/master/LICENSE",
          "note": "AGPL-3.0 and EUPL-1.2."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://pi-hole.net/privacy/",
          "note": "The software has no telemetry, and the privacy policy states the website only collects information given voluntarily."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://pi-hole.net/donate/",
          "note": "Funded by donations and sponsorships, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:56.735Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "pivpn",
      "category": "self-hosted-network-security",
      "name": "PiVPN",
      "description": "Set of shell scripts that install and manage a WireGuard or OpenVPN server on a Raspberry Pi or Debian-based server. The maintainers announced the end of the project and it is maintained only on a best-effort basis.",
      "website": "https://www.pivpn.io/",
      "source": "https://github.com/pivpn/pivpn",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "PiVPN scores 80 out of 100 (grade B) on the self-hosted network security criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/self-hosted-network-security/pivpn/",
      "markdown": "https://privacyratings.com/self-hosted-network-security/pivpn/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pivpn/pivpn/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pivpn/pivpn",
          "note": "No telemetry or analytics in the source code, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/pivpn/pivpn",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:57.019Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "technitium",
      "category": "self-hosted-network-security",
      "name": "Technitium DNS Server",
      "description": "Self-hosted authoritative and recursive DNS server with a web console, network-wide ad and tracker blocking, and support for DNS-over-TLS, DNS-over-HTTPS and DNS-over-QUIC.",
      "website": "https://technitium.com/dns",
      "source": "https://github.com/TechnitiumSoftware/DnsServer",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Technitium DNS Server scores 80 out of 100 (grade B) on the self-hosted network security criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/self-hosted-network-security/technitium/",
      "markdown": "https://privacyratings.com/self-hosted-network-security/technitium/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TechnitiumSoftware/DnsServer/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://technitium.com/dns/privacypolicy.html",
          "note": "The privacy policy states the server only contacts Technitium for update checks and the app store and collects no user data, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://technitium.com/dns/",
          "note": "Free software funded by donations through Patreon, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:59.589Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "wireguard",
      "category": "self-hosted-network-security",
      "name": "WireGuard",
      "description": "VPN protocol and implementation built on modern cryptography such as Curve25519 and ChaCha20-Poly1305, included in the Linux kernel and available as apps for other platforms.",
      "website": "https://www.wireguard.com",
      "source": "https://git.zx2c4.com/wireguard-tools/",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 90,
      "coverage": 100,
      "summary": "WireGuard scores 90 out of 100 (grade A) on the self-hosted network security criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It partly meets independent audit.",
      "url": "https://privacyratings.com/self-hosted-network-security/wireguard/",
      "markdown": "https://privacyratings.com/self-hosted-network-security/wireguard/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://git.zx2c4.com/wireguard-tools/tree/COPYING",
          "note": "GPL-2.0 for the kernel module and tools; the other implementations and apps use MIT or Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.wireguard.android/latest/",
          "note": "Exodus finds no trackers in the Android app, there is no telemetry in the source code, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.wireguard.com/donations/",
          "note": "Free software funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.wireguard.com/formal-verification/",
          "note": "Independent academic formal proofs of the protocol and a verified Curve25519 implementation are published, but they are older than three years and no recent code audit report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:31.099Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "zeek",
      "category": "self-hosted-network-security",
      "name": "Zeek",
      "description": "Open-source network security monitor that passively analyzes traffic and writes detailed logs of connections and protocols, used for intrusion detection, incident response and threat hunting.",
      "website": "https://zeek.org/",
      "source": "https://github.com/zeek/zeek",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Zeek scores 50 out of 100 (grade D) on the self-hosted network security criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/self-hosted-network-security/zeek/",
      "markdown": "https://privacyratings.com/self-hosted-network-security/zeek/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/zeek/zeek/blob/master/COPYING",
          "note": "BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads WordPress.com Stats (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://zeek.org/about/",
          "note": "Supported financially by Corelight and research funding, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "WordPress.com Stats",
            "host": "stats.wp.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:57.813Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cloudflare-mesh",
      "category": "mesh-vpns",
      "name": "Cloudflare Mesh",
      "description": "Private networking in Cloudflare One that gives devices and servers running the WARP client or connector private addresses, with all traffic passing through Cloudflare's network.",
      "website": "https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-mesh/",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 18,
      "coverage": 100,
      "summary": "Cloudflare Mesh scores 18 out of 100 (grade F) on the mesh VPNs and private networks criteria. It partly meets no ads or data sales, independent audit and no connection logs by default. It does not meet open source, no trackers or telemetry, keys stay on devices and self-hosted coordination server. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/mesh-vpns/cloudflare-mesh/",
      "markdown": "https://privacyratings.com/mesh-vpns/cloudflare-mesh/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The WARP client and Cloudflare One are closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.cloudflare.com/privacypolicy/",
          "note": "The website loads Google Tag Manager, and the privacy policy describes advertising cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.cloudflare.com/privacypolicy/",
          "note": "Funded by paid plans and does not sell personal information, but marketing and advertising partners receive website data to advertise Cloudflare's services."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://developers.cloudflare.com/fundamentals/reference/policies-compliances/compliance-docs/",
          "note": "SOC 2, ISO 27001 and PCI reports exist but are only available to account administrators in the dashboard."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "device_keys": {
          "title": "Keys stay on devices",
          "weight": 3,
          "answer": "no",
          "evidence": "https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-mesh/concepts/",
          "note": "All traffic passes through Cloudflare, where Gateway policies are applied. Devices do not encrypt traffic end to end to each other."
        },
        "self_hosted_control": {
          "title": "Self-hosted coordination server",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Only Cloudflare's hosted service can be used."
        },
        "no_connection_logs": {
          "title": "No connection logs by default",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://developers.cloudflare.com/cloudflare-one/insights/logs/gateway-logs/",
          "note": "Gateway logs all DNS, network and HTTP activity by default. Admins can turn logging off or keep only blocked requests."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:25.075Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "defguard",
      "category": "mesh-vpns",
      "name": "Defguard",
      "description": "Self-hosted WireGuard VPN platform with multi-factor authentication on every connection, identity management and access rules, from a company in Poland.",
      "website": "https://defguard.net",
      "source": "https://github.com/DefGuard/defguard",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "PL",
        "name": "Poland",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 82,
      "coverage": 100,
      "summary": "Defguard scores 82 out of 100 (grade B) on the mesh VPNs and private networks criteria. It meets 6 of 7 criteria: open source, no ads or data sales, independent audit, keys stay on devices, self-hosted coordination server and no connection logs by default. It does not meet no trackers or telemetry. It is based in Poland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/mesh-vpns/defguard/",
      "markdown": "https://privacyratings.com/mesh-vpns/defguard/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/DefGuard/defguard/blob/main/LICENSE.md",
          "note": "All code is public. The core is AGPL-3.0, and enterprise features in the same repository use the source-available Defguard Enterprise License."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://defguard.net",
          "note": "The website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://defguard.net/pricing/",
          "note": "Funded by paid enterprise licenses, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://defguard.net/pentesting/",
          "note": "Findings from periodic penetration tests by ISEC are published in full, with links to the fixes."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "device_keys": {
          "title": "Keys stay on devices",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://docs.defguard.net/features/network-devices",
          "note": "The server does not store WireGuard private keys. Traffic ends at gateways on your own infrastructure."
        },
        "self_hosted_control": {
          "title": "Self-hosted coordination server",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/DefGuard/defguard",
          "note": "The core server is open source and self-hosted only."
        },
        "no_connection_logs": {
          "title": "No connection logs by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://defguard.net",
          "note": "Defguard is self-hosted only, so connection logs stay on your own servers."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:25.283Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "firezone",
      "category": "mesh-vpns",
      "name": "Firezone",
      "description": "Zero-trust remote access platform built on WireGuard, with clients, gateways and a control plane for group-based access policies. Mostly offered as a hosted service; self-hosting the control plane is not officially supported.",
      "website": "https://www.firezone.dev",
      "source": "https://github.com/firezone/firezone",
      "license": "Apache-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 59,
      "coverage": 100,
      "summary": "Firezone scores 59 out of 100 (grade D) on the mesh VPNs and private networks criteria. It meets 3 of 7 criteria: open source, no ads or data sales and keys stay on devices. It partly meets self-hosted coordination server and no connection logs by default. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/mesh-vpns/firezone/",
      "markdown": "https://privacyratings.com/mesh-vpns/firezone/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/firezone/firezone/blob/main/elixir/LICENSE",
          "note": "All code is public. The clients and gateway are Apache-2.0, and the control plane and admin portal use the source-available Elastic License 2.0, which is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.firezone.dev/privacy-policy",
          "note": "The website uses PostHog analytics and Google Ads tags, and the apps send diagnostics and crash reports."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.firezone.dev/pricing",
          "note": "Funded by paid plans; the privacy policy states personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "device_keys": {
          "title": "Keys stay on devices",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.firezone.dev/kb/reference/faq",
          "note": "Traffic is end-to-end encrypted with WireGuard between clients and gateways on your own infrastructure. Firezone states it can never decrypt traffic, including through its relays."
        },
        "self_hosted_control": {
          "title": "Self-hosted coordination server",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.firezone.dev/kb/reference/faq",
          "note": "Gateways run on your own infrastructure, but the control plane is source-available and self-hosting it is not supported."
        },
        "no_connection_logs": {
          "title": "No connection logs by default",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.firezone.dev/kb/reference/cli/headless-linux",
          "note": "Clients send crash reports to Sentry by default. The --no-telemetry flag or FIREZONE_NO_TELEMETRY turns this off."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:57.432Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hamachi",
      "category": "mesh-vpns",
      "name": "LogMeIn Hamachi",
      "description": "Hosted VPN service from LogMeIn that joins computers into virtual LAN networks, with a free plan for up to five computers per network.",
      "website": "https://vpn.net",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 18,
      "coverage": 65,
      "summary": "LogMeIn Hamachi scores 18 out of 100 (grade F) on the mesh VPNs and private networks criteria. It meets 1 of 7 criteria: keys stay on devices. It does not meet open source, no trackers or telemetry and self-hosted coordination server. Still needing evidence: no ads or data sales, independent audit and no connection logs by default. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/mesh-vpns/hamachi/",
      "markdown": "https://privacyratings.com/mesh-vpns/hamachi/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://vpn.net/",
          "note": "The website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "device_keys": {
          "title": "Keys stay on devices",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://vpn.net/security",
          "note": "Peers agree on session keys with each other through a Diffie-Hellman exchange, and relayed traffic stays encrypted between the endpoints."
        },
        "self_hosted_control": {
          "title": "Self-hosted coordination server",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Only LogMeIn's hosted service can be used."
        },
        "no_connection_logs": {
          "title": "No connection logs by default",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:25.368Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "headscale",
      "category": "mesh-vpns",
      "name": "Headscale",
      "description": "Self-hosted, open-source implementation of the Tailscale coordination server, letting official Tailscale clients join a private network without using Tailscale's hosted service.",
      "website": "https://headscale.net",
      "source": "https://github.com/juanfont/headscale",
      "license": "BSD-3-Clause",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": true,
      "pick_reason": "The open-source, self-hosted replacement for Tailscale's coordination server. The official Tailscale clients connect to it unchanged, so the whole network runs on your own server with no account at Tailscale.",
      "disclosure": null,
      "grade": "B",
      "score": 82,
      "coverage": 100,
      "summary": "Headscale scores 82 out of 100 (grade B) on the mesh VPNs and private networks criteria. It meets 5 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, keys stay on devices and self-hosted coordination server. It partly meets no connection logs by default. It does not meet independent audit.",
      "url": "https://privacyratings.com/mesh-vpns/headscale/",
      "markdown": "https://privacyratings.com/mesh-vpns/headscale/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/juanfont/headscale/blob/main/LICENSE",
          "note": "BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/juanfont/headscale",
          "note": "No telemetry or analytics in the source code, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/juanfont/headscale",
          "note": "Free community project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "device_keys": {
          "title": "Keys stay on devices",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/juanfont/headscale#readme",
          "note": "Works with the official Tailscale clients, which create WireGuard keys on each device. The control server only exchanges public keys."
        },
        "self_hosted_control": {
          "title": "Self-hosted coordination server",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/juanfont/headscale/blob/main/LICENSE",
          "note": "The whole control server is open source and self-hosted."
        },
        "no_connection_logs": {
          "title": "No connection logs by default",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/juanfont/headscale/issues/2793",
          "note": "Headscale tells clients not to upload logs by default, but official Tailscale clients still contact log.tailscale.com at startup until TS_NO_LOGS_NO_SUPPORT is set."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:30.666Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "husarnet",
      "category": "mesh-vpns",
      "name": "Husarnet",
      "description": "Peer-to-peer VPN from a company in Poland, built for robotics and IoT, that gives each device an IPv6 address derived from its public key, with a hosted dashboard and relay servers.",
      "website": "https://husarnet.com",
      "source": "https://github.com/husarnet/husarnet",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "PL",
        "name": "Poland",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 44,
      "coverage": 88,
      "summary": "Husarnet scores 44 out of 100 (grade D) on the mesh VPNs and private networks criteria. It meets 2 of 7 criteria: no ads or data sales and keys stay on devices. It partly meets open source and self-hosted coordination server. It does not meet no trackers or telemetry and independent audit. Still needing evidence: no connection logs by default. It is based in Poland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/mesh-vpns/husarnet/",
      "markdown": "https://privacyratings.com/mesh-vpns/husarnet/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/husarnet/husarnet/blob/master/LICENSE.txt",
          "note": "The client is GPL-3.0 or MPL-2.0, but the dashboard and base servers are closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://husarnet.com",
          "note": "The website loads Google Analytics, Google Tag Manager and Hotjar."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://husarnet.com/pricing",
          "note": "Funded by paid plans, with a free plan and no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "device_keys": {
          "title": "Keys stay on devices",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/husarnet/husarnet#readme",
          "note": "Each device's address is derived from its own public key, and packets never leave devices unencrypted. Base servers only relay when a direct connection fails."
        },
        "self_hosted_control": {
          "title": "Self-hosted coordination server",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://husarnet.com/docs/selfhosted-about/",
          "note": "The dashboard and base servers can be self-hosted, but only under a paid proprietary license."
        },
        "no_connection_logs": {
          "title": "No connection logs by default",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Hotjar",
            "host": "static.hotjar.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:25.788Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "innernet",
      "category": "mesh-vpns",
      "name": "innernet",
      "description": "Open-source private network system built on WireGuard, with a self-hosted server that manages peers, CIDR-based groups and access rules.",
      "website": "https://github.com/tonarino/innernet",
      "source": "https://github.com/tonarino/innernet",
      "license": "MIT",
      "platforms": [
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "JP",
        "name": "Japan",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 88,
      "coverage": 100,
      "summary": "innernet scores 88 out of 100 (grade B) on the mesh VPNs and private networks criteria. It meets 6 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, keys stay on devices, self-hosted coordination server and no connection logs by default. It does not meet independent audit. It is based in Japan: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/mesh-vpns/innernet/",
      "markdown": "https://privacyratings.com/mesh-vpns/innernet/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/tonarino/innernet/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/tonarino/innernet",
          "note": "The project has no website beyond its repository and no hosted service."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/tonarino/innernet",
          "note": "Free open-source software from tonari, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "device_keys": {
          "title": "Keys stay on devices",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/tonarino/innernet#readme",
          "note": "When a peer redeems its invitation, it creates a new key pair and registers only the public key with the server. The key in the invitation file stops working."
        },
        "self_hosted_control": {
          "title": "Self-hosted coordination server",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/tonarino/innernet#readme",
          "note": "The coordination server is open source and self-hosted. There is no hosted version."
        },
        "no_connection_logs": {
          "title": "No connection logs by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/tonarino/innernet",
          "note": "There is no vendor service. Logs stay on your own devices and server."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:25.075Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ionscale",
      "category": "mesh-vpns",
      "name": "ionscale",
      "description": "Open-source, self-hosted Tailscale control server with support for multiple tailnets, OIDC login, ACLs and DNS, used with the official Tailscale clients.",
      "website": "https://jsiebens.github.io/ionscale/",
      "source": "https://github.com/jsiebens/ionscale",
      "license": "BSD-3-Clause",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 76,
      "coverage": 88,
      "summary": "ionscale scores 76 out of 100 (grade B) on the mesh VPNs and private networks criteria. It meets 5 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, keys stay on devices and self-hosted coordination server. It does not meet independent audit. Still needing evidence: no connection logs by default.",
      "url": "https://privacyratings.com/mesh-vpns/ionscale/",
      "markdown": "https://privacyratings.com/mesh-vpns/ionscale/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jsiebens/ionscale/blob/main/LICENSE",
          "note": "BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://jsiebens.github.io/ionscale/",
          "note": "No third-party trackers. The documentation site's Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/jsiebens/ionscale",
          "note": "Free community project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "device_keys": {
          "title": "Keys stay on devices",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://tailscale.com/blog/how-tailscale-works",
          "note": "Works with the official Tailscale clients, which create WireGuard keys on each device. The control server only exchanges public keys."
        },
        "self_hosted_control": {
          "title": "Self-hosted coordination server",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://jsiebens.github.io/ionscale/",
          "note": "The whole control server is open source and self-hosted."
        },
        "no_connection_logs": {
          "title": "No connection logs by default",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:25.309Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nebula",
      "category": "mesh-vpns",
      "name": "Nebula",
      "description": "Overlay networking tool originally built at Slack that connects hosts over mutually authenticated, encrypted tunnels using its own certificate authority and firewall rules, with self-hosted lighthouse nodes for discovery.",
      "website": "https://github.com/slackhq/nebula",
      "source": "https://github.com/slackhq/nebula",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 71,
      "coverage": 100,
      "summary": "Nebula scores 71 out of 100 (grade C) on the mesh VPNs and private networks criteria. It meets 5 of 7 criteria: open source, no ads or data sales, keys stay on devices, self-hosted coordination server and no connection logs by default. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/mesh-vpns/nebula/",
      "markdown": "https://privacyratings.com/mesh-vpns/nebula/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/slackhq/nebula/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://nebula.defined.net/docs/",
          "note": "No telemetry in the source code, but the official documentation site loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/slackhq/nebula",
          "note": "Free open-source software maintained by Defined Networking, which sells a managed version, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "device_keys": {
          "title": "Keys stay on devices",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://nebula.defined.net/docs/guides/sign-certificates-with-public-keys/",
          "note": "Each host can create its own key pair, and only the public key is sent to the certificate authority for signing. Lighthouses only help hosts find each other."
        },
        "self_hosted_control": {
          "title": "Self-hosted coordination server",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://nebula.defined.net/docs/guides/quick-start/",
          "note": "The certificate authority and lighthouses are self-hosted and open source. A managed version is sold separately."
        },
        "no_connection_logs": {
          "title": "No connection logs by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://nebula.defined.net/docs/config/logging/",
          "note": "Logs are written locally. The open-source version has no vendor service to send them to."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:30.480Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "netbird",
      "category": "mesh-vpns",
      "name": "NetBird",
      "description": "WireGuard-based mesh VPN and zero-trust access platform with open-source clients and a management server that can be self-hosted or used as NetBird's hosted service.",
      "website": "https://netbird.io",
      "source": "https://github.com/netbirdio/netbird",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 71,
      "coverage": 100,
      "summary": "NetBird scores 71 out of 100 (grade C) on the mesh VPNs and private networks criteria. It meets 5 of 7 criteria: open source, no ads or data sales, keys stay on devices, self-hosted coordination server and no connection logs by default. It does not meet no trackers or telemetry and independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/mesh-vpns/netbird/",
      "markdown": "https://privacyratings.com/mesh-vpns/netbird/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/netbirdio/netbird/blob/main/LICENSE",
          "note": "BSD-3-Clause for the clients and AGPL-3.0 for the management, signal and relay servers."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://netbird.io/privacy",
          "note": "The website uses Google Analytics, Microsoft Clarity, Hotjar, HubSpot and Reddit tracking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://netbird.io/pricing",
          "note": "Funded by paid cloud plans, with no ads in the product."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "device_keys": {
          "title": "Keys stay on devices",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://docs.netbird.io/about-netbird/how-netbird-works",
          "note": "The client creates the WireGuard private key, which never leaves the device. The management service only distributes public keys, and relays cannot decrypt traffic."
        },
        "self_hosted_control": {
          "title": "Self-hosted coordination server",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.netbird.io/selfhosted/selfhosted-guide",
          "note": "The management, signal and relay servers are open source under AGPL-3.0 and can be self-hosted."
        },
        "no_connection_logs": {
          "title": "No connection logs by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.netbird.io/manage/activity/traffic-events-logging",
          "note": "Traffic event logging is off by default. Client debug bundles are only uploaded when a user runs the upload command."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:30.661Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "netmaker",
      "category": "mesh-vpns",
      "name": "Netmaker",
      "description": "WireGuard-based platform for building mesh and site-to-site networks, with an open-source server that can be self-hosted and a hosted cloud version.",
      "website": "https://www.netmaker.io",
      "source": "https://github.com/gravitl/netmaker",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 88,
      "summary": "Netmaker scores 50 out of 100 (grade D) on the mesh VPNs and private networks criteria. It meets 3 of 7 criteria: open source, no ads or data sales and self-hosted coordination server. It partly meets keys stay on devices. It does not meet no trackers or telemetry and independent audit. Still needing evidence: no connection logs by default. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/mesh-vpns/netmaker/",
      "markdown": "https://privacyratings.com/mesh-vpns/netmaker/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gravitl/netmaker/blob/develop/LICENSE.md",
          "note": "All code is public. The core is Apache-2.0, and features in the pro directory of the same repository use a source-available enterprise license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://docs.netmaker.io/docs/references/faq",
          "note": "Self-hosted servers send usage telemetry to PostHog unless it is turned off, and the website loads PostHog and Intercom."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.netmaker.io/pricing",
          "note": "Funded by paid plans, with a free open-source community edition and no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "device_keys": {
          "title": "Keys stay on devices",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://docs.netmaker.io/docs/how-to-guides/integrating-non-native-devices",
          "note": "The netclient agent creates its own key pair, but WireGuard configs for devices without netclient, including private keys, are created on the server."
        },
        "self_hosted_control": {
          "title": "Self-hosted coordination server",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/gravitl/netmaker",
          "note": "The server is open source and can be self-hosted. Some pro features need a paid license."
        },
        "no_connection_logs": {
          "title": "No connection logs by default",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          },
          {
            "name": "Intercom",
            "host": "widget.intercom.io",
            "effect": "none"
          },
          {
            "name": "PostHog",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:25.648Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nordvpn-meshnet",
      "category": "mesh-vpns",
      "name": "NordVPN Meshnet",
      "description": "Free mesh networking feature of the NordVPN apps that links devices directly over NordLynx, a WireGuard-based protocol. Meshnet is free to use.",
      "website": "https://nordvpn.com/meshnet/",
      "source": "https://github.com/NordSecurity/libtelio",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "PA",
        "name": "Panama",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 29,
      "coverage": 76,
      "summary": "NordVPN Meshnet scores 29 out of 100 (grade F) on the mesh VPNs and private networks criteria. It meets 1 of 7 criteria: no ads or data sales. It partly meets open source and keys stay on devices. It does not meet no trackers or telemetry and self-hosted coordination server. Still needing evidence: independent audit and no connection logs by default. It is based in Panama: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/mesh-vpns/nordvpn-meshnet/",
      "markdown": "https://privacyratings.com/mesh-vpns/nordvpn-meshnet/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/NordSecurity/libtelio/blob/main/LICENSE",
          "note": "The libtelio networking library and the Linux app are GPL-3.0. The other apps and the coordination servers are closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.nordvpn.android/latest/",
          "note": "The Android app includes AppsFlyer, Google Firebase Analytics and Crashlytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://nordvpn.com/meshnet/",
          "note": "Free to use and funded by NordVPN subscriptions, with no ads in the apps."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "device_keys": {
          "title": "Keys stay on devices",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://meshnet.nordvpn.com/getting-started/meshnet-explained",
          "note": "Connections are described as end-to-end encrypted, but where keys are created and what relays can see is not documented."
        },
        "self_hosted_control": {
          "title": "Self-hosted coordination server",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Only NordVPN's hosted service can be used."
        },
        "no_connection_logs": {
          "title": "No connection logs by default",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:25.584Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "openziti",
      "category": "mesh-vpns",
      "name": "OpenZiti",
      "description": "Open-source zero-trust networking platform from NetFoundry that connects apps and devices through an overlay of self-hosted routers and a controller, with tunneler apps and SDKs.",
      "website": "https://netfoundry.io/docs/openziti/",
      "source": "https://github.com/openziti/ziti",
      "license": "Apache-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 59,
      "coverage": 88,
      "summary": "OpenZiti scores 59 out of 100 (grade D) on the mesh VPNs and private networks criteria. It meets 4 of 7 criteria: open source, no ads or data sales, keys stay on devices and self-hosted coordination server. It does not meet no trackers or telemetry and independent audit. Still needing evidence: no connection logs by default. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/mesh-vpns/openziti/",
      "markdown": "https://privacyratings.com/mesh-vpns/openziti/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/openziti/ziti/blob/main/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://netfoundry.io/docs/openziti/",
          "note": "The website loads Google Tag Manager and Hotjar."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://netfoundry.io/docs/openziti/",
          "note": "Free open-source software. NetFoundry sells a hosted version, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "device_keys": {
          "title": "Keys stay on devices",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://netfoundry.io/docs/openziti/learn/core-concepts/security/SecurityAndOpenZiti/end-to-end-encryption",
          "note": "Each side creates its own key pair and the controller only swaps public keys. Data is encrypted in the SDK and routers cannot read it."
        },
        "self_hosted_control": {
          "title": "Self-hosted coordination server",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/openziti/ziti",
          "note": "The controller and routers are open source and can be self-hosted."
        },
        "no_connection_logs": {
          "title": "No connection logs by default",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Hotjar",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:25.795Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "tailscale",
      "category": "mesh-vpns",
      "name": "Tailscale",
      "description": "Mesh VPN built on WireGuard that connects devices into a private network using a hosted coordination server for key exchange and access control, with open-source clients.",
      "website": "https://tailscale.com",
      "source": "https://github.com/tailscale/tailscale",
      "license": "BSD-3-Clause",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": true,
      "pick_reason": "A WireGuard mesh for Windows, macOS, Linux, Android and iOS, with NAT traversal and DERP relays when a direct connection fails. Keys are created on each device, so the coordination server and relays never see traffic. The clients are open source under BSD-3-Clause, ACLs and SSO come built in, and the open-source Headscale server can replace the hosted coordination server for full self-hosting.",
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Tailscale scores 50 out of 100 (grade D) on the mesh VPNs and private networks criteria. It meets 1 of 7 criteria: keys stay on devices. It partly meets open source, no ads or data sales, independent audit, self-hosted coordination server and no connection logs by default. It does not meet no trackers or telemetry. It is based in Canada: Five Eyes member.",
      "url": "https://privacyratings.com/mesh-vpns/tailscale/",
      "markdown": "https://privacyratings.com/mesh-vpns/tailscale/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://tailscale.com/opensource",
          "note": "The client daemon is BSD-3-Clause, but the Windows, macOS and iOS GUIs and the hosted coordination server are closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://tailscale.com/privacy-policy",
          "note": "The website uses third-party analytics and advertising cookies, and client logging is on by default with an opt-out."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://tailscale.com/pricing",
          "note": "Funded by paid plans with no ads in the product, though the website shares cookie data with ad partners for Tailscale's own marketing."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://tailscale.com/security",
          "note": "Latacora conducts regular security audits, but the reports are only available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "device_keys": {
          "title": "Keys stay on devices",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://tailscale.com/blog/how-tailscale-works",
          "note": "Each device creates its own WireGuard key pair. The private key never leaves the device, and DERP relays only forward encrypted packets."
        },
        "self_hosted_control": {
          "title": "Self-hosted coordination server",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://tailscale.com/opensource",
          "note": "Tailscale's coordination server is closed source. The clients can use the open-source, community-maintained Headscale server instead."
        },
        "no_connection_logs": {
          "title": "No connection logs by default",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://tailscale.com/kb/1011/log-mesh-traffic",
          "note": "Clients send logs to Tailscale by default, including connection open and close events. The --no-logs-no-support flag or TS_NO_LOGS_NO_SUPPORT turns this off."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:30.978Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "tinc",
      "category": "mesh-vpns",
      "name": "tinc",
      "description": "Long-running open-source VPN daemon that builds an encrypted mesh between nodes, sending traffic directly to its destination where possible, with no central server.",
      "website": "https://www.tinc-vpn.org",
      "source": "https://github.com/gsliepen/tinc",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 88,
      "coverage": 100,
      "summary": "tinc scores 88 out of 100 (grade B) on the mesh VPNs and private networks criteria. It meets 6 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, keys stay on devices, self-hosted coordination server and no connection logs by default. It does not meet independent audit.",
      "url": "https://privacyratings.com/mesh-vpns/tinc/",
      "markdown": "https://privacyratings.com/mesh-vpns/tinc/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gsliepen/tinc/blob/1.1/COPYING",
          "note": "GPL-2.0 or later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.tinc-vpn.org/",
          "note": "The website loads no trackers, and there is no hosted service."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.tinc-vpn.org/",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "device_keys": {
          "title": "Keys stay on devices",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.tinc-vpn.org/documentation/Generating-keypairs.html",
          "note": "Each node creates its own key pair. Nodes exchange public keys directly, with no coordination server."
        },
        "self_hosted_control": {
          "title": "Self-hosted coordination server",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.tinc-vpn.org/",
          "note": "There is no central server. Every node is configured and run by its owner."
        },
        "no_connection_logs": {
          "title": "No connection logs by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.tinc-vpn.org/",
          "note": "There is no vendor service. Logs stay on each node."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:26.087Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "twingate",
      "category": "mesh-vpns",
      "name": "Twingate",
      "description": "Hosted zero-trust remote access service that connects devices to private resources through connectors on the customer's network, managed from Twingate's cloud controller.",
      "website": "https://www.twingate.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 24,
      "coverage": 88,
      "summary": "Twingate scores 24 out of 100 (grade F) on the mesh VPNs and private networks criteria. It meets 1 of 7 criteria: keys stay on devices. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry, self-hosted coordination server and no connection logs by default. Still needing evidence: independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/mesh-vpns/twingate/",
      "markdown": "https://privacyratings.com/mesh-vpns/twingate/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The clients, connectors and controller are closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.twingate.com/privacy",
          "note": "The website uses Google Analytics and advertising cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.twingate.com/privacy",
          "note": "Funded by paid plans with no ads in the product, though website data is shared with ad partners for Twingate's own retargeting."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "device_keys": {
          "title": "Keys stay on devices",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.twingate.com/docs/how-encryption-works-in-twingate",
          "note": "The client creates the session key and connectors create their own key pairs. Relays and the controller cannot decrypt traffic."
        },
        "self_hosted_control": {
          "title": "Self-hosted coordination server",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "The controller is only offered as Twingate's hosted service."
        },
        "no_connection_logs": {
          "title": "No connection logs by default",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.twingate.com/docs/exporting-network-traffic",
          "note": "Network events for traffic through connectors are kept by Twingate for 24 hours to 12 months depending on the plan, with no documented way to turn them off."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:26.078Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "zerotier",
      "category": "mesh-vpns",
      "name": "ZeroTier",
      "description": "Peer-to-peer virtual network platform that joins devices into encrypted virtual Ethernet networks, managed through ZeroTier's hosted controller or a self-hosted one.",
      "website": "https://www.zerotier.com",
      "source": "https://github.com/zerotier/ZeroTierOne",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 88,
      "summary": "ZeroTier scores 38 out of 100 (grade F) on the mesh VPNs and private networks criteria. It meets 1 of 7 criteria: keys stay on devices. It partly meets open source, no ads or data sales and self-hosted coordination server. It does not meet no trackers or telemetry and independent audit. Still needing evidence: no connection logs by default. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/mesh-vpns/zerotier/",
      "markdown": "https://privacyratings.com/mesh-vpns/zerotier/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/zerotier/ZeroTierOne/blob/dev/LICENSE.txt",
          "note": "The core is MPL-2.0, but parts of the repository use a source-available license and the hosted ZeroTier Central is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.zerotier.com/privacy-policy/",
          "note": "The website loads Google Analytics, HubSpot, Microsoft Clarity, Facebook, LinkedIn and Reddit trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.zerotier.com/pricing/",
          "note": "Funded by paid plans with no ads in the product, though the website shares data with ad partners for ZeroTier's own marketing."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "device_keys": {
          "title": "Keys stay on devices",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://docs.zerotier.com/protocol",
          "note": "Each node creates its identity keys locally. Traffic is end-to-end encrypted and cannot be read by root servers or network controllers."
        },
        "self_hosted_control": {
          "title": "Self-hosted coordination server",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/zerotier/ZeroTierOne/blob/dev/nonfree/LICENSE.md",
          "note": "The network controller can be self-hosted, but its code uses a source-available license that forbids commercial use without a paid license."
        },
        "no_connection_logs": {
          "title": "No connection logs by default",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Clarity",
            "host": "www.clarity.ms",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:31.029Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "anydesk",
      "category": "remote-desktop",
      "name": "AnyDesk",
      "description": "Proprietary remote desktop software that connects to computers and mobile devices through AnyDesk's servers using its DeskRT codec, free for personal use and paid for commercial use.",
      "website": "https://anydesk.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "AnyDesk scores 10 out of 100 (grade F) on the remote desktop criteria. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/remote-desktop/anydesk/",
      "markdown": "https://privacyratings.com/remote-desktop/anydesk/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://anydesk.com/en/privacy",
          "note": "The website uses Google Analytics, Mixpanel, HubSpot, Meta Pixel and LinkedIn tracking, and the client sends usage and device data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://anydesk.com/en/privacy",
          "note": "Funded by paid licenses with no ads in the software; the privacy policy states personal data is not sold for money, though website cookie data is shared with ad partners."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:30.964Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "apache-guacamole",
      "category": "remote-desktop",
      "name": "Apache Guacamole",
      "description": "Clientless remote desktop gateway that runs on a server and gives browser-based access to machines over VNC, RDP, SSH and Telnet using HTML5, with no plugin or client software needed.",
      "website": "https://guacamole.apache.org",
      "source": "https://github.com/apache/guacamole-server",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Apache Guacamole scores 80 out of 100 (grade B) on the remote desktop criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/remote-desktop/apache-guacamole/",
      "markdown": "https://privacyratings.com/remote-desktop/apache-guacamole/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/apache/guacamole-server/blob/main/LICENSE",
          "note": "Apache-2.0 for the server and web client."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/apache/guacamole-client",
          "note": "No telemetry or analytics in the source code, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apache.org/foundation/sponsorship.html",
          "note": "Free software from the non-profit Apache Software Foundation, funded by sponsors and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:31.033Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "chrome-remote-desktop",
      "category": "remote-desktop",
      "name": "Chrome Remote Desktop",
      "description": "Free remote access tool from Google that connects to Windows, macOS and Linux computers through a web app or mobile apps, using a Google account and Google's relay servers.",
      "website": "https://remotedesktop.google.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Chrome Remote Desktop scores 0 out of 100 (grade F) on the remote desktop criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/remote-desktop/chrome-remote-desktop/",
      "markdown": "https://privacyratings.com/remote-desktop/chrome-remote-desktop/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source; the official apps and service are proprietary, though parts of the host code are published in the Chromium source tree."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://support.google.com/chrome/answer/1649523?hl=en",
          "note": "Google collects anonymized data on network delays and session length, with no documented way to turn it off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "The app shows no ads, but it is provided free by Google, whose privacy policy uses activity across its services to fund and personalize advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:31.189Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "meshcentral",
      "category": "remote-desktop",
      "name": "MeshCentral",
      "description": "Self-hosted web server for remote device management, offering remote desktop, terminal and file access to Windows, Linux, macOS and FreeBSD machines through an installed agent.",
      "website": "https://meshcentral.com",
      "source": "https://github.com/Ylianst/MeshCentral",
      "license": "Apache-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "MeshCentral scores 80 out of 100 (grade B) on the remote desktop criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/remote-desktop/meshcentral/",
      "markdown": "https://privacyratings.com/remote-desktop/meshcentral/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Ylianst/MeshCentral/blob/master/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Ylianst/MeshCentral",
          "note": "No telemetry or analytics in the source code, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Ylianst/MeshCentral",
          "note": "Free community project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:31.206Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "remmina",
      "category": "remote-desktop",
      "name": "Remmina",
      "description": "Remote desktop client for Linux and other Unix-like systems that supports RDP, VNC, SPICE, SSH and other protocols through plugins, with a tabbed GTK interface.",
      "website": "https://remmina.org",
      "source": "https://gitlab.com/Remmina/Remmina",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Remmina scores 80 out of 100 (grade B) on the remote desktop criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/remote-desktop/remmina/",
      "markdown": "https://privacyratings.com/remote-desktop/remmina/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/Remmina/Remmina/-/blob/master/COPYING",
          "note": "GPL-2.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/Remmina/Remmina/-/blob/master/src/remmina_info.c",
          "note": "The source states usage statistics collection was removed, news checks are off by default, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://remmina.org/donations/",
          "note": "Free volunteer project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:31.323Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "rustdesk",
      "category": "remote-desktop",
      "name": "RustDesk",
      "description": "Open-source remote desktop software that works with RustDesk's public relay servers or a self-hosted server, with a paid Pro server edition for teams.",
      "website": "https://rustdesk.com",
      "source": "https://github.com/rustdesk/rustdesk",
      "license": "AGPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "SG",
        "name": "Singapore",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "RustDesk scores 50 out of 100 (grade D) on the remote desktop criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Singapore: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/remote-desktop/rustdesk/",
      "markdown": "https://privacyratings.com/remote-desktop/rustdesk/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rustdesk/rustdesk/blob/master/LICENCE",
          "note": "AGPL-3.0 for the client and the self-hosted server; only the optional Pro server is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://rustdesk.com/privacy/",
          "note": "The website uses Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://rustdesk.com/pricing/",
          "note": "Funded by paid Pro server licenses, and the privacy policy states personal data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:31.497Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "teamviewer",
      "category": "remote-desktop",
      "name": "TeamViewer",
      "description": "Proprietary remote access and support software that connects to computers and mobile devices through TeamViewer's relay servers, free for personal use and paid for commercial use.",
      "website": "https://www.teamviewer.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "TeamViewer scores 30 out of 100 (grade F) on the remote desktop criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets independent audit. It does not meet open source and no trackers or telemetry. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/remote-desktop/teamviewer/",
      "markdown": "https://privacyratings.com/remote-desktop/teamviewer/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.teamviewer.com/en/legal/privacy-and-cookies/",
          "note": "The website loads Adobe, Facebook and LinkedIn trackers, and the privacy policy describes analysis of product usage data, including in the free version."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.teamviewer.com/en-us/pricing/overview/",
          "note": "Funded by paid licenses with no ads in the software, and the privacy policy states personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://media.teamviewer.com/is/content/teamviewergmbh/teamviewer/central-image-hub/pdf/en/teamviewer-type-2-soc-3-report-en.pdf",
          "note": "Only a public SOC 3 summary of the independent SOC 2 audit is published; the full SOC 2 report is not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:58.622Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "tigervnc",
      "category": "remote-desktop",
      "name": "TigerVNC",
      "description": "VNC server and viewer implementation focused on performance, with TLS encryption and extensions for advanced authentication, used for remote access to graphical desktops.",
      "website": "https://tigervnc.org",
      "source": "https://github.com/TigerVNC/tigervnc",
      "license": "GPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "TigerVNC scores 80 out of 100 (grade B) on the remote desktop criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/remote-desktop/tigervnc/",
      "markdown": "https://privacyratings.com/remote-desktop/tigervnc/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TigerVNC/tigervnc/blob/master/LICENCE.TXT",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TigerVNC/tigervnc",
          "note": "No telemetry or analytics in the source code, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/TigerVNC/tigervnc",
          "note": "Free community project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:31.471Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "asuswrt-merlin",
      "category": "router-firmware",
      "name": "Asuswrt-Merlin",
      "description": "Customized version of the stock Asus router firmware that fixes known issues and adds features such as user scripts and extended VPN options, while keeping Asus features and hardware acceleration.",
      "website": "https://www.asuswrt-merlin.net",
      "source": "https://github.com/RMerl/asuswrt-merlin.ng",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Asuswrt-Merlin scores 35 out of 100 (grade F) on the router firmware criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/router-firmware/asuswrt-merlin/",
      "markdown": "https://privacyratings.com/router-firmware/asuswrt-merlin/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/RMerl/asuswrt-merlin.ng/blob/main/README.proprietary",
          "note": "GPL-2.0 base, but includes proprietary binary components from Asus, Broadcom, Trend Micro and Tuxera."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.asuswrt-merlin.net/",
          "note": "The website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.asuswrt-merlin.net/",
          "note": "Developed by an independent developer and supported by PayPal donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:31.479Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "dd-wrt",
      "category": "router-firmware",
      "name": "DD-WRT",
      "description": "Linux-based replacement firmware for wireless routers, with a web interface for VPN, access control, bandwidth monitoring and quality of service.",
      "website": "https://dd-wrt.com",
      "source": "https://svn.dd-wrt.com/browser",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "DD-WRT scores 40 out of 100 (grade D) on the router firmware criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law.",
      "url": "https://privacyratings.com/router-firmware/dd-wrt/",
      "markdown": "https://privacyratings.com/router-firmware/dd-wrt/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://svn.dd-wrt.com/browser",
          "note": "GPL-2.0, based on Linux; source is in the official Subversion repository."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://dd-wrt.com/privacy-policy/",
          "note": "The website loads Google Analytics (Site Kit) and Google AdSense."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://dd-wrt.com/",
          "note": "The firmware has no ads, but the website shows Google AdSense ads, non-personalized unless cookies are accepted; also funded by paid professional licenses."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:58.254Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "freshtomato",
      "category": "router-firmware",
      "name": "FreshTomato",
      "description": "Linux-based replacement firmware for Broadcom-based routers, with a web interface for VPN, bandwidth monitoring, quality of service and access control.",
      "website": "https://freshtomato.org",
      "source": "https://github.com/FreshTomato-Project/freshtomato-arm",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "FreshTomato scores 65 out of 100 (grade C) on the router firmware criteria. It meets 2 of 4 criteria: no trackers or telemetry and no ads or data sales. It partly meets open source. It does not meet independent audit.",
      "url": "https://privacyratings.com/router-firmware/freshtomato/",
      "markdown": "https://privacyratings.com/router-firmware/freshtomato/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/FreshTomato-Project/freshtomato-arm/blob/arm-master/LICENSE.md",
          "note": "GPL-3.0, but some Broadcom wireless and acceleration drivers are included only as prebuilt binaries."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/FreshTomato-Project/freshtomato-arm",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://freshtomato.org/donations.html",
          "note": "Volunteer project funded by donations through PayPal, GitHub Sponsors, Patreon and Bitcoin, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:31.610Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "gargoyle",
      "category": "router-firmware",
      "name": "Gargoyle",
      "description": "Router firmware based on OpenWrt with a web interface focused on ease of use, offering per-device bandwidth monitoring, quotas, quality of service, website blocking and VPN.",
      "website": "https://www.gargoyle-router.com",
      "source": "https://github.com/ericpaulbishop/gargoyle",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Gargoyle scores 50 out of 100 (grade D) on the router firmware criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/router-firmware/gargoyle/",
      "markdown": "https://privacyratings.com/router-firmware/gargoyle/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ericpaulbishop/gargoyle/tree/master/LICENSES",
          "note": "GPL-2.0, with some components under LGPL-2.1, MIT and BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.gargoyle-router.com/donate.php",
          "note": "Pages of the website, such as the donation page, load Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.gargoyle-router.com/donate.php",
          "note": "Funded by donations and sales of routers with Gargoyle pre-installed, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:31.757Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "openwrt",
      "category": "router-firmware",
      "name": "OpenWrt",
      "description": "Linux distribution for routers and embedded network devices, with a writable file system, a package manager with thousands of add-on packages, and a web interface.",
      "website": "https://openwrt.org",
      "source": "https://github.com/openwrt/openwrt",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "OpenWrt scores 80 out of 100 (grade B) on the router firmware criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/router-firmware/openwrt/",
      "markdown": "https://privacyratings.com/router-firmware/openwrt/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/openwrt/openwrt/blob/main/COPYING",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://openwrt.org/privacy",
          "note": "The firmware has no telemetry, and the privacy policy states the website does no user tracking and sends no personal data to third parties."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://openwrt.org/donate",
          "note": "Volunteer project funded by donations, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:58.595Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "goodbye-dpi",
      "category": "network-analysis",
      "name": "GoodbyeDPI",
      "description": "Windows utility that circumvents deep packet inspection (DPI) censorship by modifying outgoing packets, blocking passive DPI redirects and working around active DPI blocking.",
      "website": "https://github.com/ValdikSS/GoodbyeDPI",
      "source": "https://github.com/ValdikSS/GoodbyeDPI",
      "license": "Apache-2.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "GoodbyeDPI scores 80 out of 100 (grade B) on the network analysis criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/network-analysis/goodbye-dpi/",
      "markdown": "https://privacyratings.com/network-analysis/goodbye-dpi/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ValdikSS/GoodbyeDPI/blob/master/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ValdikSS/GoodbyeDPI",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/ValdikSS/GoodbyeDPI",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:58.207Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mitmproxy",
      "category": "network-analysis",
      "name": "mitmproxy",
      "description": "Interactive HTTPS proxy for intercepting, inspecting, modifying and replaying web traffic, with a console interface, a web interface and a Python scripting API.",
      "website": "https://www.mitmproxy.org",
      "source": "https://github.com/mitmproxy/mitmproxy",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "mitmproxy scores 80 out of 100 (grade B) on the network analysis criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/network-analysis/mitmproxy/",
      "markdown": "https://privacyratings.com/network-analysis/mitmproxy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mitmproxy/mitmproxy/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mitmproxy/mitmproxy",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.mitmproxy.org/",
          "note": "Funded by grants from NLnet and GitHub Sponsors donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:31.742Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "nmap",
      "category": "network-analysis",
      "name": "Nmap",
      "description": "Network scanner for host discovery, port scanning, service and operating system detection, with a scripting engine for further checks and the Zenmap graphical interface.",
      "website": "https://nmap.org",
      "source": "https://github.com/nmap/nmap",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Nmap scores 50 out of 100 (grade D) on the network analysis criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/network-analysis/nmap/",
      "markdown": "https://privacyratings.com/network-analysis/nmap/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://nmap.org/npsl/",
          "note": "All code is public under the Nmap Public Source License, a source-available license that is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://nmap.org/",
          "note": "The scanner has no telemetry, but the website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://nmap.org/oem/",
          "note": "Funded by selling commercial OEM redistribution licenses, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:31.842Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "ooni",
      "category": "network-analysis",
      "name": "OONI",
      "description": "Free software and global measurement network that tests websites, apps and networks for censorship, blocking and traffic manipulation, and publishes the results as open data.",
      "website": "https://ooni.org",
      "source": "https://github.com/ooni/probe-cli",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "OONI scores 85 out of 100 (grade B) on the network analysis criteria. It meets 3 of 4 criteria: open source, no ads or data sales and independent audit. It partly meets no trackers or telemetry.",
      "url": "https://privacyratings.com/network-analysis/ooni/",
      "markdown": "https://privacyratings.com/network-analysis/ooni/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ooni/probe-cli/blob/master/LICENSE",
          "note": "GPL-3.0; the probe engine and the multiplatform apps are both GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://ooni.org/about/data-policy/",
          "note": "No third-party trackers. The website uses cookieless Umami Cloud analytics by default, OONI Explorer uses Sentry, and crash reporting in the apps is opt-in."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ooni.org/about/supporters/",
          "note": "Non-profit project funded by grants and donations, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ooni.org/documents/ooni-penetration-test-report.pdf",
          "note": "Full penetration test report by Radically Open Security covering the OONI API, backend and OONI Run."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:58.943Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "proxy-checker",
      "category": "network-analysis",
      "name": "Proxy Checker",
      "description": "Free web tool from ping.eu that checks whether a given host and port run an open proxy server, alongside other online network tools such as ping, traceroute and WHOIS.",
      "website": "https://ping.eu/proxy",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Proxy Checker scores 0 out of 100 (grade F) on the network analysis criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/network-analysis/proxy-checker/",
      "markdown": "https://privacyratings.com/network-analysis/proxy-checker/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google AdSense (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://ping.eu/proxy/",
          "note": "The site is funded by Google AdSense advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:59.335Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sniffnet",
      "category": "network-analysis",
      "name": "Sniffnet",
      "description": "Desktop application for monitoring network traffic, showing connections, hosts, applications and data usage in real time, with filters, charts and notifications.",
      "website": "https://sniffnet.app",
      "source": "https://github.com/GyulyVGC/sniffnet",
      "license": "Apache-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 100,
      "coverage": 100,
      "summary": "Sniffnet scores 100 out of 100 (grade A) on the network analysis criteria. It meets 4 of 4 criteria: open source, no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/network-analysis/sniffnet/",
      "markdown": "https://privacyratings.com/network-analysis/sniffnet/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/GyulyVGC/sniffnet/blob/main/LICENSE-MIT",
          "note": "Dual-licensed under MIT or Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/GyulyVGC/sniffnet",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/GyulyVGC/sniffnet/blob/main/.github/FUNDING.yml",
          "note": "Funded through GitHub Sponsors, Patreon and PayPal donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/GyulyVGC/sniffnet/blob/main/resources/audits/security_1.pdf",
          "note": "Full audit report by Radically Open Security, funded through the NGI programme."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:32.616Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "wireshark",
      "category": "network-analysis",
      "name": "Wireshark",
      "description": "Network protocol analyzer that captures network traffic and lets users inspect packets across hundreds of protocols, live or from saved capture files.",
      "website": "https://www.wireshark.org",
      "source": "https://gitlab.com/wireshark/wireshark",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Wireshark scores 50 out of 100 (grade D) on the network analysis criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/network-analysis/wireshark/",
      "markdown": "https://privacyratings.com/network-analysis/wireshark/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/wireshark/wireshark/-/blob/master/COPYING",
          "note": "GPL-2.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.wireshark.org/",
          "note": "The application has no telemetry, but the website loads Google Analytics and Cloudflare Web Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://wiresharkfoundation.org/about/",
          "note": "Maintained by the non-profit Wireshark Foundation, funded by donations and memberships, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:31.959Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "kismet",
      "category": "intrusion-detection",
      "name": "Kismet",
      "description": "A wireless network detector, sniffer and wireless intrusion detection system for Wi-Fi, Bluetooth, Zigbee and other radio protocols, running on Linux and macOS.",
      "website": "https://www.kismetwireless.net",
      "source": "https://github.com/kismetwireless/kismet",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Kismet scores 80 out of 100 (grade B) on the intrusion detection criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/intrusion-detection/kismet/",
      "markdown": "https://privacyratings.com/intrusion-detection/kismet/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/kismetwireless/kismet/blob/master/LICENSE",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/kismetwireless/kismet",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/kismetwireless/kismet/blob/master/.github/FUNDING.yml",
          "note": "Funded through GitHub Sponsors and Patreon, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:58.848Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ossec",
      "category": "intrusion-detection",
      "name": "OSSEC",
      "description": "An open source host-based intrusion detection system that performs log analysis, file integrity checking, rootkit detection, real-time alerting and active response.",
      "website": "https://www.ossec.net",
      "source": "https://github.com/ossec/ossec-hids",
      "license": "GPL-2.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "OSSEC scores 50 out of 100 (grade D) on the intrusion detection criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/intrusion-detection/ossec/",
      "markdown": "https://privacyratings.com/intrusion-detection/ossec/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ossec/ossec-hids/blob/main/LICENSE",
          "note": "GPL-2.0 and BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Analytics and Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ossec.net/products/",
          "note": "Development is funded by Atomicorp's commercial OSSEC products and support, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:01.672Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "picosnitch",
      "category": "intrusion-detection",
      "name": "picosnitch",
      "description": "A Linux tool that monitors which programs connect to the internet and records when they connect, how much data they transfer and to where.",
      "website": "https://elesiuta.github.io/picosnitch",
      "source": "https://github.com/elesiuta/picosnitch",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "picosnitch scores 80 out of 100 (grade B) on the intrusion detection criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/intrusion-detection/picosnitch/",
      "markdown": "https://privacyratings.com/intrusion-detection/picosnitch/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/elesiuta/picosnitch/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/elesiuta/picosnitch",
          "note": "No telemetry or analytics in the source code. Optional VirusTotal lookups and GeoIP downloads are off by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/elesiuta/picosnitch",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:59.212Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "security-onion",
      "category": "intrusion-detection",
      "name": "Security Onion",
      "description": "Linux distribution for threat hunting, network security monitoring and log management that bundles tools such as Suricata, Zeek and Elasticsearch with its own web console.",
      "website": "https://securityonionsolutions.com",
      "source": "https://github.com/Security-Onion-Solutions/securityonion",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Security Onion scores 50 out of 100 (grade D) on the intrusion detection criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/intrusion-detection/security-onion/",
      "markdown": "https://privacyratings.com/intrusion-detection/security-onion/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Security-Onion-Solutions/securityonion/blob/3/main/LICENSE",
          "note": "All code is public under the source-available Elastic License 2.0, which is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://docs.securityonion.net/en/3/main/telemetry/",
          "note": "Console telemetry, chosen during setup, sends feature usage data to Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://securityonionsolutions.com/pro/",
          "note": "Funded by Security Onion Pro licenses, hardware appliances, training and support, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:32.008Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "snare",
      "category": "intrusion-detection",
      "name": "Snare",
      "description": "A commercial log management suite whose agents collect operating system audit and event logs and forward them to a central server for analysis and compliance reporting.",
      "website": "https://www.snaresolutions.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "AU",
        "name": "Australia",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Snare scores 20 out of 100 (grade F) on the intrusion detection criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in Australia: Five Eyes member; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/intrusion-detection/snare/",
      "markdown": "https://privacyratings.com/intrusion-detection/snare/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Tag Manager and LinkedIn Insight."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.snaresolutions.com/request-pricing/",
          "note": "Funded by commercial licenses."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "snap.licdn.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:00.194Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "suricata",
      "category": "intrusion-detection",
      "name": "Suricata",
      "description": "Network intrusion detection and prevention engine and network security monitoring tool that inspects traffic against rule sets and logs protocol events and alerts.",
      "website": "https://suricata.io",
      "source": "https://github.com/OISF/suricata",
      "license": "GPL-2.0",
      "platforms": [
        "linux",
        "windows",
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Suricata scores 50 out of 100 (grade D) on the intrusion detection criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/intrusion-detection/suricata/",
      "markdown": "https://privacyratings.com/intrusion-detection/suricata/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/OISF/suricata/blob/main/LICENSE",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://suricata.io/privacy-policy/",
          "note": "The engine has no telemetry, but the website privacy policy lists Google Analytics, Google AdWords and Facebook tracking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://oisf.net/",
          "note": "Developed by the non-profit Open Information Security Foundation, funded by consortium memberships and training, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:32.210Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "wazuh",
      "category": "intrusion-detection",
      "name": "Wazuh",
      "description": "Security platform for threat detection, integrity monitoring, log analysis, vulnerability detection and compliance, using agents on endpoints that report to a central server and dashboard.",
      "website": "https://wazuh.com",
      "source": "https://github.com/wazuh/wazuh",
      "license": null,
      "platforms": [
        "linux",
        "windows",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Wazuh scores 50 out of 100 (grade D) on the intrusion detection criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/intrusion-detection/wazuh/",
      "markdown": "https://privacyratings.com/intrusion-detection/wazuh/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/wazuh/wazuh/blob/main/LICENSE",
          "note": "GPL-2.0 for the agent and server; the indexer and dashboard are Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://wazuh.com/privacy-policy/",
          "note": "The website loads Google Tag Manager, and the privacy policy names Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://wazuh.com/services/professional-support/",
          "note": "Funded by paid support, professional services and the hosted Wazuh Cloud, with no ads; the privacy policy says personal data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:32.177Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "android",
      "category": "mobile-operating-systems",
      "name": "Android",
      "description": "Google's mobile operating system, shipped on Pixel phones with Google Mobile Services such as Google Play, Play services and Google apps on top of the open source Android base.",
      "website": "https://www.android.com",
      "source": "https://android.googlesource.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Android scores 25 out of 100 (grade F) on the mobile operating systems criteria. It partly meets open source and independent audit. It does not meet no trackers or telemetry and no ads or data sales. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/mobile-operating-systems/android/",
      "markdown": "https://privacyratings.com/mobile-operating-systems/android/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://android.googlesource.com/",
          "note": "The Android Open Source Project is mostly Apache-2.0, but Google Play services, Google apps and parts of the Pixel software are closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://support.google.com/accounts/answer/6078260",
          "note": "Google Play services and Google apps send usage and device data to Google, and some data is sent even with usage and diagnostics turned off; the website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/technologies/ads",
          "note": "Google is funded by advertising and uses an advertising ID and account data for ad targeting."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://services.google.com/fh/files/misc/2026_android_security_paper.pdf",
          "note": "Android devices hold Common Criteria and FIPS 140 certifications from accredited labs, but no full audit report is published by Google."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:32.575Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "calyxos",
      "category": "mobile-operating-systems",
      "name": "CalyxOS",
      "description": "An open source, de-Googled Android OS with optional microG, a built-in firewall and encrypted backups.",
      "website": "https://calyxos.org",
      "source": "https://gitlab.com/CalyxOS",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "CalyxOS scores 80 out of 100 (grade B) on the mobile operating systems criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/mobile-operating-systems/calyxos/",
      "markdown": "https://privacyratings.com/mobile-operating-systems/calyxos/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/CalyxOS",
          "note": "Based on the Android Open Source Project, mostly Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://calyxos.org/docs/guide/security/network-activity/",
          "note": "No analytics or telemetry. Default network connections are documented and limited to updates, connectivity checks and optional services."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://members.calyx.org/donate",
          "note": "Developed by the non-profit Calyx Institute and funded by donations and memberships."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:59.928Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "e-os",
      "category": "mobile-operating-systems",
      "name": "/e/OS",
      "description": "Android-based mobile operating system without Google apps or services, using microG for app compatibility and shipping its own app store, privacy controls and optional Murena cloud services.",
      "website": "https://e.foundation/e-os/",
      "source": "https://gitlab.e.foundation/e",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "/e/OS scores 50 out of 100 (grade D) on the mobile operating systems criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source and no trackers or telemetry. It does not meet independent audit. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/mobile-operating-systems/e-os/",
      "markdown": "https://privacyratings.com/mobile-operating-systems/e-os/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://doc.e.foundation/os/apps/maps/",
          "note": "Built from open source code, but the default Magic Earth maps app is proprietary."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://e.foundation/legal-notice-privacy/",
          "note": "No third-party trackers; the website uses self-hosted Matomo, and update servers collect statistics for internal use."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://e.foundation/legal-notice-privacy/",
          "note": "Funded by sales of Murena phones and cloud plans and by donations; the privacy policy says data is never sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:33.390Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "grapheneos",
      "category": "mobile-operating-systems",
      "name": "GrapheneOS",
      "description": "A privacy and security focused mobile operating system with Android app compatibility, developed as a non-profit open source project for Google Pixel devices.",
      "website": "https://grapheneos.org",
      "source": "https://github.com/GrapheneOS",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": true,
      "pick_reason": "Hardened Android for Pixel phones with no Google services by default, sandboxed Google Play only if you choose it, and no analytics or telemetry. Open source and funded by donations.",
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "GrapheneOS scores 80 out of 100 (grade B) on the mobile operating systems criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mobile-operating-systems/grapheneos/",
      "markdown": "https://privacyratings.com/mobile-operating-systems/grapheneos/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://grapheneos.org/faq#copyright-and-licensing",
          "note": "Released under OSI-approved licenses, inherited from upstream projects or MIT for its own projects."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://grapheneos.org/faq#default-connections",
          "note": "No analytics or telemetry. Default connections are limited to GrapheneOS update and service servers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://grapheneos.org/donate",
          "note": "Funded by donations to the non-profit GrapheneOS Foundation."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit report is published. The project relies on continuous public code review."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:59.938Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "iodeos",
      "category": "mobile-operating-systems",
      "name": "iodéOS",
      "description": "Android-based mobile operating system derived from LineageOS, without Google apps, with microG and a built-in blocker that filters ads and trackers across all apps.",
      "website": "https://iode.tech",
      "source": "https://gitlab.iode.tech",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "iodéOS scores 80 out of 100 (grade B) on the mobile operating systems criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/mobile-operating-systems/iodeos/",
      "markdown": "https://privacyratings.com/mobile-operating-systems/iodeos/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.iode.tech/os/public/blocker/iode/-/blob/main/LICENSE",
          "note": "Based on LineageOS under Apache-2.0; the iodé blocker app is AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://iode.tech/privacy-policy/",
          "note": "No third-party trackers. The website's self-hosted Matomo has tracking cookies disabled and anonymizes IP addresses."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://iode.tech/documentation/faq/",
          "note": "Funded by sales of phones with iodéOS preinstalled and by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:33.479Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "ios",
      "category": "mobile-operating-systems",
      "name": "iOS",
      "description": "Apple's closed source operating system for the iPhone, with the App Store as the main app source and integration with iCloud and other Apple services.",
      "website": "https://www.apple.com/os/ios/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "iOS scores 35 out of 100 (grade F) on the mobile operating systems criteria. It partly meets no trackers or telemetry, no ads or data sales and independent audit. It does not meet open source. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/mobile-operating-systems/ios/",
      "markdown": "https://privacyratings.com/mobile-operating-systems/ios/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://opensource.apple.com/",
          "note": "Closed source; Apple publishes only some components, such as the Darwin kernel and WebKit."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/device-analytics/",
          "note": "No third-party trackers in the system; Apple collects first-party analytics, and device analytics sharing can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/apple-advertising/",
          "note": "Apple shows its own ads in the App Store, News, Stocks, Maps and TV apps; personalized ads can be turned off and Apple states it does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.apple.com/guide/certifications/ios-security-certifications-apc3fa917cb49/web",
          "note": "iOS holds Common Criteria and FIPS 140-3 certifications from accredited labs, but Apple publishes the certification list rather than a full audit report."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:32.675Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "lineageos",
      "category": "mobile-operating-systems",
      "name": "LineageOS",
      "description": "A free and open source operating system based on Android that supports many phones and tablets, including ones no longer updated by their manufacturers.",
      "website": "https://www.lineageos.org",
      "source": "https://github.com/LineageOS",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": true,
      "pick_reason": "Keeps many phones beyond Pixels updated with open-source, Google-free Android. Anonymous device statistics are on by default and can be turned off.",
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "LineageOS scores 65 out of 100 (grade C) on the mobile operating systems criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/mobile-operating-systems/lineageos/",
      "markdown": "https://privacyratings.com/mobile-operating-systems/lineageos/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/LineageOS",
          "note": "Based on the Android Open Source Project, mostly Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.lineageos.org/legal/",
          "note": "Anonymous device statistics are sent by default and can be turned off in the privacy settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.lineageos.org/legal/",
          "note": "Funded by donations through PayPal and Patreon, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:00.504Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nura",
      "category": "mobile-operating-systems",
      "name": "Nura",
      "description": "Linux distribution for phones and other mobile devices, formerly named postmarketOS, based on Alpine Linux and aiming to keep devices usable long after vendor support ends, with a choice of mobile interfaces.",
      "website": "https://nura.eco",
      "source": "https://gitlab.postmarketos.org/postmarketOS",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Nura scores 80 out of 100 (grade B) on the mobile operating systems criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/mobile-operating-systems/nura/",
      "markdown": "https://privacyratings.com/mobile-operating-systems/nura/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.postmarketos.org/postmarketOS/pmaports/-/blob/main/LICENSE",
          "note": "GPL-3.0 for the project's packaging and tools, on top of open source Alpine Linux packages; some devices need proprietary firmware."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://nura.eco/privacy-policy/",
          "note": "No telemetry in the system, and the privacy policy states the website processes no personal data and uses no cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/postmarketOS",
          "note": "Community project funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:33.550Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "sailfish-os",
      "category": "mobile-operating-systems",
      "name": "Sailfish OS",
      "description": "Linux-based mobile operating system developed by Jolla, with a gesture-based interface and optional Android app support, available on Jolla phones and as a paid license for selected Sony Xperia models.",
      "website": "https://sailfishos.org",
      "source": "https://github.com/sailfishos",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "FI",
        "name": "Finland",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Sailfish OS scores 50 out of 100 (grade D) on the mobile operating systems criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source and no trackers or telemetry. It does not meet independent audit. It is based in Finland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/mobile-operating-systems/sailfish-os/",
      "markdown": "https://privacyratings.com/mobile-operating-systems/sailfish-os/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://docs.sailfishos.org/Develop/Collaborate/",
          "note": "Mainly open source, but parts such as the Silica user interface and Android App Support are closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://jolla.com/privacy-policy/",
          "note": "No third-party trackers found; Jolla collects anonymous usage data about its services, and the website uses Plausible analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://jolla.com/privacy-policy/",
          "note": "Funded by sales of Sailfish OS licenses and devices; the privacy policy says the business is not built on monetizing personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:33.456Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "ubuntu-touch",
      "category": "mobile-operating-systems",
      "name": "Ubuntu Touch",
      "description": "Mobile operating system for phones and tablets developed by the UBports community, using the Lomiri interface and running on devices originally shipped with Android.",
      "website": "https://ubports.com",
      "source": "https://gitlab.com/ubports",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Ubuntu Touch scores 65 out of 100 (grade C) on the mobile operating systems criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/mobile-operating-systems/ubuntu-touch/",
      "markdown": "https://privacyratings.com/mobile-operating-systems/ubuntu-touch/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/ubports/development/core/lomiri/-/blob/main/COPYING",
          "note": "Mostly GPL-3.0 and LGPL; device support relies on proprietary Android vendor drivers."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://ubports.com/",
          "note": "No telemetry in the system; the website uses Matomo analytics, self-hosted and also sent to the Matomo instance of its web host Onestein."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ubports.com/donate",
          "note": "Developed by the non-profit UBports Foundation and funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:33.136Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "anysoftkeyboard",
      "category": "keyboards",
      "name": "AnySoftKeyboard",
      "description": "Open source keyboard for Android with add-on packs for languages, layouts and themes, gesture typing, voice input and a clipboard manager.",
      "website": "https://anysoftkeyboard.github.io",
      "source": "https://github.com/AnySoftKeyboard/AnySoftKeyboard",
      "license": "Apache-2.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "AnySoftKeyboard scores 85 out of 100 (grade B) on the mobile keyboards criteria. It meets 4 of 5 criteria: open source, no trackers or telemetry, no ads or data sales and works offline. It does not meet independent audit.",
      "url": "https://privacyratings.com/keyboards/anysoftkeyboard/",
      "markdown": "https://privacyratings.com/keyboards/anysoftkeyboard/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/AnySoftKeyboard/AnySoftKeyboard/blob/main/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.menny.android.anysoftkeyboard/latest/",
          "note": "Exodus found no trackers, and the app has no network permission."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/AnySoftKeyboard/AnySoftKeyboard/blob/main/.github/FUNDING.yml",
          "note": "Funded through GitHub Sponsors and PayPal donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/AnySoftKeyboard/AnySoftKeyboard/blob/main/ime/app/src/main/AndroidManifest.xml",
          "note": "The app does not request the internet permission."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:33.259Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "florisboard",
      "category": "keyboards",
      "name": "FlorisBoard",
      "description": "Open source keyboard for Android with glide typing, clipboard manager, emoji panel, themes and extension support, with no network access.",
      "website": "https://florisboard.org",
      "source": "https://github.com/florisboard/florisboard",
      "license": "Apache-2.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "FlorisBoard scores 85 out of 100 (grade B) on the mobile keyboards criteria. It meets 4 of 5 criteria: open source, no trackers or telemetry, no ads or data sales and works offline. It does not meet independent audit.",
      "url": "https://privacyratings.com/keyboards/florisboard/",
      "markdown": "https://privacyratings.com/keyboards/florisboard/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/florisboard/florisboard/blob/main/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/dev.patrickgold.florisboard/latest/",
          "note": "Exodus found no trackers, and the app has no network permission."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/florisboard/florisboard/blob/main/.github/FUNDING.yml",
          "note": "Funded through GitHub Sponsors, Liberapay and PayPal donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/florisboard/florisboard/blob/main/app/src/main/AndroidManifest.xml",
          "note": "The app does not request the internet permission."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:33.675Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "futo-keyboard",
      "category": "keyboards",
      "name": "FUTO Keyboard",
      "description": "Android keyboard with on-device word prediction, swipe typing and offline voice input, built without network access.",
      "website": "https://keyboard.futo.tech",
      "source": "https://gitlab.futo.org/keyboard/latinime",
      "license": null,
      "platforms": [
        "android"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "FUTO Keyboard scores 85 out of 100 (grade B) on the mobile keyboards criteria. It meets 4 of 5 criteria: open source, no trackers or telemetry, no ads or data sales and works offline. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/keyboards/futo-keyboard/",
      "markdown": "https://privacyratings.com/keyboards/futo-keyboard/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.futo.org/keyboard/latinime/-/blob/master/LICENSE.md",
          "note": "All code is public under the source-available FUTO Source First License, which is not OSI-approved and limits commercial modification."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.futo.inputmethod.latin.playstore/latest/",
          "note": "Exodus found no trackers, and the app has no network permission."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://keyboard.futo.tech/",
          "note": "Funded by optional one-time license payments and by FUTO, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://keyboard.futo.tech/privacy",
          "note": "The app does not request the network permission; dictionary and model downloads open in the browser."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:33.517Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "gboard",
      "category": "keyboards",
      "name": "Gboard",
      "description": "Google's keyboard app for Android and iOS, with glide typing, voice typing, built-in Google search, translation, emoji and GIF search.",
      "website": "https://play.google.com/store/apps/details?id=com.google.android.inputmethod.latin",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 12,
      "coverage": 100,
      "summary": "Gboard scores 12 out of 100 (grade F) on the mobile keyboards criteria. It partly meets no trackers or telemetry. It does not meet open source, no ads or data sales, independent audit and works offline. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/keyboards/gboard/",
      "markdown": "https://privacyratings.com/keyboards/gboard/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://support.google.com/gboard/answer/12373137",
          "note": "Exodus found no third-party trackers, but Gboard sends federated learning data from typing to Google by default, which can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/technologies/ads",
          "note": "The app shows no ads, but it is a free Google product funded by Google's advertising business."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 3,
          "answer": "no",
          "evidence": "https://support.google.com/gboard/answer/12373137",
          "note": "Has network access and sends learnings from typing to Google through federated learning by default."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:33.457Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "heliboard",
      "category": "keyboards",
      "name": "HeliBoard",
      "description": "Open source keyboard for Android based on AOSP LatinIME, with themes, clipboard history, multilingual typing and optional glide typing through a user-supplied library, without network access.",
      "website": "https://github.com/Helium314/HeliBoard",
      "source": "https://github.com/Helium314/HeliBoard",
      "license": "GPL-3.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "HeliBoard scores 85 out of 100 (grade B) on the mobile keyboards criteria. It meets 4 of 5 criteria: open source, no trackers or telemetry, no ads or data sales and works offline. It does not meet independent audit.",
      "url": "https://privacyratings.com/keyboards/heliboard/",
      "markdown": "https://privacyratings.com/keyboards/heliboard/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Helium314/HeliBoard/blob/main/LICENSE",
          "note": "GPL-3.0, with parts inherited from AOSP under Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/helium314.keyboard/latest/",
          "note": "Exodus found no trackers, and the app has no network permission."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Helium314/HeliBoard/blob/main/.github/FUNDING.yml",
          "note": "Volunteer project supported by Liberapay donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Helium314/HeliBoard/blob/main/app/src/main/AndroidManifest.xml",
          "note": "The app does not request the internet permission."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:33.457Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "microsoft-swiftkey",
      "category": "keyboards",
      "name": "Microsoft SwiftKey",
      "description": "Microsoft's keyboard app for Android and iOS, with learned word predictions, swipe typing, cloud backup through a Microsoft account, and built-in Copilot and Bing features.",
      "website": "https://www.microsoft.com/en-us/swiftkey",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Microsoft SwiftKey scores 0 out of 100 (grade F) on the mobile keyboards criteria. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit and works offline. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/keyboards/microsoft-swiftkey/",
      "markdown": "https://privacyratings.com/keyboards/microsoft-swiftkey/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.touchtype.swiftkey/latest/",
          "note": "Exodus found Adjust, Google Analytics, Google Crashlytics and Google Tag Manager in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "The app bundles the Adjust ad attribution SDK, and Microsoft's privacy statement covers using data for personalized advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "Has network access for built-in cloud features such as Copilot, Bing, GIF search and backup, and can send typing snippets to Microsoft when opted in."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Impact",
            "host": "d.impactradius-event.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Ads",
            "host": "bat.bing.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Clarity",
            "host": "www.clarity.ms",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:34.693Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "simple-keyboard",
      "category": "keyboards",
      "name": "Simple Keyboard",
      "description": "Minimal open source keyboard for Android with a number row, adjustable height, custom colors and cursor movement by swiping the space bar, requesting only the vibrate permission.",
      "website": "https://github.com/rkkr/simple-keyboard",
      "source": "https://github.com/rkkr/simple-keyboard",
      "license": "Apache-2.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "Simple Keyboard scores 85 out of 100 (grade B) on the mobile keyboards criteria. It meets 4 of 5 criteria: open source, no trackers or telemetry, no ads or data sales and works offline. It does not meet independent audit.",
      "url": "https://privacyratings.com/keyboards/simple-keyboard/",
      "markdown": "https://privacyratings.com/keyboards/simple-keyboard/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rkkr/simple-keyboard/blob/master/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/rkr.simplekeyboard.inputmethod/latest/",
          "note": "Exodus found no trackers, and the app has no network permission."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/rkkr/simple-keyboard",
          "note": "Free volunteer project that states it is ad-free."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rkkr/simple-keyboard/blob/master/app/src/main/AndroidManifest.xml",
          "note": "The app requests only the vibrate permission and has no internet access."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:33.480Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "thumb-key",
      "category": "keyboards",
      "name": "Thumb-Key",
      "description": "Open source Android keyboard with a compact 3x3 key grid and swipe gestures designed for typing with the thumbs, with layouts for many languages.",
      "website": "https://github.com/dessalines/thumb-key",
      "source": "https://github.com/dessalines/thumb-key",
      "license": "AGPL-3.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "Thumb-Key scores 85 out of 100 (grade B) on the mobile keyboards criteria. It meets 4 of 5 criteria: open source, no trackers or telemetry, no ads or data sales and works offline. It does not meet independent audit.",
      "url": "https://privacyratings.com/keyboards/thumb-key/",
      "markdown": "https://privacyratings.com/keyboards/thumb-key/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dessalines/thumb-key/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.dessalines.thumbkey/latest/",
          "note": "Exodus found no trackers, and the app has no network permission."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/dessalines/thumb-key",
          "note": "Funded by donations through Liberapay and other platforms, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dessalines/thumb-key/blob/main/app/src/main/AndroidManifest.xml",
          "note": "The app does not request the internet permission."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:33.480Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "alpine-linux",
      "category": "desktop-operating-systems",
      "name": "Alpine Linux",
      "description": "Alpine is a security-oriented, lightweight distro based on musl libc and busybox. It compiles all user-space binaries as position-independent executables with stack-smashing protection.",
      "website": "https://www.alpinelinux.org",
      "source": "https://gitlab.alpinelinux.org/alpine/aports",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Alpine Linux scores 80 out of 100 (grade B) on the desktop operating systems criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/desktop-operating-systems/alpine-linux/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/alpine-linux/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.alpinelinux.org/alpine/aports",
          "note": "Built entirely from open source packages. Each package lists its license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/alpinelinux/aports",
          "note": "No telemetry or analytics in the base system."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.alpinelinux.org/sponsors/",
          "note": "Funded by sponsors and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:01.034Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "arch-linux",
      "category": "desktop-operating-systems",
      "name": "Arch Linux",
      "description": "A minimal, rolling-release Linux distribution for x86-64 that users configure themselves, using the pacman package manager and the community Arch User Repository.",
      "website": "https://archlinux.org",
      "source": "https://gitlab.archlinux.org/archlinux",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Arch Linux scores 80 out of 100 (grade B) on the desktop operating systems criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/desktop-operating-systems/arch-linux/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/arch-linux/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.archlinux.org/pacman/pacman/-/blob/master/COPYING",
          "note": "Built from open source packages; pacman is GPL-2.0 or later. The repositories also carry some proprietary drivers."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://wiki.archlinux.org/title/Pkgstats",
          "note": "No trackers on the website and no telemetry by default. Package statistics are only sent if the optional pkgstats package is installed."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://archlinux.org/donate/",
          "note": "Funded by donations through Software in the Public Interest and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:34.796Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "chromeos",
      "category": "desktop-operating-systems",
      "name": "ChromeOS",
      "description": "Google's Linux-based operating system for Chromebooks, built around the Chrome browser and tied to a Google account.",
      "website": "https://chromeos.google",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "ChromeOS scores 0 out of 100 (grade F) on the desktop operating systems criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/desktop-operating-systems/chromeos/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/chromeos/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.chromium.org/chromium-os/",
          "note": "Closed source. It is built on the open source ChromiumOS project, but ChromeOS itself includes proprietary components."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://support.google.com/chromebook/answer/96817",
          "note": "The website loads Google Tag Manager, and ChromeOS sends usage statistics and crash reports to Google unless turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Google's privacy policy, which covers ChromeOS, allows data from its services to be used for personalized advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:33.749Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "debian",
      "category": "desktop-operating-systems",
      "name": "Debian",
      "description": "A community-developed Linux distribution made entirely of free software, known for stable releases and a large package archive, and the base of many other distributions.",
      "website": "https://www.debian.org",
      "source": "https://salsa.debian.org/",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Debian scores 80 out of 100 (grade B) on the desktop operating systems criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/desktop-operating-systems/debian/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/debian/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.debian.org/social_contract",
          "note": "The Debian Social Contract requires the main archive to be entirely free software."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.debian.org/legal/privacy",
          "note": "No trackers on the website. Package usage reporting through popularity-contest requires explicit opt-in."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.debian.org/donations",
          "note": "Funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:33.952Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "elementary-os",
      "category": "desktop-operating-systems",
      "name": "elementary OS",
      "description": "An Ubuntu-based Linux distribution with its own Pantheon desktop and apps, and AppCenter, a store for pay-what-you-want apps and Flatpaks.",
      "website": "https://elementary.io",
      "source": "https://github.com/elementary",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "elementary OS scores 80 out of 100 (grade B) on the desktop operating systems criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/desktop-operating-systems/elementary-os/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/elementary-os/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://elementary.io/open-source",
          "note": "The elementary OS platform is entirely open source and built on free and open source software."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://elementary.io/privacy",
          "note": "No third-party trackers, and the operating system collects no data. The website's Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://elementary.io/privacy",
          "note": "Funded by users paying what they want for the OS and AppCenter apps, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:33.967Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "fedora",
      "category": "desktop-operating-systems",
      "name": "Fedora",
      "description": "A Linux distribution developed by the Fedora Project and sponsored by Red Hat, offering recent software in Workstation, Server and Atomic desktop editions.",
      "website": "https://fedoraproject.org",
      "source": "https://src.fedoraproject.org/",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Fedora scores 65 out of 100 (grade C) on the desktop operating systems criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/desktop-operating-systems/fedora/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/fedora/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://docs.fedoraproject.org/en-US/legal/license-approval/",
          "note": "Only software under licenses approved by Fedora, which are free and open source licenses, is included."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://fedoraproject.org/wiki/Changes/DNF_Better_Counting",
          "note": "No third-party trackers. The package manager sends an anonymous weekly count-me flag to Fedora mirrors by default, which can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://fedoraproject.org/sponsors/",
          "note": "Sponsored by Red Hat and other organizations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:34.012Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "freebsd",
      "category": "desktop-operating-systems",
      "name": "FreeBSD",
      "description": "A Unix-like operating system descended from BSD, developed as a complete system of kernel and userland, with ZFS, jails and the bhyve hypervisor.",
      "website": "https://www.freebsd.org",
      "source": "https://cgit.freebsd.org/src",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 100,
      "coverage": 100,
      "summary": "FreeBSD scores 100 out of 100 (grade A) on the desktop operating systems criteria. It meets 4 of 4 criteria: open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/desktop-operating-systems/freebsd/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/freebsd/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.freebsd.org/copyright/freebsd-license/",
          "note": "BSD-2-Clause for the base system, with some components under other open source licenses."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.freebsd.org/privacy/",
          "note": "No third-party trackers, and the operating system has no telemetry. The website's Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://freebsdfoundation.org/donate-to-freebsd-foundation/",
          "note": "Funded by donations to the FreeBSD Foundation, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://freebsdfoundation.org/wp-content/uploads/2024/11/2024_Code_Audit_Capsicum_Bhyve_FreeBSD_Foundation.pdf",
          "note": "Synacktiv audited the bhyve hypervisor and the Capsicum sandbox, and the full report is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:34.283Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "kicksecure",
      "category": "desktop-operating-systems",
      "name": "Kicksecure",
      "description": "A security-hardened Linux distribution based on Debian, with hardened kernel and system settings, from the developers of Whonix.",
      "website": "https://www.kicksecure.com",
      "source": "https://github.com/Kicksecure/derivative-maker",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "MH",
        "name": "Marshall Islands",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Kicksecure scores 65 out of 100 (grade C) on the desktop operating systems criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the Marshall Islands: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/desktop-operating-systems/kicksecure/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/kicksecure/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/Kicksecure/derivative-maker/master/COPYING",
          "note": "AGPL-3.0 and GPL-2.0 or later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.kicksecure.com/wiki/Census",
          "note": "No third-party analytics. The system fetches a warrant canary over Tor daily, which also counts users, and this can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.kicksecure.com/wiki/Donate",
          "note": "Funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:34.836Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "linux-mint",
      "category": "desktop-operating-systems",
      "name": "Linux Mint",
      "description": "A desktop Linux distribution based on Ubuntu or Debian, with the Cinnamon, MATE and Xfce desktops and its own tools for updates and system settings.",
      "website": "https://linuxmint.com",
      "source": "https://github.com/linuxmint",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Linux Mint scores 30 out of 100 (grade F) on the desktop operating systems criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/desktop-operating-systems/linux-mint/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/linux-mint/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/linuxmint",
          "note": "Linux Mint's own tools are open source, mostly under the GPL, on top of Ubuntu or Debian packages."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://linuxmint.com/privacy.php",
          "note": "The website uses Google Analytics on the browser start pages and Google AdSense cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://linuxmint.com/privacy.php",
          "note": "The website shows Google AdSense ads to help fund the project, alongside donations and sponsors."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:34.745Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "macos",
      "category": "desktop-operating-systems",
      "name": "macOS",
      "description": "Apple's proprietary desktop operating system for Mac computers, built on the open source Darwin core.",
      "website": "https://www.apple.com/os/macos/",
      "license": null,
      "platforms": [
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "macOS scores 35 out of 100 (grade F) on the desktop operating systems criteria. It partly meets no trackers or telemetry, no ads or data sales and independent audit. It does not meet open source. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/desktop-operating-systems/macos/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/macos/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://opensource.apple.com/",
          "note": "Closed source. Apple publishes the source of Darwin and some components, but most of macOS is proprietary."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/en-ww/",
          "note": "No third-party trackers in the app, and sharing device analytics with Apple is opt-in. Apple web pages load Apple's own analytics (ac-analytics, sent to metrics.apple.com) by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/apple-advertising/",
          "note": "Funded by hardware sales. Apple's ad platform shows ads in the App Store, News and Stocks apps; personalized ads can be turned off and Apple does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.niap-ccevs.org/products/11648",
          "note": "Common Criteria evaluations by independent labs are published as certification and validation reports, but no full security audit report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:34.494Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "nixos",
      "category": "desktop-operating-systems",
      "name": "NixOS",
      "description": "A Linux distribution built on the Nix package manager, where the whole system is configured declaratively and upgrades can be rolled back.",
      "website": "https://nixos.org",
      "source": "https://github.com/NixOS/nixpkgs",
      "license": "MIT",
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "NixOS scores 80 out of 100 (grade B) on the desktop operating systems criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the Netherlands: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/desktop-operating-systems/nixos/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/nixos/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/NixOS/nixpkgs/master/COPYING",
          "note": "Nixpkgs and NixOS are MIT-licensed; packaged software keeps its own licenses."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://nixos.org/privacy/",
          "note": "The privacy policy lists only server logs, with no analytics on the website and no telemetry in the operating system."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://nixos.org/backing/",
          "note": "Funded by donations and sponsorships to the NixOS Foundation, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:34.675Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "omarchy",
      "category": "desktop-operating-systems",
      "name": "Omarchy",
      "description": "Opinionated Arch Linux setup built around the Hyprland tiling window manager, with preinstalled apps, themes and AI agent integration. Created by David Heinemeier Hansson and funded by the Omacom Foundation.",
      "website": "https://omarchy.org",
      "source": "https://github.com/omacom/omarchy",
      "license": "MIT",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Omarchy scores 80 out of 100 (grade B) on the desktop operating systems criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/desktop-operating-systems/omarchy/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/omarchy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/omacom/omarchy/blob/HEAD/LICENSE",
          "note": "Omarchy's scripts and configuration are MIT, on top of open source Arch Linux packages. The default install also includes some proprietary apps, such as Obsidian."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/omacom/omarchy",
          "note": "No third-party trackers, and the installed system has no telemetry. The omarchy.org website's Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://omarchy.org/foundation/",
          "note": "Funded by patrons through the nonprofit Omacom Foundation, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:43.237Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "openbsd",
      "category": "desktop-operating-systems",
      "name": "OpenBSD",
      "description": "A security-focused Unix-like operating system descended from BSD, known for code auditing, secure defaults and exploit mitigations such as pledge and unveil.",
      "website": "https://www.openbsd.org",
      "source": "https://cvsweb.openbsd.org/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "OpenBSD scores 80 out of 100 (grade B) on the desktop operating systems criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Canada: Five Eyes member.",
      "url": "https://privacyratings.com/desktop-operating-systems/openbsd/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/openbsd/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.openbsd.org/policy.html",
          "note": "ISC and BSD licenses for the base system, with a policy against restrictive licenses."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://cvsweb.openbsd.org/",
          "note": "No telemetry or analytics in the source code, and no trackers on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.openbsdfoundation.org/",
          "note": "Funded by donations through the OpenBSD Foundation, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:34.917Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "opensuse",
      "category": "desktop-operating-systems",
      "name": "openSUSE",
      "description": "A community Linux distribution sponsored by SUSE, available as the rolling Tumbleweed and the fixed-release Leap, with the YaST and Zypper system tools.",
      "website": "https://www.opensuse.org",
      "source": "https://build.opensuse.org/project/show/openSUSE:Factory",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "openSUSE scores 65 out of 100 (grade C) on the desktop operating systems criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/desktop-operating-systems/opensuse/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/opensuse/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://build.opensuse.org/project/show/openSUSE:Factory",
          "note": "Built from open source packages whose sources are public on the Open Build Service."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.opensuse.org/",
          "note": "No telemetry in the distribution. The website uses self-hosted Matomo analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://en.opensuse.org/Sponsors",
          "note": "Funded by SUSE and other sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:35.296Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "parrot",
      "category": "desktop-operating-systems",
      "name": "Parrot",
      "description": "A Debian-based Linux distribution geared towards security, privacy and development, with editions for penetration testing and everyday use.",
      "website": "https://www.parrotsec.org",
      "source": "https://gitlab.com/parrotsec",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Parrot scores 80 out of 100 (grade B) on the desktop operating systems criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/desktop-operating-systems/parrot/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/parrot/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/parrotsec",
          "note": "Debian-based and built from open source packages."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.parrotsec.org/privacy/",
          "note": "The operating system includes no trackers or telemetry. The website uses self-hosted, cookieless analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.parrotsec.org/donate/",
          "note": "Funded by donations and partnerships, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:30.196Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "pop-os",
      "category": "desktop-operating-systems",
      "name": "Pop!_OS",
      "description": "An Ubuntu-based Linux distribution from the hardware maker System76, with its own COSMIC desktop environment.",
      "website": "https://system76.com/pop",
      "source": "https://github.com/pop-os",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Pop!_OS scores 50 out of 100 (grade D) on the desktop operating systems criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/desktop-operating-systems/pop-os/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/pop-os/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/pop-os/cosmic-comp/master/LICENSE",
          "note": "System76's own components, including the COSMIC desktop, are open source under the GPL-3.0, on top of Ubuntu packages."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://system76.com/privacy/",
          "note": "Pop!_OS sends no telemetry or error reports, but the website loads Google Analytics and HubSpot."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://system76.com/privacy/",
          "note": "Funded by System76 hardware sales. System76 states it does not sell user data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js-na2.hsforms.net",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "ecommplugins-trustboxsettings.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:37.358Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "qubes-os",
      "category": "desktop-operating-systems",
      "name": "Qubes OS",
      "description": "A security-oriented desktop operating system that uses Xen virtualization to run applications in separate, isolated virtual machines called qubes.",
      "website": "https://www.qubes-os.org",
      "source": "https://github.com/QubesOS",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Qubes OS scores 80 out of 100 (grade B) on the desktop operating systems criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/desktop-operating-systems/qubes-os/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/qubes-os/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/QubesOS/qubes-core-admin/blob/main/LICENSE",
          "note": "GPL-2.0 or later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://doc.qubes-os.org/en/latest/introduction/privacy.html",
          "note": "No ads or trackers on the website and no telemetry in the operating system."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://doc.qubes-os.org/en/latest/introduction/privacy.html",
          "note": "Funded by donations and grants. User data is never sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:01.313Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "secureblue",
      "category": "desktop-operating-systems",
      "name": "secureblue",
      "description": "Hardened images of Fedora Atomic desktops and servers, with a hardened memory allocator and hardened kernel and system settings.",
      "website": "https://secureblue.dev",
      "source": "https://github.com/secureblue/secureblue",
      "license": "Apache-2.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "secureblue scores 80 out of 100 (grade B) on the desktop operating systems criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/desktop-operating-systems/secureblue/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/secureblue/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/secureblue/secureblue/blob/live/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/secureblue/secureblue/blob/live/files/system/usr/lib/systemd/system-preset/40-secureblue.preset",
          "note": "No trackers on the website, and Fedora's count-me reporting is disabled by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://secureblue.dev/donate",
          "note": "Volunteer project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:34.935Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "tails",
      "category": "desktop-operating-systems",
      "name": "Tails",
      "description": "A portable live operating system that starts from a USB stick, routes all connections through Tor and leaves no trace on the computer unless Persistent Storage is used.",
      "website": "https://tails.net",
      "source": "https://gitlab.tails.net/tails/tails",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 100,
      "coverage": 100,
      "summary": "Tails scores 100 out of 100 (grade A) on the desktop operating systems criteria. It meets 4 of 4 criteria: open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/desktop-operating-systems/tails/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/tails/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://tails.net/doc/about/license/index.en.html",
          "note": "GPL-3.0 or later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.torproject.org/about/privacy_policy/",
          "note": "Tails is made by the Tor Project, whose privacy policy rules out tracking, telemetry and analytics in its applications."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tails.net/about/index.en.html",
          "note": "Funded by donations from individuals and organizations through the Tor Project."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tails.net/news/audit_by_ROS_2024/",
          "note": "Radically Open Security audited automatic upgrades and recent changes, and the full report is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:01.905Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ubuntu",
      "category": "desktop-operating-systems",
      "name": "Ubuntu",
      "description": "A Debian-based Linux distribution developed by Canonical, with regular and long-term support releases for desktops, servers and cloud.",
      "website": "https://ubuntu.com",
      "source": "https://launchpad.net/ubuntu",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Ubuntu scores 40 out of 100 (grade D) on the desktop operating systems criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/desktop-operating-systems/ubuntu/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/ubuntu/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://canonical.com/legal/open-source-licences",
          "note": "Built from open source packages, with licences listed per package. Optional proprietary drivers are available."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://canonical.com/legal/systems-information-notice",
          "note": "The website loads Google Tag Manager. Sharing system information with Canonical is offered during installation and at first login."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://canonical.com/legal/data-privacy",
          "note": "Funded by Canonical's commercial services, and personal data is not sold. The package manager and login messages promote Canonical's paid Ubuntu Pro service."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:35.476Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "whonix",
      "category": "desktop-operating-systems",
      "name": "Whonix",
      "description": "A Debian-based operating system that runs in virtual machines and routes all traffic through Tor, separating the Tor gateway from the workstation to prevent IP address leaks.",
      "website": "https://www.whonix.org",
      "source": "https://github.com/Whonix/derivative-maker",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "MH",
        "name": "Marshall Islands",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Whonix scores 65 out of 100 (grade C) on the desktop operating systems criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the Marshall Islands: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/desktop-operating-systems/whonix/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/whonix/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Whonix/derivative-maker/blob/master/COPYING",
          "note": "AGPL-3.0 and GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.whonix.org/wiki/Census",
          "note": "No third-party analytics. Whonix-Gateway fetches a warrant canary daily for a user count, which can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.whonix.org/wiki/Donate",
          "note": "Funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:02.261Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "windows-11",
      "category": "desktop-operating-systems",
      "name": "Windows 11",
      "description": "Microsoft's proprietary desktop operating system for PCs, the successor to Windows 10.",
      "website": "https://www.microsoft.com/en-us/windows/windows-11",
      "license": null,
      "platforms": [
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Windows 11 scores 10 out of 100 (grade F) on the desktop operating systems criteria. It partly meets independent audit. It does not meet open source, no trackers or telemetry and no ads or data sales. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/desktop-operating-systems/windows-11/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/windows-11/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/windows/privacy/configure-windows-diagnostic-data-in-your-organization",
          "note": "Required diagnostic data is sent to Microsoft and can only be turned off on Enterprise, Education and Server editions. The website loads Adobe Experience Platform tags."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "Windows has an advertising ID that apps and Microsoft use for personalized ads, and Microsoft uses product usage data for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://learn.microsoft.com/en-us/windows/security/security-foundations/certification/validations/cc-windows11",
          "note": "Common Criteria evaluations by independent labs are published as certification and validation reports, but no full security audit report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:36.079Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "zorin-os",
      "category": "desktop-operating-systems",
      "name": "Zorin OS",
      "description": "An Ubuntu-based Linux distribution from Zorin Technology Group, with desktop layouts that resemble Windows or macOS.",
      "website": "https://zorin.com/os/",
      "source": "https://launchpad.net/~zorinos",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "IE",
        "name": "Ireland",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Zorin OS scores 65 out of 100 (grade C) on the desktop operating systems criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in Ireland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/desktop-operating-systems/zorin-os/",
      "markdown": "https://privacyratings.com/desktop-operating-systems/zorin-os/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://zorin.com/about/#source-code",
          "note": "Built on open source software, with source packages published on Launchpad and GitHub."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://zorin.com/legal/privacy/",
          "note": "No third-party trackers. The Zorin OS Census package pings Zorin's servers with an anonymous installation ID by default and can be removed; the website uses Plausible analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://zorin.com/about/#funding",
          "note": "Funded by Zorin OS Pro sales and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:35.117Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "balenaetcher",
      "category": "os-installers",
      "name": "balenaEtcher",
      "description": "A cross-platform app from balena that writes OS images to SD cards and USB drives and validates the written data.",
      "website": "https://etcher.balena.io",
      "source": "https://github.com/balena-io/etcher",
      "license": "Apache-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "balenaEtcher scores 40 out of 100 (grade D) on the OS downloaders and bootable USB tools criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/os-installers/balenaetcher/",
      "markdown": "https://privacyratings.com/os-installers/balenaetcher/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/balena-io/etcher/blob/master/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/balena-io/etcher/blob/master/lib/gui/app/models/settings.ts",
          "note": "Error reporting to balena through Sentry is on by default and can be turned off. The website loads Google Analytics, Amplitude and LinkedIn tracking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.balena.io/privacy-policy",
          "note": "The app shows balena project banners while flashing. Balena shares data with advertising partners to market its own services and states it does not sell personal information."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Amplitude",
            "host": "cdn.amplitude.com",
            "effect": "no"
          },
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:49.029Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "crystalfetch",
      "category": "os-installers",
      "name": "CrystalFetch",
      "description": "A macOS app from the makers of UTM that builds Windows 11 installer ISO images from Microsoft's update files, using UUP dump APIs and converter scripts.",
      "website": "https://github.com/TuringSoftware/CrystalFetch",
      "source": "https://github.com/TuringSoftware/CrystalFetch",
      "license": "Apache-2.0",
      "platforms": [
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "CrystalFetch scores 80 out of 100 (grade B) on the OS downloaders and bootable USB tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/os-installers/crystalfetch/",
      "markdown": "https://privacyratings.com/os-installers/crystalfetch/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TuringSoftware/CrystalFetch/blob/main/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TuringSoftware/CrystalFetch",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/TuringSoftware/CrystalFetch",
          "note": "Free and open source app with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:48.674Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fedora-media-writer",
      "category": "os-installers",
      "name": "Fedora Media Writer",
      "description": "The Fedora Project's tool for downloading Fedora images and writing them, or other ISO files, to USB drives, with a restore option to reformat the drive afterwards.",
      "website": "https://github.com/FedoraQt/MediaWriter",
      "source": "https://github.com/FedoraQt/MediaWriter",
      "license": "GPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Fedora Media Writer scores 65 out of 100 (grade C) on the OS downloaders and bootable USB tools criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/os-installers/fedora-media-writer/",
      "markdown": "https://privacyratings.com/os-installers/fedora-media-writer/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/FedoraQt/MediaWriter/blob/main/LICENSE.GPL-2",
          "note": "GPL-2.0, with some parts under LGPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/FedoraQt/MediaWriter/blob/main/PRIVACY.md",
          "note": "No third-party analytics. A custom User-Agent with version, OS and locale is sent to Fedora servers for download statistics by default and can be disabled with --no-user-agent."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/FedoraQt/MediaWriter",
          "note": "Free and open source app from the Fedora Project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:48.674Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "impression",
      "category": "os-installers",
      "name": "Impression",
      "description": "A GNOME app for writing disk images to USB drives, which can also download popular Linux distribution images directly.",
      "website": "https://apps.gnome.org/Impression/",
      "source": "https://gitlab.com/adhami3310/Impression",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Impression scores 80 out of 100 (grade B) on the OS downloaders and bootable USB tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/os-installers/impression/",
      "markdown": "https://privacyratings.com/os-installers/impression/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/adhami3310/Impression/-/blob/main/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/adhami3310/Impression",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gitlab.com/adhami3310/Impression",
          "note": "Free and open source app with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:48.977Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "media-creation-tool",
      "category": "os-installers",
      "name": "Media Creation Tool",
      "description": "Microsoft's Windows tool that downloads Windows 11 and creates a bootable USB drive or ISO file for installing or reinstalling Windows.",
      "website": "https://www.microsoft.com/en-us/software-download/windows11",
      "license": null,
      "platforms": [
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Media Creation Tool scores 10 out of 100 (grade F) on the OS downloaders and bootable USB tools criteria. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/os-installers/media-creation-tool/",
      "markdown": "https://privacyratings.com/os-installers/media-creation-tool/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "The Windows download page loads Microsoft Clarity and Bing ads tracking, and Microsoft collects diagnostic data from its software."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "The tool has no ads. Microsoft websites use advertising cookies and tags to market Microsoft products."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Impact",
            "host": "d.impactradius-event.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Ads",
            "host": "bat.bing.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Clarity",
            "host": "www.clarity.ms",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:51.982Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mist",
      "category": "os-installers",
      "name": "Mist",
      "description": "A macOS utility that lists and downloads macOS installers and Apple silicon firmware files from Apple's servers, and can build app bundles, disk images, bootable ISOs and installer packages.",
      "website": "https://github.com/ninxsoft/Mist",
      "source": "https://github.com/ninxsoft/Mist",
      "license": "MIT",
      "platforms": [
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Mist scores 80 out of 100 (grade B) on the OS downloaders and bootable USB tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/os-installers/mist/",
      "markdown": "https://privacyratings.com/os-installers/mist/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ninxsoft/Mist/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ninxsoft/Mist",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/ninxsoft/Mist",
          "note": "Free and open source app with no ads, supported by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:48.734Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "quickemu",
      "category": "os-installers",
      "name": "Quickemu",
      "description": "Command-line tools that download Windows, macOS and Linux images (quickget) and create and run QEMU virtual machines with preset configurations (quickemu).",
      "website": "https://github.com/quickemu-project/quickemu",
      "source": "https://github.com/quickemu-project/quickemu",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Quickemu scores 80 out of 100 (grade B) on the OS downloaders and bootable USB tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/os-installers/quickemu/",
      "markdown": "https://privacyratings.com/os-installers/quickemu/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/quickemu-project/quickemu/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/quickemu-project/quickemu",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/quickemu-project/quickemu",
          "note": "Free and open source tool with no ads, supported by GitHub Sponsors."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:48.734Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "raspberry-pi-imager",
      "category": "os-installers",
      "name": "Raspberry Pi Imager",
      "description": "Raspberry Pi's official tool for downloading operating system images and writing them to SD cards and USB drives, with options to preconfigure hostname, Wi-Fi, users and SSH.",
      "website": "https://www.raspberrypi.com/software/",
      "source": "https://github.com/raspberrypi/rpi-imager",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Raspberry Pi Imager scores 65 out of 100 (grade C) on the OS downloaders and bootable USB tools criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/os-installers/raspberry-pi-imager/",
      "markdown": "https://privacyratings.com/os-installers/raspberry-pi-imager/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/raspberrypi/rpi-imager/blob/main/license.txt",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/raspberrypi/rpi-imager#anonymous-metrics-telemetry",
          "note": "Anonymous download statistics are sent to a Raspberry Pi server by default and can be turned off in App Options. Analytics cookies on the website are optional."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.raspberrypi.com/privacy/",
          "note": "No ads in the app. Raspberry Pi states it does not share data with other companies for their marketing."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:48.979Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "rufus",
      "category": "os-installers",
      "name": "Rufus",
      "description": "A Windows utility that formats USB drives and writes bootable USB media from ISO and disk images, and can download Windows ISOs.",
      "website": "https://rufus.ie",
      "source": "https://github.com/pbatard/rufus",
      "license": "GPL-3.0",
      "platforms": [
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Rufus scores 30 out of 100 (grade F) on the OS downloaders and bootable USB tools criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/os-installers/rufus/",
      "markdown": "https://privacyratings.com/os-installers/rufus/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pbatard/rufus/blob/master/LICENSE.txt",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/pbatard/rufus/wiki/FAQ#Rufus_connects_to_the_internet_but_I_never_allowed_it_to__why",
          "note": "The rufus.ie website loads Google Analytics and Google AdSense. The app's update check asks first, unless the executable is named rufus.exe, and can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://github.com/pbatard/rufus/wiki/FAQ#I_have_seen_some_deceptive_ads_on_your_website_How_dare_you",
          "note": "The rufus.ie website shows Google AdSense ads. The app itself has no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:49.502Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "uup-dump",
      "category": "os-installers",
      "name": "UUP dump",
      "description": "A website and set of scripts that fetch Windows update files (UUP) from Microsoft's servers and convert them into Windows installation ISO images.",
      "website": "https://uupdump.net",
      "source": "https://git.uupdump.net/uup-dump",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "UUP dump scores 65 out of 100 (grade C) on the OS downloaders and bootable USB tools criteria. It meets 2 of 4 criteria: no trackers or telemetry and no ads or data sales. It partly meets open source. It does not meet independent audit.",
      "url": "https://privacyratings.com/os-installers/uup-dump/",
      "markdown": "https://privacyratings.com/os-installers/uup-dump/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://git.uupdump.net/uup-dump/api/src/branch/master/LICENSE",
          "note": "The API (Apache-2.0) and converter scripts (MIT) are public. The source of the uupdump.net website itself is not public."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://uupdump.net/",
          "note": "The website loads only self-hosted scripts, with no third-party analytics or trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://uupdump.net/",
          "note": "Free website and scripts with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:51.190Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ventoy",
      "category": "os-installers",
      "name": "Ventoy",
      "description": "A tool that prepares a USB drive so ISO, WIM, IMG, VHD and EFI files copied onto it can be booted from a menu, without reformatting the drive for each image.",
      "website": "https://www.ventoy.net",
      "source": "https://github.com/ventoy/Ventoy",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Ventoy scores 30 out of 100 (grade F) on the OS downloaders and bootable USB tools criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/os-installers/ventoy/",
      "markdown": "https://privacyratings.com/os-installers/ventoy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ventoy/Ventoy/blob/master/BLOB_List.md",
          "note": "GPL-3.0. Prebuilt binaries in the repository are listed with their build instructions or upstream sources."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.ventoy.net/en/index.html",
          "note": "The ventoy.net website loads Google Analytics and Google AdSense."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.ventoy.net/en/index.html",
          "note": "The ventoy.net website shows Google AdSense ads, alongside donations. The app itself has no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:50.013Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "woeusb",
      "category": "os-installers",
      "name": "WoeUSB",
      "description": "A Linux command-line tool that creates bootable Windows installation USB drives from an ISO file or DVD, with legacy BIOS and UEFI support.",
      "website": "https://github.com/WoeUSB/WoeUSB",
      "source": "https://github.com/WoeUSB/WoeUSB",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "WoeUSB scores 80 out of 100 (grade B) on the OS downloaders and bootable USB tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/os-installers/woeusb/",
      "markdown": "https://privacyratings.com/os-installers/woeusb/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/WoeUSB/WoeUSB/blob/master/LICENSES/GPL-3.0-or-later.txt",
          "note": "GPL-3.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/WoeUSB/WoeUSB",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/WoeUSB/WoeUSB",
          "note": "Free and open source tool with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:48.979Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "daisydisk",
      "category": "disk-usage-analyzers",
      "name": "DaisyDisk",
      "description": "Paid disk space analyzer for macOS from Software Ambience Corp. It shows disks as an interactive sunburst chart, can scan Google Drive, Dropbox, OneDrive and Box, and collects files for deletion.",
      "website": "https://daisydiskapp.com",
      "license": null,
      "platforms": [
        "macos"
      ],
      "jurisdiction": {
        "code": "UA",
        "name": "Ukraine",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 15,
      "coverage": 100,
      "summary": "DaisyDisk scores 15 out of 100 (grade F) on the disk usage analyzers criteria. It partly meets no ads or data sales and works offline. It does not meet open source, no trackers or telemetry, independent audit and no account needed. It is based in Ukraine: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/disk-usage-analyzers/daisydisk/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/daisydisk/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://daisydiskapp.com/privacy",
          "note": "The privacy policy states that the website uses Google Analytics and remarketing cookies shared with Facebook, X and Google. It says the app itself does not send scan data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://daisydiskapp.com/privacy",
          "note": "Funded by license sales, with no ads in the app. The website shares visitor IDs with Facebook, X and Google to retarget its own ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://daisydiskapp.com/privacy",
          "note": "File names and sizes stay on the computer. The app contacts the vendor's server to activate the trial or license with an email address and a hardware ID."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "no",
          "evidence": "https://daisydiskapp.com/privacy",
          "note": "The trial and the license are registered to an email address in the vendor's database. The Mac App Store version uses an Apple ID instead."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:25.900Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "disk-inventory-x",
      "category": "disk-usage-analyzers",
      "name": "Disk Inventory X",
      "description": "Disk usage utility for macOS that shows files and folders as a treemap, with a layout algorithm based on KDirStat.",
      "website": "https://www.derlien.com",
      "source": "https://gitlab.com/tderlien/disk-inventory-x",
      "license": null,
      "platforms": [
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "Disk Inventory X scores 85 out of 100 (grade B) on the disk usage analyzers criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, works offline and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/disk-usage-analyzers/disk-inventory-x/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/disk-inventory-x/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/tderlien/disk-inventory-x/-/blob/master/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/tderlien/disk-inventory-x",
          "note": "No telemetry or analytics in the source code, and no third-party trackers were found on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.derlien.com",
          "note": "Free app funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gitlab.com/tderlien/disk-inventory-x",
          "note": "The source code contains no network or update check code."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.derlien.com",
          "note": "No account needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:27.058Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "disk-usage-analyzer",
      "category": "disk-usage-analyzers",
      "name": "Disk Usage Analyzer",
      "description": "GNOME's disk usage app, also known as Baobab. It scans folders, drives and remote locations and shows sizes as a tree with a ring or treemap chart.",
      "website": "https://apps.gnome.org/Baobab/",
      "source": "https://gitlab.gnome.org/GNOME/baobab",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "Disk Usage Analyzer scores 85 out of 100 (grade B) on the disk usage analyzers criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, works offline and no account needed. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/disk-usage-analyzers/disk-usage-analyzer/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/disk-usage-analyzer/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/GNOME/baobab/-/blob/main/COPYING",
          "note": "GPL-2.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://apps.gnome.org/Baobab/",
          "note": "No telemetry or analytics in the source code, and no third-party trackers were found on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://apps.gnome.org/Baobab/",
          "note": "Free GNOME project supported by donations to the GNOME Foundation, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/GNOME/baobab",
          "note": "The app makes no network requests of its own. Remote locations are scanned only when the user opens them."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://apps.gnome.org/Baobab/",
          "note": "No account needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:26.113Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "diskonaut",
      "category": "disk-usage-analyzers",
      "name": "diskonaut",
      "description": "Terminal disk space navigator written in Rust that shows a folder as an interactive treemap and can delete files while tracking the space freed.",
      "website": "https://github.com/imsnif/diskonaut",
      "source": "https://github.com/imsnif/diskonaut",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "diskonaut scores 85 out of 100 (grade B) on the disk usage analyzers criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, works offline and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/disk-usage-analyzers/diskonaut/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/diskonaut/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/imsnif/diskonaut/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/imsnif/diskonaut",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/imsnif/diskonaut",
          "note": "Free open-source volunteer project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/imsnif/diskonaut",
          "note": "The source code contains no network code."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/imsnif/diskonaut",
          "note": "No account needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:25.900Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "diskusage",
      "category": "disk-usage-analyzers",
      "name": "DiskUsage",
      "description": "Android app that shows internal and external storage as a zoomable map of folders sized by the space they use.",
      "website": "https://f-droid.org/packages/com.google.android.diskusage/",
      "source": "https://github.com/IvanVolosyuk/diskusage",
      "license": "GPL-2.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "DiskUsage scores 85 out of 100 (grade B) on the disk usage analyzers criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, works offline and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/disk-usage-analyzers/diskusage/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/diskusage/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/IvanVolosyuk/diskusage/blob/master/COPYING.txt",
          "note": "GPL-2.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://f-droid.org/packages/com.google.android.diskusage/",
          "note": "Built and signed by F-Droid, with no tracking libraries and no internet permission."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/IvanVolosyuk/diskusage",
          "note": "Free volunteer project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://f-droid.org/packages/com.google.android.diskusage/",
          "note": "The app does not request the internet permission."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://f-droid.org/packages/com.google.android.diskusage/",
          "note": "No account needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:25.901Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dua-cli",
      "category": "disk-usage-analyzers",
      "name": "dua",
      "description": "Parallel disk usage analyzer for the terminal written in Rust, with an interactive mode for browsing folders and deleting files.",
      "website": "https://github.com/Byron/dua-cli",
      "source": "https://github.com/Byron/dua-cli",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "dua scores 85 out of 100 (grade B) on the disk usage analyzers criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, works offline and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/disk-usage-analyzers/dua-cli/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/dua-cli/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Byron/dua-cli/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Byron/dua-cli",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Byron/dua-cli",
          "note": "Free open-source volunteer project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Byron/dua-cli",
          "note": "The source code contains no network code."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/Byron/dua-cli",
          "note": "No account needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:25.901Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "duc",
      "category": "disk-usage-analyzers",
      "name": "Duc",
      "description": "Tools for indexing disk usage into a database and browsing it from the command line, an ncurses interface, a graphical viewer or a CGI web page. Built for large file systems.",
      "website": "https://duc.zevv.nl",
      "source": "https://github.com/zevv/duc",
      "license": "LGPL-3.0",
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "Duc scores 85 out of 100 (grade B) on the disk usage analyzers criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, works offline and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/disk-usage-analyzers/duc/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/duc/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/zevv/duc/blob/master/LICENSE",
          "note": "LGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/zevv/duc",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/zevv/duc",
          "note": "Free open-source volunteer project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/zevv/duc",
          "note": "The source code contains no network code. The optional CGI interface is served only by the user's own web server."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/zevv/duc",
          "note": "No account needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:27.596Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dust",
      "category": "disk-usage-analyzers",
      "name": "dust",
      "description": "Command-line tool written in Rust that works like du but draws a tree of the largest folders with bars showing each one's share of the space.",
      "website": "https://github.com/bootandy/dust",
      "source": "https://github.com/bootandy/dust",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "dust scores 85 out of 100 (grade B) on the disk usage analyzers criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, works offline and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/disk-usage-analyzers/dust/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/dust/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bootandy/dust/blob/master/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bootandy/dust",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/bootandy/dust",
          "note": "Free open-source volunteer project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/bootandy/dust",
          "note": "The source code contains no network code."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/bootandy/dust",
          "note": "No account needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:26.079Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "erdtree",
      "category": "disk-usage-analyzers",
      "name": "erdtree",
      "description": "Cross-platform file tree and disk usage tool written in Rust, invoked as erd. It respects .gitignore rules and reports size by bytes, blocks, words or lines.",
      "website": "https://github.com/solidiquis/erdtree",
      "source": "https://github.com/solidiquis/erdtree",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "erdtree scores 85 out of 100 (grade B) on the disk usage analyzers criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, works offline and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/disk-usage-analyzers/erdtree/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/erdtree/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/solidiquis/erdtree/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/solidiquis/erdtree",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/solidiquis/erdtree",
          "note": "Free open-source volunteer project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/solidiquis/erdtree",
          "note": "The source code contains no network code."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/solidiquis/erdtree",
          "note": "No account needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:26.079Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "filelight",
      "category": "disk-usage-analyzers",
      "name": "Filelight",
      "description": "KDE's disk usage app. It shows folders as concentric rings, scans local, removable and remote disks, and integrates with the Dolphin file manager.",
      "website": "https://apps.kde.org/filelight/",
      "source": "https://invent.kde.org/utilities/filelight",
      "license": null,
      "platforms": [
        "linux",
        "windows"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "Filelight scores 85 out of 100 (grade B) on the disk usage analyzers criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, works offline and no account needed. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/disk-usage-analyzers/filelight/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/filelight/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://invent.kde.org/utilities/filelight/-/tree/master/LICENSES",
          "note": "GPL-2.0-only or GPL-3.0-only."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kde.org/privacypolicy-apps/",
          "note": "No third-party trackers, and the app has no telemetry. KDE websites use self-hosted Matomo with cookies disabled and IP addresses anonymized."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kde.org/donate/",
          "note": "Free open-source app with no ads, funded by donations to KDE e.V."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kde.org/privacypolicy-apps/",
          "note": "Scans run locally. KDE apps only send data as a result of an explicit user action, such as scanning a remote folder."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://apps.kde.org/filelight/",
          "note": "No account needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:27.154Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gdu",
      "category": "disk-usage-analyzers",
      "name": "gdu",
      "description": "Fast disk usage analyzer for the terminal written in Go, built for parallel scanning of SSDs, with an interactive interface, exports and an optional local web interface.",
      "website": "https://github.com/dundee/gdu",
      "source": "https://github.com/dundee/gdu",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "gdu scores 85 out of 100 (grade B) on the disk usage analyzers criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, works offline and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/disk-usage-analyzers/gdu/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/gdu/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dundee/gdu/blob/master/LICENSE.md",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dundee/gdu",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/dundee/gdu",
          "note": "Free open-source volunteer project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/dundee/gdu",
          "note": "Makes no outbound network requests. The optional web interface and profiling server listen only on the local machine."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/dundee/gdu",
          "note": "No account needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:26.088Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "grandperspective",
      "category": "disk-usage-analyzers",
      "name": "GrandPerspective",
      "description": "Disk usage app for macOS that draws files as a treemap of rectangles sized by file size. Free from SourceForge, or as a paid build of the same app in the Mac App Store.",
      "website": "https://grandperspectiv.sourceforge.net",
      "source": "https://sourceforge.net/p/grandperspectiv/source/",
      "license": null,
      "platforms": [
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "GrandPerspective scores 85 out of 100 (grade B) on the disk usage analyzers criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, works offline and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/disk-usage-analyzers/grandperspective/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/grandperspective/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://sourceforge.net/p/grandperspectiv/source/ci/master/tree/LICENSE",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://sourceforge.net/p/grandperspectiv/source/",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://grandperspectiv.sourceforge.net",
          "note": "Funded by donations and Mac App Store sales, with no ads in the app."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://sourceforge.net/p/grandperspectiv/source/",
          "note": "The source code contains no network or update check code. App Store builds are updated by the App Store."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://grandperspectiv.sourceforge.net",
          "note": "No account needed for the SourceForge download."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:26.088Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "jdiskreport",
      "category": "disk-usage-analyzers",
      "name": "JDiskReport",
      "description": "Freeware disk usage analyzer from JGoodies that runs on Java and shows folder sizes, file types and file ages as charts and tables.",
      "website": "https://www.jgoodies.com/freeware/jdiskreport/",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 23,
      "coverage": 62,
      "summary": "JDiskReport scores 23 out of 100 (grade F) on the disk usage analyzers criteria. It meets 2 of 6 criteria: no ads or data sales and no account needed. It does not meet open source and independent audit. Still needing evidence: no trackers or telemetry and works offline.",
      "url": "https://privacyratings.com/disk-usage-analyzers/jdiskreport/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/jdiskreport/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed-source freeware."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.jgoodies.com/freeware/jdiskreport/",
          "note": "JGoodies describes it as ad-free, no-charge software."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.jgoodies.com/freeware/jdiskreport/",
          "note": "Free download with no account."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:27.313Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "k4dirstat",
      "category": "disk-usage-analyzers",
      "name": "K4DirStat",
      "description": "KDE port of the original KDirStat disk usage analyzer for Linux, with a folder tree, a treemap and cleanup actions.",
      "website": "https://github.com/jeromerobert/k4dirstat",
      "source": "https://github.com/jeromerobert/k4dirstat",
      "license": "GPL-2.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "K4DirStat scores 85 out of 100 (grade B) on the disk usage analyzers criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, works offline and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/disk-usage-analyzers/k4dirstat/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/k4dirstat/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jeromerobert/k4dirstat/blob/master/COPYING",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jeromerobert/k4dirstat",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/jeromerobert/k4dirstat",
          "note": "Free volunteer project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/jeromerobert/k4dirstat",
          "note": "No network code of its own. Remote folders are read through KDE's KIO only when the user opens them."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/jeromerobert/k4dirstat",
          "note": "No account needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:26.113Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ncdu",
      "category": "disk-usage-analyzers",
      "name": "ncdu",
      "description": "Disk usage analyzer with a text-mode interface, built to find large files on servers over SSH. Version 2 is written in Zig and version 1 in C.",
      "website": "https://dev.yorhel.nl/ncdu",
      "source": "https://code.blicky.net/yorhel/ncdu",
      "license": null,
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "ncdu scores 85 out of 100 (grade B) on the disk usage analyzers criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, works offline and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/disk-usage-analyzers/ncdu/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/ncdu/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://code.blicky.net/yorhel/ncdu/src/branch/zig/LICENSES/MIT.txt",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://code.blicky.net/yorhel/ncdu",
          "note": "No telemetry or analytics in the source code, and no third-party trackers were found on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://code.blicky.net/yorhel/ncdu",
          "note": "Free open-source volunteer project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://code.blicky.net/yorhel/ncdu",
          "note": "The source code contains no network code."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://code.blicky.net/yorhel/ncdu",
          "note": "No account needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:46.778Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "omnidisksweeper",
      "category": "disk-usage-analyzers",
      "name": "OmniDiskSweeper",
      "description": "Free disk space utility for macOS from The Omni Group. It lists files and folders sorted by size in a column browser and moves selected items to the Trash.",
      "website": "https://www.omnigroup.com/more",
      "license": null,
      "platforms": [
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 85,
      "summary": "OmniDiskSweeper scores 35 out of 100 (grade F) on the disk usage analyzers criteria. It meets 2 of 6 criteria: no ads or data sales and no account needed. It partly meets no trackers or telemetry. It does not meet open source and independent audit. Still needing evidence: works offline. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/disk-usage-analyzers/omnidisksweeper/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/omnidisksweeper/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed-source freeware."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.omnigroup.com/legal/privacy",
          "note": "No third-party trackers. Omni apps send anonymous usage statistics only with permission, and the Omni website uses a self-hosted Matomo instance."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.omnigroup.com/privacy",
          "note": "Free app with no ads. Omni states it does not share app or website data with advertising services."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.omnigroup.com/more",
          "note": "Free download with no account."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:27.146Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "qdirstat",
      "category": "disk-usage-analyzers",
      "name": "QDirStat",
      "description": "Qt-based disk usage analyzer for Linux, BSD and macOS by the author of the original KDirStat. It shows a folder tree and treemap, with cleanup actions and views by file type, age and installed package.",
      "website": "https://github.com/shundhammer/qdirstat",
      "source": "https://github.com/shundhammer/qdirstat",
      "license": "GPL-2.0",
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "QDirStat scores 85 out of 100 (grade B) on the disk usage analyzers criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, works offline and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/disk-usage-analyzers/qdirstat/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/qdirstat/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/shundhammer/qdirstat/blob/master/LICENSE",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/shundhammer/qdirstat",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/shundhammer/qdirstat",
          "note": "Free volunteer project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/shundhammer/qdirstat",
          "note": "The source code does not use Qt's network module and makes no network requests."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/shundhammer/qdirstat",
          "note": "No account needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:27.059Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "spacesniffer",
      "category": "disk-usage-analyzers",
      "name": "SpaceSniffer",
      "description": "Portable freeware disk space analyzer for Windows that shows folders and files as a zoomable treemap, with filters by type, size, date and tags.",
      "website": "https://www.uderzo.it/main_products/space_sniffer/index.html",
      "license": null,
      "platforms": [
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 23,
      "coverage": 62,
      "summary": "SpaceSniffer scores 23 out of 100 (grade F) on the disk usage analyzers criteria. It meets 2 of 6 criteria: no ads or data sales and no account needed. It does not meet open source and independent audit. Still needing evidence: no trackers or telemetry and works offline.",
      "url": "https://privacyratings.com/disk-usage-analyzers/spacesniffer/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/spacesniffer/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed-source freeware."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.uderzo.it/main_products/space_sniffer/index.html",
          "note": "Freeware funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "unknown",
          "evidence": null,
          "note": null
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.uderzo.it/main_products/space_sniffer/index.html",
          "note": "Portable app with no account."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:28.096Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "squirreldisk",
      "category": "disk-usage-analyzers",
      "name": "SquirrelDisk",
      "description": "Disk usage analyzer for macOS, Windows and Linux written in Rust, with a sunburst or treemap view, cleanup tools and optional scanning of servers over SSH and cloud storage through rclone. The free app shows a sponsor banner.",
      "website": "https://www.squirreldisk.com",
      "source": "https://github.com/adileo/squirreldisk",
      "license": "AGPL-3.0",
      "platforms": [
        "macos",
        "windows",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "SquirrelDisk scores 38 out of 100 (grade F) on the disk usage analyzers criteria. It meets 2 of 6 criteria: open source and no account needed. It partly meets works offline. It does not meet no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/disk-usage-analyzers/squirreldisk/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/squirreldisk/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/adileo/squirreldisk/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.squirreldisk.com/privacy",
          "note": "No third-party analytics, but the app downloads the sponsor list at every launch, and the vendor uses that request to count launches and daily users by country, city and app version. This cannot be turned off. Daily sponsor view totals are also sent unless turned off in Settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://github.com/adileo/squirreldisk/blob/main/src/sponsor/mod.rs",
          "note": "Funded by a sponsor banner in the app. By default the banner is chosen from interests the app infers from folder names and sizes after a scan. The matching happens on the device and can be turned off in Settings."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/adileo/squirreldisk/blob/main/src/sponsor/wire.rs",
          "note": "Scans run locally and file names are not uploaded. The app fetches the sponsor list at launch and checks GitHub for updates by default. The update check can be turned off; the sponsor list request cannot."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.squirreldisk.com/privacy",
          "note": "No account or sign-in. Scanning cloud storage uses the user's own rclone or SSH setup."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:27.529Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "treesize-free",
      "category": "disk-usage-analyzers",
      "name": "TreeSize Free",
      "description": "Free edition of JAM Software's disk space manager for Windows. It shows folder sizes in an Explorer-like tree with charts. Paid Personal and Professional editions add search, reports and cleanup tools.",
      "website": "https://www.jam-software.com/treesize",
      "license": null,
      "platforms": [
        "windows"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 23,
      "coverage": 100,
      "summary": "TreeSize Free scores 23 out of 100 (grade F) on the disk usage analyzers criteria. It meets 1 of 6 criteria: no account needed. It partly meets no ads or data sales and works offline. It does not meet open source, no trackers or telemetry and independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/disk-usage-analyzers/treesize-free/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/treesize-free/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.jam-software.com/company/privacy.shtml",
          "note": "The privacy policy says JAM's applications send usage data with a unique ID to JAM's servers, and the opt-out is only in the paid editions. The website uses self-hosted Matomo plus Google Ads and Microsoft Advertising cookies for visitors who arrive from an ad."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.jam-software.com/company/privacy.shtml",
          "note": "Funded by paid editions, with no ads in the app. The website uses Google Ads remarketing to advertise JAM's own products."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.jam-software.com/company/privacy.shtml",
          "note": "Scans run locally, but the privacy policy says JAM's applications send usage data to JAM's servers, with the opt-out only in the paid editions."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.jam-software.com/treesize",
          "note": "Free download with no account."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:28.221Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "windirstat",
      "category": "disk-usage-analyzers",
      "name": "WinDirStat",
      "description": "Disk usage analyzer for Windows that shows a sortable folder tree, file type statistics and a treemap, with duplicate file search and cleanup actions.",
      "website": "https://windirstat.net",
      "source": "https://github.com/windirstat/windirstat",
      "license": "GPL-2.0",
      "platforms": [
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "WinDirStat scores 85 out of 100 (grade B) on the disk usage analyzers criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, works offline and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/disk-usage-analyzers/windirstat/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/windirstat/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/windirstat/windirstat/blob/master/LICENSE.md",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/windirstat/windirstat",
          "note": "No telemetry or analytics in the source code, and no third-party trackers were found on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://windirstat.net",
          "note": "Free open-source volunteer project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/windirstat/windirstat",
          "note": "The source code contains no network or update check code."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://windirstat.net",
          "note": "No account needed. A portable build is available."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:27.708Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "wiztree",
      "category": "disk-usage-analyzers",
      "name": "WizTree",
      "description": "Fast disk space analyzer for Windows and macOS from Antibody Software. On NTFS drives it reads the Master File Table directly. Free for personal use, with paid supporter and enterprise licenses.",
      "website": "https://diskanalyzer.com",
      "license": null,
      "platforms": [
        "windows",
        "macos"
      ],
      "jurisdiction": {
        "code": "NZ",
        "name": "New Zealand",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 31,
      "coverage": 100,
      "summary": "WizTree scores 31 out of 100 (grade F) on the disk usage analyzers criteria. It meets 2 of 6 criteria: no ads or data sales and no account needed. It partly meets works offline. It does not meet open source, no trackers or telemetry and independent audit. It is based in New Zealand: Five Eyes member.",
      "url": "https://privacyratings.com/disk-usage-analyzers/wiztree/",
      "markdown": "https://privacyratings.com/disk-usage-analyzers/wiztree/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://diskanalyzer.com/privacy-policy",
          "note": "The website loads Google Analytics, and the privacy policy says aggregate cookie and tracking data may be shared with third parties."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://diskanalyzer.com/donate",
          "note": "Funded by optional supporter codes and paid commercial licenses. No ads in the app."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://diskanalyzer.com/whats-new",
          "note": "Scans run locally. WizTree can check for updates automatically, a setting that can be turned off, and supporter codes are validated with the vendor's server."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://diskanalyzer.com",
          "note": "No account needed. A supporter code is optional for personal use."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:28.177Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "albert",
      "category": "launchers",
      "name": "Albert",
      "description": "A plugin-based keyboard launcher for Linux and macOS, written in C++ and Qt, with plugins for apps, files, calculations, web searches and Python extensions.",
      "website": "https://albertlauncher.github.io",
      "source": "https://github.com/albertlauncher/albert",
      "license": null,
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Albert scores 80 out of 100 (grade B) on the app launchers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/launchers/albert/",
      "markdown": "https://privacyratings.com/launchers/albert/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/albertlauncher/albert/blob/main/LICENSE.md",
          "note": "All code is public under the custom Albert license, a source-available license that forbids redistributing modified versions and is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://albertlauncher.github.io/privacy/",
          "note": "Telemetry is sent only after the user agrees on first launch, and the privacy notice states no data is shared with third parties."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://albertlauncher.github.io/donation/",
          "note": "Free app with no ads, supported by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:49.489Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "alfred",
      "category": "launchers",
      "name": "Alfred",
      "description": "A macOS launcher for searching apps, files and the web, with a paid Powerpack that adds workflows, clipboard history, snippets and other features.",
      "website": "https://www.alfredapp.com",
      "license": null,
      "platforms": [
        "macos"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Alfred scores 20 out of 100 (grade F) on the app launchers criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/launchers/alfred/",
      "markdown": "https://privacyratings.com/launchers/alfred/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.alfredapp.com/terms/",
          "note": "The website uses Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.alfredapp.com/powerpack/",
          "note": "Funded by paid Powerpack licenses, with no ads in the app."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:49.729Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "flow-launcher",
      "category": "launchers",
      "name": "Flow Launcher",
      "description": "An open source keyboard launcher for Windows that searches apps, files and bookmarks and supports plugins, themes and web searches.",
      "website": "https://www.flowlauncher.com",
      "source": "https://github.com/Flow-Launcher/Flow.Launcher",
      "license": "MIT",
      "platforms": [
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Flow Launcher scores 80 out of 100 (grade B) on the app launchers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/launchers/flow-launcher/",
      "markdown": "https://privacyratings.com/launchers/flow-launcher/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Flow-Launcher/Flow.Launcher/blob/dev/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Flow-Launcher/Flow.Launcher",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/Flow-Launcher",
          "note": "Free and open source app with no ads, supported by sponsors."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:49.616Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "krunner",
      "category": "launchers",
      "name": "KRunner",
      "description": "KDE Plasma's search and launcher for starting apps, finding files and running commands, calculations and conversions through plugins called runners.",
      "website": "https://userbase.kde.org/Plasma/Krunner",
      "source": "https://invent.kde.org/frameworks/krunner",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "KRunner scores 80 out of 100 (grade B) on the app launchers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/launchers/krunner/",
      "markdown": "https://privacyratings.com/launchers/krunner/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://invent.kde.org/frameworks/krunner/-/tree/master/LICENSES",
          "note": "LGPL-2.1-or-later and other open licenses. The launcher interface is part of Plasma Workspace, also open source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kde.org/privacypolicy-apps/",
          "note": "No third-party trackers, and KDE app telemetry is opt-in. KDE websites use self-hosted Matomo with cookies disabled and IP addresses anonymized."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kde.org/donate/",
          "note": "Funded by donations and sponsors of KDE e.V., with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:50.263Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "powertoys-command-palette",
      "category": "launchers",
      "name": "PowerToys Command Palette",
      "description": "A keyboard launcher in Microsoft PowerToys for Windows that searches apps, files and settings and runs commands and extensions. It replaces PowerToys Run.",
      "website": "https://learn.microsoft.com/en-us/windows/powertoys/command-palette/overview",
      "source": "https://github.com/microsoft/PowerToys",
      "license": "MIT",
      "platforms": [
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "PowerToys Command Palette scores 65 out of 100 (grade C) on the app launchers criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/launchers/powertoys-command-palette/",
      "markdown": "https://privacyratings.com/launchers/powertoys-command-palette/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/microsoft/PowerToys/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/microsoft/PowerToys/blob/main/DATA_AND_PRIVACY.md",
          "note": "Diagnostic data in PowerToys is off by default. The documentation site on learn.microsoft.com loads Microsoft's own analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/microsoft/PowerToys",
          "note": "Free and open source with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:49.818Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "raycast",
      "category": "launchers",
      "name": "Raycast",
      "description": "A keyboard launcher for macOS and Windows with extensions, clipboard history, snippets and window management. An account is needed only for Pro, Teams, AI and cloud sync features.",
      "website": "https://www.raycast.com",
      "license": null,
      "platforms": [
        "macos",
        "windows",
        "ios"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Raycast scores 30 out of 100 (grade F) on the app launchers criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets independent audit. It does not meet open source and no trackers or telemetry. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/launchers/raycast/",
      "markdown": "https://privacyratings.com/launchers/raycast/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. Extensions and the extension API are published on GitHub."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.raycast.com/privacy",
          "note": "The privacy policy lists web analytics services among the vendors that receive personal data, and the website loads Sentry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.raycast.com/privacy",
          "note": "Funded by Pro and Teams subscriptions. Raycast states it does not sell personal data or share it for interest-based advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.raycast.com/enterprise",
          "note": "Raycast states it holds a SOC 2 Type II report and runs annual penetration tests, but the reports are not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:50.104Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "rofi",
      "category": "launchers",
      "name": "rofi",
      "description": "A window switcher, application launcher and dmenu replacement for X11 and Wayland that can be scripted to build custom menus.",
      "website": "https://github.com/davatorium/rofi",
      "source": "https://github.com/davatorium/rofi",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "rofi scores 80 out of 100 (grade B) on the app launchers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/launchers/rofi/",
      "markdown": "https://privacyratings.com/launchers/rofi/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/davatorium/rofi/blob/next/COPYING",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/davatorium/rofi",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/davatorium/rofi",
          "note": "Free and open source tool with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:49.819Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sol",
      "category": "launchers",
      "name": "Sol",
      "description": "An open source launcher for macOS with app search, custom shortcuts, calendar, clipboard history, window management and scripted commands.",
      "website": "https://sol.ospfranco.com",
      "source": "https://github.com/ospfranco/sol",
      "license": "MIT",
      "platforms": [
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Sol scores 50 out of 100 (grade D) on the app launchers criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/launchers/sol/",
      "markdown": "https://privacyratings.com/launchers/sol/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ospfranco/sol/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/ospfranco/sol/blob/main/src/config.ts",
          "note": "Release builds send crash and error reports to Sentry, with no setting to turn this off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/ospfranco",
          "note": "Free and open source app with no ads, supported by GitHub Sponsors."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:49.995Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "spotlight",
      "category": "launchers",
      "name": "Spotlight",
      "description": "The search and launcher built into macOS and iOS for finding apps, files, settings and information, with online suggestions from Apple that can be turned off.",
      "website": "https://support.apple.com/guide/mac-help/find-what-you-need-with-spotlight-mchlp1008/mac",
      "license": null,
      "platforms": [
        "macos",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Spotlight scores 35 out of 100 (grade F) on the app launchers criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets no trackers or telemetry. It does not meet open source and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/launchers/spotlight/",
      "markdown": "https://privacyratings.com/launchers/spotlight/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/siri-suggestions-search/",
          "note": "No third-party trackers. Spotlight sends queries, location and related data to Apple for suggestions by default, linked to a rotating identifier, and this can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/en-ww/",
          "note": "No ads in Spotlight. Apple states it does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:50.481Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ulauncher",
      "category": "launchers",
      "name": "Ulauncher",
      "description": "An open source application launcher for Linux with fuzzy search, shortcuts, themes and Python extensions.",
      "website": "https://ulauncher.io",
      "source": "https://github.com/Ulauncher/Ulauncher",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Ulauncher scores 80 out of 100 (grade B) on the app launchers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/launchers/ulauncher/",
      "markdown": "https://privacyratings.com/launchers/ulauncher/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Ulauncher/Ulauncher/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Ulauncher/Ulauncher",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Ulauncher/Ulauncher",
          "note": "Free and open source app with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:50.428Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "clipy",
      "category": "clipboard-managers",
      "name": "Clipy",
      "description": "Open-source clipboard manager for macOS, based on ClipMenu, with a clipboard history menu, snippets and keyboard shortcuts.",
      "website": "https://clipy-app.com",
      "source": "https://github.com/Clipy/Clipy",
      "license": "MIT",
      "platforms": [
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Clipy scores 50 out of 100 (grade D) on the clipboard managers criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/clipboard-managers/clipy/",
      "markdown": "https://privacyratings.com/clipboard-managers/clipy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Clipy/Clipy/blob/develop/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/Clipy/Clipy/blob/develop/Clipy/Sources/Dependencies/Firebase.swift",
          "note": "The app sends Google Firebase Analytics events and crash reports by default, with a setting to turn them off. The website loads Google Analytics and the Facebook SDK."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://clipy-app.com",
          "note": "Free open-source app with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Facebook SDK",
            "host": "connect.facebook.net",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:50.421Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "copyq",
      "category": "clipboard-managers",
      "name": "CopyQ",
      "description": "Open-source clipboard manager for Linux, Windows and macOS that saves clipboard history in tabs, with item editing, tags, search, command-line control and scripting.",
      "website": "https://hluk.github.io/CopyQ/",
      "source": "https://github.com/hluk/CopyQ",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "CopyQ scores 80 out of 100 (grade B) on the clipboard managers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/clipboard-managers/copyq/",
      "markdown": "https://privacyratings.com/clipboard-managers/copyq/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hluk/CopyQ/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hluk/CopyQ",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://hluk.github.io/CopyQ/",
          "note": "Free open-source app with no ads, supported by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:50.401Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ditto",
      "category": "clipboard-managers",
      "name": "Ditto",
      "description": "Open-source clipboard manager for Windows that saves text, images, HTML and custom formats in a searchable history, with optional encrypted sync between computers on a network.",
      "website": "https://ditto-cp.sourceforge.io",
      "source": "https://github.com/sabrogden/Ditto",
      "license": "GPL-3.0",
      "platforms": [
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Ditto scores 50 out of 100 (grade D) on the clipboard managers criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/clipboard-managers/ditto/",
      "markdown": "https://privacyratings.com/clipboard-managers/ditto/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sabrogden/Ditto/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://ditto-cp.sourceforge.io",
          "note": "The app has no telemetry, as its README states, but the project website loads Statcounter analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sabrogden/Ditto",
          "note": "Free open-source app with no ads, supported by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:50.563Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "flycut",
      "category": "clipboard-managers",
      "name": "Flycut",
      "description": "Open-source clipboard manager for macOS and iOS, based on Jumpcut, that keeps a history of copied text for developers, with optional iCloud sync.",
      "website": "https://github.com/TermiT/Flycut",
      "source": "https://github.com/TermiT/Flycut",
      "license": "MIT",
      "platforms": [
        "macos",
        "ios"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Flycut scores 80 out of 100 (grade B) on the clipboard managers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/clipboard-managers/flycut/",
      "markdown": "https://privacyratings.com/clipboard-managers/flycut/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TermiT/Flycut/blob/master/license.txt",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TermiT/Flycut",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/TermiT/Flycut",
          "note": "Free open-source app with no ads, supported by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:50.421Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gpaste",
      "category": "clipboard-managers",
      "name": "GPaste",
      "description": "Open-source clipboard manager for GNOME, made of a daemon, a GTK interface, a GNOME Shell extension and a command-line client, with optional encrypted history.",
      "website": "https://github.com/Keruspe/GPaste",
      "source": "https://github.com/Keruspe/GPaste",
      "license": "BSD-2-Clause",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "GPaste scores 80 out of 100 (grade B) on the clipboard managers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/clipboard-managers/gpaste/",
      "markdown": "https://privacyratings.com/clipboard-managers/gpaste/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Keruspe/GPaste/blob/master/COPYING",
          "note": "BSD-2-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Keruspe/GPaste",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Keruspe/GPaste",
          "note": "Free open-source app with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:50.421Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "maccy",
      "category": "clipboard-managers",
      "name": "Maccy",
      "description": "Open-source clipboard manager for macOS that keeps a searchable history of copied items, stored locally on the computer, with keyboard-first navigation.",
      "website": "https://maccy.app",
      "source": "https://github.com/p0deje/Maccy",
      "license": "MIT",
      "platforms": [
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Maccy scores 80 out of 100 (grade B) on the clipboard managers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/clipboard-managers/maccy/",
      "markdown": "https://privacyratings.com/clipboard-managers/maccy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/p0deje/Maccy/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/p0deje/Maccy",
          "note": "No telemetry or analytics in the source code. The website states everything is stored on the computer."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://maccy.app",
          "note": "Free open-source app with no ads, with an optional paid App Store version."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:50.642Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "paste",
      "category": "clipboard-managers",
      "name": "Paste",
      "description": "Clipboard manager for Mac, iPhone and iPad that keeps a searchable history of copied items, with pinboards and optional sync through iCloud.",
      "website": "https://pasteapp.io",
      "license": null,
      "platforms": [
        "macos",
        "ios"
      ],
      "jurisdiction": {
        "code": "DK",
        "name": "Denmark",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Paste scores 20 out of 100 (grade F) on the clipboard managers criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in Denmark: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/clipboard-managers/paste/",
      "markdown": "https://privacyratings.com/clipboard-managers/paste/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://pasteapp.io/privacy",
          "note": "The privacy policy lists PostHog product analytics and Sentry crash reporting in the app, and Plausible analytics on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://pasteapp.io/privacy",
          "note": "Funded by subscriptions, with no ads. The policy states personal data is never sold, and clipboard data is not stored on the vendor's servers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:50.647Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "windows-clipboard-history",
      "category": "clipboard-managers",
      "name": "Windows Clipboard History",
      "description": "Clipboard history built into Windows, opened with Windows key + V. It keeps recent copied items and pinned items, with optional sync across devices through a Microsoft account.",
      "website": "https://support.microsoft.com/en-us/windows/apps/using-the-clipboard",
      "license": null,
      "platforms": [
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Windows Clipboard History scores 20 out of 100 (grade F) on the clipboard managers criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/clipboard-managers/windows-clipboard-history/",
      "markdown": "https://privacyratings.com/clipboard-managers/windows-clipboard-history/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/windows/privacy/configure-windows-diagnostic-data-in-your-organization",
          "note": "Required Windows diagnostic data is sent to Microsoft and can only be turned off on Enterprise, Education and Server editions."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement#mainadvertisingmodule",
          "note": "No ads in the feature, which is included with Windows. Microsoft states it does not use personal files, photos or documents to target ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:50.639Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "apparmor",
      "category": "linux-hardening",
      "name": "AppArmor",
      "description": "A Linux kernel security module that confines programs with per-application profiles restricting file access, network access and capabilities. It is enabled by default on Ubuntu and Debian.",
      "website": "https://apparmor.net",
      "source": "https://gitlab.com/apparmor/apparmor",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "AppArmor scores 80 out of 100 (grade B) on the Linux hardening criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/linux-hardening/apparmor/",
      "markdown": "https://privacyratings.com/linux-hardening/apparmor/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/apparmor/apparmor/-/blob/master/LICENSE",
          "note": "GPL-2.0, with some libraries under other open source licenses."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/apparmor/apparmor",
          "note": "No telemetry or analytics in the source code, and no trackers on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://apparmor.net",
          "note": "Open source project developed by Canonical and community contributors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:35.797Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "bleachbit",
      "category": "linux-hardening",
      "name": "BleachBit",
      "description": "A disk cleaner that deletes caches, cookies, logs, temporary files and other traces left by applications, and can shred files and wipe free space.",
      "website": "https://www.bleachbit.org",
      "source": "https://github.com/bleachbit/bleachbit",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "BleachBit scores 30 out of 100 (grade F) on the Linux hardening criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/linux-hardening/bleachbit/",
      "markdown": "https://privacyratings.com/linux-hardening/bleachbit/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bleachbit/bleachbit/blob/master/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google AdSense (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.bleachbit.org/",
          "note": "The website shows Google AdSense ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:02.047Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "chkrootkit",
      "category": "linux-hardening",
      "name": "chkrootkit",
      "description": "A set of shell scripts and small programs that locally check a Unix-like system for signs of known rootkits.",
      "website": "https://www.chkrootkit.org",
      "source": "https://www.chkrootkit.org/download/",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "chkrootkit scores 30 out of 100 (grade F) on the Linux hardening criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/linux-hardening/chkrootkit/",
      "markdown": "https://privacyratings.com/linux-hardening/chkrootkit/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.chkrootkit.org/COPYRIGHT",
          "note": "BSD-2-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google AdSense."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.chkrootkit.org/",
          "note": "The website shows Google AdSense ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:02.780Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "clamtk",
      "category": "linux-hardening",
      "name": "ClamTk",
      "description": "A graphical front end for the ClamAV antivirus engine that runs on-demand virus scans on Linux. The project is no longer maintained.",
      "website": "https://gitlab.com/dave_m/clamtk/-/wikis/home",
      "source": "https://github.com/dave-theunsub/clamtk",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "ClamTk scores 80 out of 100 (grade B) on the Linux hardening criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/linux-hardening/clamtk/",
      "markdown": "https://privacyratings.com/linux-hardening/clamtk/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dave-theunsub/clamtk/blob/master/LICENSE",
          "note": "Perl license (GPL-1.0 or later, or Artistic License)."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dave-theunsub/clamtk",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/dave-theunsub/clamtk",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:02.047Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "crowdsec",
      "category": "linux-hardening",
      "name": "CrowdSec",
      "description": "An open source security engine that detects attacks in logs and blocks offending IP addresses, and shares signals with a crowdsourced blocklist run by the French company CrowdSec.",
      "website": "https://www.crowdsec.net",
      "source": "https://github.com/crowdsecurity/crowdsec",
      "license": "MIT",
      "platforms": [
        "linux",
        "windows"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "CrowdSec scores 35 out of 100 (grade F) on the Linux hardening criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source. It does not meet no trackers or telemetry and independent audit. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/linux-hardening/crowdsec/",
      "markdown": "https://privacyratings.com/linux-hardening/crowdsec/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/crowdsecurity/crowdsec/blob/master/LICENSE",
          "note": "The Security Engine is MIT-licensed, but the Central API and console that provide the community blocklist are closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://docs.crowdsec.net/docs/central_api/intro/",
          "note": "The website loads Google Analytics, Hotjar, HubSpot and LinkedIn tracking. The engine sends signal metadata and usage metrics to CrowdSec unless the Central API is disabled."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.crowdsec.net/pricing",
          "note": "Funded by paid plans and threat intelligence built from community signals about attacking IP addresses, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Hotjar",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js-na1.hs-scripts.com",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "px.ads.linkedin.com",
            "effect": "no"
          },
          {
            "name": "X (Twitter) Pixel",
            "host": "static.ads-twitter.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:35.721Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "fail2ban",
      "category": "linux-hardening",
      "name": "Fail2Ban",
      "description": "A daemon that scans log files for repeated failed logins and other abuse, and bans the offending IP addresses through firewall rules for a set time.",
      "website": "https://github.com/fail2ban/fail2ban",
      "source": "https://github.com/fail2ban/fail2ban",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Fail2Ban scores 80 out of 100 (grade B) on the Linux hardening criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/linux-hardening/fail2ban/",
      "markdown": "https://privacyratings.com/linux-hardening/fail2ban/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/fail2ban/fail2ban/blob/master/COPYING",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/fail2ban/fail2ban",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/fail2ban/fail2ban",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:35.476Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "firejail",
      "category": "linux-hardening",
      "name": "Firejail",
      "description": "Firejail is a SUID sandbox program that reduces the risk of security breaches by restricting the running environment of untrusted applications using Linux namespaces and seccomp-bpf.",
      "website": "https://github.com/netblue30/firejail",
      "source": "https://github.com/netblue30/firejail",
      "license": "GPL-2.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Firejail scores 80 out of 100 (grade B) on the Linux hardening criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/linux-hardening/firejail/",
      "markdown": "https://privacyratings.com/linux-hardening/firejail/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/netblue30/firejail/blob/master/COPYING",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/netblue30/firejail",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/netblue30/firejail",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:02.048Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "lynis",
      "category": "linux-hardening",
      "name": "Lynis",
      "description": "A command-line security auditing tool from CISOfy that scans Linux, macOS and other Unix-like systems and suggests hardening steps.",
      "website": "https://cisofy.com/lynis/",
      "source": "https://github.com/CISOfy/lynis",
      "license": "GPL-3.0",
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Lynis scores 80 out of 100 (grade B) on the Linux hardening criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the Netherlands: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/linux-hardening/lynis/",
      "markdown": "https://privacyratings.com/linux-hardening/lynis/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/CISOfy/lynis/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://cisofy.com/privacy/",
          "note": "The website avoids analytics tools and third-party cookies, and the tool has no telemetry in its source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cisofy.com/pricing/",
          "note": "Funded by the paid Lynis Enterprise product, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:36.105Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "rkhunter",
      "category": "linux-hardening",
      "name": "Rootkit Hunter",
      "description": "A shell-script scanner that checks Unix-like systems for rootkits, backdoors and local exploits by comparing file hashes and looking for suspicious files and settings. It has had no new release since version 1.4.6.",
      "website": "https://rkhunter.sourceforge.net",
      "source": "https://sourceforge.net/p/rkhunter/rkh_code/ci/master/tree/",
      "license": null,
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Rootkit Hunter scores 80 out of 100 (grade B) on the Linux hardening criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/linux-hardening/rkhunter/",
      "markdown": "https://privacyratings.com/linux-hardening/rkhunter/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://sourceforge.net/projects/rkhunter/",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://rkhunter.sourceforge.net",
          "note": "No telemetry or analytics in the source code. It only contacts the network when the user asks it to check for updates."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://rkhunter.sourceforge.net",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:35.722Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "snort",
      "category": "linux-hardening",
      "name": "Snort",
      "description": "Open source intrusion prevention system capable of real-time traffic analysis and packet logging.",
      "website": "https://www.snort.org",
      "source": "https://github.com/snort3/snort3",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Snort scores 80 out of 100 (grade B) on the Linux hardening criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/linux-hardening/snort/",
      "markdown": "https://privacyratings.com/linux-hardening/snort/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/snort3/snort3/blob/master/COPYING",
          "note": "GPL-3.0 and GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/snort3/snort3",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.snort.org/products",
          "note": "Funded by Cisco and paid rule subscriptions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:02.422Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "syswarden",
      "category": "linux-hardening",
      "name": "SysWarden",
      "description": "Open-source, host-local Linux security orchestrator combining nftables enforcement, system telemetry, threat-intelligence feeds, out-of-band WAAP log analysis and a terminal dashboard.",
      "website": "https://syswarden.io",
      "source": "https://github.com/duggytuxy/syswarden",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "SysWarden scores 80 out of 100 (grade B) on the Linux hardening criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/linux-hardening/syswarden/",
      "markdown": "https://privacyratings.com/linux-hardening/syswarden/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/duggytuxy/syswarden/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/duggytuxy/syswarden",
          "note": "Telemetry is collected and analyzed only on the local host. No analytics are sent to the developer."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/duggytuxy/syswarden/blob/main/.github/FUNDING.yml",
          "note": "Funded through Ko-fi donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:02.888Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "usbguard",
      "category": "linux-hardening",
      "name": "USBGuard",
      "description": "A Linux daemon that blocks or allows USB devices based on a policy of device attributes, protecting against rogue USB devices such as BadUSB.",
      "website": "https://usbguard.github.io",
      "source": "https://github.com/USBGuard/usbguard",
      "license": "GPL-2.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "USBGuard scores 80 out of 100 (grade B) on the Linux hardening criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/linux-hardening/usbguard/",
      "markdown": "https://privacyratings.com/linux-hardening/usbguard/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/USBGuard/usbguard/blob/main/LICENSE",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/USBGuard/usbguard",
          "note": "No telemetry or analytics in the source code, and no trackers on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/USBGuard/usbguard",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:35.891Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "ghostpress",
      "category": "windows-hardening",
      "name": "GhostPress",
      "description": "An anti-keylogger for Windows that blocks low-level keyboard hooks system-wide and can protect selected windows from screenshots.",
      "website": "https://schiffer.tech/ghostpress.html",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "GhostPress scores 50 out of 100 (grade D) on the Windows hardening criteria. It meets 2 of 4 criteria: no trackers or telemetry and no ads or data sales. It does not meet open source and independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/windows-hardening/ghostpress/",
      "markdown": "https://privacyratings.com/windows-hardening/ghostpress/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://schiffer.tech/privacy.html",
          "note": "The privacy policy lists no analytics or tracking, and no trackers were found on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://schiffer.tech/ghostpress.html",
          "note": "Funded by paid Pro and Business licenses, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:02.955Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hardentools",
      "category": "windows-hardening",
      "name": "HardenTools",
      "description": "A utility that disables risky Windows, Microsoft Office, Adobe Reader and LibreOffice features that are commonly abused by malware.",
      "website": "https://github.com/hardentools/hardentools",
      "source": "https://github.com/hardentools/hardentools",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "HardenTools scores 80 out of 100 (grade B) on the Windows hardening criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/windows-hardening/hardentools/",
      "markdown": "https://privacyratings.com/windows-hardening/hardentools/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hardentools/hardentools/blob/master/LICENSE.txt",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hardentools/hardentools",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/hardentools/hardentools",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:02.780Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "iis-crypto",
      "category": "windows-hardening",
      "name": "IIS Crypto",
      "description": "A Windows Server utility for enabling or disabling protocols, ciphers, hashes and key exchange algorithms and reordering TLS cipher suites for IIS and other Windows components.",
      "website": "https://www.nartac.com/Products/IISCrypto",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "IIS Crypto scores 20 out of 100 (grade F) on the Windows hardening criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/windows-hardening/iis-crypto/",
      "markdown": "https://privacyratings.com/windows-hardening/iis-crypto/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.nartac.com/Products/IISCrypto",
          "note": "Free tool from Nartac Software with no ads in the application."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:03.024Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "keyscrambler",
      "category": "windows-hardening",
      "name": "KeyScrambler",
      "description": "Provides protection against software keyloggers. Encrypts keypresses at driver level, and decrypts at application level, to protect against common keyloggers.",
      "website": "https://www.qfxsoftware.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "KeyScrambler scores 50 out of 100 (grade D) on the Windows hardening criteria. It meets 2 of 4 criteria: no trackers or telemetry and no ads or data sales. It does not meet open source and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/windows-hardening/keyscrambler/",
      "markdown": "https://privacyratings.com/windows-hardening/keyscrambler/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.qfxsoftware.com/home/privacy/",
          "note": "Data generated while using the software stays on the computer, and only purchase and support details are collected."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.qfxsoftware.com/home/privacy/",
          "note": "Funded by paid Pro and Premium editions. Personal information is not sold or rented."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:03.164Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "netlimiter",
      "category": "windows-hardening",
      "name": "NetLimiter",
      "description": "An internet traffic control and monitoring tool for Windows that shows per-application connections and sets bandwidth limits, quotas and blocking rules.",
      "website": "https://netlimiter.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CZ",
        "name": "Czechia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "NetLimiter scores 50 out of 100 (grade D) on the Windows hardening criteria. It meets 2 of 4 criteria: no trackers or telemetry and no ads or data sales. It does not meet open source and independent audit. It is based in Czechia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/windows-hardening/netlimiter/",
      "markdown": "https://privacyratings.com/windows-hardening/netlimiter/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://netlimiter.com/privacy-notice",
          "note": "No user data leaves the computer. The program connects only for update checks, license registration and optional VirusTotal checks."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://netlimiter.com/privacy-notice",
          "note": "Funded by paid licenses. Customer data is not shared with others."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:03.273Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "privacy-sexy",
      "category": "windows-hardening",
      "name": "privacy.sexy",
      "description": "An open source web and desktop app that generates and runs scripts to change privacy and security settings and remove telemetry on Windows, macOS and Linux.",
      "website": "https://privacy.sexy",
      "source": "https://github.com/undergroundwires/privacy.sexy",
      "license": "AGPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "privacy.sexy scores 80 out of 100 (grade B) on the Windows hardening criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/windows-hardening/privacy-sexy/",
      "markdown": "https://privacyratings.com/windows-hardening/privacy-sexy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/undergroundwires/privacy.sexy/blob/master/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/undergroundwires/privacy.sexy",
          "note": "No telemetry or analytics in the source code, and no trackers on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://undergroundwires.dev/donate/",
          "note": "Free project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:35.894Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "rkill",
      "category": "windows-hardening",
      "name": "RKill",
      "description": "A Windows utility that terminates known malware processes and removes some of their settings so that regular security software can then run and clean the computer.",
      "website": "https://www.bleepingcomputer.com/download/rkill/",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "RKill scores 0 out of 100 (grade F) on the Windows hardening criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/windows-hardening/rkill/",
      "markdown": "https://privacyratings.com/windows-hardening/rkill/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.bleepingcomputer.com/download/rkill/",
          "note": "The download page loads Google Analytics, Google Tag Manager and DoubleClick."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.bleepingcomputer.com/download/rkill/",
          "note": "Distributed by BleepingComputer, whose website is funded by advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google DoubleClick",
            "host": "securepubads.g.doubleclick.net",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:03.492Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "shutup10",
      "category": "windows-hardening",
      "name": "ShutUp10",
      "description": "A portable freeware tool from O&O Software that controls Windows 10 and 11 privacy settings, telemetry and built-in features.",
      "website": "https://www.oo-software.com/en/shutup10",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "ShutUp10 scores 20 out of 100 (grade F) on the Windows hardening criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/windows-hardening/shutup10/",
      "markdown": "https://privacyratings.com/windows-hardening/shutup10/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics and Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.oo-software.com/en/shutup10",
          "note": "Freeware funded by O&O Software's commercial products and a paid Premium edition, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:04.174Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sigcheck",
      "category": "windows-hardening",
      "name": "SigCheck",
      "description": "A CLI utility that shows file version number, timestamp information, and digital signature details.",
      "website": "https://learn.microsoft.com/en-us/sysinternals/downloads/sigcheck",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "SigCheck scores 50 out of 100 (grade D) on the Windows hardening criteria. It meets 2 of 4 criteria: no trackers or telemetry and no ads or data sales. It does not meet open source and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/windows-hardening/sigcheck/",
      "markdown": "https://privacyratings.com/windows-hardening/sigcheck/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://learn.microsoft.com/en-us/sysinternals/downloads/sigcheck",
          "note": "The tool sends file hashes to VirusTotal only when that option is chosen, and the documentation site loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://learn.microsoft.com/en-us/sysinternals/downloads/sigcheck",
          "note": "Free Microsoft Sysinternals utility with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:03.519Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "usbfix",
      "category": "windows-hardening",
      "name": "USBFix",
      "description": "A Windows tool that detects and removes malware spread through USB removable drives.",
      "website": "https://www.usb-antivirus.com",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "USBFix scores 0 out of 100 (grade F) on the Windows hardening criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/windows-hardening/usbfix/",
      "markdown": "https://privacyratings.com/windows-hardening/usbfix/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google AdSense, Google DoubleClick and Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.usb-antivirus.com/",
          "note": "The website shows Google AdSense ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          },
          {
            "name": "Google DoubleClick",
            "host": "googleads.g.doubleclick.net",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:07.546Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "win11debloat",
      "category": "windows-hardening",
      "name": "Win11Debloat",
      "description": "An open source PowerShell script that removes preinstalled apps, disables telemetry and changes other settings on Windows 10 and 11, with options to undo changes.",
      "website": "https://github.com/Raphire/Win11Debloat",
      "source": "https://github.com/Raphire/Win11Debloat",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Win11Debloat scores 80 out of 100 (grade B) on the Windows hardening criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/windows-hardening/win11debloat/",
      "markdown": "https://privacyratings.com/windows-hardening/win11debloat/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Raphire/Win11Debloat/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Raphire/Win11Debloat",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Raphire/Win11Debloat/blob/master/.github/FUNDING.yml",
          "note": "Funded through GitHub Sponsors and Ko-fi, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:03.520Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "windows-spy-blocker",
      "category": "windows-hardening",
      "name": "Windows Spy Blocker",
      "description": "A Go tool that blocks Windows telemetry and tracking through firewall rules and hosts files built from captured network traffic. It is no longer actively maintained.",
      "website": "https://github.com/crazy-max/WindowsSpyBlocker",
      "source": "https://github.com/crazy-max/WindowsSpyBlocker",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Windows Spy Blocker scores 80 out of 100 (grade B) on the Windows hardening criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/windows-hardening/windows-spy-blocker/",
      "markdown": "https://privacyratings.com/windows-hardening/windows-spy-blocker/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/crazy-max/WindowsSpyBlocker/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/crazy-max/WindowsSpyBlocker",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/crazy-max/WindowsSpyBlocker/blob/master/.github/FUNDING.yml",
          "note": "Funded through GitHub Sponsors and PayPal donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:03.520Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "wpd",
      "category": "windows-hardening",
      "name": "WPD",
      "description": "A portable Windows tool that uses the Windows API to configure group policy, services, tasks and firewall rules related to telemetry, and to remove preinstalled apps.",
      "website": "https://wpd.app",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "WPD scores 20 out of 100 (grade F) on the Windows hardening criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/windows-hardening/wpd/",
      "markdown": "https://privacyratings.com/windows-hardening/wpd/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source with no privacy policy or telemetry statement, so the absence of tracking cannot be checked."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://wpd.app/",
          "note": "Free and without ads, supported by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:03.753Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "blockblock",
      "category": "macos-hardening",
      "name": "BlockBlock",
      "description": "A free macOS tool from Objective-See that monitors common persistence locations and alerts when software tries to install itself to run at startup.",
      "website": "https://objective-see.org/products/blockblock.html",
      "source": "https://github.com/objective-see/BlockBlock",
      "license": "GPL-3.0",
      "platforms": [
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "BlockBlock scores 80 out of 100 (grade B) on the macOS hardening criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/macos-hardening/blockblock/",
      "markdown": "https://privacyratings.com/macos-hardening/blockblock/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/objective-see/BlockBlock/blob/master/LICENSE.md",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/objective-see/BlockBlock",
          "note": "No telemetry or analytics in the source code, and no trackers on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://objective-see.org/about.html",
          "note": "Free tool from the non-profit Objective-See Foundation, funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:36.034Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "knockknock",
      "category": "macos-hardening",
      "name": "KnockKnock",
      "description": "A free macOS tool from Objective-See that lists software installed to run persistently, such as launch agents, login items and extensions, to help find malware.",
      "website": "https://objective-see.org/products/knockknock.html",
      "source": "https://github.com/objective-see/KnockKnock",
      "license": "GPL-3.0",
      "platforms": [
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "KnockKnock scores 80 out of 100 (grade B) on the macOS hardening criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/macos-hardening/knockknock/",
      "markdown": "https://privacyratings.com/macos-hardening/knockknock/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/objective-see/KnockKnock/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/objective-see/KnockKnock",
          "note": "No telemetry or analytics in the source code, and no trackers on the website. File hashes are only sent to VirusTotal when the user adds an API key."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://objective-see.org/about.html",
          "note": "Free tool from the non-profit Objective-See Foundation, funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:36.126Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "oversight",
      "category": "macos-hardening",
      "name": "OverSight",
      "description": "A free macOS tool from Objective-See that alerts when the microphone or webcam is turned on and shows which process is using it.",
      "website": "https://objective-see.org/products/oversight.html",
      "source": "https://github.com/objective-see/OverSight",
      "license": "GPL-3.0",
      "platforms": [
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "OverSight scores 80 out of 100 (grade B) on the macOS hardening criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/macos-hardening/oversight/",
      "markdown": "https://privacyratings.com/macos-hardening/oversight/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/objective-see/OverSight/blob/main/LICENSE.md",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/objective-see/OverSight",
          "note": "No telemetry or analytics in the source code, and no trackers on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://objective-see.org/about.html",
          "note": "Free tool from the non-profit Objective-See Foundation, funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:36.286Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "santa",
      "category": "macos-hardening",
      "name": "Santa",
      "description": "A binary and file access authorization system for macOS that allows or blocks apps by hash, signing certificate or team ID. Created at Google and now maintained by North Pole Security.",
      "website": "https://northpole.dev",
      "source": "https://github.com/northpolesec/santa",
      "license": "Apache-2.0",
      "platforms": [
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Santa scores 50 out of 100 (grade D) on the macOS hardening criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/macos-hardening/santa/",
      "markdown": "https://privacyratings.com/macos-hardening/santa/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/northpolesec/santa/blob/main/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://northpole.security/privacy",
          "note": "The agent reports only to a sync server chosen by the administrator, but the website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://northpole.security",
          "note": "Funded by North Pole Security's commercial management service, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:36.305Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "stronghold",
      "category": "macos-hardening",
      "name": "Stronghold",
      "description": "A command-line tool that configures macOS firewall, logging, sharing and other security settings. It was designed for older macOS releases.",
      "website": "https://github.com/alichtman/stronghold",
      "source": "https://github.com/alichtman/stronghold",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Stronghold scores 80 out of 100 (grade B) on the macOS hardening criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/macos-hardening/stronghold/",
      "markdown": "https://privacyratings.com/macos-hardening/stronghold/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/alichtman/stronghold/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/alichtman/stronghold",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/alichtman/stronghold",
          "note": "Free volunteer project funded by optional donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:03.754Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gnome-boxes",
      "category": "virtual-machines",
      "name": "GNOME Boxes",
      "description": "GNOME desktop app for creating, running and viewing local and remote virtual machines, built on QEMU, KVM and libvirt. It can download operating system images and set up guests automatically.",
      "website": "https://apps.gnome.org/Boxes/",
      "source": "https://gitlab.gnome.org/GNOME/gnome-boxes",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "GNOME Boxes scores 80 out of 100 (grade B) on the virtual machines criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/virtual-machines/gnome-boxes/",
      "markdown": "https://privacyratings.com/virtual-machines/gnome-boxes/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://apps.gnome.org/Boxes/",
          "note": "LGPL-2.1-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://apps.gnome.org/Boxes/",
          "note": "No telemetry or analytics in the source code, and no third-party trackers were found on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://apps.gnome.org/Boxes/",
          "note": "Free GNOME project supported by donations to the GNOME Foundation, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:36.367Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "hyper-v",
      "category": "virtual-machines",
      "name": "Hyper-V",
      "description": "Microsoft's type-1 hypervisor built into Windows Server and the Pro, Enterprise and Education editions of Windows. It runs guest operating systems in isolated virtual machines.",
      "website": "https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/overview",
      "license": null,
      "platforms": [
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Hyper-V scores 10 out of 100 (grade F) on the virtual machines criteria. It partly meets independent audit. It does not meet open source, no trackers or telemetry and no ads or data sales. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/virtual-machines/hyper-v/",
      "markdown": "https://privacyratings.com/virtual-machines/hyper-v/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/windows/privacy/configure-windows-diagnostic-data-in-your-organization",
          "note": "Hyper-V runs as part of Windows, which sends required diagnostic data to Microsoft that can only be turned off on Enterprise, Education and Server editions."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "Included with Windows, which has an advertising ID for personalized ads, and Microsoft uses product usage data for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://learn.microsoft.com/en-us/windows/security/security-foundations/certification/validations/cc-windows-server-2022-2019-2016",
          "note": "Hyper-V has Common Criteria certifications against the virtualization protection profiles, with validation reports published, but no full security audit report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:36.405Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "parallels-desktop",
      "category": "virtual-machines",
      "name": "Parallels Desktop",
      "description": "Proprietary virtualization app for Macs that runs Windows, Linux and macOS guests in virtual machines, including Windows on ARM on Apple silicon. Sold by subscription.",
      "website": "https://www.parallels.com/products/desktop/",
      "license": null,
      "platforms": [
        "macos"
      ],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Parallels Desktop scores 0 out of 100 (grade F) on the virtual machines criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law.",
      "url": "https://privacyratings.com/virtual-machines/parallels-desktop/",
      "markdown": "https://privacyratings.com/virtual-machines/parallels-desktop/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.parallels.com/about/legal/privacy/",
          "note": "The website loads Google Analytics, Google Ads, Hotjar, Marketo, Optimizely, Microsoft Advertising and X ads trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.parallels.com/about/legal/privacy/",
          "note": "The privacy policy allows selling or sharing personal data and using product usage data for personalized advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Ads",
            "host": "www.googleadservices.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google DoubleClick",
            "host": "googleads.g.doubleclick.net",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Hotjar",
            "host": "script.hotjar.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Ads",
            "host": "bat.bing.com",
            "effect": "no"
          },
          {
            "name": "Optimizely",
            "host": "cdn.optimizely.com",
            "effect": "no"
          },
          {
            "name": "X (Twitter) Pixel",
            "host": "analytics.twitter.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:36.517Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "proxmox-ve",
      "category": "virtual-machines",
      "name": "Proxmox VE",
      "description": "Open source server virtualization platform based on Debian that manages KVM virtual machines and LXC containers through a web interface, with clustering, software-defined storage and backup integration.",
      "website": "https://www.proxmox.com/en/products/proxmox-virtual-environment/overview",
      "source": "https://git.proxmox.com",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "AT",
        "name": "Austria",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Proxmox VE scores 65 out of 100 (grade C) on the virtual machines criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in Austria: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/virtual-machines/proxmox-ve/",
      "markdown": "https://privacyratings.com/virtual-machines/proxmox-ve/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://git.proxmox.com/?p=pve-manager.git;a=blob;f=debian/copyright",
          "note": "AGPL-3.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.proxmox.com/en/products/proxmox-virtual-environment/overview",
          "note": "The website runs self-hosted Matomo analytics. The platform itself has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.proxmox.com/en/products/proxmox-virtual-environment/pricing",
          "note": "Free software funded by paid support subscriptions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:37.191Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "qemu",
      "category": "virtual-machines",
      "name": "QEMU",
      "description": "Open source machine emulator and virtualizer. It emulates many CPU architectures and, with KVM, Xen, Hypervisor.framework or WHPX, runs virtual machines at near-native speed.",
      "website": "https://www.qemu.org",
      "source": "https://gitlab.com/qemu-project/qemu",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "QEMU scores 80 out of 100 (grade B) on the virtual machines criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/virtual-machines/qemu/",
      "markdown": "https://privacyratings.com/virtual-machines/qemu/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/qemu-project/qemu/-/blob/master/LICENSE",
          "note": "GPL-2.0, with some parts under compatible licenses."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/qemu-project/qemu",
          "note": "No telemetry or analytics in the source code, and no third-party trackers were found on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.qemu.org/conservancy/",
          "note": "Software Freedom Conservancy member project funded by donations and contributors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:37.349Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "utm",
      "category": "virtual-machines",
      "name": "UTM",
      "description": "Virtual machine app for macOS and iOS built on QEMU and Apple Virtualization. It can run and emulate x86-64, ARM and other guest systems, including on Apple Silicon Macs.",
      "website": "https://mac.getutm.app",
      "source": "https://github.com/utmapp/UTM",
      "license": "Apache-2.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "UTM scores 50 out of 100 (grade D) on the virtual machines criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/virtual-machines/utm/",
      "markdown": "https://privacyratings.com/virtual-machines/utm/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/utmapp/UTM/blob/main/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mac.getutm.app/",
          "note": "Free app funded by optional Mac App Store purchases and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:03.905Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "virt-manager",
      "category": "virtual-machines",
      "name": "virt-manager",
      "description": "Desktop app for managing virtual machines through libvirt, mainly KVM guests, with Xen and LXC support. It includes creation wizards, performance statistics and a built-in VNC and SPICE console.",
      "website": "https://virt-manager.org",
      "source": "https://github.com/virt-manager/virt-manager",
      "license": "GPL-2.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "virt-manager scores 80 out of 100 (grade B) on the virtual machines criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/virtual-machines/virt-manager/",
      "markdown": "https://privacyratings.com/virtual-machines/virt-manager/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/virt-manager/virt-manager/blob/main/COPYING",
          "note": "GPL-2.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/virt-manager/virt-manager",
          "note": "No telemetry or analytics in the source code, and no third-party trackers were found on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://virt-manager.org",
          "note": "Free open source project distributed through operating system repositories, with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:36.880Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "virtualbox",
      "category": "virtual-machines",
      "name": "VirtualBox",
      "description": "Type 2 hypervisor from Oracle for x86-64 and ARM hosts, running on Windows, macOS, Linux and Solaris. It runs guest operating systems in virtual machines on a desktop or server.",
      "website": "https://www.virtualbox.org",
      "source": "https://github.com/VirtualBox/virtualbox",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "VirtualBox scores 65 out of 100 (grade C) on the virtual machines criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/virtual-machines/virtualbox/",
      "markdown": "https://privacyratings.com/virtual-machines/virtualbox/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.virtualbox.org/wiki/Licensing_FAQ",
          "note": "The base package is GPL-3.0 and runs on its own. The optional Extension Pack is proprietary under the PUEL."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.virtualbox.org/manual/ch08.html#vboxmanage-updatecheck",
          "note": "No third-party trackers were found, but an automatic update check that contacts Oracle is on by default and can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.virtualbox.org/wiki/Licensing_FAQ",
          "note": "Free base package, funded by Oracle through paid Extension Pack enterprise licenses, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:04.406Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vmware-workstation-pro",
      "category": "virtual-machines",
      "name": "VMware Workstation Pro",
      "description": "Proprietary desktop hypervisor from Broadcom for Windows and Linux hosts that runs multiple guest operating systems in virtual machines. Free for personal and commercial use.",
      "website": "https://www.vmware.com/products/desktop-hypervisor/workstation-and-fusion",
      "license": null,
      "platforms": [
        "windows",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "VMware Workstation Pro scores 20 out of 100 (grade F) on the virtual machines criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/virtual-machines/vmware-workstation-pro/",
      "markdown": "https://privacyratings.com/virtual-machines/vmware-workstation-pro/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Tag Manager and OneTrust."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://blogs.vmware.com/cloud-foundation/2024/11/11/vmware-fusion-and-workstation-are-now-free-for-all-users/",
          "note": "Free product backed by Broadcom's paid enterprise business, with no ads in the software."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:36.936Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "xen-project",
      "category": "virtual-machines",
      "name": "Xen Project",
      "description": "Open source type-1 hypervisor that runs directly on hardware and hosts multiple isolated operating systems side by side. Used in servers, cloud platforms, embedded systems and Qubes OS.",
      "website": "https://xenproject.org",
      "source": "https://xenbits.xen.org/gitweb/?p=xen.git;a=summary",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Xen Project scores 80 out of 100 (grade B) on the virtual machines criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/virtual-machines/xen-project/",
      "markdown": "https://privacyratings.com/virtual-machines/xen-project/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://xenbits.xen.org/gitweb/?p=xen.git;a=blob;f=COPYING",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://xenbits.xen.org/gitweb/?p=xen.git;a=summary",
          "note": "No telemetry or analytics in the source code, and no third-party trackers were found on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://xenproject.org/about/",
          "note": "Linux Foundation project funded by member organizations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:04.462Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "android-emulator",
      "category": "emulators",
      "name": "Android Emulator",
      "description": "Google's emulator for running Android virtual devices on a computer, included with Android Studio and based on QEMU.",
      "website": "https://developer.android.com/studio/run/emulator",
      "source": "https://android.googlesource.com/platform/external/qemu",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Android Emulator scores 30 out of 100 (grade F) on the emulators and compatibility layers criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/emulators/android-emulator/",
      "markdown": "https://privacyratings.com/emulators/android-emulator/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://android.googlesource.com/platform/external/qemu/+/refs/heads/emu-main-dev/COPYING",
          "note": "GPL-2.0. Google Play system images are proprietary."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "The developer.android.com website uses Google Analytics, and Android Studio and the emulator can send usage statistics and crash reports to Google."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Made by Google, which is funded by advertising and uses data collected across its services for ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:44.044Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "azahar",
      "category": "emulators",
      "name": "Azahar",
      "description": "Open source Nintendo 3DS emulator based on Citra, for desktop and Android.",
      "website": "https://azahar-emu.org",
      "source": "https://github.com/azahar-emu/azahar",
      "license": "GPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Azahar scores 80 out of 100 (grade B) on the emulators and compatibility layers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/emulators/azahar/",
      "markdown": "https://privacyratings.com/emulators/azahar/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/azahar-emu/azahar/blob/master/license.txt",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/io.github.lime3ds.android/latest/",
          "note": "The Android app has 0 trackers in its Exodus report, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/azahar-emu/azahar",
          "note": "Community project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:43.720Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bluestacks",
      "category": "emulators",
      "name": "BlueStacks",
      "description": "Closed source Android emulator for running Android apps and games on Windows and macOS.",
      "website": "https://www.bluestacks.com",
      "license": null,
      "platforms": [
        "windows",
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "BlueStacks scores 0 out of 100 (grade F) on the emulators and compatibility layers criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/emulators/bluestacks/",
      "markdown": "https://privacyratings.com/emulators/bluestacks/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.bluestacks.com/terms-and-privacy.html",
          "note": "The website and services use Google Analytics and advertising cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.bluestacks.com/terms-and-privacy.html",
          "note": "Shows third-party ads, and the privacy policy allows sharing non-identifying user data with advertisers for targeting."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:43.416Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cemu",
      "category": "emulators",
      "name": "Cemu",
      "description": "Open source emulator for the Nintendo Wii U.",
      "website": "https://cemu.info",
      "source": "https://github.com/cemu-project/Cemu",
      "license": "MPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Cemu scores 80 out of 100 (grade B) on the emulators and compatibility layers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/emulators/cemu/",
      "markdown": "https://privacyratings.com/emulators/cemu/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cemu-project/Cemu/blob/main/LICENSE.txt",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cemu-project/Cemu",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/cemu-project/Cemu",
          "note": "Community project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:43.737Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "crossover",
      "category": "emulators",
      "name": "CrossOver",
      "description": "Commercial Wine-based compatibility layer from CodeWeavers that runs Windows applications on macOS, Linux and ChromeOS.",
      "website": "https://www.codeweavers.com/crossover",
      "license": null,
      "platforms": [
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "CrossOver scores 25 out of 100 (grade F) on the emulators and compatibility layers criteria. It partly meets open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/emulators/crossover/",
      "markdown": "https://privacyratings.com/emulators/crossover/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.codeweavers.com/crossover/source",
          "note": "The Wine and other open source components are published, but the CrossOver interface is proprietary."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.codeweavers.com/privacy-policy",
          "note": "The website uses Google Analytics and Google Ads through Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.codeweavers.com/privacy-policy",
          "note": "Funded by license sales, but website data is shared with Google Ads for remarketing."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:43.642Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dolphin",
      "category": "emulators",
      "name": "Dolphin",
      "description": "Open source emulator for the Nintendo GameCube and Wii consoles.",
      "website": "https://dolphin-emu.org",
      "source": "https://github.com/dolphin-emu/dolphin",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Dolphin scores 40 out of 100 (grade D) on the emulators and compatibility layers criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/emulators/dolphin/",
      "markdown": "https://privacyratings.com/emulators/dolphin/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dolphin-emu/dolphin/blob/master/COPYING",
          "note": "GPL-2.0-or-later, with some files under compatible licenses."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://dolphin-emu.org/docs/privacy/",
          "note": "The website loads Google AdSense. The emulator's anonymous usage statistics are opt-in."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://dolphin-emu.org/docs/privacy/",
          "note": "The website shows non-targeted ads to cover hosting costs. The emulator has no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:44.443Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "duckstation",
      "category": "emulators",
      "name": "DuckStation",
      "description": "Emulator for the Sony PlayStation (PS1) for desktop and Android, with source code published under a non-commercial Creative Commons license.",
      "website": "https://www.duckstation.org",
      "source": "https://github.com/stenzek/duckstation",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "DuckStation scores 80 out of 100 (grade B) on the emulators and compatibility layers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/emulators/duckstation/",
      "markdown": "https://privacyratings.com/emulators/duckstation/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/stenzek/duckstation/blob/master/LICENSE",
          "note": "All code is public under CC BY-NC-ND 4.0, a source-available license that is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.github.stenzek.duckstation/latest/",
          "note": "The Android app has 0 trackers in its Exodus report, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/stenzek/duckstation/blob/master/README.md",
          "note": "Free project with no ads and no revenue."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:44.031Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "genymotion",
      "category": "emulators",
      "name": "Genymotion",
      "description": "Closed source Android emulator for app development and testing, offered as a desktop app and as a cloud service.",
      "website": "https://www.genymotion.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "web"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Genymotion scores 20 out of 100 (grade F) on the emulators and compatibility layers criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/emulators/genymotion/",
      "markdown": "https://privacyratings.com/emulators/genymotion/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.genymotion.com/privacy-statement/",
          "note": "Product usage statistics are sent to Amplitude unless turned off, and the website uses Google Tag Manager and Segment."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.genymotion.com/privacy-statement/",
          "note": "Funded by paid licenses, and the privacy statement says user data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:44.240Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mame",
      "category": "emulators",
      "name": "MAME",
      "description": "Open source emulator for arcade machines and many vintage computers and consoles, aimed at preserving and documenting hardware.",
      "website": "https://www.mamedev.org",
      "source": "https://github.com/mamedev/mame",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "MAME scores 80 out of 100 (grade B) on the emulators and compatibility layers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/emulators/mame/",
      "markdown": "https://privacyratings.com/emulators/mame/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mamedev/mame/blob/master/COPYING",
          "note": "GPL-2.0, with some files under less restrictive licenses."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mamedev/mame",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.mamedev.org/",
          "note": "Volunteer project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:44.759Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "pcsx2",
      "category": "emulators",
      "name": "PCSX2",
      "description": "Open source emulator for the Sony PlayStation 2.",
      "website": "https://pcsx2.net",
      "source": "https://github.com/PCSX2/pcsx2",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "PCSX2 scores 80 out of 100 (grade B) on the emulators and compatibility layers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/emulators/pcsx2/",
      "markdown": "https://privacyratings.com/emulators/pcsx2/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/PCSX2/pcsx2/blob/master/COPYING.GPLv3",
          "note": "GPL-3.0, with some components under compatible licenses."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/PCSX2/pcsx2",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/PCSX2/pcsx2",
          "note": "Volunteer project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:44.038Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ppsspp",
      "category": "emulators",
      "name": "PPSSPP",
      "description": "Open source emulator for the Sony PlayStation Portable (PSP).",
      "website": "https://www.ppsspp.org",
      "source": "https://github.com/hrydgard/ppsspp",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "PPSSPP scores 30 out of 100 (grade F) on the emulators and compatibility layers criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/emulators/ppsspp/",
      "markdown": "https://privacyratings.com/emulators/ppsspp/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hrydgard/ppsspp/blob/master/LICENSE.TXT",
          "note": "GPL-2.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.ppsspp.org/privacy/",
          "note": "The website loads Google Analytics and Google AdSense. The apps only send compatibility reports when enabled."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.ppsspp.org/privacy/",
          "note": "The website shows Google AdSense ads. The apps have no ads and are funded by PPSSPP Gold sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:44.517Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "retroarch",
      "category": "emulators",
      "name": "RetroArch",
      "description": "Open source frontend for the libretro API that runs emulators, game engines and media players (cores) through one interface.",
      "website": "https://www.retroarch.com",
      "source": "https://github.com/libretro/RetroArch",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "RetroArch scores 30 out of 100 (grade F) on the emulators and compatibility layers criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/emulators/retroarch/",
      "markdown": "https://privacyratings.com/emulators/retroarch/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/libretro/RetroArch/blob/master/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.retroarch.com/?page=privacy",
          "note": "The website uses Google Analytics and Google AdSense. The Android app has no known trackers in its Exodus report."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.retroarch.com/?page=privacy",
          "note": "The website shows Google AdSense ads based on visits to other sites. The apps have no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cookiebot",
            "host": "consent.cookiebot.com",
            "effect": "none"
          },
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:44.737Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "rpcs3",
      "category": "emulators",
      "name": "RPCS3",
      "description": "Open source emulator for the Sony PlayStation 3.",
      "website": "https://rpcs3.net",
      "source": "https://github.com/RPCS3/rpcs3",
      "license": "GPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "RPCS3 scores 30 out of 100 (grade F) on the emulators and compatibility layers criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/emulators/rpcs3/",
      "markdown": "https://privacyratings.com/emulators/rpcs3/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/RPCS3/rpcs3/blob/master/LICENSE",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google AdSense and Cloudflare Web Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "The website shows Google AdSense ads. The emulator has no ads and is funded mainly by Patreon."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:44.367Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "trinityemulator",
      "category": "emulators",
      "name": "TrinityEmulator",
      "description": "Research Android emulator for Windows, built on QEMU, that runs Android-x86 and renders graphics through a technique called graphics projection. Released as a beta research artifact.",
      "website": "https://github.com/TrinityEmulator/TrinityEmulator",
      "source": "https://github.com/TrinityEmulator/TrinityEmulator",
      "license": null,
      "platforms": [
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "TrinityEmulator scores 50 out of 100 (grade D) on the emulators and compatibility layers criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/emulators/trinityemulator/",
      "markdown": "https://privacyratings.com/emulators/trinityemulator/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TrinityEmulator/TrinityEmulator/blob/main/LICENSE",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/TrinityEmulator/TrinityEmulator/blob/main/README.md",
          "note": "The bundled Android-x86 guest image includes Google apps (OpenGApps), which send data to Google."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/TrinityEmulator/TrinityEmulator/blob/main/README.md",
          "note": "Academic research project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:44.241Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "waydroid",
      "category": "emulators",
      "name": "Waydroid",
      "description": "Open source tool that runs a full Android system in a container on Linux, using LXC and Wayland.",
      "website": "https://waydro.id",
      "source": "https://github.com/waydroid/waydroid",
      "license": "GPL-3.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Waydroid scores 80 out of 100 (grade B) on the emulators and compatibility layers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/emulators/waydroid/",
      "markdown": "https://privacyratings.com/emulators/waydroid/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/waydroid/waydroid/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/waydroid/waydroid",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/waydroid",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:44.425Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "wine",
      "category": "emulators",
      "name": "Wine",
      "description": "Open source compatibility layer that runs Windows applications on Linux, macOS and other Unix-like systems.",
      "website": "https://www.winehq.org",
      "source": "https://gitlab.winehq.org/wine/wine",
      "license": null,
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Wine scores 50 out of 100 (grade D) on the emulators and compatibility layers criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/emulators/wine/",
      "markdown": "https://privacyratings.com/emulators/wine/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.winehq.org/wine/wine/-/blob/master/LICENSE",
          "note": "LGPL-2.1-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://gitlab.winehq.org/winehq/winehq/-/wikis/Privacy-Policy",
          "note": "The WineHQ privacy policy states that the website uses Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gitlab.winehq.org/winehq/winehq/-/wikis/Privacy-Policy",
          "note": "Funded by donations and sponsors with no ads, and the privacy policy says user information is not given to third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:44.702Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "xemu",
      "category": "emulators",
      "name": "xemu",
      "description": "Open source emulator for the original Microsoft Xbox, based on QEMU.",
      "website": "https://xemu.app",
      "source": "https://github.com/xemu-project/xemu",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "xemu scores 50 out of 100 (grade D) on the emulators and compatibility layers criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/emulators/xemu/",
      "markdown": "https://privacyratings.com/emulators/xemu/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/xemu-project/xemu/blob/master/LICENSE",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.patreon.com/mborgerson",
          "note": "Funded by donations through Patreon, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:44.881Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "affine",
      "category": "notes",
      "name": "AFFiNE",
      "description": "Workspace that combines documents, whiteboards and databases on one canvas, with local-first storage, real-time collaboration, AI features and optional cloud sync or self-hosting.",
      "website": "https://affine.pro",
      "source": "https://github.com/toeverything/AFFiNE",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "SG",
        "name": "Singapore",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "AFFiNE scores 40 out of 100 (grade D) on the notes criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Singapore: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/notes/affine/",
      "markdown": "https://privacyratings.com/notes/affine/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/toeverything/AFFiNE/blob/canary/LICENSE",
          "note": "All code is public. The apps are MIT, and the server backend in the same repository uses a source-available Enterprise Edition license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/app.affine.pro/latest/",
          "note": "Exodus finds Google Firebase Analytics and CrashLytics in the Android app, and the website loads Google Analytics, PostHog and TikTok scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://affine.pro/privacy",
          "note": "Funded by paid plans with no ads in the apps, but the privacy policy allows using personal data to personalize advertising within the services."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:37.027Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "anytype",
      "category": "notes",
      "name": "Anytype",
      "description": "Local-first workspace for notes, documents, tasks and databases built from linked objects and types. Data is end-to-end encrypted and syncs peer to peer or through the Any network, which can be self-hosted.",
      "website": "https://anytype.io",
      "source": "https://github.com/anyproto/anytype-ts",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Anytype scores 35 out of 100 (grade F) on the notes criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source. It does not meet no trackers or telemetry and independent audit. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law.",
      "url": "https://privacyratings.com/notes/anytype/",
      "markdown": "https://privacyratings.com/notes/anytype/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/anyproto/anytype-ts/blob/develop/LICENSE.md",
          "note": "The apps are published under the Any Source Available License, which is not OSI-approved and limits commercial use."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://doc.anytype.io/anytype/data/analytics-and-tracking",
          "note": "The apps send usage events to Amplitude and crash reports to Sentry, and this cannot be turned off in settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://anytype.io/pricing/",
          "note": "Funded by paid memberships, with no ads. Content is end-to-end encrypted."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:37.832Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "appflowy",
      "category": "notes",
      "name": "AppFlowy",
      "description": "Open source workspace for notes, documents, wikis, databases and kanban boards, with AI features and optional self-hosted or AppFlowy Cloud sync. Local-first desktop and mobile apps.",
      "website": "https://appflowy.com",
      "source": "https://github.com/AppFlowy-IO/AppFlowy",
      "license": "AGPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "SG",
        "name": "Singapore",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "AppFlowy scores 50 out of 100 (grade D) on the notes criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Singapore: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/notes/appflowy/",
      "markdown": "https://privacyratings.com/notes/appflowy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/AppFlowy-IO/AppFlowy/blob/main/LICENSE",
          "note": "AGPL-3.0. The AppFlowy Cloud server is also AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://appflowy.com/privacy",
          "note": "The website uses Google Analytics. Exodus finds no trackers in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://appflowy.com/pricing",
          "note": "Funded by paid cloud plans, with no ads in the apps."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:38.681Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "apple-notes",
      "category": "notes",
      "name": "Apple Notes",
      "description": "Apple's built-in notes app for iPhone, iPad and Mac, with checklists, attachments, scanned documents, folders and tags. Notes sync through iCloud and are end-to-end encrypted only when Advanced Data Protection is turned on.",
      "website": "https://support.apple.com/guide/notes/welcome/mac",
      "license": null,
      "platforms": [
        "macos",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Apple Notes scores 35 out of 100 (grade F) on the notes criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets no trackers or telemetry. It does not meet open source and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/notes/apple-notes/",
      "markdown": "https://privacyratings.com/notes/apple-notes/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/device-analytics/",
          "note": "No third-party trackers in the app, and sharing device analytics with Apple is opt-in. Apple web pages load Apple's own analytics (ac-analytics, sent to metrics.apple.com) by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/en-ww/",
          "note": "No ads in the app, which is included with Apple devices. Apple states it does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:37.493Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "bear",
      "category": "notes",
      "name": "Bear",
      "description": "Markdown note-taking app for Apple devices with nested tags, backlinks, note encryption with a password and iCloud sync. A Pro subscription adds sync, themes and export options.",
      "website": "https://bear.app",
      "license": null,
      "platforms": [
        "macos",
        "ios"
      ],
      "jurisdiction": {
        "code": "IE",
        "name": "Ireland",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Bear scores 20 out of 100 (grade F) on the notes criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in Ireland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/notes/bear/",
      "markdown": "https://privacyratings.com/notes/bear/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://bear.app/privacy/",
          "note": "The website, including the privacy policy page, loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://bear.app/",
          "note": "Funded by Bear Pro subscriptions, with no ads in the app."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:37.892Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "cryptee",
      "category": "notes",
      "name": "Cryptee",
      "description": "Encrypted documents editor and photo storage with client-side encryption, usable in the browser or as an installable app. Sign-up needs no personal information.",
      "website": "https://crypt.ee",
      "source": "https://github.com/cryptee/web-client",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "EE",
        "name": "Estonia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Cryptee scores 50 out of 100 (grade D) on the notes criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source and no trackers or telemetry. It does not meet independent audit. It is based in Estonia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/notes/cryptee/",
      "markdown": "https://privacyratings.com/notes/cryptee/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/cryptee/web-client/blob/v3/license.md",
          "note": "The web client is MIT-licensed. The server code is not published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://crypt.ee/privacy",
          "note": "No third-party analytics; the service uses its own anonymous analytics and automatic error reporting through Sentry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://crypt.ee/privacy",
          "note": "Funded by paid plans. The privacy policy states there are no ads and data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:04.940Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "evernote",
      "category": "notes",
      "name": "Evernote",
      "description": "Proprietary note-taking app for text, web clips, images, PDFs and tasks, with notebooks, tags and search across devices. Notes are stored on Evernote's servers without end-to-end encryption. Owned by Bending Spoons.",
      "website": "https://evernote.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "IT",
        "name": "Italy",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Evernote scores 30 out of 100 (grade F) on the notes criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets independent audit. It does not meet open source and no trackers or telemetry. It is based in Italy: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/notes/evernote/",
      "markdown": "https://privacyratings.com/notes/evernote/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://evernote.com/privacy/policy",
          "note": "The website loads OneTrust, TikTok and Sentry scripts, and the privacy policy describes profiling cookies used for advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://evernote.com/privacy/policy",
          "note": "Funded by paid subscriptions. The privacy policy states personal data is not sold or shared with third parties for their own advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://evernote.com/security",
          "note": "Yearly penetration tests by an external firm and ISO 27001 certification are stated, but the reports are only available on request under NDA."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:39.207Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "fossify-notes",
      "category": "notes",
      "name": "Fossify Notes",
      "description": "Open source Android note-taking app for text notes and checklists, with a home screen widget. Works offline with no internet permission.",
      "website": "https://github.com/FossifyOrg/Notes",
      "source": "https://github.com/FossifyOrg/Notes",
      "license": "GPL-3.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Fossify Notes scores 80 out of 100 (grade B) on the notes criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/notes/fossify-notes/",
      "markdown": "https://privacyratings.com/notes/fossify-notes/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/FossifyOrg/Notes/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.fossify.notes/latest/",
          "note": "Exodus finds no trackers, and the app has no internet permission."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/FossifyOrg/Notes",
          "note": "Free, community-maintained app with no ads, as stated in the project README."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:37.358Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "google-keep",
      "category": "notes",
      "name": "Google Keep",
      "description": "Google's note-taking app for quick text notes, checklists, images, drawings and voice memos, with labels, colors and reminders. Notes sync through a Google account and are not end-to-end encrypted.",
      "website": "https://keep.google.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Google Keep scores 30 out of 100 (grade F) on the notes criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/notes/google-keep/",
      "markdown": "https://privacyratings.com/notes/google-keep/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://play.google.com/store/apps/datasafety?id=com.google.android.keep",
          "note": "Exodus finds no third-party trackers, but the Play data safety listing declares collection of app interactions, diagnostics and device IDs for analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://play.google.com/store/apps/datasafety?id=com.google.android.keep",
          "note": "Free app with no ads. The Play data safety listing declares no sharing with third parties and no data use for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cloud.google.com/security/compliance/soc-3",
          "note": "Google Workspace, which includes Keep, has third-party SOC 2 audits. Only the SOC 3 summary report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:58.894Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "joplin",
      "category": "notes",
      "name": "Joplin",
      "description": "Open source note-taking and to-do app for desktop, mobile and terminal, using Markdown notes organised in notebooks. Supports end-to-end encrypted sync through Joplin Cloud, Nextcloud, WebDAV, Dropbox, OneDrive or S3.",
      "website": "https://joplinapp.org",
      "source": "https://github.com/laurent22/joplin",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Joplin scores 50 out of 100 (grade D) on the notes criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/notes/joplin/",
      "markdown": "https://privacyratings.com/notes/joplin/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/laurent22/joplin/blob/dev/LICENSE",
          "note": "All code is public. The apps are AGPL-3.0, and Joplin Server, which runs Joplin Cloud, uses the source-available Joplin Server Personal Use License, which is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Analytics and Google Tag Manager. The apps have no trackers according to Exodus."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://joplinapp.org/donate/",
          "note": "Funded by donations and paid Joplin Cloud plans, with no ads in the apps."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:05.375Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "logseq",
      "category": "notes",
      "name": "Logseq",
      "description": "Open source outliner and knowledge base that stores notes as local Markdown or Org-mode files, with linked references, a graph view and journals. Available for desktop and mobile.",
      "website": "https://logseq.com",
      "source": "https://github.com/logseq/logseq",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Logseq scores 50 out of 100 (grade D) on the notes criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/notes/logseq/",
      "markdown": "https://privacyratings.com/notes/logseq/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/logseq/logseq/blob/master/LICENSE.md",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/logseq/logseq/blob/master/src/main/frontend/modules/instrumentation/core.cljs",
          "note": "The apps send usage data to PostHog and error reports to Sentry by default. This can be turned off in settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://blog.logseq.com/privacy-policy/",
          "note": "The privacy policy states that data is not sold or used for advertising. Funded by sponsors and paid sync."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:05.057Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "markor",
      "category": "notes",
      "name": "Markor",
      "description": "Open source Android text editor and notebook for Markdown, todo.txt and plain-text files stored locally. Works offline and can use any sync app for the files.",
      "website": "https://github.com/gsantner/markor",
      "source": "https://github.com/gsantner/markor",
      "license": null,
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Markor scores 80 out of 100 (grade B) on the notes criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/notes/markor/",
      "markdown": "https://privacyratings.com/notes/markor/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gsantner/markor/blob/master/LICENSE.txt",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/net.gsantner.markor/latest/",
          "note": "Exodus finds no trackers, and the app does not connect to the internet unless notes reference external resources."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/gsantner/markor",
          "note": "Free app with no ads, as stated in the project README."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:37.359Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "memos",
      "category": "notes",
      "name": "Memos",
      "description": "Open source, self-hosted note-taking service for quick Markdown notes in a timeline, with tags, file attachments and an API. Runs as a single lightweight server with a web interface and stores data in SQLite, MySQL or PostgreSQL.",
      "website": "https://usememos.com",
      "source": "https://github.com/usememos/memos",
      "license": "MIT",
      "platforms": [
        "linux",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Memos scores 80 out of 100 (grade B) on the notes criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/notes/memos/",
      "markdown": "https://privacyratings.com/notes/memos/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/usememos/memos/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/usememos/memos",
          "note": "No telemetry or analytics in the source code, and no third-party trackers were found on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/usememos/memos",
          "note": "Free self-hosted software funded by sponsors, with no ads in the app."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:37.464Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "microsoft-onenote",
      "category": "notes",
      "name": "Microsoft OneNote",
      "description": "Microsoft's note-taking app that organizes typed, handwritten and audio notes in notebooks, sections and pages, synced through OneDrive. Free with a Microsoft account and included in Microsoft 365.",
      "website": "https://www.microsoft.com/en-us/microsoft-365/onenote/digital-note-taking-app",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Microsoft OneNote scores 30 out of 100 (grade F) on the notes criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/notes/microsoft-onenote/",
      "markdown": "https://privacyratings.com/notes/microsoft-onenote/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.microsoft.office.onenote/latest/",
          "note": "Exodus finds HockeyApp, App Center Crashes and OpenTelemetry in the Android app, and Office apps send required diagnostic data to Microsoft by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "No ads in OneNote, and the privacy statement says personal files and documents are not used to target ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2",
          "note": "OneNote is covered by independent Office 365 SOC 2 Type 2 audits, but the reports are only available to signed-in Microsoft 365 customers."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:37.736Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "notable",
      "category": "notes",
      "name": "Notable",
      "description": "Markdown-based note-taking app for desktop that stores notes and attachments as plain files on disk. No mobile app, built-in sync or encryption.",
      "website": "https://notable.app",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Notable scores 35 out of 100 (grade F) on the notes criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets no trackers or telemetry. It does not meet open source and independent audit.",
      "url": "https://privacyratings.com/notes/notable/",
      "markdown": "https://privacyratings.com/notes/notable/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/notable/notable/blob/master/SOURCE_CODE.md",
          "note": "Closed source since version 1.6. Only versions up to 1.5.1 were published as open source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://notable.app/",
          "note": "No third-party trackers were found, but the website sends page views and clicks to its own telemetry endpoint. The closed-source app cannot be checked."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://notable.app/",
          "note": "The desktop app is free and has no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:05.671Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "notesnook",
      "category": "notes",
      "name": "Notesnook",
      "description": "End-to-end encrypted note-taking app with rich text notes, notebooks, tags, app lock and private vault. Open source clients and sync server; paid plans add storage and features.",
      "website": "https://notesnook.com",
      "source": "https://github.com/streetwriters/notesnook",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "PK",
        "name": "Pakistan",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Notesnook scores 65 out of 100 (grade C) on the notes criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in Pakistan: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/notes/notesnook/",
      "markdown": "https://privacyratings.com/notes/notesnook/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/streetwriters/notesnook/blob/master/LICENSE",
          "note": "GPL-3.0 for the apps. The sync server is AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://notesnook.com/privacy",
          "note": "First-party usage telemetry is on by default and can be turned off in settings, and the website uses self-hosted Umami analytics. Exodus finds no trackers in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://notesnook.com/pricing",
          "note": "Funded by paid subscriptions. The privacy policy states user data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:38.213Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "notion",
      "category": "notes",
      "name": "Notion",
      "description": "Proprietary workspace app that combines notes, documents, wikis, databases and project management, with real-time collaboration and built-in AI features. Content is stored on Notion's servers without end-to-end encryption.",
      "website": "https://www.notion.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Notion scores 20 out of 100 (grade F) on the notes criteria. It partly meets no ads or data sales and independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/notes/notion/",
      "markdown": "https://privacyratings.com/notes/notion/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.notion.com/trust/privacy-policy",
          "note": "The privacy policy allows third-party analytics and advertising cookies and pixels on the website, and Exodus finds Google CrashLytics in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.notion.com/trust/privacy-policy",
          "note": "No ads in the app, but the privacy policy discloses device and browsing data to advertising partners, which it says may count as a sale."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.notion.com/security",
          "note": "SOC 2 Type 2 and ISO audits by independent firms are stated, but the reports are only available on request through the Trust Center."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:37.849Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "obsidian",
      "category": "notes",
      "name": "Obsidian",
      "description": "Knowledge base and note-taking app that works on local Markdown files, with links between notes, a graph view and a large community plugin and theme ecosystem. Optional paid sync and publishing services.",
      "website": "https://obsidian.md",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 70,
      "coverage": 100,
      "summary": "Obsidian scores 70 out of 100 (grade C) on the notes criteria. It meets 3 of 4 criteria: no trackers or telemetry, no ads or data sales and independent audit. It does not meet open source. It is based in Canada: Five Eyes member.",
      "url": "https://privacyratings.com/notes/obsidian/",
      "markdown": "https://privacyratings.com/notes/obsidian/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. The GitHub repository only holds releases and community plugin lists."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://obsidian.md/privacy",
          "note": "The privacy policy states the apps collect no personal data or telemetry. The update check can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://obsidian.md/about",
          "note": "Funded by users through paid licences and add-on services, with no investors or ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://obsidian.md/files/security/2024-Obsidian-Cure53-Client-Audit-Full.pdf",
          "note": "Cure53 published a full penetration test and source code audit of the desktop and mobile apps. Obsidian Sync was also audited by Trail of Bits."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:05.410Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "poznote",
      "category": "notes",
      "name": "Poznote",
      "description": "Self-hosted notes and tasks web app with rich-text, Markdown and drawing editors, tags, multiple users, OIDC login and a REST API. Runs in Docker with PHP and SQLite.",
      "website": "https://poznote.com",
      "source": "https://github.com/timothepoznanski/poznote",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Poznote scores 80 out of 100 (grade B) on the notes criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/notes/poznote/",
      "markdown": "https://privacyratings.com/notes/poznote/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/timothepoznanski/poznote/blob/main/LICENCE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/timothepoznanski/poznote/blob/main/README.md",
          "note": "The documentation states the only default outbound connection is a daily update check, with no analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/timothepoznanski/poznote/blob/main/.github/FUNDING.yml",
          "note": "Free self-hosted software funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:06.033Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "qownnotes",
      "category": "notes",
      "name": "QOwnNotes",
      "description": "Open source desktop notepad that stores notes as plain-text Markdown files, with optional Nextcloud or ownCloud sync, note versioning, per-note encryption, scripting and a to-do list integration.",
      "website": "https://www.qownnotes.org",
      "source": "https://github.com/pbek/QOwnNotes",
      "license": "GPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "QOwnNotes scores 65 out of 100 (grade C) on the notes criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/notes/qownnotes/",
      "markdown": "https://privacyratings.com/notes/qownnotes/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pbek/QOwnNotes/blob/main/LICENSE",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.qownnotes.org/faq/metrics.html",
          "note": "Usage metrics are sent to a self-hosted Matomo server by default and can be turned off at first start or in settings. No data is shared with third parties."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.qownnotes.org/contributing/donate.html",
          "note": "Free app funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:38.476Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "simplenote",
      "category": "notes",
      "name": "Simplenote",
      "description": "Plain-text note-taking app from Automattic with Markdown support, tags, version history and sync across devices. Free, with open source client apps.",
      "website": "https://simplenote.com",
      "source": "https://github.com/Automattic/simplenote-electron",
      "license": "GPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Simplenote scores 25 out of 100 (grade F) on the notes criteria. It partly meets open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/notes/simplenote/",
      "markdown": "https://privacyratings.com/notes/simplenote/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/Automattic/simplenote-electron/blob/trunk/LICENSE.md",
          "note": "The desktop, Android and iOS apps are GPL-2.0, but the Simperium sync server is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.automattic.simplenote/latest/",
          "note": "Exodus finds Sentry in the Android app, and the Automattic privacy policy allows third-party analytics providers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://automattic.com/privacy/",
          "note": "No ads in the app, but the Automattic privacy policy shares device identifiers and browsing activity with advertising partners."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "WordPress.com Stats",
            "host": "stats.wp.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:38.037Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "siyuan",
      "category": "notes",
      "name": "SiYuan",
      "description": "Local-first personal knowledge management app with Markdown editing, block-level references, bidirectional links and databases. Data stays on the device, with optional paid end-to-end encrypted cloud sync or third-party storage sync.",
      "website": "https://b3log.org/siyuan/en/",
      "source": "https://github.com/siyuan-note/siyuan",
      "license": "AGPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CN",
        "name": "China",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "SiYuan scores 80 out of 100 (grade B) on the notes criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in China: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/notes/siyuan/",
      "markdown": "https://privacyratings.com/notes/siyuan/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/siyuan-note/siyuan/blob/master/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://b3log.org/siyuan/en/privacy.html",
          "note": "The privacy policy states the app collects no personal information or usage data. Exodus finds no trackers in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://b3log.org/siyuan/en/pricing.html",
          "note": "Free core app funded by one-time Pro licences, cloud sync subscriptions and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:38.483Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "standard-notes",
      "category": "notes",
      "name": "Standard Notes",
      "description": "End-to-end encrypted notes app for web, desktop and mobile, with open source clients and server. Paid plans add editors, file storage and more; the server can be self-hosted.",
      "website": "https://standardnotes.com",
      "source": "https://github.com/standardnotes/app",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 90,
      "coverage": 100,
      "summary": "Standard Notes scores 90 out of 100 (grade A) on the notes criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It partly meets independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/notes/standard-notes/",
      "markdown": "https://privacyratings.com/notes/standard-notes/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/standardnotes/app/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://standardnotes.com/privacy",
          "note": "The privacy policy rules out third-party tracking and uses self-hosted analytics. Exodus finds no trackers in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://standardnotes.com/plans",
          "note": "Funded by paid subscriptions. Notes are end-to-end encrypted and not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://assets.standardnotes.com/security/2022-Pentest-Report.pdf",
          "note": "Cure53 and Trail of Bits have published full reports, but the most recent covers the server backend and is older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:06.002Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "trilium-notes",
      "category": "notes",
      "name": "Trilium Notes",
      "description": "Open source hierarchical note-taking app for building a personal knowledge base, with rich text, code, diagrams, scripting and per-note encryption. Runs on the desktop or syncs with a self-hosted server. Maintained by the TriliumNext community.",
      "website": "https://triliumnotes.org",
      "source": "https://github.com/TriliumNext/Trilium",
      "license": "AGPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Trilium Notes scores 80 out of 100 (grade B) on the notes criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/notes/trilium-notes/",
      "markdown": "https://privacyratings.com/notes/trilium-notes/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TriliumNext/Trilium/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://triliumnotes.org",
          "note": "No third-party trackers, and the app has no telemetry. The website's Cloudflare Web Analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://triliumnotes.org",
          "note": "Free community project with no paid tiers, accounts or ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:38.174Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "turtl",
      "category": "notes",
      "name": "Turtl",
      "description": "End-to-end encrypted, collaborative notebook for notes, bookmarks, passwords and files, with desktop and mobile apps. Can be self-hosted or used with the hosted service.",
      "website": "https://turtlapp.com",
      "source": "https://github.com/turtl/desktop",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Turtl scores 65 out of 100 (grade C) on the notes criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/notes/turtl/",
      "markdown": "https://privacyratings.com/notes/turtl/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/turtl/desktop/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.lyonbros.turtl/latest/",
          "note": "Exodus finds no trackers in the Android app, but the website uses self-hosted Matomo analytics that is not stated to be cookieless."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://turtlapp.com/privacy/",
          "note": "Funded by paid plans. The privacy policy rules out third-party advertising and sharing data with third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:06.072Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vnote",
      "category": "notes",
      "name": "VNote",
      "description": "Qt-based note-taking app for Linux, Windows and macOS focused on Markdown editing. Notes are stored as plain files on the local system.",
      "website": "https://docs.vnote.fun",
      "source": "https://github.com/vnotex/vnote",
      "license": "LGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "VNote scores 80 out of 100 (grade B) on the notes criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/notes/vnote/",
      "markdown": "https://privacyratings.com/notes/vnote/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/vnotex/vnote/blob/master/COPYING.LESSER",
          "note": "LGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/vnotex/vnote",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/vnotex/vnote/wiki/Donate-List",
          "note": "Free app supported by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:06.202Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "zettlr",
      "category": "notes",
      "name": "Zettlr",
      "description": "Open source Markdown editor for notes and academic writing, with Zettelkasten linking, citation management through Zotero and CSL, and export through Pandoc. Works on local files.",
      "website": "https://www.zettlr.com",
      "source": "https://github.com/Zettlr/Zettlr",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Zettlr scores 65 out of 100 (grade C) on the notes criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/notes/zettlr/",
      "markdown": "https://privacyratings.com/notes/zettlr/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Zettlr/Zettlr/blob/develop/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.zettlr.com/privacy",
          "note": "The app has no telemetry, but the website runs self-hosted Matomo analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.zettlr.com/supporters",
          "note": "Free app funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:38.721Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "apple-journal",
      "category": "journaling",
      "name": "Apple Journal",
      "description": "Apple's built-in journaling app for iPhone, iPad and Mac, with multimedia entries, multiple journals and on-device writing suggestions. Journal data syncs through iCloud with end-to-end encryption.",
      "website": "https://support.apple.com/guide/journal/welcome/mac",
      "license": null,
      "platforms": [
        "ios",
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Apple Journal scores 35 out of 100 (grade F) on the journaling apps criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets no trackers or telemetry. It does not meet open source and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/journaling/apple-journal/",
      "markdown": "https://privacyratings.com/journaling/apple-journal/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/device-analytics/",
          "note": "No third-party trackers in the app, and sharing device analytics with Apple is opt-in. Apple web pages load Apple's own analytics (ac-analytics, sent to metrics.apple.com) by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/en-ww/",
          "note": "No ads in the app, which is included with Apple devices. Apple states it does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:51.047Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dailytxt",
      "category": "journaling",
      "name": "DailyTxT",
      "description": "Self-hosted, encrypted diary web app run with Docker, with Markdown entries, tags, encrypted file uploads and multiple users.",
      "website": "https://github.com/PhiTux/DailyTxT",
      "source": "https://github.com/PhiTux/DailyTxT",
      "license": "MIT",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "DailyTxT scores 80 out of 100 (grade B) on the journaling apps criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/journaling/dailytxt/",
      "markdown": "https://privacyratings.com/journaling/dailytxt/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/PhiTux/DailyTxT/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/PhiTux/DailyTxT",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/PhiTux/DailyTxT/blob/main/README.md",
          "note": "Free software supported by donations. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:50.640Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "day-one",
      "category": "journaling",
      "name": "Day One",
      "description": "Closed-source journaling app from Automattic for iOS, Android, macOS, Windows and the web, with photos, audio, templates, cloud sync and end-to-end encrypted journals.",
      "website": "https://dayoneapp.com",
      "license": null,
      "platforms": [
        "ios",
        "android",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Day One scores 20 out of 100 (grade F) on the journaling apps criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/journaling/day-one/",
      "markdown": "https://privacyratings.com/journaling/day-one/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.dayoneapp.dayone/latest/",
          "note": "The website uses Google Analytics, and Exodus finds Sentry and OpenTelemetry in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://dayoneapp.com/privacy-policy/",
          "note": "Funded by Day One Gold subscriptions. The privacy policy states personal data is not sold or shared for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "WordPress.com Stats",
            "host": "stats.wp.com",
            "effect": "no"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:50.856Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "daylio",
      "category": "journaling",
      "name": "Daylio",
      "description": "Closed-source mood tracker and micro-diary for Android and iOS where entries are made by picking moods and activities, with statistics and optional backups to Google Drive or iCloud. Entries are stored on the device.",
      "website": "https://daylio.net",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "SK",
        "name": "Slovakia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Daylio scores 10 out of 100 (grade F) on the journaling apps criteria. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in Slovakia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/journaling/daylio/",
      "markdown": "https://privacyratings.com/journaling/daylio/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/net.daylio/latest/",
          "note": "Exodus finds Google Analytics, Firebase Analytics and Crashlytics in the Android app, and the privacy policy lists Firebase Analytics on iOS too."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://daylio.net/faq/privacy-policy/",
          "note": "Funded by Premium subscriptions with no ads in the app, but the Google Advertising ID is used, with permission, to measure Daylio's own ad campaigns."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:51.931Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "diarium",
      "category": "journaling",
      "name": "Diarium",
      "description": "Closed-source journal app for Windows, Android, iOS and macOS that stores entries locally and can sync them through the user's own cloud storage, such as OneDrive, Google Drive, Dropbox, iCloud or WebDAV.",
      "website": "https://diariumapp.com",
      "license": null,
      "platforms": [
        "windows",
        "android",
        "ios",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Diarium scores 20 out of 100 (grade F) on the journaling apps criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/journaling/diarium/",
      "markdown": "https://privacyratings.com/journaling/diarium/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://diariumapp.com/privacypolicy",
          "note": "The privacy policy lists Firebase Analytics, Crashlytics and Mixpanel in the app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://diariumapp.com",
          "note": "Funded by one-time Diarium Pro purchases. The privacy policy states connected data is not used for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:59.254Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "journey",
      "category": "journaling",
      "name": "Journey",
      "description": "Closed-source journal and diary app for Android, iOS, macOS, Windows and the web, with photos, location tagging, cloud sync and optional end-to-end encryption.",
      "website": "https://journey.cloud",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": {
        "code": "SG",
        "name": "Singapore",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Journey scores 20 out of 100 (grade F) on the journaling apps criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in Singapore: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/journaling/journey/",
      "markdown": "https://privacyratings.com/journaling/journey/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.journey.app/latest/",
          "note": "Exodus finds Crashlytics and Firebase Analytics in the Android app, and the website uses Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://journey.cloud/policy",
          "note": "Funded by Journey Membership subscriptions. The privacy policy states personal data is not sold or shared for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:20.175Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "journiv",
      "category": "journaling",
      "name": "Journiv",
      "description": "Self-hosted journal web app with mood tracking, writing prompts, media uploads, search and writing statistics, run with Docker. Released as beta software.",
      "website": "https://www.journiv.com",
      "source": "https://github.com/journiv/journiv-app",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Journiv scores 65 out of 100 (grade C) on the journaling apps criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/journaling/journiv/",
      "markdown": "https://privacyratings.com/journaling/journiv/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/journiv/journiv-app/blob/main/LICENSE.md",
          "note": "All code is public under the source-available PolyForm Noncommercial License 1.0.0, which is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/journiv/journiv-app/blob/main/app/services/version_checker.py",
          "note": "No third-party trackers, but each instance registers with the Journiv Plus server and sends its version, platform and database type for update checks by default. An admin can turn this off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.journiv.com/plus",
          "note": "Funded by optional Journiv Plus licenses. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:21.269Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "jrnl",
      "category": "journaling",
      "name": "jrnl",
      "description": "Command-line journal that stores entries in plain text files, with tags, search, optional AES encryption and editor integration.",
      "website": "https://jrnl.sh/en/stable/",
      "source": "https://github.com/jrnl-org/jrnl",
      "license": "GPL-3.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "jrnl scores 80 out of 100 (grade B) on the journaling apps criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/journaling/jrnl/",
      "markdown": "https://privacyratings.com/journaling/jrnl/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jrnl-org/jrnl/blob/main/LICENSE.md",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jrnl-org/jrnl",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/jrnl-org/jrnl",
          "note": "Volunteer free software project. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:21.752Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "lifeograph",
      "category": "journaling",
      "name": "Lifeograph",
      "description": "Offline journal and note-taking application with built-in encryption, WYSIWYG editing, tags and tools that turn entries into tables and charts.",
      "website": "https://launchpad.net/lifeograph",
      "source": "https://git.launchpad.net/lifeograph",
      "license": null,
      "platforms": [
        "linux",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Lifeograph scores 80 out of 100 (grade B) on the journaling apps criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/journaling/lifeograph/",
      "markdown": "https://privacyratings.com/journaling/lifeograph/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://git.launchpad.net/lifeograph/tree/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://git.launchpad.net/lifeograph",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://launchpad.net/lifeograph",
          "note": "Volunteer free software project. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:20.938Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bookstack",
      "category": "wikis",
      "name": "BookStack",
      "description": "Self-hosted wiki platform that organizes documentation into shelves, books, chapters and pages. Built with PHP and Laravel, with a WYSIWYG and Markdown editor, search and role-based permissions.",
      "website": "https://www.bookstackapp.com",
      "source": "https://codeberg.org/bookstack/bookstack",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "BookStack scores 80 out of 100 (grade B) on the wikis and knowledge bases criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/wikis/bookstack/",
      "markdown": "https://privacyratings.com/wikis/bookstack/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/bookstack/bookstack/src/branch/development/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.bookstackapp.com/about/project-faq/",
          "note": "No third-party trackers, and no telemetry is documented for the software. The website's self-hosted Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.bookstackapp.com/about/project-faq/",
          "note": "Funded by donations, sponsorships and paid support services, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:38.799Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "confluence",
      "category": "wikis",
      "name": "Confluence",
      "description": "Atlassian's team wiki for writing, organizing and sharing pages and documentation. Available as a hosted cloud service and as a self-managed Data Center edition.",
      "website": "https://www.atlassian.com/software/confluence",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 41,
      "coverage": 100,
      "summary": "Confluence scores 41 out of 100 (grade D) on the wikis and knowledge bases criteria. It meets 3 of 8 criteria: transparency report, tells users about requests and TLS configuration. It partly meets no ads or data sales and security headers. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/wikis/confluence/",
      "markdown": "https://privacyratings.com/wikis/confluence/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.atlassian.com/legal/privacy-policy",
          "note": "Atlassian and its advertising and analytics partners use cookies and other tracking technologies on its sites and services."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.atlassian.com/legal/privacy-policy",
          "note": "Funded by subscriptions with no ads in the product, but the policy allows targeted advertising and sharing identifiers with third-party advertising providers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.atlassian.com/trust/privacy/transparency-report",
          "note": "Publishes yearly counts of government requests for user data and how Atlassian responded."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.atlassian.com/trust/privacy/guidelines-for-law-enforcement",
          "note": "Atlassian notifies customers of requests for their data unless prohibited by law."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=id.atlassian.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=id.atlassian.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:54.408Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "docmost",
      "category": "wikis",
      "name": "Docmost",
      "description": "Self-hostable collaborative wiki and documentation tool with real-time editing, spaces, permissions, comments and diagram support. Also offered as a paid cloud service.",
      "website": "https://docmost.com",
      "source": "https://github.com/docmost/docmost",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Docmost scores 35 out of 100 (grade F) on the wikis and knowledge bases criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/wikis/docmost/",
      "markdown": "https://privacyratings.com/wikis/docmost/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/docmost/docmost/blob/main/LICENSE",
          "note": "Open core. The core is AGPL-3.0, while enterprise features are under a separate proprietary license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/docmost/docmost/blob/main/.env.example",
          "note": "The docmost.com website loads a Google Ads tag, and self-hosted servers send daily anonymous usage statistics unless DISABLE_TELEMETRY is set."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docmost.com/pricing",
          "note": "Funded by paid cloud and enterprise plans, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:39.112Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "dokuwiki",
      "category": "wikis",
      "name": "DokuWiki",
      "description": "Self-hosted wiki software written in PHP that stores pages in plain text files, so it needs no database. Includes access control, authentication connectors and a large plugin collection.",
      "website": "https://www.dokuwiki.org",
      "source": "https://github.com/dokuwiki/dokuwiki",
      "license": "GPL-2.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "DokuWiki scores 30 out of 100 (grade F) on the wikis and knowledge bases criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/wikis/dokuwiki/",
      "markdown": "https://privacyratings.com/wikis/dokuwiki/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dokuwiki/dokuwiki/blob/master/COPYING",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The dokuwiki.org website loads Google Analytics, as its privacy page states. The software's popularity feedback plugin only sends data when an administrator submits it."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "The software has no ads, but the project shows Google AdSense ads on some of its websites, such as the forum."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:39.328Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "mediawiki",
      "category": "wikis",
      "name": "MediaWiki",
      "description": "Wiki software developed by the Wikimedia Foundation that runs Wikipedia. Self-hosted PHP application with page history, templates, a visual editor and a large extension ecosystem.",
      "website": "https://www.mediawiki.org",
      "source": "https://github.com/wikimedia/mediawiki",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "MediaWiki scores 65 out of 100 (grade C) on the wikis and knowledge bases criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/wikis/mediawiki/",
      "markdown": "https://privacyratings.com/wikis/mediawiki/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/wikimedia/mediawiki/blob/master/COPYING",
          "note": "GPL-2.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.mediawiki.org/wiki/Manual:$wgPingback",
          "note": "No third-party trackers. The web installer pre-selects an anonymous pingback that sends installation statistics to the Wikimedia Foundation, which can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://foundation.wikimedia.org/wiki/Policy:Privacy_policy",
          "note": "Developed by the donation-funded Wikimedia Foundation. The privacy policy states personal information is not sold or rented."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:58.748Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "outline",
      "category": "wikis",
      "name": "Outline",
      "description": "Team knowledge base and wiki with real-time collaborative editing, Markdown support and integrations such as Slack. Available as a hosted service or self-hosted.",
      "website": "https://www.getoutline.com",
      "source": "https://github.com/outline/outline",
      "license": null,
      "platforms": [
        "web",
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 44,
      "coverage": 100,
      "summary": "Outline scores 44 out of 100 (grade D) on the wikis and knowledge bases criteria. It meets 3 of 8 criteria: open source, no ads or data sales and security headers. It partly meets TLS configuration. It does not meet no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/wikis/outline/",
      "markdown": "https://privacyratings.com/wikis/outline/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/outline/outline/blob/main/LICENSE",
          "note": "All code is public under the source-available Business Source License 1.1, which is not OSI-approved. Each release converts to Apache-2.0 after the change date."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://app.getoutline.com",
          "note": "The hosted app is configured with Google Analytics and sends error reports to Sentry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.getoutline.com/privacy",
          "note": "Funded by paid plans. The privacy policy states personal information is not rented or sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.getoutline.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.getoutline.com",
          "note": "Grade A+ (110/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:54.467Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "wiki-js",
      "category": "wikis",
      "name": "Wiki.js",
      "description": "Self-hosted wiki built on Node.js, with Markdown, visual and HTML editors, Git storage sync, full-text search and many authentication options.",
      "website": "https://js.wiki",
      "source": "https://github.com/requarks/wiki",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Wiki.js scores 50 out of 100 (grade D) on the wikis and knowledge bases criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/wikis/wiki-js/",
      "markdown": "https://privacyratings.com/wikis/wiki-js/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/requarks/wiki/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://docs.requarks.io/telemetry",
          "note": "The js.wiki website loads Google Analytics, and the software's anonymized telemetry is switched on by default in the setup wizard."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://js.wiki/donate",
          "note": "Funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:39.651Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "xwiki",
      "category": "wikis",
      "name": "XWiki",
      "description": "Self-hosted enterprise wiki written in Java, with structured data, scripting and an extension system for building wiki applications. Developed by XWiki SAS and its community.",
      "website": "https://www.xwiki.org",
      "source": "https://github.com/xwiki/xwiki-platform",
      "license": "LGPL-2.1",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "XWiki scores 65 out of 100 (grade C) on the wikis and knowledge bases criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/wikis/xwiki/",
      "markdown": "https://privacyratings.com/wikis/xwiki/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/xwiki/xwiki-platform/blob/master/LICENSE",
          "note": "LGPL-2.1."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.xwiki.org/xwiki/bin/view/Main/LegalNotice/",
          "note": "No third-party trackers. The xwiki.org site uses Matomo analytics, and installations send a daily anonymous ping to XWiki by default, which can be disabled."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://xwiki.com/en/pricing",
          "note": "Funded by paid support, XWiki Pro and cloud subscriptions from XWiki SAS, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:59.086Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "draw-io",
      "category": "diagrams",
      "name": "draw.io",
      "description": "An open-source diagramming app for flowcharts, UML, network and architecture diagrams that runs in the browser or as a desktop app, and saves files to the device or to a storage service the user chooses.",
      "website": "https://www.drawio.com",
      "source": "https://github.com/jgraph/drawio",
      "license": "Apache-2.0",
      "platforms": [
        "web",
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "draw.io scores 80 out of 100 (grade B) on the diagrams and whiteboards criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/diagrams/draw-io/",
      "markdown": "https://privacyratings.com/diagrams/draw-io/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jgraph/drawio/blob/dev/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.drawio.com/trust/",
          "note": "The privacy statement says no personal data is collected when using the app, and the website and web app load no third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.drawio.com/trust/",
          "note": "No ads, and the privacy statement says information collected through the website or app is not shared or sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:21.147Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "excalidraw",
      "category": "diagrams",
      "name": "Excalidraw",
      "description": "An open-source virtual whiteboard for sketching hand-drawn style diagrams in the browser. Drawings are stored locally, and shared links and live collaboration are end-to-end encrypted. A paid hosted workspace, Excalidraw+, is also offered.",
      "website": "https://excalidraw.com",
      "source": "https://github.com/excalidraw/excalidraw",
      "license": "MIT",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "CZ",
        "name": "Czechia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Excalidraw scores 65 out of 100 (grade C) on the diagrams and whiteboards criteria. It meets 1 of 4 criteria: open source. It partly meets no trackers or telemetry, no ads or data sales and independent audit. It is based in Czechia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/diagrams/excalidraw/",
      "markdown": "https://privacyratings.com/diagrams/excalidraw/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/excalidraw/excalidraw/blob/master/LICENSE",
          "note": "MIT. The paid Excalidraw+ service is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/excalidraw/excalidraw/blob/master/excalidraw-app/index.html",
          "note": "No third-party ad trackers, but excalidraw.com loads Simple Analytics and sends error reports to Sentry by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://plus.excalidraw.com/privacy-policy",
          "note": "Funded by Excalidraw+ subscriptions with no ads in the app, but the privacy notice says marketing cookies and third parties may be used for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://plus.excalidraw.com/security-and-compliance",
          "note": "Excalidraw+ has SOC 2 Type 1 and Type 2 reports and yearly penetration tests, with reports provided through its trust center rather than published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:21.487Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "figjam",
      "category": "diagrams",
      "name": "FigJam",
      "description": "Figma's online whiteboard for brainstorming, diagrams, flowcharts and meetings, with sticky notes, templates, widgets and AI features, running in the browser and in Figma's apps.",
      "website": "https://www.figma.com/figjam/",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 47,
      "coverage": 100,
      "summary": "FigJam scores 47 out of 100 (grade D) on the diagrams and whiteboards criteria. It meets 3 of 8 criteria: transparency report, tells users about requests and TLS configuration. It partly meets no ads or data sales, independent audit and security headers. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/diagrams/figjam/",
      "markdown": "https://privacyratings.com/diagrams/figjam/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.figma.com/legal/privacy/",
          "note": "Uses Google Analytics and third-party advertising trackers. Content training for AI is on by default for Starter and Professional teams and can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.figma.com/legal/privacy/",
          "note": "Sold by subscription, but the privacy policy says its retargeting pixels and third-party cookies may count as a sale or sharing of personal information for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.figma.com/security/",
          "note": "Lists SOC 2 Type 2, SOC 3 and ISO 27001 audits, with reports provided through its Trust Center rather than published in full."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.figma.com/legal/transparency-report/",
          "note": "Figma publishes an annual transparency report with the number of government requests by country and how it responded."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.figma.com/legal/figma-principles-regarding-government-and-other-third-party-requests-for-customer-personal-data/",
          "note": "Figma's published principles promise prompt notice of government requests unless legally prohibited, and notice once a prohibition ends."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.figma.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.figma.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:20:56.135Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "lucidchart",
      "category": "diagrams",
      "name": "Lucidchart",
      "description": "A web-based diagramming app from Lucid Software for flowcharts, org charts, network and architecture diagrams, with real-time collaboration, data linking and AI features.",
      "website": "https://lucid.co/lucidchart",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "Lucidchart scores 38 out of 100 (grade F) on the diagrams and whiteboards criteria. It meets 2 of 8 criteria: tells users about requests and TLS configuration. It partly meets no ads or data sales, independent audit and transparency report. It does not meet open source, no trackers or telemetry and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/diagrams/lucidchart/",
      "markdown": "https://privacyratings.com/diagrams/lucidchart/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://lucid.co/cookies",
          "note": "The website loads Google Tag Manager and Microsoft Clarity, and the cookie policy lists Google Analytics, Google Ads, LinkedIn, Meta and other analytics and marketing cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://lucid.co/cookies",
          "note": "Sold by subscription with a free plan, but the cookie policy lists Google Ads, LinkedIn, Meta and other marketing cookies used to advertise its own products."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://trust.lucid.co/",
          "note": "Lists SOC 2 Type II, ISO 27001, ISO 27701 and FedRAMP Moderate audits, with reports provided through its trust center rather than published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://trust.lucid.co/",
          "note": "The trust center states that customer data is provided to governments only with a legal basis such as a subpoena, but no counts of requests are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://trust.lucid.co/",
          "note": "The trust center states that Lucid notifies the customer before responding to a subpoena or other legal request, to the extent legally permitted."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=lucid.app&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=lucid.app",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:25:52.061Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mermaid",
      "category": "diagrams",
      "name": "Mermaid",
      "description": "An open-source JavaScript library that renders flowcharts, sequence, class, Gantt and other diagrams from Markdown-like text definitions. It is built into many documentation tools and code hosting sites.",
      "website": "https://mermaid.js.org",
      "source": "https://github.com/mermaid-js/mermaid",
      "license": "MIT",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Mermaid scores 80 out of 100 (grade B) on the diagrams and whiteboards criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/diagrams/mermaid/",
      "markdown": "https://privacyratings.com/diagrams/mermaid/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mermaid-js/mermaid/blob/develop/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mermaid-js/mermaid",
          "note": "No telemetry or analytics in the source code, and the documentation site loads no third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/mermaid-js/mermaid/blob/develop/LICENSE",
          "note": "A free open-source library with no ads or data collection."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:21.734Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "microsoft-visio",
      "category": "diagrams",
      "name": "Microsoft Visio",
      "description": "Microsoft's diagramming app for flowcharts, org charts, floor plans and network diagrams, available as a Windows desktop app and in the browser as part of Microsoft 365. Cloud files are stored in OneDrive or SharePoint.",
      "website": "https://www.microsoft.com/en-us/microsoft-365/visio",
      "license": null,
      "platforms": [
        "windows",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 56,
      "coverage": 100,
      "summary": "Microsoft Visio scores 56 out of 100 (grade D) on the diagrams and whiteboards criteria. It meets 5 of 8 criteria: no ads or data sales, transparency report, tells users about requests, TLS configuration and security headers. It partly meets independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/diagrams/microsoft-visio/",
      "markdown": "https://privacyratings.com/diagrams/microsoft-visio/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/microsoft-365-apps/privacy/required-diagnostic-data",
          "note": "Visio, like other Microsoft 365 apps, always sends required diagnostic data to Microsoft, which cannot be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement#mainadvertisingmodule",
          "note": "Sold by subscription with no ads in Visio, and the privacy statement says personal files and documents are not used to target ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2",
          "note": "Microsoft 365 services have SOC 2 audits by an independent CPA firm. The reports are only available to customers through the Service Trust Portal."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Publishes counts of government requests for consumer and enterprise data twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Microsoft notifies users and enterprise customers of requests for their data unless legally prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=m365.cloud.microsoft&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=m365.cloud.microsoft",
          "note": "Grade A+ (110/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:21:28.061Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "miro",
      "category": "diagrams",
      "name": "Miro",
      "description": "An online collaborative whiteboard for diagrams, sticky notes, mind maps, flowcharts and workshops, with templates, AI features and desktop and mobile apps.",
      "website": "https://miro.com",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 34,
      "coverage": 100,
      "summary": "Miro scores 34 out of 100 (grade F) on the diagrams and whiteboards criteria. It meets 2 of 8 criteria: tells users about requests and TLS configuration. It partly meets no ads or data sales, independent audit and security headers. It does not meet open source, no trackers or telemetry and transparency report. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/diagrams/miro/",
      "markdown": "https://privacyratings.com/diagrams/miro/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://miro.com/legal/privacy-policy/",
          "note": "The website loads Google Tag Manager, and the privacy policy describes third-party advertising and analytics services that use cookies and trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://miro.com/legal/privacy-policy/",
          "note": "Sold by subscription, but the privacy policy says it uses cookies and trackers with advertising partners for interest-based advertising of its own service."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://trust.miro.com/",
          "note": "Holds SOC 2 Type II, ISO 27001 and ISO 42001 certifications, with reports available on request through its trust center rather than published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://miro.com/legal/terms-of-service/",
          "note": "The terms of service say Miro notifies the customer in advance of legally required disclosures of customer content when the law permits."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=miro.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=miro.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:21:28.111Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mural",
      "category": "diagrams",
      "name": "Mural",
      "description": "An online visual collaboration whiteboard for workshops, brainstorming, diagrams and planning, with templates, facilitation tools and AI features, plus desktop and mobile apps.",
      "website": "https://www.mural.co",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 34,
      "coverage": 100,
      "summary": "Mural scores 34 out of 100 (grade F) on the diagrams and whiteboards criteria. It meets 2 of 8 criteria: tells users about requests and TLS configuration. It partly meets no ads or data sales, independent audit and security headers. It does not meet open source, no trackers or telemetry and transparency report. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/diagrams/mural/",
      "markdown": "https://privacyratings.com/diagrams/mural/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.mural.co/terms/privacy-statement",
          "note": "The website loads Segment, Optimizely and other third-party scripts, and the privacy statement lists Amplitude and Segment for product analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.mural.co/terms/california-privacy",
          "note": "Sold by subscription with a free plan, but the California privacy notice says its online advertising and analytics providers may amount to a sale or sharing of online identifiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cdn.prod.website-files.com/62e11362da2667ac3d0e6ed5/683d9416606f12e85948b26a_Mural%20-%20SOC%203%20Report%2003-31-25.pdf",
          "note": "A SOC 3 summary report is public. The full SOC 2 Type 2 report is only provided to customers on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.mural.co/terms/terms-of-service",
          "note": "The terms of service require advance notice to the customer before confidential information is disclosed to a court or government agency."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.mural.co&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.mural.co",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Optimizely",
            "host": "cdn.optimizely.com",
            "effect": "no"
          },
          {
            "name": "Segment",
            "host": "cdn.segment.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:21:28.156Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "plantuml",
      "category": "diagrams",
      "name": "PlantUML",
      "description": "An open-source Java tool that generates UML and other diagrams, such as sequence, class, activity, Gantt and mind maps, from plain-text descriptions. It runs locally or through a public or self-hosted rendering server.",
      "website": "https://plantuml.com",
      "source": "https://github.com/plantuml/plantuml",
      "license": "LGPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "PlantUML scores 30 out of 100 (grade F) on the diagrams and whiteboards criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/diagrams/plantuml/",
      "markdown": "https://privacyratings.com/diagrams/plantuml/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/plantuml/plantuml/blob/master/LICENSE",
          "note": "GPL-3.0, with builds also offered under GPL-2.0, LGPL, Apache-2.0, BSD, EPL-2.0 and MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://plantuml.com",
          "note": "The plantuml.com website loads Google Analytics and Google ad scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://plantuml.com",
          "note": "The software has no ads, but the plantuml.com website is funded by Google ads served through Ezoic."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:22.224Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "tldraw",
      "category": "diagrams",
      "name": "tldraw",
      "description": "A collaborative infinite-canvas whiteboard for sketching and diagramming in the browser, with optional accounts for saving and sharing files. It is built on the tldraw SDK, which developers can embed in their own apps.",
      "website": "https://www.tldraw.com",
      "source": "https://github.com/tldraw/tldraw",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 29,
      "coverage": 100,
      "summary": "tldraw scores 29 out of 100 (grade F) on the diagrams and whiteboards criteria. It meets 1 of 7 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: Mozilla HTTP Observatory grade C+.",
      "url": "https://privacyratings.com/diagrams/tldraw/",
      "markdown": "https://privacyratings.com/diagrams/tldraw/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/tldraw/tldraw/blob/main/LICENSE.md",
          "note": "All code is public, including the tldraw.com app, under the source-available tldraw license, which is not OSI-approved and requires a paid license key for production use."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/tldraw/tldraw/blob/main/apps/dotcom/client/src/utils/analytics.tsx",
          "note": "tldraw.com loads Google Analytics and PostHog after cookie consent, runs PostHog in cookieless mode when consent is declined, and sends error reports to Sentry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.tldraw.com/privacy.html",
          "note": "No ads in the app, but the privacy policy says data may be shared with advertising partners for interest-based advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.tldraw.com",
          "note": "Grade C+ (60/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "C+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:24:28.350Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "whimsical",
      "category": "diagrams",
      "name": "Whimsical",
      "description": "An online workspace for flowcharts, mind maps, wireframes and diagrams on shared boards, with real-time collaboration, AI generation and desktop apps.",
      "website": "https://whimsical.com",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 31,
      "coverage": 100,
      "summary": "Whimsical scores 31 out of 100 (grade F) on the diagrams and whiteboards criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It partly meets independent audit. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/diagrams/whimsical/",
      "markdown": "https://privacyratings.com/diagrams/whimsical/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://whimsical.com/terms/cookie-policy",
          "note": "The website uses Plausible, and the cookie policy lists third-party analytics cookies set through Cloudflare Zaraz in some regions."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://whimsical.com/terms/privacy",
          "note": "Funded by subscriptions with no ads, and the privacy notice says personal information is not sold or shared for cross-context advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://whimsical.com/company/security",
          "note": "Has a SOC 2 Type II report and yearly third-party penetration tests, with the report provided through its trust center rather than published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=whimsical.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=whimsical.com",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:28:57.752Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "yed",
      "category": "diagrams",
      "name": "yEd",
      "description": "A free desktop diagram editor from yWorks for flowcharts, network diagrams, UML and org charts, known for its automatic layout algorithms. A browser version, yEd Live, is also available.",
      "website": "https://www.yworks.com/products/yed",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "web"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "yEd scores 25 out of 100 (grade F) on the diagrams and whiteboards criteria. It partly meets no trackers or telemetry and no ads or data sales. It does not meet open source and independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/diagrams/yed/",
      "markdown": "https://privacyratings.com/diagrams/yed/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source freeware."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.yworks.com/company/legal/privacy",
          "note": "No third-party analytics on the website, which uses self-hosted Matomo without cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.yworks.com/company/legal/privacy",
          "note": "Free with no ads, funded by yWorks' commercial libraries, but the privacy policy says Google Ads, Facebook, LinkedIn and X remarketing are used to advertise to website visitors."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:22.625Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "baikal",
      "category": "calendars",
      "name": "Baïkal",
      "description": "Self-hosted CalDAV and CardDAV server written in PHP and built on the sabre/dav library, with a web interface for managing users, calendars and address books.",
      "website": "https://sabre.io/baikal/",
      "source": "https://github.com/sabre-io/Baikal",
      "license": "GPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Baïkal scores 80 out of 100 (grade B) on the calendars criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/calendars/baikal/",
      "markdown": "https://privacyratings.com/calendars/baikal/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sabre-io/Baikal/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sabre-io/Baikal",
          "note": "No telemetry or analytics in the source code. The admin dashboard checks GitHub for new releases."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sabre-io/Baikal",
          "note": "Free, volunteer-maintained software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:39.197Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "davx5",
      "category": "calendars",
      "name": "DAVx⁵",
      "description": "Android app that syncs calendars, contacts, tasks and files with CalDAV, CardDAV and WebDAV servers, so they appear in the device's own calendar and contacts apps.",
      "website": "https://www.davx5.com",
      "source": "https://github.com/bitfireAT/davx5-ose",
      "license": "GPL-3.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": {
        "code": "AT",
        "name": "Austria",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "DAVx⁵ scores 80 out of 100 (grade B) on the calendars criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Austria: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/calendars/davx5/",
      "markdown": "https://privacyratings.com/calendars/davx5/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bitfireAT/davx5-ose/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.davx5.com/privacy",
          "note": "The privacy policy states the app collects no personal or statistical usage data and has no tracking. Exodus also finds no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.davx5.com/donate",
          "note": "The privacy policy states there are no ads. Funded by app store sales and donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:40.007Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "etar",
      "category": "calendars",
      "name": "Etar",
      "description": "Open source Android calendar app based on the AOSP Calendar. Shows calendars stored on the device, including offline calendars and CalDAV calendars synced by an app such as DAVx5.",
      "website": "https://github.com/Etar-Group/Etar-Calendar",
      "source": "https://github.com/Etar-Group/Etar-Calendar",
      "license": "GPL-3.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Etar scores 80 out of 100 (grade B) on the calendars criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/calendars/etar/",
      "markdown": "https://privacyratings.com/calendars/etar/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Etar-Group/Etar-Calendar/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/ws.xsoh.etar/latest/",
          "note": "Exodus finds no trackers in the app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Etar-Group/Etar-Calendar",
          "note": "Free, volunteer-developed app with no ads or paid features."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:39.197Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "forward-email-calendar",
      "category": "calendars",
      "name": "Forward Email Calendar",
      "description": "CalDAV calendar, task and CardDAV contacts service included with paid Forward Email plans. It works with any CalDAV or CardDAV app and with Forward Email's own webmail, desktop and mobile apps, and stores data in each alias's encrypted SQLite mailbox.",
      "website": "https://forwardemail.net/en/faq#do-you-support-calendars-caldav",
      "source": "https://github.com/forwardemail/forwardemail.net",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": "Privacy Ratings is maintained by the team behind Forward Email. This entry is scored by the same criteria as every other entry in this category, and changes to it are reviewed under the published conflict-of-interest rules.",
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "Forward Email Calendar scores 85 out of 100 (grade B) on the calendars criteria. It meets 3 of 4 criteria: open source, no ads or data sales and independent audit. It partly meets no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/calendars/forward-email-calendar/",
      "markdown": "https://privacyratings.com/calendars/forward-email-calendar/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/forwardemail/forwardemail.net/blob/master/LICENSE.md",
          "note": "All code is public, including the CalDAV and CardDAV servers that run the service. The CalDAV and CardDAV code is under the source-available Business Source License 1.1, which becomes MPL-2.0 four years after each release."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://forwardemail.net/en/privacy#analytics",
          "note": "No third-party analytics. First-party anonymized analytics of page views and service usage is on by default, and Cloudflare Turnstile loads on sign-in and sign-up forms."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://forwardemail.net/en/private-business-email",
          "note": "Funded by paid plans. No ads, and the privacy policy states user data is not shared with third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://forwardemail.net/pentest-report_forward-email.pdf",
          "note": "Two independent Cure53 audits are published. The latest covers the full forwardemail.net code repository, which contains the CalDAV and CardDAV servers."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:28.173Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fossify-calendar",
      "category": "calendars",
      "name": "Fossify Calendar",
      "description": "Offline Android calendar from Fossify, a community fork of Simple Mobile Tools. Supports widgets, reminders and ICS import and export, and can show CalDAV calendars synced by an app such as DAVx5.",
      "website": "https://www.fossify.org/apps/calendar/",
      "source": "https://github.com/FossifyOrg/Calendar",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Fossify Calendar scores 80 out of 100 (grade B) on the calendars criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/calendars/fossify-calendar/",
      "markdown": "https://privacyratings.com/calendars/fossify-calendar/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/FossifyOrg/Calendar/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.fossify.calendar/latest/",
          "note": "Exodus finds no trackers in the app, and the website states it uses no analytics or tracking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.fossify.org/donate/",
          "note": "Free app funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:06.144Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "google-calendar",
      "category": "calendars",
      "name": "Google Calendar",
      "description": "Google's calendar service for web, Android and iOS, with shared calendars, event invitations and integration with Gmail and Google Meet.",
      "website": "https://calendar.google.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Google Calendar scores 10 out of 100 (grade F) on the calendars criteria. It partly meets independent audit. It does not meet open source, no trackers or telemetry and no ads or data sales. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/calendars/google-calendar/",
      "markdown": "https://privacyratings.com/calendars/google-calendar/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Google collects activity data across its services and uses it for analytics and personalized ads."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Free for personal accounts and funded by Google's advertising business, which uses activity data across services."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cloud.google.com/security/compliance/soc-3",
          "note": "Google Workspace, which includes Calendar, has third-party SOC 2 audits. Only the SOC 3 summary report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:59.239Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kashcal",
      "category": "calendars",
      "name": "KashCal",
      "description": "Offline-first Android calendar that syncs with iCloud, CalDAV and the device calendar. Needs no account, has no telemetry and stores credentials in the Android Keystore.",
      "website": "https://kashcal.onekash.org",
      "source": "https://github.com/KashCal/KashCal",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "KashCal scores 80 out of 100 (grade B) on the calendars criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/calendars/kashcal/",
      "markdown": "https://privacyratings.com/calendars/kashcal/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/KashCal/KashCal/blob/main/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.onekash.kashcal/latest/",
          "note": "Exodus finds no trackers, and the project states the app has no analytics or telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/KashCal/KashCal/blob/main/README.md",
          "note": "Free app supported by GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:06.474Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nextcloud-calendar",
      "category": "calendars",
      "name": "Nextcloud Calendar",
      "description": "Calendar app for self-hosted Nextcloud servers. Syncs across devices with CalDAV and supports shared calendars and appointment booking. No end-to-end encryption.",
      "website": "https://apps.nextcloud.com/apps/calendar",
      "source": "https://github.com/nextcloud/calendar",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Nextcloud Calendar scores 80 out of 100 (grade B) on the calendars criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/calendars/nextcloud-calendar/",
      "markdown": "https://privacyratings.com/calendars/nextcloud-calendar/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nextcloud/calendar/blob/main/COPYING",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nextcloud/calendar",
          "note": "No telemetry or analytics in the source code. The Nextcloud usage survey is only sent if an administrator opts in."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://nextcloud.com/pricing/",
          "note": "Free software funded by Nextcloud GmbH's enterprise subscriptions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:07.177Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "outlook-calendar",
      "category": "calendars",
      "name": "Outlook Calendar",
      "description": "Microsoft's calendar built into Outlook on the web, Windows, macOS, Android and iOS, used with Outlook.com and Microsoft 365 accounts. Supports shared calendars, meeting scheduling and Teams integration.",
      "website": "https://www.microsoft.com/en-us/microsoft-365/outlook/calendar-in-outlook",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Outlook Calendar scores 10 out of 100 (grade F) on the calendars criteria. It partly meets independent audit. It does not meet open source, no trackers or telemetry and no ads or data sales. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/calendars/outlook-calendar/",
      "markdown": "https://privacyratings.com/calendars/outlook-calendar/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.microsoft.office.outlook/latest/",
          "note": "Exodus finds trackers in the Outlook Android app, including Facebook Ads, AppNexus, Singular and App Center Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "The free Outlook.com version shows ads, and Microsoft uses personal data for personalized advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2",
          "note": "Microsoft 365, which hosts Outlook calendars for business accounts, is in scope of SOC 2 Type 2 audits. The full reports are only available through the Service Trust Portal after sign-in."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:40.003Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "proton-calendar",
      "category": "calendars",
      "name": "Proton Calendar",
      "description": "End-to-end encrypted calendar from Proton for web, Android and iOS. Supports shared calendars, recurring events, time zones, ICS import and subscriptions, and integrates with Proton Mail.",
      "website": "https://proton.me/calendar",
      "source": "https://github.com/ProtonMail/android-calendar",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 60,
      "coverage": 100,
      "summary": "Proton Calendar scores 60 out of 100 (grade C) on the calendars criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source, no trackers or telemetry and independent audit. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law.",
      "url": "https://privacyratings.com/calendars/proton-calendar/",
      "markdown": "https://privacyratings.com/calendars/proton-calendar/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/ProtonMail/WebClients/blob/main/LICENSE",
          "note": "The web, Android and iOS apps are GPL-3.0. The server code is not published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://proton.me/support/share-usage-statistics",
          "note": "No third-party trackers, but anonymous usage statistics and crash reports are sent by default and can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://proton.me/legal/privacy",
          "note": "Funded by paid plans. The privacy policy rules out targeted advertising and profiling."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://res.cloudinary.com/dbulfrlrz/images/v1707571626/wp-pme/securitum-protonmail-security-audit/securitum-protonmail-security-audit.pdf",
          "note": "Securitum published a full audit of the Proton Mail and Calendar web apps, but it is older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:07.067Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "radicale",
      "category": "calendars",
      "name": "Radicale",
      "description": "Lightweight self-hosted CalDAV and CardDAV server written in Python, for syncing calendars, contacts and task lists across devices. Stores data as plain files.",
      "website": "https://radicale.org",
      "source": "https://github.com/Kozea/Radicale",
      "license": "GPL-3.0",
      "platforms": [
        "linux",
        "windows",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Radicale scores 80 out of 100 (grade B) on the calendars criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/calendars/radicale/",
      "markdown": "https://privacyratings.com/calendars/radicale/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Kozea/Radicale/blob/master/COPYING.md",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Kozea/Radicale",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Kozea/Radicale",
          "note": "Free, volunteer-maintained software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:39.674Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "tuta-calendar",
      "category": "calendars",
      "name": "Tuta Calendar",
      "description": "End-to-end encrypted calendar from Tuta, available as a standalone Android and iOS app and in Tuta's web and desktop clients. Events, invitations and shared calendars are encrypted.",
      "website": "https://tuta.com/calendar",
      "source": "https://github.com/tutao/tutanota",
      "license": "GPL-3.0",
      "platforms": [
        "android",
        "ios",
        "web",
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Tuta Calendar scores 65 out of 100 (grade C) on the calendars criteria. It meets 2 of 4 criteria: no trackers or telemetry and no ads or data sales. It partly meets open source. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/calendars/tuta-calendar/",
      "markdown": "https://privacyratings.com/calendars/tuta-calendar/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/tutao/tutanota/blob/master/LICENSE.txt",
          "note": "Apps are open source under GPL-3.0. The server is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://tuta.com/privacy-policy",
          "note": "No third-party analysis tools. Anonymized usage statistics are collected only with prior consent, and Exodus finds no trackers in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tuta.com/pricing",
          "note": "Funded by paid plans. No ads on any plan, including the free plan."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:40.455Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "acuity-scheduling",
      "category": "scheduling",
      "name": "Acuity Scheduling",
      "description": "Hosted appointment scheduling service owned by Squarespace, with client booking pages, intake forms, payments, packages, reminders and calendar integrations.",
      "website": "https://acuityscheduling.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 28,
      "coverage": 100,
      "summary": "Acuity Scheduling scores 28 out of 100 (grade F) on the scheduling criteria. It meets 2 of 8 criteria: tells users about requests and TLS configuration. It partly meets no ads or data sales and security headers. It does not meet open source, no trackers or telemetry, independent audit and transparency report. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/scheduling/acuity-scheduling/",
      "markdown": "https://privacyratings.com/scheduling/acuity-scheduling/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.squarespace.com/privacy",
          "note": "The website loads Amplitude, Datadog and Google Tag Manager, and Squarespace uses cookies and third-party online services for analytics and ad targeting."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.squarespace.com/privacy",
          "note": "Funded by subscriptions with no ads in the product, but Squarespace shares data with third-party online services to target ads for its own products."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.squarespace.com/dpa",
          "note": "The Squarespace data protection addendum promises notice to customers of binding government or law enforcement demands for their data, where legally permitted."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=secure.acuityscheduling.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=secure.acuityscheduling.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Amplitude",
            "host": "cdn.amplitude.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "TrustArc",
            "host": "consent.trustarc.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:26:05.044Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cal-ai",
      "category": "scheduling",
      "name": "Cal.ai",
      "description": "AI phone agent from Cal.com that makes scheduling calls to book meetings, confirm appointments, send reminders and follow up on no-shows, triggered from Cal.com workflows.",
      "website": "https://cal.com/ai",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "Cal.ai scores 38 out of 100 (grade F) on the scheduling criteria. It meets 3 of 8 criteria: no ads or data sales, TLS configuration and security headers. It partly meets independent audit. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/scheduling/cal-ai/",
      "markdown": "https://privacyratings.com/scheduling/cal-ai/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://cal.com/blog/cal-com-goes-closed-source-why",
          "note": "Closed source. Cal.ai is part of the Cal.com production codebase, which moved to a private repository."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://cal.com/privacy",
          "note": "The marketing site runs analytics and ad measurement, loading Google Tag Manager, PostHog and LinkedIn scripts, and the product uses opt-out product analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cal.com/privacy",
          "note": "Funded by paid usage. The privacy policy states personal data is never sold and booking data is not used for advertising profiles."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cal.com/security",
          "note": "Cal.com lists SOC 2 Type II and ISO 27001 certification and third-party penetration tests, but the reports are not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.cal.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.cal.com",
          "note": "Grade A+ (125/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "PostHog",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "trustpilot.com",
            "effect": "none"
          },
          {
            "name": "X (Twitter) Pixel",
            "host": "static.ads-twitter.com",
            "effect": "no"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:23:20.585Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cal-com",
      "category": "scheduling",
      "name": "Cal.com",
      "description": "Hosted scheduling platform for booking pages, team round-robin, routing forms and workflows, with calendar and video conferencing integrations.",
      "website": "https://cal.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": true,
      "pick_reason": "Booking pages, team round-robin, routing forms and workflows with calendar and video integrations, in a hosted service. The MIT-licensed Cal.diy edition covers self-hosting on your own server.",
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "Cal.com scores 38 out of 100 (grade F) on the scheduling criteria. It meets 3 of 8 criteria: no ads or data sales, TLS configuration and security headers. It partly meets independent audit. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/scheduling/cal-com/",
      "markdown": "https://privacyratings.com/scheduling/cal-com/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://cal.com/blog/cal-com-goes-closed-source-why",
          "note": "Closed source. The production code moved to a private repository, and only the self-hosted community fork Cal.diy remains MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://cal.com/privacy",
          "note": "The marketing site runs analytics and ad measurement, loading Google Tag Manager, PostHog, Facebook and LinkedIn scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cal.com/privacy",
          "note": "Funded by paid plans. The privacy policy states personal data is never sold and booking data is not used for advertising profiles."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cal.com/security",
          "note": "SOC 2 Type II and annual third-party penetration test reports exist, but are only available to signed-in users."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.cal.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.cal.com",
          "note": "Grade A+ (125/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "PostHog",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "trustpilot.com",
            "effect": "none"
          },
          {
            "name": "X (Twitter) Pixel",
            "host": "static.ads-twitter.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:54.569Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "cal-diy",
      "category": "scheduling",
      "name": "Cal.diy",
      "description": "Self-hosted, MIT-licensed community edition of Cal.com for booking pages and calendar scheduling, with enterprise features such as teams, workflows and SSO removed. There is no hosted version.",
      "website": "https://github.com/calcom/cal.diy",
      "source": "https://github.com/calcom/cal.diy",
      "license": "MIT",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Cal.diy scores 65 out of 100 (grade C) on the scheduling criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/scheduling/cal-diy/",
      "markdown": "https://privacyratings.com/scheduling/cal-diy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/calcom/cal.diy/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/calcom/cal.diy/blob/main/packages/lib/telemetry.ts",
          "note": "Self-hosted instances send anonymous usage telemetry to Cal.com by default, which can be turned off with CALCOM_TELEMETRY_DISABLED=1."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/calcom/cal.diy",
          "note": "Free, community-maintained open source software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:22.225Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "calendly",
      "category": "scheduling",
      "name": "Calendly",
      "description": "Hosted scheduling service that lets people book meetings through a shared link based on the host's calendar availability. Connects to Google, Outlook and iCloud calendars and video conferencing tools.",
      "website": "https://calendly.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios",
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Calendly scores 25 out of 100 (grade F) on the scheduling criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales and independent audit. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/scheduling/calendly/",
      "markdown": "https://privacyratings.com/scheduling/calendly/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://calendly.com/legal/privacy-notice",
          "note": "Uses Google Analytics and advertising trackers such as Facebook Pixel, Clearbit and MNTN."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://calendly.com/legal/privacy-notice",
          "note": "Funded by subscriptions with no ads in the product, but identifiers and browsing activity are shared with targeted advertising partners."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://calendly.com/security",
          "note": "Calendly lists SOC 2 Type 2, SOC 3 and ISO 27001 audits, but the reports are only shared through its trust center."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=calendly.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=calendly.com",
          "note": "Grade C (55/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:54.635Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "crab-fit",
      "category": "scheduling",
      "name": "Crab Fit",
      "description": "Free web tool for finding a time that suits a group. Participants mark their availability on a shared grid, and the results show when most people are free. No account is needed.",
      "website": "https://crab.fit",
      "source": "https://github.com/GRA0007/crab.fit",
      "license": "GPL-3.0",
      "platforms": [
        "web",
        "android"
      ],
      "jurisdiction": {
        "code": "AU",
        "name": "Australia",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 44,
      "coverage": 100,
      "summary": "Crab Fit scores 44 out of 100 (grade D) on the scheduling criteria. It meets 3 of 8 criteria: open source, no ads or data sales and TLS configuration. It does not meet no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in Australia: Five Eyes member; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/scheduling/crab-fit/",
      "markdown": "https://privacyratings.com/scheduling/crab-fit/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/GRA0007/crab.fit/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://crab.fit/privacy",
          "note": "The privacy policy states Google Analytics cookies are used, along with Vercel Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://crab.fit/",
          "note": "Free service funded by donations through Ko-fi, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=crab.fit&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=crab.fit",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:54.689Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "doodle",
      "category": "scheduling",
      "name": "Doodle",
      "description": "Hosted scheduling service for group polls, booking pages and one-on-one meeting invitations. Free accounts show ads, and paid plans remove them.",
      "website": "https://doodle.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 16,
      "coverage": 100,
      "summary": "Doodle scores 16 out of 100 (grade F) on the scheduling criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets security headers. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report and tells users about requests. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/scheduling/doodle/",
      "markdown": "https://privacyratings.com/scheduling/doodle/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://doodle.com/en/privacy-policy/",
          "note": "Uses Google Analytics, Intercom and advertising partners such as Google AdSense, Freestar and LiveRamp."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://doodle.com/en/privacy-policy/",
          "note": "The free service shows targeted ads, and hashed email addresses are shared with LiveRamp for ad targeting."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=doodle.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=doodle.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:20:20.096Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "easy-appointments",
      "category": "scheduling",
      "name": "Easy!Appointments",
      "description": "Self-hosted web application for booking appointments, written in PHP. Customers book online, and staff manage services, providers and schedules, with Google Calendar and CalDAV sync.",
      "website": "https://easyappointments.org",
      "source": "https://github.com/alextselegidis/easyappointments",
      "license": "GPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Easy!Appointments scores 50 out of 100 (grade D) on the scheduling criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/scheduling/easy-appointments/",
      "markdown": "https://privacyratings.com/scheduling/easy-appointments/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/alextselegidis/easyappointments/blob/develop/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://easyappointments.org/privacy-policy/",
          "note": "The easyappointments.org website loads Google Analytics through Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://easyappointments.org/premium",
          "note": "Funded by paid custom development, hosting, support and white-label licenses, with no ads in the software."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:40.950Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "framadate",
      "category": "scheduling",
      "name": "Framadate",
      "description": "Free online polling service from the French non-profit Framasoft for choosing a meeting date or deciding between options, without registration. Runs on the open source Pollaris software.",
      "website": "https://framadate.org",
      "source": "https://framagit.org/framasoft/framadate/pollaris",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 53,
      "coverage": 100,
      "summary": "Framadate scores 53 out of 100 (grade D) on the scheduling criteria. It meets 3 of 8 criteria: open source, no ads or data sales and TLS configuration. It partly meets no trackers or telemetry. It does not meet independent audit, transparency report, tells users about requests and security headers. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/scheduling/framadate/",
      "markdown": "https://privacyratings.com/scheduling/framadate/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://framagit.org/framasoft/framadate/pollaris/-/blob/frama/LICENSE.txt",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://framasoft.org/en/legals/",
          "note": "No third-party trackers. Framasoft sites use a self-hosted Matomo instance for statistics, with an opt-out."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://soutenir.framasoft.org/en/",
          "note": "Free service run by a non-profit association funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=framadate.org&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=framadate.org",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:20:05.715Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "microsoft-bookings",
      "category": "scheduling",
      "name": "Microsoft Bookings",
      "description": "Appointment scheduling service included in Microsoft 365 business plans, with public booking pages, staff calendars, email and SMS reminders, and Teams meetings.",
      "website": "https://www.microsoft.com/en-us/microsoft-365/business/scheduling-and-booking-app",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 32,
      "coverage": 100,
      "summary": "Microsoft Bookings scores 32 out of 100 (grade F) on the scheduling criteria. It meets 2 of 7 criteria: transparency report and tells users about requests. It partly meets independent audit and security headers. It does not meet open source, no trackers or telemetry and no ads or data sales. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/scheduling/microsoft-bookings/",
      "markdown": "https://privacyratings.com/scheduling/microsoft-bookings/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "Microsoft collects usage and diagnostic data, and its websites use analytics and advertising cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement#mainadvertisingmodule",
          "note": "Bookings shows no ads, but Microsoft uses data about users of its services and websites for personalized advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2",
          "note": "Bookings is part of Office 365, which is in scope of Microsoft's SOC 2 Type 2 audits. The full reports are only available through the Service Trust Portal after sign-in."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Publishes counts of government requests for customer data twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Microsoft gives prior notice to enterprise customers whose data is requested, except where prohibited by law."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=bookings.cloud.microsoft",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:26:20.858Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "rallly",
      "category": "scheduling",
      "name": "Rallly",
      "description": "Open source, self-hostable scheduling poll tool. Create a poll with date and time options, share the link and let participants vote on when they are available.",
      "website": "https://rallly.co",
      "source": "https://github.com/lukevella/rallly",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 44,
      "coverage": 100,
      "summary": "Rallly scores 44 out of 100 (grade D) on the scheduling criteria. It meets 3 of 8 criteria: open source, no ads or data sales and TLS configuration. It does not meet no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C-.",
      "url": "https://privacyratings.com/scheduling/rallly/",
      "markdown": "https://privacyratings.com/scheduling/rallly/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/lukevella/rallly/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://rallly.co/privacy-policy",
          "note": "The hosted service sends product analytics to PostHog, tied to account name and email, and error reports to Sentry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://rallly.co/pricing",
          "note": "Funded by paid plans. The privacy policy states personal data is not shared for marketing or commercial purposes."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=rallly.co&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=rallly.co",
          "note": "Grade C- (45/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:36.264Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "savvycal",
      "category": "scheduling",
      "name": "SavvyCal",
      "description": "Hosted scheduling service with booking links that let invitees overlay their own calendar, plus meeting polls, team round-robin scheduling, payments and workflows.",
      "website": "https://savvycal.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "SavvyCal scores 25 out of 100 (grade F) on the scheduling criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/scheduling/savvycal/",
      "markdown": "https://privacyratings.com/scheduling/savvycal/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://savvycal.com",
          "note": "The website loads PostHog product analytics through a first-party proxy, alongside Fathom analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://savvycal.com/privacy",
          "note": "Funded by paid plans. The privacy notice states personal information is not sold or shared for others' marketing."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": "https://savvycal.com/security",
          "note": "No independent audit is published. The security page states SavvyCal does not hold SOC 2 or ISO 27001 certification."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=savvycal.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=savvycal.com",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:24:28.477Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "tidycal",
      "category": "scheduling",
      "name": "TidyCal",
      "description": "Hosted booking page service from AppSumo's parent company Sumo Group, sold mainly as a one-time lifetime license, with calendar sync, paid bookings and group events.",
      "website": "https://tidycal.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 6,
      "coverage": 100,
      "summary": "TidyCal scores 6 out of 100 (grade F) on the scheduling criteria. It partly meets TLS configuration. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade C-.",
      "url": "https://privacyratings.com/scheduling/tidycal/",
      "markdown": "https://privacyratings.com/scheduling/tidycal/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://tidycal.com/privacy-policy",
          "note": "The website loads Google Tag Manager and Google Analytics, and the privacy policy allows third-party advertisers to place cookies and web beacons."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://tidycal.com/privacy-policy",
          "note": "The privacy policy allows third-party ad networks to serve interest-based ads on the website and uses Google remarketing, and promotional emails may advertise partners' products."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=tidycal.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=tidycal.com",
          "note": "Grade C- (45/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "C-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:24:28.745Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "tymeslot",
      "category": "scheduling",
      "name": "Tymeslot",
      "description": "Open source (AGPL-3.0), self-hostable meeting scheduling and booking platform. Guests book without creating an account, and hosts get two-way calendar sync with Google, Outlook, iCloud and CalDAV.",
      "website": "https://tymeslot.app",
      "source": "https://github.com/Tymeslot/tymeslot",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "EE",
        "name": "Estonia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 59,
      "coverage": 100,
      "summary": "Tymeslot scores 59 out of 100 (grade D) on the scheduling criteria. It meets 4 of 8 criteria: open source, no ads or data sales, TLS configuration and security headers. It partly meets no trackers or telemetry. It does not meet independent audit, transparency report and tells users about requests. It is based in Estonia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/scheduling/tymeslot/",
      "markdown": "https://privacyratings.com/scheduling/tymeslot/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Tymeslot/tymeslot/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://tymeslot.app/legal/privacy-policy",
          "note": "Uses self-hosted Umami without cookies instead of third-party analytics, but email opens are recorded through Postmark."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tymeslot.app/legal/privacy-policy",
          "note": "Funded by paid plans. The privacy policy states personal information is never sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=tymeslot.app&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=tymeslot.app",
          "note": "Grade A+ (120/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:36.310Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "youcanbookme",
      "category": "scheduling",
      "name": "YouCanBookMe",
      "description": "Hosted scheduling service that turns calendar availability into customizable booking pages, with reminders, payments, team scheduling and calendar integrations.",
      "website": "https://youcanbook.me",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 18,
      "coverage": 100,
      "summary": "YouCanBookMe scores 18 out of 100 (grade F) on the scheduling criteria. It partly meets no ads or data sales, independent audit and security headers. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/scheduling/youcanbookme/",
      "markdown": "https://privacyratings.com/scheduling/youcanbookme/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://youcanbook.me/privacy",
          "note": "Uses Google Analytics, Mixpanel, Hotjar and HubSpot, plus Google Ads, DoubleClick and Meta advertising cookies after consent."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://youcanbook.me/privacy",
          "note": "Funded by subscriptions with no ads in the product, but website data is shared with advertising partners for remarketing. Personal data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://youcanbook.me/privacy",
          "note": "The privacy notice cites ISO/IEC 27001 certification, but no audit report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.youcanbook.me",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Hotjar",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "cta-eu1.hubspot.com",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:27:28.960Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "zcal",
      "category": "scheduling",
      "name": "zcal",
      "description": "Hosted scheduling service with customizable booking pages, unlimited links and calendars on a free plan, and paid features for teams such as collective and round-robin scheduling.",
      "website": "https://zcal.co",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 13,
      "coverage": 100,
      "summary": "zcal scores 13 out of 100 (grade F) on the scheduling criteria. It partly meets no ads or data sales and TLS configuration. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/scheduling/zcal/",
      "markdown": "https://privacyratings.com/scheduling/zcal/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://zcal.co/privacy",
          "note": "The website loads Google Analytics, and the privacy policy describes cookies, web beacons and pixels for tracking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://zcal.co/privacy",
          "note": "Funded by paid plans with no ads in the product, but the privacy policy allows marketing partners and interest-based advertising cookies on the website."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=zcal.co&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=zcal.co",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:29:53.020Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "asana",
      "category": "task-management",
      "name": "Asana",
      "description": "Work management platform for teams, with tasks, projects, timelines, boards and workflow automation. Data is hosted by Asana.",
      "website": "https://asana.com",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Asana scores 20 out of 100 (grade F) on the task management criteria. It partly meets no ads or data sales and independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/task-management/asana/",
      "markdown": "https://privacyratings.com/task-management/asana/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.asana.app/latest/",
          "note": "Exodus finds Google Analytics, Crashlytics, Firebase Analytics and Tag Manager in the Android app, and the website loads advertising trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://asana.com/terms/privacy-statement",
          "note": "Funded by subscriptions with no ads in the product, but the privacy statement describes targeting cookies and sharing data with partners for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://asana.com/trust",
          "note": "States SOC 2 Type 2 and ISO 27001 audits, but the reports are only available through its trust center on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google DoubleClick",
            "host": "ad.doubleclick.net",
            "effect": "no"
          },
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:40.352Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "basecamp",
      "category": "task-management",
      "name": "Basecamp",
      "description": "Project management and team communication tool from 37signals, with to-dos, message boards, schedules, docs and chat. Data is hosted by 37signals in the United States.",
      "website": "https://basecamp.com",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Basecamp scores 10 out of 100 (grade F) on the task management criteria. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/task-management/basecamp/",
      "markdown": "https://privacyratings.com/task-management/basecamp/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://basecamp.com/about/policies/privacy",
          "note": "The privacy policy describes web analytics, third-party cookies and ad-company scripts for visitors who arrive from ads. Exodus finds Sentry in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://basecamp.com/about/policies/privacy",
          "note": "Funded by subscriptions with no ads in the product, and data is never sold. Visitors who click Basecamp ads may get an ad-company script that sends conversion data to the ad network."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:28.072Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "clickup",
      "category": "task-management",
      "name": "ClickUp",
      "description": "Work management platform with tasks, docs, whiteboards, chat, goals and AI features. Data is hosted by ClickUp on AWS.",
      "website": "https://clickup.com",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "ClickUp scores 20 out of 100 (grade F) on the task management criteria. It partly meets no ads or data sales and independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/task-management/clickup/",
      "markdown": "https://privacyratings.com/task-management/clickup/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/co.mangotechnologies.clickup/latest/",
          "note": "Exodus finds Amplitude, Sentry, Singular and Split in the Android app, and the privacy policy describes advertising and analytics partners that use cookies and pixels."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://clickup.com/privacy",
          "note": "Funded by subscriptions, and the privacy policy states that data is not sold. Advertising partners use cookies and tracking technologies, and data is used to deliver ClickUp advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://clickup.com/security",
          "note": "States SOC 1 Type 2, SOC 2 Type 2, SOC 3 and ISO 27001 certifications, but the reports are only available from sales."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:28.443Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "huly",
      "category": "task-management",
      "name": "Huly",
      "description": "Open-source work platform from Huly Labs that combines issue tracking, docs, chat, video calls and planning, available as a hosted service or self-hosted.",
      "website": "https://huly.io",
      "source": "https://github.com/hcengineering/platform",
      "license": "EPL-2.0",
      "platforms": [
        "web",
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Huly scores 40 out of 100 (grade D) on the task management criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/task-management/huly/",
      "markdown": "https://privacyratings.com/task-management/huly/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hcengineering/platform/blob/develop/LICENSE",
          "note": "EPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://huly.io/legal/privacy",
          "note": "The privacy policy states that the website uses Google Analytics and lets advertising networks and social media companies collect usage data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://huly.io/legal/privacy",
          "note": "Funded by paid plans with no ads in the product, but the privacy policy allows advertising networks to collect site usage for targeted ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:28.450Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "jira",
      "category": "task-management",
      "name": "Jira",
      "description": "Atlassian's issue and project tracking tool for software and business teams, with Scrum and Kanban boards, workflows and reporting. Available as a cloud service or self-managed Data Center edition.",
      "website": "https://www.atlassian.com/software/jira",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Jira scores 20 out of 100 (grade F) on the task management criteria. It partly meets no ads or data sales and independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/task-management/jira/",
      "markdown": "https://privacyratings.com/task-management/jira/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.atlassian.android.jira.core/latest/",
          "note": "Exodus finds Google Analytics, Segment and Sentry in the Android app, and the privacy policy describes advertising and analytics partners."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.atlassian.com/legal/privacy-policy",
          "note": "Funded by subscriptions with no ads in the product, but the policy allows targeted advertising and sharing identifiers with third-party advertising providers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.atlassian.com/trust/compliance/resources/soc2",
          "note": "Jira Cloud is covered by SOC 2 audits, but reports are only available under NDA."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:40.739Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "kanboard",
      "category": "task-management",
      "name": "Kanboard",
      "description": "Minimalist, self-hosted Kanban project management software written in PHP, with plugins, automatic actions and an API. The project is in maintenance mode, receiving small fixes and community contributions.",
      "website": "https://kanboard.org",
      "source": "https://github.com/kanboard/kanboard",
      "license": "MIT",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Kanboard scores 80 out of 100 (grade B) on the task management criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/task-management/kanboard/",
      "markdown": "https://privacyratings.com/task-management/kanboard/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/kanboard/kanboard/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/kanboard/kanboard",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kanboard.org/",
          "note": "Free software with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:40.580Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "leantime",
      "category": "task-management",
      "name": "Leantime",
      "description": "Open source project management system aimed at non-project managers, with tasks, Kanban boards, timesheets, goals and idea boards. Can be self-hosted or used as a paid cloud service.",
      "website": "https://leantime.io",
      "source": "https://github.com/Leantime/leantime",
      "license": "AGPL-3.0",
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Leantime scores 50 out of 100 (grade D) on the task management criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/task-management/leantime/",
      "markdown": "https://privacyratings.com/task-management/leantime/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Leantime/leantime/blob/master/LICENSE",
          "note": "AGPL-3.0. Some plugins are sold separately."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://leantime.io/privacy/",
          "note": "The website uses Google Analytics and Google Tag Manager, and the mobile app sends PostHog usage data unless turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://leantime.io/privacy/",
          "note": "Funded by cloud subscriptions and paid plugins. The privacy policy says data is not used for advertising or sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Crisp",
            "host": "client.crisp.chat",
            "effect": "none"
          },
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Clarity",
            "host": "www.clarity.ms",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:40.675Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "linear",
      "category": "task-management",
      "name": "Linear",
      "description": "Issue tracking and project management tool for software teams, with cycles, roadmaps and triage. Data is hosted by Linear.",
      "website": "https://linear.app",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Linear scores 20 out of 100 (grade F) on the task management criteria. It partly meets no ads or data sales and independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/task-management/linear/",
      "markdown": "https://privacyratings.com/task-management/linear/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://linear.app/privacy",
          "note": "The privacy policy describes third-party analytics providers and analytics cookies that also measure advertising campaigns. Exodus finds Sentry in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://linear.app/privacy",
          "note": "Funded by subscriptions with no ads in the product, but the privacy policy says some disclosures may count as a sale under state laws and cookies are used to measure advertising campaigns."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://linear.app/security",
          "note": "States SOC 2 Type II audits and ISO 27001 certification, but the reports are only available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:28.512Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mattermost-boards",
      "category": "task-management",
      "name": "Mattermost Boards",
      "description": "Open-source Kanban and project board plugin for self-hosted Mattermost servers, continuing the Focalboard project.",
      "website": "https://github.com/mattermost/mattermost-plugin-boards",
      "source": "https://github.com/mattermost/mattermost-plugin-boards",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Mattermost Boards scores 50 out of 100 (grade D) on the task management criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/task-management/mattermost-boards/",
      "markdown": "https://privacyratings.com/task-management/mattermost-boards/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mattermost/mattermost-plugin-boards/blob/main/LICENSE.txt",
          "note": "AGPL-3.0 and Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://docs.mattermost.com/administration-guide/manage/telemetry",
          "note": "Runs inside Mattermost, whose server telemetry is on by default. Self-hosted administrators can turn it off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mattermost.com/pricing/",
          "note": "Free plugin for Mattermost, which is funded by commercial licenses and subscriptions, with no ads in the product."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit of the plugin is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:28.178Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "microsoft-to-do",
      "category": "task-management",
      "name": "Microsoft To Do",
      "description": "Microsoft's to-do list app with lists, reminders, due dates and a My Day planner. Tasks are stored in a Microsoft account and sync with Outlook tasks.",
      "website": "https://www.microsoft.com/en-us/microsoft-365/microsoft-to-do-list-app",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Microsoft To Do scores 20 out of 100 (grade F) on the task management criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/task-management/microsoft-to-do/",
      "markdown": "https://privacyratings.com/task-management/microsoft-to-do/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "Microsoft websites use third-party cookies, including for ads, and Exodus finds Microsoft App Center crash reporting in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://play.google.com/store/apps/datasafety?id=com.microsoft.todos",
          "note": "Free app with no ads. The Play data safety listing declares no data shared with third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published. To Do is not listed in the scope of Microsoft 365 SOC 2 audits."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:41.367Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "mindwtr",
      "category": "task-management",
      "name": "Mindwtr",
      "description": "A Getting Things Done + Pomodoro productivity system for desktop and mobile. Local-first, no account required, can sync via WebDAV/Dropbox/local file or self-hosted deployment.",
      "website": "https://mindwtr.app",
      "source": "https://github.com/dongdongbh/Mindwtr",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Mindwtr scores 65 out of 100 (grade C) on the task management criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/task-management/mindwtr/",
      "markdown": "https://privacyratings.com/task-management/mindwtr/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dongdongbh/Mindwtr/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://mindwtr.app/privacy",
          "note": "No third-party trackers, but a daily anonymous usage heartbeat is sent by default and can be turned off in settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mindwtr.app/donate",
          "note": "Free app funded by GitHub Sponsors and Ko-fi donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:06.715Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "monday-com",
      "category": "task-management",
      "name": "monday.com",
      "description": "Work management platform with boards, automations, dashboards and AI features, run by monday.com Ltd. in Israel. Data is hosted by monday.com.",
      "website": "https://monday.com",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "IL",
        "name": "Israel",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "monday.com scores 20 out of 100 (grade F) on the task management criteria. It partly meets no ads or data sales and independent audit. It does not meet open source and no trackers or telemetry. It is based in Israel: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/task-management/monday-com/",
      "markdown": "https://privacyratings.com/task-management/monday-com/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.monday.monday/latest/",
          "note": "Exodus finds 5 trackers in the Android app, including AppsFlyer, Google Crashlytics and Google Firebase Analytics, and the website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://monday.com/l/privacy/privacy-policy/",
          "note": "Funded by subscriptions with no ads in the product, but the privacy policy describes behavioral and interest-based advertising for monday.com, using social and advertising networks."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://monday.com/trustcenter",
          "note": "The trust center lists SOC 1 Type II, SOC 2 Type II and SOC 3 reports and ISO 27001 certification, but the full audit reports are not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:28.840Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nextcloud-deck",
      "category": "task-management",
      "name": "Nextcloud Deck",
      "description": "Kanban-style board app for Nextcloud, with boards, stacks, cards, labels, due dates and sharing with Nextcloud users and groups. Data stays on the Nextcloud server.",
      "website": "https://apps.nextcloud.com/apps/deck",
      "source": "https://github.com/nextcloud/deck",
      "license": "AGPL-3.0",
      "platforms": [
        "web",
        "android"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Nextcloud Deck scores 80 out of 100 (grade B) on the task management criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/task-management/nextcloud-deck/",
      "markdown": "https://privacyratings.com/task-management/nextcloud-deck/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nextcloud/deck/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/it.niedermann.nextcloud.deck/latest/",
          "note": "The server app has no telemetry, and Exodus finds no trackers in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://nextcloud.com/pricing/",
          "note": "Free software funded by Nextcloud GmbH's enterprise subscriptions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:46.004Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "openproject",
      "category": "task-management",
      "name": "OpenProject",
      "description": "Open source project management software with Gantt charts, work packages, agile boards, time tracking and wikis. Can be self-hosted or used as a cloud service from OpenProject GmbH.",
      "website": "https://www.openproject.org",
      "source": "https://github.com/opf/openproject",
      "license": "GPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "OpenProject scores 65 out of 100 (grade C) on the task management criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/task-management/openproject/",
      "markdown": "https://privacyratings.com/task-management/openproject/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/opf/openproject/blob/dev/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": null,
          "note": "No third-party trackers, but the home page loads Matomo Cloud, which can set cookies (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.openproject.org/pricing/",
          "note": "Funded by Enterprise subscriptions and hosting, with no ads. The privacy policy describes no data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Matomo Cloud",
            "host": "openproject.matomo.cloud",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:41.761Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "plane",
      "category": "task-management",
      "name": "Plane",
      "description": "Open source project management tool with issues, cycles, modules, pages and Kanban, list and Gantt views. Available as a hosted cloud service or a self-hosted Community Edition.",
      "website": "https://plane.so",
      "source": "https://github.com/makeplane/plane",
      "license": "AGPL-3.0",
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": true,
      "pick_reason": "Open-source project management with issues, cycles, modules, pages and Kanban, list and Gantt views, as a replacement for Jira and Linear. The AGPL-3.0 Community Edition can be self-hosted, and its telemetry is opt-in.",
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "Plane scores 45 out of 100 (grade D) on the task management criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source and independent audit. It does not meet no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/task-management/plane/",
      "markdown": "https://privacyratings.com/task-management/plane/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/makeplane/plane/blob/preview/LICENSE.txt",
          "note": "The Community Edition is AGPL-3.0, but commercial editions add proprietary features that are not published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://plane.so/legals/privacy-policy",
          "note": "The website uses Google Tag Manager and analytics cookies. Telemetry in self-hosted instances is opt-in."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://plane.so/legals/privacy-policy",
          "note": "Funded by paid plans. The privacy policy says personal information is not sold or shared for cross-context behavioral advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://plane.so/security",
          "note": "States SOC 2 and ISO 27001 compliance, but the reports are only available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          },
          {
            "name": "VWO",
            "host": "dev.visualwebsiteoptimizer.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:43.063Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "planify",
      "category": "task-management",
      "name": "Planify",
      "description": "Open source task manager for Linux built with GTK4 and libadwaita, with projects, sections, labels and reminders. Works offline and can sync with Todoist or CalDAV servers such as Nextcloud.",
      "website": "https://github.com/alainm23/planify",
      "source": "https://github.com/alainm23/planify",
      "license": "GPL-3.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Planify scores 80 out of 100 (grade B) on the task management criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/task-management/planify/",
      "markdown": "https://privacyratings.com/task-management/planify/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/alainm23/planify/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/alainm23/planify",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/alainm23/planify/blob/main/README.md",
          "note": "Free app funded by donations through Patreon, Ko-fi, Liberapay and PayPal, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:40.950Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "planka",
      "category": "task-management",
      "name": "PLANKA",
      "description": "Self-hostable kanban board for teams with real-time updates, card attachments, notifications and Markdown descriptions. Offered as a free Community edition and a paid Pro edition or hosted service.",
      "website": "https://planka.app",
      "source": "https://github.com/plankanban/planka",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "PLANKA scores 65 out of 100 (grade C) on the task management criteria. It meets 2 of 4 criteria: no trackers or telemetry and no ads or data sales. It partly meets open source. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/task-management/planka/",
      "markdown": "https://privacyratings.com/task-management/planka/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/plankanban/planka/blob/master/LICENSE.md",
          "note": "Source-available under the PLANKA Community License, a fair-use license that restricts commercial hosting and is not OSI-approved. Pro features are proprietary."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://planka.app/privacy",
          "note": "No third-party trackers. The website counts visits on its own servers as daily totals, with no cookies, IP addresses or identifiers, and the software sends no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://planka.app/pricing",
          "note": "Funded by Pro licenses and hosted plans, with no ads. The privacy policy says data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:41.824Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "super-productivity",
      "category": "task-management",
      "name": "Super Productivity",
      "description": "Open source to-do list and time tracker with timeboxing, Pomodoro and integrations with Jira, GitHub, GitLab and calendars. Data stays on the device, with optional sync through WebDAV, Dropbox or end-to-end encrypted Super Sync.",
      "website": "https://super-productivity.com",
      "source": "https://github.com/super-productivity/super-productivity",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Super Productivity scores 80 out of 100 (grade B) on the task management criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/task-management/super-productivity/",
      "markdown": "https://privacyratings.com/task-management/super-productivity/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/super-productivity/super-productivity/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://super-productivity.com/privacy/",
          "note": "The privacy policy states no data is collected, apart from an update check that can be turned off. Exodus finds no trackers in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/johannesjo",
          "note": "Free app funded by GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:07.811Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "taiga",
      "category": "task-management",
      "name": "Taiga",
      "description": "Open source agile project management platform with Scrum and Kanban boards, backlogs, issues and wiki. Can be self-hosted or used as the hosted Taiga cloud service.",
      "website": "https://taiga.io",
      "source": "https://github.com/taigaio/taiga-back",
      "license": "MPL-2.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "ES",
        "name": "Spain",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Taiga scores 50 out of 100 (grade D) on the task management criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Spain: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/task-management/taiga/",
      "markdown": "https://privacyratings.com/task-management/taiga/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/taigaio/taiga-back/blob/main/LICENSE",
          "note": "The backend is MPL-2.0 and the web frontend is AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://taiga.io/cookie-policy/",
          "note": "The cookie policy lists Google Analytics and Leadfeeder on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://taiga.io/terms-and-conditions/",
          "note": "Funded by paid Taiga cloud subscriptions, with no ads in the service."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:41.886Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "tasks-org",
      "category": "task-management",
      "name": "Tasks.org",
      "description": "Open source to-do list app descended from Astrid, with subtasks, tags, reminders and location alerts. Syncs with CalDAV, EteSync, DAVx5, Microsoft Exchange, Google Tasks or its own Tasks.org sync service.",
      "website": "https://tasks.org",
      "source": "https://github.com/tasks/tasks",
      "license": "GPL-3.0",
      "platforms": [
        "android",
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Tasks.org scores 50 out of 100 (grade D) on the task management criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/task-management/tasks-org/",
      "markdown": "https://privacyratings.com/task-management/tasks-org/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/tasks/tasks/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/tasks/tasks/blob/main/app/src/googleplay/java/org/tasks/analytics/Firebase.kt",
          "note": "The Google Play build enables Firebase Crashlytics and PostHog analytics by default, with an opt-out. The website also loads PostHog. The F-Droid build has no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tasks.org/docs/subscribe/",
          "note": "Funded by optional subscriptions and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "PostHog",
            "host": "us.i.posthog.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:42.833Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "todoist",
      "category": "task-management",
      "name": "Todoist",
      "description": "To-do list and task manager with projects, labels, filters, reminders and shared projects. Tasks sync through Doist's servers across web, desktop and mobile apps.",
      "website": "https://www.todoist.com",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Todoist scores 20 out of 100 (grade F) on the task management criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/task-management/todoist/",
      "markdown": "https://privacyratings.com/task-management/todoist/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.todoist/latest/",
          "note": "Exodus finds Google Firebase Analytics, Sentry and Facebook SDKs in the Android app, and the website uses Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.todoist.com/pricing",
          "note": "Funded by paid plans with no ads in the apps. The privacy policy does not describe selling user data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google DoubleClick",
            "host": "stats.g.doubleclick.net",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:42.925Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "trello",
      "category": "task-management",
      "name": "Trello",
      "description": "Kanban-style project management tool from Atlassian that organizes work into boards, lists and cards. Data is hosted by Atlassian.",
      "website": "https://trello.com",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Trello scores 20 out of 100 (grade F) on the task management criteria. It partly meets no ads or data sales and independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/task-management/trello/",
      "markdown": "https://privacyratings.com/task-management/trello/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.trello/latest/",
          "note": "Exodus finds Google Crashlytics, Firebase Analytics, Segment and Sentry in the Android app, and the website loads third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.atlassian.com/legal/privacy-policy",
          "note": "Funded by subscriptions with no ads in the product, but the policy allows targeted advertising and sharing identifiers with third-party advertising providers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.atlassian.com/trust/compliance/resources/soc2",
          "note": "Trello is covered by SOC 2 audits, but reports are only available under NDA."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Meta Pixel",
            "host": "www.facebook.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:43.078Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "vikunja",
      "category": "task-management",
      "name": "Vikunja",
      "description": "Open source, self-hostable to-do and project management app with list, Gantt, table and Kanban views. Also available as a hosted service through Vikunja Cloud.",
      "website": "https://vikunja.io",
      "source": "https://github.com/go-vikunja/vikunja",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Vikunja scores 65 out of 100 (grade C) on the task management criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/task-management/vikunja/",
      "markdown": "https://privacyratings.com/task-management/vikunja/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/go-vikunja/vikunja/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://vikunja.io/docs/config-options/",
          "note": "The server and web app send no telemetry, and Sentry error reporting is off by default. The beta Android app includes Sentry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://vikunja.io/support/",
          "note": "Funded by Vikunja Cloud subscriptions, sponsors and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:07.246Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "wekan",
      "category": "task-management",
      "name": "WeKan",
      "description": "Open source, self-hosted kanban board with swimlanes, checklists, custom fields and import from Trello. Runs as a web app on the user's own server.",
      "website": "https://wekan.fi",
      "source": "https://github.com/wekan/wekan",
      "license": "MIT",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "FI",
        "name": "Finland",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "WeKan scores 80 out of 100 (grade B) on the task management criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Finland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/task-management/wekan/",
      "markdown": "https://privacyratings.com/task-management/wekan/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/wekan/wekan/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/wekan/wekan",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://wekan.fi/commercial-support/",
          "note": "Funded by paid commercial support and sponsors, with no ads. The privacy policy says data is not given to third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:43.030Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "backblaze-personal-backup",
      "category": "file-sync",
      "name": "Backblaze Personal Backup",
      "description": "Automatic cloud backup service for Windows and Mac computers with unlimited storage, file versioning and restores by download or mailed drive. An optional private encryption key keeps data unreadable to Backblaze.",
      "website": "https://www.backblaze.com/cloud-backup/personal",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Backblaze Personal Backup scores 30 out of 100 (grade F) on the file sync and backup criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/file-sync/backblaze-personal-backup/",
      "markdown": "https://privacyratings.com/file-sync/backblaze-personal-backup/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.backblaze.com/company/policy/privacy",
          "note": "The website uses Google Tag Manager, VWO and third-party tools that record visitor clicks and mouse movement."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.backblaze.com/cloud-backup/pricing",
          "note": "Funded by paid subscriptions, with no ads. The privacy policy says contact details are not shared with other companies for marketing."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.backblaze.com/cloud-backup/security",
          "note": "States it is SSAE-18 SOC 2 compliant, but the report is not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          },
          {
            "name": "VWO",
            "host": "dev.visualwebsiteoptimizer.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:43.192Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "bewcloud",
      "category": "file-sync",
      "name": "bewCloud",
      "description": "Self-hosted personal cloud written in TypeScript and Deno, with files, notes, photos, contacts and calendar. A lighter alternative to Nextcloud and ownCloud.",
      "website": "https://bewcloud.com",
      "source": "https://github.com/bewcloud/bewcloud",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "bewCloud scores 80 out of 100 (grade B) on the file sync and backup criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-sync/bewcloud/",
      "markdown": "https://privacyratings.com/file-sync/bewcloud/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bewcloud/bewcloud/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bewcloud/bewcloud",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/bewcloud/bewcloud/blob/main/.github/FUNDING.yml",
          "note": "Free self-hosted software funded by sponsors and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:07.753Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "borgbackup",
      "category": "file-sync",
      "name": "BorgBackup",
      "description": "Deduplicating command-line backup program with compression and authenticated encryption. Backs up to local disks or remote servers over SSH.",
      "website": "https://www.borgbackup.org",
      "source": "https://github.com/borgbackup/borg",
      "license": null,
      "platforms": [
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "BorgBackup scores 80 out of 100 (grade B) on the file sync and backup criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-sync/borgbackup/",
      "markdown": "https://privacyratings.com/file-sync/borgbackup/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/borgbackup/borg/blob/master/LICENSE",
          "note": "BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/borgbackup/borg",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.borgbackup.org/support/fund.html",
          "note": "Funded by donations and bounties, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:43.473Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "borgbase",
      "category": "file-sync",
      "name": "BorgBase",
      "description": "Hosted backup storage for BorgBackup and restic repositories, with append-only mode, monitoring alerts and a choice of EU or US storage regions.",
      "website": "https://www.borgbase.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "MT",
        "name": "Malta",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "BorgBase scores 50 out of 100 (grade D) on the file sync and backup criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source and no trackers or telemetry. It does not meet independent audit. It is based in Malta: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/file-sync/borgbase/",
      "markdown": "https://privacyratings.com/file-sync/borgbase/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/borgbase/vorta",
          "note": "Works with open source clients such as Borg, restic and its own Vorta app, but the hosting service is not published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.borgbase.com/privacy/",
          "note": "The website uses self-hosted Fathom analytics with no third-party service, and Sentry for error reports."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.borgbase.com/privacy/",
          "note": "Funded by paid plans. The privacy policy says backups are not sold or used for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:43.548Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "deja-dup",
      "category": "file-sync",
      "name": "Déjà Dup",
      "description": "Backup app for the GNOME desktop that schedules encrypted, incremental backups to local drives, network servers or cloud storage, using restic or duplicity.",
      "website": "https://apps.gnome.org/DejaDup/",
      "source": "https://gitlab.gnome.org/World/deja-dup",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Déjà Dup scores 80 out of 100 (grade B) on the file sync and backup criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-sync/deja-dup/",
      "markdown": "https://privacyratings.com/file-sync/deja-dup/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/World/deja-dup/-/blob/main/LICENSES/GPL-3.0-or-later.md",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/World/deja-dup",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://apps.gnome.org/DejaDup/",
          "note": "Free GNOME app with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:43.620Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "duplicati",
      "category": "file-sync",
      "name": "Duplicati",
      "description": "Backup client with deduplication, compression and AES-256 encryption, managed through a web interface. Stores backups on local disks, SFTP, WebDAV and many cloud storage services.",
      "website": "https://duplicati.com",
      "source": "https://github.com/duplicati/duplicati",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Duplicati scores 50 out of 100 (grade D) on the file sync and backup criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/file-sync/duplicati/",
      "markdown": "https://privacyratings.com/file-sync/duplicati/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/duplicati/duplicati/blob/master/LICENSE",
          "note": "Most code is MIT. A disk imaging module in the proprietary directory of the same repository uses the source-available Duplicati Inc Software license and needs a paid subscription."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/duplicati/duplicati/blob/master/Duplicati/Library/UsageReporter/Reporter.cs",
          "note": "The client sends usage reports to Duplicati by default unless turned off, and the website loads PostHog and Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://duplicati.com/pricing",
          "note": "Free client funded by paid Duplicati Console and enterprise plans, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "PostHog",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Zendesk",
            "host": "static.zdassets.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:43.689Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "freefilesync",
      "category": "file-sync",
      "name": "FreeFileSync",
      "description": "Folder comparison and synchronization tool for backups and mirroring, with two-way sync, versioning and batch jobs. Syncs local drives, network shares, FTP, SFTP, MTP and Google Drive.",
      "website": "https://freefilesync.org",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 15,
      "coverage": 100,
      "summary": "FreeFileSync scores 15 out of 100 (grade F) on the file sync and backup criteria. It partly meets open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/file-sync/freefilesync/",
      "markdown": "https://privacyratings.com/file-sync/freefilesync/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://freefilesync.org/faq.php#commercial",
          "note": "Source code is published under GPL-3.0, but the official builds are licensed for personal use only, and commercial use requires the paid Business Edition."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://freefilesync.org/privacy.php",
          "note": "The website loads Google ads with DoubleClick cookies. The Donation and Business Editions record a user name and hardware ID for licensing."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://freefilesync.org/privacy.php",
          "note": "The app has no ads, but the project is funded by donations and personalized Google ads on the website."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          },
          {
            "name": "Google DoubleClick",
            "host": "securepubads.g.doubleclick.net",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:43.670Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "kopia",
      "category": "file-sync",
      "name": "Kopia",
      "description": "Backup tool with a command-line interface and a desktop app, offering deduplication, compression and end-to-end encryption. Stores snapshots on local disks, SFTP, WebDAV and cloud storage.",
      "website": "https://kopia.io",
      "source": "https://github.com/kopia/kopia",
      "license": "Apache-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Kopia scores 50 out of 100 (grade D) on the file sync and backup criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/file-sync/kopia/",
      "markdown": "https://privacyratings.com/file-sync/kopia/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/kopia/kopia/blob/master/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://kopia.io/",
          "note": "The app has no telemetry, but the website loads Google Analytics after cookie consent."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kopia.io/",
          "note": "Free open source project with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:43.832Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "nextcloud",
      "category": "file-sync",
      "name": "Nextcloud",
      "description": "Self-hosted collaboration platform for file sync and sharing, with desktop and mobile clients plus apps for calendar, contacts, office documents and chat. Supports optional server-side and end-to-end encryption.",
      "website": "https://nextcloud.com",
      "source": "https://github.com/nextcloud/server",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Nextcloud scores 65 out of 100 (grade C) on the file sync and backup criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/file-sync/nextcloud/",
      "markdown": "https://privacyratings.com/file-sync/nextcloud/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nextcloud/server/blob/master/COPYING",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": null,
          "note": "No third-party trackers, but the home page loads Matomo Cloud, which can set cookies (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://nextcloud.com/pricing/",
          "note": "Free software funded by Nextcloud GmbH's enterprise subscriptions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published by Nextcloud. A third-party penetration test of one university deployment exists but does not cover the product as a whole."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Matomo Cloud",
            "host": "cdn.matomo.cloud",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:08.056Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "owncloud-infinite-scale",
      "category": "file-sync",
      "name": "ownCloud Infinite Scale",
      "description": "Self-hosted file sync and sharing platform from ownCloud, written in Go without a database. Offers web access, desktop and mobile sync clients, and spaces for team folders.",
      "website": "https://owncloud.com/infinite-scale/",
      "source": "https://github.com/owncloud/ocis",
      "license": "Apache-2.0",
      "platforms": [
        "web",
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "ownCloud Infinite Scale scores 40 out of 100 (grade D) on the file sync and backup criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/file-sync/owncloud-infinite-scale/",
      "markdown": "https://privacyratings.com/file-sync/owncloud-infinite-scale/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/owncloud/ocis/blob/master/LICENSE",
          "note": "The server is Apache-2.0 and the desktop and mobile clients are GPL."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://owncloud.com/privacy-statement/",
          "note": "The website uses Google Analytics, Google Ads remarketing, HubSpot and social media pixels. The Android app does not collect personal data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://owncloud.com/privacy-statement/",
          "note": "Funded by enterprise subscriptions with no ads in the product, but the website uses data for interest-based advertising through Google remarketing."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cookiebot",
            "host": "consent.cookiebot.com",
            "effect": "none"
          },
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:44.364Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "pika-backup",
      "category": "file-sync",
      "name": "Pika Backup",
      "description": "Backup app for the GNOME desktop built on BorgBackup, with scheduled, deduplicated and encrypted backups to local drives or remote repositories.",
      "website": "https://apps.gnome.org/PikaBackup/",
      "source": "https://gitlab.gnome.org/World/pika-backup",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Pika Backup scores 80 out of 100 (grade B) on the file sync and backup criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-sync/pika-backup/",
      "markdown": "https://privacyratings.com/file-sync/pika-backup/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/World/pika-backup/-/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/World/pika-backup",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://apps.gnome.org/PikaBackup/",
          "note": "Free GNOME Circle app with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:43.961Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "pydio-cells",
      "category": "file-sync",
      "name": "Pydio Cells",
      "description": "Self-hosted file sharing and collaboration platform written in Go, with web access, sync clients and fine-grained access rules. Developed by Pydio, now part of Wire.",
      "website": "https://www.pydio.com",
      "source": "https://github.com/pydio/cells",
      "license": "AGPL-3.0",
      "platforms": [
        "web",
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Pydio Cells scores 35 out of 100 (grade F) on the file sync and backup criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source. It does not meet no trackers or telemetry and independent audit. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/file-sync/pydio-cells/",
      "markdown": "https://privacyratings.com/file-sync/pydio-cells/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/pydio/cells/blob/v5-dev/LICENSE",
          "note": "Cells Home is AGPL-3.0, but Enterprise edition features are proprietary and unpublished."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.pydio.com/en/privacy-policy",
          "note": "The website uses Google Analytics and HubSpot. The server checks for updates and licenses, which can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.pydio.com/en/privacy-policy",
          "note": "Funded by Enterprise licenses. The privacy policy says data is not sold or used for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "snap.licdn.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:59.769Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "rclone",
      "category": "file-sync",
      "name": "rclone",
      "description": "Command-line program to sync, copy and mount files on more than 70 cloud storage services, with optional client-side encryption through its crypt backend.",
      "website": "https://rclone.org",
      "source": "https://github.com/rclone/rclone",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "rclone scores 40 out of 100 (grade D) on the file sync and backup criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/file-sync/rclone/",
      "markdown": "https://privacyratings.com/file-sync/rclone/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rclone/rclone/blob/master/COPYING",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://rclone.org/privacy/",
          "note": "The rclone program sends no data, but the website privacy policy describes Google Analytics and referral-tracking cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://rclone.org/sponsor/",
          "note": "Funded by donations and sponsors. The website shows sponsor placements that are not based on user data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:44.317Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "resilio-sync",
      "category": "file-sync",
      "name": "Resilio Sync",
      "description": "Peer-to-peer file synchronization app that syncs folders directly between devices without storing files on a central server. Made by Resilio, now part of Nasuni.",
      "website": "https://www.resilio.com/sync/",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Resilio Sync scores 10 out of 100 (grade F) on the file sync and backup criteria. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/file-sync/resilio-sync/",
      "markdown": "https://privacyratings.com/file-sync/resilio-sync/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.resilio.sync/latest/",
          "note": "Exodus finds Amplitude, Google Crashlytics and Firebase Analytics in the Android app, and the website uses Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.nasuni.com/wp-content/uploads/2026/07/Nasuni_Privacy_Notice.pdf",
          "note": "Free app with no ads, but Nasuni's privacy notice allows sharing personal information with advertising partners for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:44.226Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "restic",
      "category": "file-sync",
      "name": "restic",
      "description": "Command-line backup program with deduplication and end-to-end encryption. Backs up to local disks, SFTP, REST servers and cloud storage such as S3, Backblaze B2 and Azure.",
      "website": "https://restic.net",
      "source": "https://github.com/restic/restic",
      "license": "BSD-2-Clause",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "restic scores 80 out of 100 (grade B) on the file sync and backup criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-sync/restic/",
      "markdown": "https://privacyratings.com/file-sync/restic/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/restic/restic/blob/master/LICENSE",
          "note": "BSD-2-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/restic/restic",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://restic.net/",
          "note": "Free volunteer project with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:45.096Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "rsync-net",
      "category": "file-sync",
      "name": "rsync.net",
      "description": "Cloud storage for offsite backups, accessed over SSH with standard tools such as rsync, SFTP, rclone, restic and Borg. Accounts are stored on ZFS with snapshots.",
      "website": "https://www.rsync.net",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 75,
      "coverage": 100,
      "summary": "rsync.net scores 75 out of 100 (grade B) on the file sync and backup criteria. It meets 2 of 4 criteria: no trackers or telemetry and no ads or data sales. It partly meets open source and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/file-sync/rsync-net/",
      "markdown": "https://privacyratings.com/file-sync/rsync-net/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.rsync.net/resources/howto/unix.html",
          "note": "Works with open source clients such as rsync, SFTP and Borg over SSH, but the service platform is not published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.rsync.net/resources/regulatory/privacy.html",
          "note": "The privacy policy states no third-party analytics or trackers are used, and cookies are only set for account login."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.rsync.net/pricing.html",
          "note": "Funded by paid storage plans. The privacy policy says personal information is not shared with any party."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.rsync.net/resources/regulatory/sas70.html",
          "note": "States its US datacenter locations are SSAE16 certified, but no audit report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:44.274Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "seafile",
      "category": "file-sync",
      "name": "Seafile",
      "description": "Self-hosted file sync and sharing platform. Files are grouped into libraries that can be synced, shared, and individually protected with client-side encryption.",
      "website": "https://www.seafile.com",
      "source": "https://github.com/haiwen/seafile",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CN",
        "name": "China",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Seafile scores 35 out of 100 (grade F) on the file sync and backup criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source. It does not meet no trackers or telemetry and independent audit. It is based in China: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/file-sync/seafile/",
      "markdown": "https://privacyratings.com/file-sync/seafile/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/haiwen/seafile-server/blob/master/LICENSE.txt",
          "note": "The Community Edition server is AGPL-3.0 and the clients are GPL-2.0, but Professional Edition features are proprietary and unpublished."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.seafile.seadroid2/latest/",
          "note": "Exodus finds Google Crashlytics in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.seafile.com/en/product/seafile_on_premise/",
          "note": "Funded by Professional Edition licences and support, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:59.860Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "syncthing",
      "category": "file-sync",
      "name": "Syncthing",
      "description": "Open source, peer-to-peer continuous file synchronization between two or more devices. Data is encrypted in transit and never stored on a central server.",
      "website": "https://syncthing.net",
      "source": "https://github.com/syncthing/syncthing",
      "license": "MPL-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "SE",
        "name": "Sweden",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Syncthing scores 80 out of 100 (grade B) on the file sync and backup criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Sweden: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/file-sync/syncthing/",
      "markdown": "https://privacyratings.com/file-sync/syncthing/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/syncthing/syncthing/blob/main/LICENSE",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://docs.syncthing.net/users/security.html#usage-reporting",
          "note": "Usage reporting is off by default and only sent if the user agrees when asked. No third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://syncthing.net/donations/",
          "note": "Run by the non-profit Syncthing Foundation and funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:07.751Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vorta",
      "category": "file-sync",
      "name": "Vorta",
      "description": "Desktop front end for BorgBackup that schedules backups, browses archives and restores files. Works with local drives, SSH servers and hosted Borg repositories.",
      "website": "https://vorta.borgbase.com",
      "source": "https://github.com/borgbase/vorta",
      "license": "GPL-3.0",
      "platforms": [
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Vorta scores 80 out of 100 (grade B) on the file sync and backup criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-sync/vorta/",
      "markdown": "https://privacyratings.com/file-sync/vorta/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/borgbase/vorta/blob/master/LICENSE.txt",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://vorta.borgbase.com/",
          "note": "No third-party trackers, and the app has no telemetry. The website's self-hosted Umami analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/borgbase/vorta",
          "note": "Free open source project with no ads, supported by BorgBase and contributors."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:44.802Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "ark",
      "category": "archivers",
      "name": "Ark",
      "description": "Open source archive manager from the KDE community that creates, browses and extracts ZIP, 7z, RAR, tar and other archives, and integrates with the Dolphin file manager.",
      "website": "https://apps.kde.org/ark/",
      "source": "https://invent.kde.org/utilities/ark",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Ark scores 80 out of 100 (grade B) on the file archivers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/archivers/ark/",
      "markdown": "https://privacyratings.com/archivers/ark/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://invent.kde.org/utilities/ark/-/blob/master/LICENSES/GPL-2.0-or-later.txt",
          "note": "GPL-2.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kde.org/privacypolicy/",
          "note": "No third-party trackers, and the app has no telemetry. KDE websites use self-hosted Matomo with cookies disabled and IP addresses anonymized."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kde.org/donate/",
          "note": "Developed by the KDE community and funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:23.191Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bandizip",
      "category": "archivers",
      "name": "Bandizip",
      "description": "File archiver for Windows and macOS from Bandisoft that creates and extracts ZIP, 7z and many other formats. The free Windows edition shows ads, and paid editions remove them and add extra features.",
      "website": "https://www.bandisoft.com/bandizip/",
      "license": null,
      "platforms": [
        "windows",
        "macos"
      ],
      "jurisdiction": {
        "code": "KR",
        "name": "South Korea",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Bandizip scores 0 out of 100 (grade F) on the file archivers criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in South Korea: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/archivers/bandizip/",
      "markdown": "https://privacyratings.com/archivers/bandizip/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.bandisoft.com/about/gdpr/",
          "note": "The website uses Google Analytics and Google AdSense."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.bandisoft.com/bandizip/help/edition-comparison/",
          "note": "The free edition is ad-supported, with ad removal only in paid editions, and the website shows Google AdSense ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:23.113Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "betterzip",
      "category": "archivers",
      "name": "BetterZip",
      "description": "Paid file archiver for macOS from MacItBetter that creates, previews and extracts ZIP, RAR, 7z and many other formats, with encryption, presets and Finder integration.",
      "website": "https://macitbetter.com",
      "license": null,
      "platforms": [
        "macos"
      ],
      "jurisdiction": {
        "code": "AT",
        "name": "Austria",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "BetterZip scores 50 out of 100 (grade D) on the file archivers criteria. It meets 2 of 4 criteria: no trackers or telemetry and no ads or data sales. It does not meet open source and independent audit. It is based in Austria: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/archivers/betterzip/",
      "markdown": "https://privacyratings.com/archivers/betterzip/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://macitbetter.com/imprint-en/",
          "note": "The privacy policy states the website has no visitor tracking or third-party resources and the apps collect no personal data. Crash reports are sent only with consent."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://macitbetter.com/buy/",
          "note": "Funded by license sales. The privacy policy states customer data is not shared with third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:29.619Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "file-roller",
      "category": "archivers",
      "name": "File Roller",
      "description": "Open source archive manager for the GNOME desktop, also called Archive Manager, that creates, browses and extracts archives using tools such as tar, zip and 7z.",
      "website": "https://gitlab.gnome.org/GNOME/file-roller",
      "source": "https://gitlab.gnome.org/GNOME/file-roller",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "File Roller scores 80 out of 100 (grade B) on the file archivers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/archivers/file-roller/",
      "markdown": "https://privacyratings.com/archivers/file-roller/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/GNOME/file-roller/-/raw/master/COPYING",
          "note": "GPL-2.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/GNOME/file-roller",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://donate.gnome.org/en/",
          "note": "Developed by the GNOME project and funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:29.702Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "keka",
      "category": "archivers",
      "name": "Keka",
      "description": "File archiver for macOS that creates 7z, ZIP and other archives and extracts many formats including RAR, with AES-256 encryption and archive splitting. An iOS version is also available.",
      "website": "https://www.keka.io",
      "license": null,
      "platforms": [
        "macos",
        "ios"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Keka scores 10 out of 100 (grade F) on the file archivers criteria. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/archivers/keka/",
      "markdown": "https://privacyratings.com/archivers/keka/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. The GitHub repository only hosts issues, a wiki, translations and release downloads."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.keka.io/en/",
          "note": "The app sends no data apart from an optional update check, but the website loads Google Analytics and Google AdSense."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.keka.io/en/",
          "note": "The app has no ads and is funded by App Store sales and tips, but the download website shows Google AdSense ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:30.831Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nanazip",
      "category": "archivers",
      "name": "NanaZip",
      "description": "Open source file archiver for Windows derived from 7-Zip, with Windows 11 context menu integration, dark mode and extra compression codecs such as Zstandard and Brotli.",
      "website": "https://nanazip.org",
      "source": "https://github.com/M2Team/NanaZip",
      "license": null,
      "platforms": [
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "NanaZip scores 80 out of 100 (grade B) on the file archivers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/archivers/nanazip/",
      "markdown": "https://privacyratings.com/archivers/nanazip/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/M2Team/NanaZip/blob/main/License.md",
          "note": "MIT, with the 7-Zip code under the 7-Zip license (LGPL-2.1 with an unRAR restriction)."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/M2Team/NanaZip/blob/main/Documents/Privacy.md",
          "note": "The app collects no information. It only contacts the Microsoft Store to check the Sponsor Edition license status."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/M2Team/NanaZip/blob/main/Documents/SponsorEdition.md",
          "note": "Funded by an optional paid Sponsor Edition add-on and contributions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:30.281Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "peazip",
      "category": "archivers",
      "name": "PeaZip",
      "description": "Free, open source file archiver and file manager for Windows, macOS and Linux that handles over 200 archive formats, with strong encryption and two-factor authentication for archives.",
      "website": "https://peazip.github.io",
      "source": "https://github.com/giorgiotani/PeaZip",
      "license": "LGPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "PeaZip scores 80 out of 100 (grade B) on the file archivers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/archivers/peazip/",
      "markdown": "https://privacyratings.com/archivers/peazip/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/giorgiotani/PeaZip/blob/sources/LICENSE",
          "note": "LGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://peazip.github.io/peazip-tos-privacy.html",
          "note": "The project states that neither the software nor the website collects user data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://peazip.github.io/donations.html",
          "note": "Funded by donations. Installers contain no advertising modules."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:31.274Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "the-unarchiver",
      "category": "archivers",
      "name": "The Unarchiver",
      "description": "Free archive extraction app for macOS by MacPaw that opens RAR, 7z, ZIP, StuffIt and many older formats. Command-line tools unar and lsar are also available for other systems.",
      "website": "https://theunarchiver.com",
      "source": "https://github.com/MacPaw/XADMaster",
      "license": "LGPL-2.1",
      "platforms": [
        "macos"
      ],
      "jurisdiction": {
        "code": "CY",
        "name": "Cyprus",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "The Unarchiver scores 25 out of 100 (grade F) on the file archivers criteria. It partly meets open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Cyprus: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/archivers/the-unarchiver/",
      "markdown": "https://privacyratings.com/archivers/the-unarchiver/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/MacPaw/XADMaster/blob/master/LICENSE",
          "note": "The XADMaster extraction engine and command-line tools are LGPL-2.1, but the macOS app itself is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://macpaw.com/legal/the-unarchiver-privacy-policy",
          "note": "The privacy policy lists Google Analytics, Hotjar and Sentry, and the website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://macpaw.com/legal/the-unarchiver-privacy-policy",
          "note": "Free with no ads in the app, but the privacy policy lists social and advertising networks among service providers used for MacPaw marketing."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Ads",
            "host": "www.googleadservices.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:30.232Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "winrar",
      "category": "archivers",
      "name": "WinRAR",
      "description": "Trialware file archiver for Windows that creates and extracts RAR and ZIP archives and opens many other formats, with AES encryption and recovery records. Developed by Alexander Roshal and sold by win.rar GmbH.",
      "website": "https://www.win-rar.com",
      "license": null,
      "platforms": [
        "windows"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "WinRAR scores 10 out of 100 (grade F) on the file archivers criteria. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/archivers/winrar/",
      "markdown": "https://privacyratings.com/archivers/winrar/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.win-rar.com/winrarlicense.html",
          "note": "Closed source. The UnRAR extraction code is published separately under a restrictive license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.win-rar.com/cookies.html",
          "note": "The website uses Google Tag Manager and Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.win-rar.com/winrarlicense.html",
          "note": "Funded by license sales. The unlicensed trial can show a reminder dialog loading a web page that may contain advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:00.787Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "winzip",
      "category": "archivers",
      "name": "WinZip",
      "description": "Commercial file archiver for Windows and macOS, with mobile apps, that creates and extracts ZIP and other archive formats, with encryption, cloud storage integration and PDF tools. Sold by Corel Corporation.",
      "website": "https://www.winzip.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "WinZip scores 0 out of 100 (grade F) on the file archivers criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in Canada: Five Eyes member.",
      "url": "https://privacyratings.com/archivers/winzip/",
      "markdown": "https://privacyratings.com/archivers/winzip/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.corel.com/en/privacy/",
          "note": "The website loads Google Tag Manager and Optimizely, and the apps collect product usage data such as feature use, a hardware fingerprint and installed software."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.winzip.android/latest/",
          "note": "The Android app includes the Google AdMob ad SDK, and the privacy statement uses website data for interest-based advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Optimizely",
            "host": "cdn.optimizely.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:59.817Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "apple-iwork",
      "category": "office-suites",
      "name": "Apple iWork",
      "description": "Apple's free Pages, Numbers and Keynote apps for documents, spreadsheets and presentations on Mac, iPhone and iPad, also available in the browser through iCloud.",
      "website": "https://www.apple.com/apps/",
      "license": null,
      "platforms": [
        "macos",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Apple iWork scores 35 out of 100 (grade F) on the office suites criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets no trackers or telemetry. It does not meet open source and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/office-suites/apple-iwork/",
      "markdown": "https://privacyratings.com/office-suites/apple-iwork/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/device-analytics/",
          "note": "Sharing device analytics with Apple is opt-in, but Apple's website collects its own analytics by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/en-ww/",
          "note": "No ads in the apps. Apple's privacy policy states that Apple does not sell or share personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:44.799Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "calligra",
      "category": "office-suites",
      "name": "Calligra",
      "description": "Office and graphics suite from KDE with Words, Sheets, Stage, Karbon and other apps, using OpenDocument as its native file format.",
      "website": "https://calligra.org",
      "source": "https://invent.kde.org/office/calligra",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Calligra scores 80 out of 100 (grade B) on the office suites criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/office-suites/calligra/",
      "markdown": "https://privacyratings.com/office-suites/calligra/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://invent.kde.org/office/calligra/-/blob/master/COPYING",
          "note": "GPL-2.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kde.org/privacypolicy-apps/",
          "note": "KDE apps only send telemetry if the user opts in, and the Calligra website has no analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kde.org/donate/",
          "note": "Developed by the KDE community, which is funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:45.109Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "collabora-online",
      "category": "office-suites",
      "name": "Collabora Online",
      "description": "Online office suite based on LibreOffice for documents, spreadsheets and presentations, with real-time collaborative editing. It is self-hosted or used through integrations such as Nextcloud.",
      "website": "https://www.collaboraonline.com",
      "source": "https://github.com/CollaboraOnline/online.mirror",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Collabora Online scores 65 out of 100 (grade C) on the office suites criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/office-suites/collabora-online/",
      "markdown": "https://privacyratings.com/office-suites/collabora-online/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/CollaboraOnline/online.mirror/blob/main/COPYING",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.collaboraonline.com/privacy-notice/",
          "note": "No telemetry in the server software. The website uses Collabora's self-hosted Matomo analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.collaboraonline.com/privacy-notice/",
          "note": "Funded by support subscriptions. The privacy notice states that Collabora does not sell customer data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:45.355Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "cryptpad",
      "category": "office-suites",
      "name": "CryptPad",
      "description": "End-to-end encrypted collaboration suite with rich text, spreadsheets, presentations, Markdown, Kanban, forms, diagrams and a file drive. Use the hosted CryptPad.fr service or self-host it.",
      "website": "https://cryptpad.org",
      "source": "https://github.com/cryptpad/cryptpad",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 56,
      "coverage": 100,
      "summary": "CryptPad scores 56 out of 100 (grade D) on the office suites criteria. It meets 3 of 8 criteria: open source, no ads or data sales and TLS configuration. It partly meets no trackers or telemetry and security headers. It does not meet independent audit, transparency report and tells users about requests. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/office-suites/cryptpad/",
      "markdown": "https://privacyratings.com/office-suites/cryptpad/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cryptpad/cryptpad/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/cryptpad/cryptpad/blob/main/lib/stats.js",
          "note": "No third-party trackers. Self-hosted servers send a daily instance report to the CryptPad team by default, which administrators can turn off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cryptpad.org/pricing/",
          "note": "Funded by paid plans on CryptPad.fr, support contracts, grants and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=cryptpad.org&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=cryptpad.org",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:36.363Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "etherpad",
      "category": "office-suites",
      "name": "Etherpad",
      "description": "Self-hosted, real-time collaborative text editor where several people edit the same document at once, with a plugin system and an HTTP API.",
      "website": "https://etherpad.org",
      "source": "https://github.com/ether/etherpad",
      "license": "Apache-2.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Etherpad scores 80 out of 100 (grade B) on the office suites criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/office-suites/etherpad/",
      "markdown": "https://privacyratings.com/office-suites/etherpad/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ether/etherpad/blob/develop/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ether/etherpad",
          "note": "No telemetry or analytics in the source code. The server only checks static.etherpad.org for new versions."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/ether/etherpad",
          "note": "Free volunteer-run project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:44.898Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "google-docs",
      "category": "office-suites",
      "name": "Google Docs",
      "description": "Google's browser-based word processor with real-time collaboration, part of Google Workspace alongside Sheets and Slides. Files are stored in Google Drive.",
      "website": "https://docs.google.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 34,
      "coverage": 100,
      "summary": "Google Docs scores 34 out of 100 (grade F) on the office suites criteria. It meets 2 of 8 criteria: transparency report and tells users about requests. It partly meets independent audit, TLS configuration and security headers. It does not meet open source, no trackers or telemetry and no ads or data sales. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/office-suites/google-docs/",
      "markdown": "https://privacyratings.com/office-suites/google-docs/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Google collects activity data across its services and uses it for analytics and personalized ads."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Docs shows no ads, but Google is funded mainly by advertising and uses account activity across its services for personalized ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cloud.google.com/security/compliance/soc-3",
          "note": "Google Workspace, which includes Docs, has third-party SOC 2 audits. Only the SOC 3 summary report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://transparencyreport.google.com/user-data/overview",
          "note": "Publishes counts of government requests for user data and how often data is disclosed, updated twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://policies.google.com/terms/information-requests",
          "note": "Google emails the user before disclosing information unless legally prohibited or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=docs.google.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=docs.google.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:17:29.892Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "libreoffice",
      "category": "office-suites",
      "name": "LibreOffice",
      "description": "Office suite from The Document Foundation with Writer, Calc, Impress, Draw, Base and Math, using OpenDocument as its native file format.",
      "website": "https://www.libreoffice.org",
      "source": "https://git.libreoffice.org/core",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "LibreOffice scores 65 out of 100 (grade C) on the office suites criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/office-suites/libreoffice/",
      "markdown": "https://privacyratings.com/office-suites/libreoffice/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://git.libreoffice.org/core/+/refs/heads/master/COPYING.MPL",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.libreoffice.org/privacy-policy/",
          "note": "No telemetry in the apps, and crash reports are sent only with the user's confirmation. The website uses self-hosted Matomo analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.libreoffice.org/donate/",
          "note": "Funded by donations to The Document Foundation, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:45.412Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "microsoft-365",
      "category": "office-suites",
      "name": "Microsoft 365",
      "description": "Microsoft's office suite with Word, Excel, PowerPoint, Outlook and OneDrive, available as desktop and mobile apps and in the browser. Cloud files are stored on Microsoft's servers.",
      "website": "https://www.microsoft.com/en-us/microsoft-365",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 44,
      "coverage": 100,
      "summary": "Microsoft 365 scores 44 out of 100 (grade D) on the office suites criteria. It meets 4 of 8 criteria: transparency report, tells users about requests, TLS configuration and security headers. It partly meets independent audit. It does not meet open source, no trackers or telemetry and no ads or data sales. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/office-suites/microsoft-365/",
      "markdown": "https://privacyratings.com/office-suites/microsoft-365/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/microsoft-365-apps/privacy/required-diagnostic-data",
          "note": "The apps always send required diagnostic data to Microsoft, which cannot be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "Microsoft uses data from its services, including Copilot prompts, for advertising. Documents are not used to target ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2",
          "note": "Office 365 has SOC 2 audits by an independent CPA firm. The reports are only available to customers through the Service Trust Portal."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Publishes counts of government requests for consumer and enterprise data twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Microsoft notifies users and enterprise customers of requests for their data unless legally prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=m365.cloud.microsoft&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=m365.cloud.microsoft",
          "note": "Grade A+ (110/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:54.766Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "onlyoffice",
      "category": "office-suites",
      "name": "ONLYOFFICE",
      "description": "Office suite for documents, spreadsheets, presentations and PDFs with a focus on Microsoft Office format compatibility, available as desktop editors, mobile apps, a self-hosted server and the DocSpace cloud.",
      "website": "https://www.onlyoffice.com",
      "source": "https://github.com/ONLYOFFICE/DesktopEditors",
      "license": "AGPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "LV",
        "name": "Latvia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "ONLYOFFICE scores 35 out of 100 (grade F) on the office suites criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source. It does not meet no trackers or telemetry and independent audit. It is based in Latvia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/office-suites/onlyoffice/",
      "markdown": "https://privacyratings.com/office-suites/onlyoffice/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/ONLYOFFICE/DesktopEditors/blob/master/LICENSE",
          "note": "The desktop editors and Docs server are AGPL-3.0. The mobile apps are closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.onlyoffice.documents/latest/",
          "note": "The Android app includes Google Firebase Analytics, Crashlytics and Facebook Login, and the website uses Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.onlyoffice.com/privacy",
          "note": "Funded by commercial editions and cloud plans. The privacy policy states that personal data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:45.335Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "proton-docs",
      "category": "office-suites",
      "name": "Proton Docs",
      "description": "End-to-end encrypted document editor built into Proton Drive, with real-time collaboration, comments and suggestions.",
      "website": "https://proton.me/drive/docs",
      "source": "https://github.com/ProtonMail/WebClients",
      "license": "GPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 75,
      "coverage": 100,
      "summary": "Proton Docs scores 75 out of 100 (grade B) on the office suites criteria. It meets 5 of 8 criteria: no ads or data sales, transparency report, tells users about requests, TLS configuration and security headers. It partly meets open source, no trackers or telemetry and independent audit. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/office-suites/proton-docs/",
      "markdown": "https://privacyratings.com/office-suites/proton-docs/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/ProtonMail/WebClients/blob/main/LICENSE",
          "note": "The web apps, including Docs, are GPL-3.0. The server is not open source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://proton.me/legal/privacy",
          "note": "Website analytics are self-hosted. The apps include crash reporting and usage statistics, which are on by default and can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://proton.me/drive/pricing",
          "note": "Funded by paid plans, with no ads on any plan."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://proton.me/blog/soc-2",
          "note": "Proton completed a SOC 2 Type II audit, but the report is not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://proton.me/legal/transparency",
          "note": "Publishes yearly counts of legal orders received, complied with and contested."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://proton.me/legal/law-enforcement",
          "note": "Targeted users are notified of data requests, with delays only when Swiss law, a court order or a risk to life requires it."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=docs.proton.me&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=docs.proton.me",
          "note": "Grade A+ (115/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:54.873Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "sandstorm",
      "category": "office-suites",
      "name": "Sandstorm",
      "description": "Open source platform for self-hosting web apps. Apps are installed from the Sandstorm App Market with a few clicks, and each document or chat runs in its own isolated sandbox.",
      "website": "https://sandstorm.org",
      "source": "https://github.com/sandstorm-io/sandstorm",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Sandstorm scores 80 out of 100 (grade B) on the office suites criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/office-suites/sandstorm/",
      "markdown": "https://privacyratings.com/office-suites/sandstorm/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sandstorm-io/sandstorm/blob/master/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sandstorm-io/sandstorm/blob/master/shell/imports/server/stats-server.js",
          "note": "Usage statistics are only sent after a server administrator opts in. No third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/sandstormcommunity",
          "note": "Volunteer project funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:27.535Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "softmaker-freeoffice",
      "category": "office-suites",
      "name": "SoftMaker FreeOffice",
      "description": "Free office suite from SoftMaker with TextMaker, PlanMaker and Presentations, compatible with Microsoft Office formats. It is a reduced version of the paid SoftMaker Office.",
      "website": "https://www.freeoffice.com/en/",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "SoftMaker FreeOffice scores 35 out of 100 (grade F) on the office suites criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets no trackers or telemetry. It does not meet open source and independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/office-suites/softmaker-freeoffice/",
      "markdown": "https://privacyratings.com/office-suites/softmaker-freeoffice/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.freeoffice.com/en/privacy-policy",
          "note": "No third-party trackers, but the website uses self-hosted Matomo analytics after consent."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.freeoffice.com/en/",
          "note": "Free with no ads, funded by sales of the paid SoftMaker Office."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:45.946Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "wps-office",
      "category": "office-suites",
      "name": "WPS Office",
      "description": "Office suite from Kingsoft with word processor, spreadsheet, presentation and PDF tools, compatible with Microsoft Office formats. The free version shows ads.",
      "website": "https://www.wps.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "SG",
        "name": "Singapore",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "WPS Office scores 0 out of 100 (grade F) on the office suites criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in Singapore: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/office-suites/wps-office/",
      "markdown": "https://privacyratings.com/office-suites/wps-office/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/cn.wps.moffice_eng/latest/",
          "note": "The Android app includes 15 trackers, including Facebook SDKs, and the website uses Microsoft Clarity."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.wps.com/privacy-policy/",
          "note": "The free version is supported by ads, and the privacy policy covers advertising identifiers and third-party advertisers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Microsoft Clarity",
            "host": "www.clarity.ms",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:45.661Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "zoho-workplace",
      "category": "office-suites",
      "name": "Zoho Workplace",
      "description": "Zoho's hosted business suite with Zoho Mail, the Writer, Sheet and Show office apps, WorkDrive file storage and Cliq team chat.",
      "website": "https://www.zoho.com/workplace/",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "IN",
        "name": "India",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 47,
      "coverage": 100,
      "summary": "Zoho Workplace scores 47 out of 100 (grade D) on the office suites criteria. It meets 3 of 8 criteria: no ads or data sales, TLS configuration and security headers. It partly meets no trackers or telemetry and independent audit. It does not meet open source, transparency report and tells users about requests. It is based in India: Not in the Five, Nine or Fourteen Eyes. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/office-suites/zoho-workplace/",
      "markdown": "https://privacyratings.com/office-suites/zoho-workplace/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.zoho.com/privacy.html",
          "note": "Zoho states it does not use third-party tracking on its websites, but it uses first-party cookies to track visitor activity."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.zoho.com/privacy.html",
          "note": "Funded by subscriptions. The privacy policy states that Zoho does not sell personal information or earn money from advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.zoho.com/compliance.html",
          "note": "Zoho has SOC 2 Type 2 audits by an independent firm. The reports are available to customers, not publicly."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=workplace.zoho.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=workplace.zoho.com",
          "note": "Grade A+ (110/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:54.928Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "adobe-acrobat-reader",
      "category": "pdf-tools",
      "name": "Adobe Acrobat Reader",
      "description": "Adobe's free app for viewing, printing, signing and commenting on PDF files. Paid Acrobat features and Adobe cloud storage are offered in the same app.",
      "website": "https://www.adobe.com/acrobat/pdf-reader.html",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Adobe Acrobat Reader scores 0 out of 100 (grade F) on the PDF readers and editors criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/pdf-tools/adobe-acrobat-reader/",
      "markdown": "https://privacyratings.com/pdf-tools/adobe-acrobat-reader/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.adobe.reader/latest/",
          "note": "The Android app includes 9 trackers, including Facebook Analytics, Google AdMob and Google Firebase Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.adobe.com/privacy/policy.html",
          "note": "Adobe discloses information about actions in its websites and apps to social media and advertising partners, and may share data with third parties for their own marketing."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit of Acrobat Reader is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:39:15.412Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "mupdf",
      "category": "pdf-tools",
      "name": "MuPDF",
      "description": "PDF, XPS and e-book rendering library from Artifex, with a lightweight viewer, command-line tools and bindings for Python, JavaScript and .NET.",
      "website": "https://mupdf.com",
      "source": "https://github.com/ArtifexSoftware/mupdf",
      "license": "AGPL-3.0",
      "platforms": [
        "windows",
        "linux",
        "android"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "MuPDF scores 50 out of 100 (grade D) on the PDF readers and editors criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/pdf-tools/mupdf/",
      "markdown": "https://privacyratings.com/pdf-tools/mupdf/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ArtifexSoftware/mupdf/blob/master/COPYING",
          "note": "AGPL-3.0, with a commercial license available from Artifex."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://mupdf.com/privacy",
          "note": "The Android viewer has no known trackers, but the website uses Google Analytics and Microsoft Clarity."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://artifex.com/licensing",
          "note": "Funded by commercial licenses, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Microsoft Clarity",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:45.921Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "okular",
      "category": "pdf-tools",
      "name": "Okular",
      "description": "KDE document viewer for PDF, EPUB, DjVu, comic books and other formats, with annotations, form filling and digital signatures.",
      "website": "https://okular.kde.org",
      "source": "https://invent.kde.org/graphics/okular",
      "license": null,
      "platforms": [
        "windows",
        "linux"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Okular scores 80 out of 100 (grade B) on the PDF readers and editors criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/pdf-tools/okular/",
      "markdown": "https://privacyratings.com/pdf-tools/okular/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://invent.kde.org/graphics/okular/-/blob/master/LICENSES/GPL-2.0-or-later.txt",
          "note": "GPL-2.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kde.org/privacypolicy-apps/",
          "note": "No third-party trackers, and KDE app telemetry is opt-in. KDE websites use self-hosted Matomo with cookies disabled and IP addresses anonymized."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kde.org/donate/",
          "note": "Developed by the KDE community, which is funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:46.211Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "papers",
      "category": "pdf-tools",
      "name": "Papers",
      "description": "GNOME's document viewer for PDF, DjVu, TIFF and comic book files. It is the successor to Evince.",
      "website": "https://apps.gnome.org/Papers/",
      "source": "https://gitlab.gnome.org/GNOME/papers",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Papers scores 80 out of 100 (grade B) on the PDF readers and editors criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/pdf-tools/papers/",
      "markdown": "https://privacyratings.com/pdf-tools/papers/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/GNOME/papers/-/raw/main/COPYING",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/GNOME/papers",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://donate.gnome.org/en/",
          "note": "Developed by the GNOME project, which is funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:45.898Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "pdf-arranger",
      "category": "pdf-tools",
      "name": "PDF Arranger",
      "description": "Desktop app for merging, splitting, rotating, cropping and reordering the pages of PDF documents through a drag-and-drop interface.",
      "website": "https://github.com/pdfarranger/pdfarranger",
      "source": "https://github.com/pdfarranger/pdfarranger",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "PDF Arranger scores 80 out of 100 (grade B) on the PDF readers and editors criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/pdf-tools/pdf-arranger/",
      "markdown": "https://privacyratings.com/pdf-tools/pdf-arranger/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pdfarranger/pdfarranger/blob/main/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pdfarranger/pdfarranger",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/pdfarranger/pdfarranger",
          "note": "Free volunteer-run project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:45.899Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "stirling-pdf",
      "category": "pdf-tools",
      "name": "Stirling PDF",
      "description": "Open-core PDF toolkit that runs as a desktop app, in the browser or on a self-hosted server, with tools to merge, split, convert, OCR, sign and redact PDFs.",
      "website": "https://www.stirling.com",
      "source": "https://github.com/Stirling-Tools/Stirling-PDF",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Stirling PDF scores 50 out of 100 (grade D) on the PDF readers and editors criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/pdf-tools/stirling-pdf/",
      "markdown": "https://privacyratings.com/pdf-tools/stirling-pdf/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Stirling-Tools/Stirling-PDF/blob/main/LICENSE",
          "note": "All code is public. The core is MIT, and the engine, proprietary and SaaS directories in the same repository use the source-available Stirling PDF User License."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.stirling.com/legal/privacy-policy",
          "note": "The website uses Google Analytics through Google Tag Manager, and the product can send PostHog analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.stirling.com/legal/privacy-policy",
          "note": "Funded by paid plans. The privacy policy states that personal data is not sold or shared for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:46.226Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "sumatrapdf",
      "category": "pdf-tools",
      "name": "SumatraPDF",
      "description": "Lightweight reader for PDF, EPUB, MOBI, XPS, DjVu and comic book files on Windows, available as an installer or a portable app.",
      "website": "https://www.sumatrapdfreader.org",
      "source": "https://github.com/sumatrapdfreader/sumatrapdf",
      "license": "GPL-3.0",
      "platforms": [
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "SumatraPDF scores 65 out of 100 (grade C) on the PDF readers and editors criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/pdf-tools/sumatrapdf/",
      "markdown": "https://privacyratings.com/pdf-tools/sumatrapdf/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sumatrapdfreader/sumatrapdf/blob/master/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/sumatrapdfreader/sumatrapdf/blob/master/src/base/CrashHandler.cpp",
          "note": "No third-party analytics. Official builds send crash reports and update checks to the SumatraPDF server, which a restriction policy file can block."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.sumatrapdfreader.org/free-pdf-reader",
          "note": "Free with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:01.381Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "xournal",
      "category": "pdf-tools",
      "name": "Xournal++",
      "description": "Handwriting note-taking app that also annotates PDF files with pen, highlighter, text and shapes, with support for pressure-sensitive tablets.",
      "website": "https://xournalpp.github.io",
      "source": "https://github.com/xournalpp/xournalpp",
      "license": "GPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Xournal++ scores 80 out of 100 (grade B) on the PDF readers and editors criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/pdf-tools/xournal/",
      "markdown": "https://privacyratings.com/pdf-tools/xournal/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/xournalpp/xournalpp/blob/master/LICENSE",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/xournalpp/xournalpp",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://xournalpp.github.io/",
          "note": "Free volunteer-run project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:46.027Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "zathura",
      "category": "pdf-tools",
      "name": "Zathura",
      "description": "Minimal, keyboard-driven document viewer with Vim-like key bindings. PDF, PostScript, DjVu and comic book support comes from plugins.",
      "website": "https://pwmt.org/projects/zathura/",
      "source": "https://github.com/pwmt/zathura",
      "license": "Zlib",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Zathura scores 80 out of 100 (grade B) on the PDF readers and editors criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/pdf-tools/zathura/",
      "markdown": "https://privacyratings.com/pdf-tools/zathura/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pwmt/zathura/blob/master/LICENSE",
          "note": "zlib license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pwmt/zathura",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://pwmt.org/projects/zathura/",
          "note": "Free volunteer-run project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:46.534Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "cap",
      "category": "screen-recording",
      "name": "Cap",
      "description": "Open-source screen recorder for macOS, Windows and Linux. Recordings can be edited locally, or uploaded to Cap's cloud, a self-hosted server, S3-compatible storage or Google Drive and shared as a link.",
      "website": "https://cap.so",
      "source": "https://github.com/CapSoftware/Cap",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 69,
      "coverage": 100,
      "summary": "Cap scores 69 out of 100 (grade C) on the screenshots and screen recording criteria. It meets 2 of 6 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry, independent audit, saved locally by default and no account needed.",
      "url": "https://privacyratings.com/screen-recording/cap/",
      "markdown": "https://privacyratings.com/screen-recording/cap/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/CapSoftware/Cap/blob/main/LICENSE",
          "note": "AGPL-3.0, with some recording crates under MIT. The web platform is included and can be self-hosted."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/CapSoftware/Cap/blob/main/apps/desktop/src/utils/analytics.ts",
          "note": "The desktop app and website send usage analytics to OpenPanel, a cookieless analytics service, by default. The app has a setting to turn telemetry off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cap.so/pricing",
          "note": "Funded by paid licenses and subscriptions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cap.so/faq",
          "note": "Cap states SOC 2 Type II and ISO 27001 compliance, but the reports are only available on request through its Trust Portal."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_by_default": {
          "title": "Saved locally by default",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cap.so/docs/recording/studio-mode",
          "note": "Studio Mode keeps recordings local until you choose to share them. Instant Mode uploads recordings to the cloud while recording."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://github.com/CapSoftware/Cap/blob/main/apps/desktop/src-tauri/src/recording.rs",
          "note": "Local Studio recordings work without signing in. Instant Mode and shareable links need a Cap account."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:33.215Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cleanshot-x",
      "category": "screen-recording",
      "name": "CleanShot X",
      "description": "Screenshot and screen recording app for macOS with annotation, scrolling capture, text recognition and optional upload to the CleanShot Cloud sharing service.",
      "website": "https://cleanshot.com",
      "license": null,
      "platforms": [
        "macos"
      ],
      "jurisdiction": {
        "code": "PL",
        "name": "Poland",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 58,
      "coverage": 100,
      "summary": "CleanShot X scores 58 out of 100 (grade D) on the screenshots and screen recording criteria. It meets 3 of 6 criteria: no ads or data sales, saved locally by default and no account needed. It partly meets no trackers or telemetry and independent audit. It does not meet open source. It is based in Poland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/screen-recording/cleanshot-x/",
      "markdown": "https://privacyratings.com/screen-recording/cleanshot-x/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://cleanshot.com/legal/cloud/subprocessors",
          "note": "The website uses Simple Analytics, a cookieless analytics service, and the subprocessor list names no analytics or ad companies. No statement covers telemetry in the app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cleanshot.com/pricing",
          "note": "Funded by paid licenses and subscriptions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cleanshot.com/security",
          "note": "Only the ISO 27001 certificate is public. Third-party penetration tests are stated, but no report is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_by_default": {
          "title": "Saved locally by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cleanshot.com/faq",
          "note": "Captures are saved locally. CleanShot Cloud is only used when you choose to upload."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://cleanshot.com/faq",
          "note": "A CleanShot Cloud account is only needed for uploading, not for using the app."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:30.604Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "flameshot",
      "category": "screen-recording",
      "name": "Flameshot",
      "description": "Open-source screenshot tool for Linux, Windows and macOS with in-app annotation tools such as arrows, text, blur and highlighting, plus a command-line interface.",
      "website": "https://flameshot.org",
      "source": "https://github.com/flameshot-org/flameshot",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "Flameshot scores 85 out of 100 (grade B) on the screenshots and screen recording criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, saved locally by default and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/screen-recording/flameshot/",
      "markdown": "https://privacyratings.com/screen-recording/flameshot/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/flameshot-org/flameshot/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/flameshot-org/flameshot",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://flameshot.org/donate/",
          "note": "Free open-source app with no ads, supported by donations and sponsors."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_by_default": {
          "title": "Saved locally by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://flameshot.org/docs/advanced/protecting-your-privacy/",
          "note": "Screenshots are saved locally or copied to the clipboard. Uploading to Imgur is an optional tool that asks for confirmation first."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://flameshot.org",
          "note": "No account is needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:30.521Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "greenshot",
      "category": "screen-recording",
      "name": "Greenshot",
      "description": "Open-source screenshot tool for Windows that captures a region, window or full screen and adds annotations, highlighting and redaction before saving, printing or exporting.",
      "website": "https://getgreenshot.org",
      "source": "https://github.com/greenshot/greenshot",
      "license": "GPL-3.0",
      "platforms": [
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 46,
      "coverage": 100,
      "summary": "Greenshot scores 46 out of 100 (grade D) on the screenshots and screen recording criteria. It meets 3 of 6 criteria: open source, saved locally by default and no account needed. It does not meet no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/screen-recording/greenshot/",
      "markdown": "https://privacyratings.com/screen-recording/greenshot/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/greenshot/greenshot/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://getgreenshot.org/privacy-policy/",
          "note": "The website uses Google Analytics and Google AdSense cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://getgreenshot.org/privacy-policy/",
          "note": "The app has no ads, but the project is partly funded by Google AdSense ads on its website that use third-party cookies for interest-based ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_by_default": {
          "title": "Saved locally by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/greenshot/greenshot",
          "note": "Screenshots are saved to local files or the clipboard. Uploading to online services is an optional export destination."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://getgreenshot.org/downloads/",
          "note": "No account is needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Cookiebot",
            "host": "consent.cookiebot.com",
            "effect": "none"
          },
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:31.250Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kap",
      "category": "screen-recording",
      "name": "Kap",
      "description": "Open-source screen recorder for macOS built with Electron. It exports recordings as GIF, MP4, WebM or APNG and supports plugins for sharing to other services.",
      "website": "https://getkap.co",
      "source": "https://github.com/wulkano/Kap",
      "license": "MIT",
      "platforms": [
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 62,
      "coverage": 100,
      "summary": "Kap scores 62 out of 100 (grade C) on the screenshots and screen recording criteria. It meets 4 of 6 criteria: open source, no ads or data sales, saved locally by default and no account needed. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/screen-recording/kap/",
      "markdown": "https://privacyratings.com/screen-recording/kap/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/wulkano/Kap/blob/main/LICENSE.md",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/wulkano/Kap/blob/main/main/utils/sentry.ts",
          "note": "Crash and error reports are sent to Sentry by default and can be turned off in the settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://getkap.co",
          "note": "Free open-source app with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_by_default": {
          "title": "Saved locally by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://getkap.co",
          "note": "Recordings are exported to local files. Uploading to services such as Giphy or Streamable is done through optional plugins."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://getkap.co",
          "note": "No account is needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:30.536Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kooha",
      "category": "screen-recording",
      "name": "Kooha",
      "description": "Open-source screen recorder for Linux built with GTK and GStreamer. It records the screen or a region with audio to WebM, MP4, GIF or Matroska files.",
      "website": "https://github.com/SeaDve/Kooha",
      "source": "https://github.com/SeaDve/Kooha",
      "license": "GPL-3.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "Kooha scores 85 out of 100 (grade B) on the screenshots and screen recording criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, saved locally by default and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/screen-recording/kooha/",
      "markdown": "https://privacyratings.com/screen-recording/kooha/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/SeaDve/Kooha/blob/main/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/SeaDve/Kooha",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://seadve.github.io/donate/",
          "note": "Free open-source app with no ads, supported by donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_by_default": {
          "title": "Saved locally by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/SeaDve/Kooha",
          "note": "Recordings are saved to a local folder."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/SeaDve/Kooha",
          "note": "No account is needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:30.605Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "loom",
      "category": "screen-recording",
      "name": "Loom",
      "description": "Video messaging service from Atlassian for recording the screen and camera and sharing the result as a link. Recordings are uploaded to and hosted on Loom's servers.",
      "website": "https://www.loom.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 15,
      "coverage": 100,
      "summary": "Loom scores 15 out of 100 (grade F) on the screenshots and screen recording criteria. It partly meets no ads or data sales and independent audit. It does not meet open source, no trackers or telemetry, saved locally by default and no account needed. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/screen-recording/loom/",
      "markdown": "https://privacyratings.com/screen-recording/loom/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.loom.android/latest/",
          "note": "Exodus finds HMS Core analytics, OneSignal, Segment and Sentry in the Android app, and the website loads Google Tag Manager and connects to Google Analytics and Amplitude."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.atlassian.com/legal/privacy-policy",
          "note": "Funded by subscriptions with no ads in the product, but the policy allows cookies and identifiers from advertising partners."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.atlassian.com/loom/docs/download-the-loom-soc-2-report/",
          "note": "Loom has SOC 2 audits, but the report is only available on request through the Atlassian Trust portal."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_by_default": {
          "title": "Saved locally by default",
          "weight": 2,
          "answer": "no",
          "evidence": "https://support.atlassian.com/loom/docs/how-secure-are-my-videos/",
          "note": "Videos are uploaded to Loom's servers while recording."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "no",
          "evidence": "https://www.loom.com/pricing",
          "note": "A Loom account is required to record and share videos."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Amplitude",
            "host": "cdn.amplitude.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:30.813Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "quicktime-player",
      "category": "screen-recording",
      "name": "QuickTime Player",
      "description": "Apple's media player built into macOS. It can also record the screen, camera and audio and make basic edits such as trimming and splitting clips.",
      "website": "https://support.apple.com/guide/quicktime-player/welcome/mac",
      "license": null,
      "platforms": [
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "QuickTime Player scores 50 out of 100 (grade D) on the screenshots and screen recording criteria. It meets 3 of 6 criteria: no ads or data sales, saved locally by default and no account needed. It partly meets no trackers or telemetry. It does not meet open source and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/screen-recording/quicktime-player/",
      "markdown": "https://privacyratings.com/screen-recording/quicktime-player/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/device-analytics/",
          "note": "No third-party trackers in the app, and sharing device analytics with Apple is opt-in. Apple web pages load Apple's own analytics by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/en-ww/",
          "note": "No ads in the app, which is included with macOS. Apple states it does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_by_default": {
          "title": "Saved locally by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.apple.com/en-us/102618",
          "note": "Screen recordings are saved as local files, on the desktop by default."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://support.apple.com/guide/quicktime-player/record-your-screen-qtp97b08e666/mac",
          "note": "Screen recording works without an Apple Account."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:31.567Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "screen-studio",
      "category": "screen-recording",
      "name": "Screen Studio",
      "description": "Screen recorder for macOS that adds automatic zoom, smooth cursor movement and styling to recordings for product demos and tutorials. Recordings are edited locally, with optional shareable links.",
      "website": "https://screen.studio",
      "license": null,
      "platforms": [
        "macos"
      ],
      "jurisdiction": {
        "code": "PL",
        "name": "Poland",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 31,
      "coverage": 100,
      "summary": "Screen Studio scores 31 out of 100 (grade F) on the screenshots and screen recording criteria. It meets 2 of 6 criteria: no ads or data sales and saved locally by default. It does not meet open source, no trackers or telemetry, independent audit and no account needed. It is based in Poland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/screen-recording/screen-studio/",
      "markdown": "https://privacyratings.com/screen-recording/screen-studio/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://screen.studio/legal/privacy-and-cookie-policy",
          "note": "The privacy policy lists PostHog product analytics and Sentry error reporting in the app, and Plausible analytics on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://screen.studio/legal/privacy-and-cookie-policy",
          "note": "Funded by paid subscriptions and licenses. The policy states that data of identifiable users is never shared."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_by_default": {
          "title": "Saved locally by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://screen.studio/legal/privacy-and-cookie-policy",
          "note": "Recordings are processed locally and only uploaded when you create a shareable link."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "no",
          "evidence": "https://screen.studio/guide/activating-screen-studio",
          "note": "Subscriptions are activated by signing in with the purchase email address. Only legacy one-time licenses use a license key."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:32.067Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "screentogif",
      "category": "screen-recording",
      "name": "ScreenToGif",
      "description": "Open-source screen, webcam and sketchboard recorder for Windows with a built-in editor. Recordings can be saved as GIF, APNG, video or image files.",
      "website": "https://nicke.tech/screentogif",
      "source": "https://github.com/NickeManarin/ScreenToGif",
      "license": "MS-PL",
      "platforms": [
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 73,
      "coverage": 100,
      "summary": "ScreenToGif scores 73 out of 100 (grade C) on the screenshots and screen recording criteria. It meets 4 of 6 criteria: open source, no ads or data sales, saved locally by default and no account needed. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/screen-recording/screentogif/",
      "markdown": "https://privacyratings.com/screen-recording/screentogif/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/NickeManarin/ScreenToGif/blob/master/LICENSE.txt",
          "note": "Ms-PL."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/NickeManarin/ScreenToGif",
          "note": "No telemetry or analytics in the source code, but the website loads Microsoft Clarity analytics after the visitor accepts analytics cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/NickeManarin/ScreenToGif",
          "note": "Free open-source app with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_by_default": {
          "title": "Saved locally by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/NickeManarin/ScreenToGif",
          "note": "Recordings are edited and saved as local files. Uploading to online services is an optional export step."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/NickeManarin/ScreenToGif",
          "note": "No account is needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:31.346Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "shottr",
      "category": "screen-recording",
      "name": "Shottr",
      "description": "Screenshot tool for macOS with annotation, scrolling capture, on-device text recognition, pixel measurement and optional image upload.",
      "website": "https://shottr.cc",
      "license": null,
      "platforms": [
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Shottr scores 50 out of 100 (grade D) on the screenshots and screen recording criteria. It meets 3 of 6 criteria: no ads or data sales, saved locally by default and no account needed. It partly meets no trackers or telemetry. It does not meet open source and independent audit.",
      "url": "https://privacyratings.com/screen-recording/shottr/",
      "markdown": "https://privacyratings.com/screen-recording/shottr/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://shottr.cc/kb/privacy",
          "note": "No third-party analytics in the app. Anonymized diagnostic telemetry is sent to shottr.cc and can be turned off in Preferences."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://shottr.cc/kb/privacy",
          "note": "Funded by paid licenses, with no ads. The policy states purchase data is not shared with third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_by_default": {
          "title": "Saved locally by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://shottr.cc/kb/privacy",
          "note": "Screenshots are stored and processed locally unless you use the Upload feature."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://shottr.cc/kb/privacy",
          "note": "No account is needed. An email address is only collected for a license purchase or an upload token."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:31.737Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "simplescreenrecorder",
      "category": "screen-recording",
      "name": "SimpleScreenRecorder",
      "description": "Open-source screen recorder for Linux, built on FFmpeg, that records the screen, a window or a region with audio to video files and can also live stream.",
      "website": "https://www.maartenbaert.be/simplescreenrecorder/",
      "source": "https://github.com/MaartenBaert/ssr",
      "license": "GPL-3.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "SimpleScreenRecorder scores 85 out of 100 (grade B) on the screenshots and screen recording criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, saved locally by default and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/screen-recording/simplescreenrecorder/",
      "markdown": "https://privacyratings.com/screen-recording/simplescreenrecorder/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/MaartenBaert/ssr/blob/master/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/MaartenBaert/ssr",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.maartenbaert.be/simplescreenrecorder/",
          "note": "Free open-source app with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_by_default": {
          "title": "Saved locally by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.maartenbaert.be/simplescreenrecorder/",
          "note": "Recordings are saved to local files. Live streaming only happens when set up by the user."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.maartenbaert.be/simplescreenrecorder/",
          "note": "No account is needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:32.868Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "snagit",
      "category": "screen-recording",
      "name": "Snagit",
      "description": "Screenshot and screen recording app from TechSmith for Windows and macOS, with an image editor, annotations, scrolling capture and text recognition.",
      "website": "https://www.techsmith.com/snagit/",
      "license": null,
      "platforms": [
        "windows",
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Snagit scores 35 out of 100 (grade F) on the screenshots and screen recording criteria. It meets 1 of 6 criteria: saved locally by default. It partly meets no ads or data sales, independent audit and no account needed. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/screen-recording/snagit/",
      "markdown": "https://privacyratings.com/screen-recording/snagit/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.techsmith.com/trust-center/privacy-policy/",
          "note": "The privacy notice describes third-party analytics tools that collect usage data from the software and websites, and the website loads Google Tag Manager, Hotjar, Facebook and Bing tags."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.techsmith.com/trust-center/privacy-policy/",
          "note": "Funded by paid licenses and subscriptions with no ads in the app, but TechSmith lets third-party advertising companies track site and service use to tailor ads. It states it does not sell personal information."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.techsmith.com/trust-center/",
          "note": "TechSmith states SOC 2 compliance, but the report is only available through its Trust Center, not published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_by_default": {
          "title": "Saved locally by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.techsmith.com/hc/en-us/articles/18514512148365-Can-the-Snagit-Library-Be-Used-as-a-Storage-Location",
          "note": "Captures are saved to a local folder. Sharing to Screencast or other destinations is optional."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://support.techsmith.com/hc/en-us/articles/360021040791-Snagit-Enter-My-Software-Key",
          "note": "Subscriptions are activated by signing in to a TechSmith account. Licenses unlocked with a software key work without signing in."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:32.817Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "snipping-tool",
      "category": "screen-recording",
      "name": "Snipping Tool",
      "description": "Microsoft's screenshot and screen recording tool built into Windows. It captures the full screen, a window or a region, with basic markup and on-device text recognition.",
      "website": "https://apps.microsoft.com/detail/9mz95kl8mr0l",
      "license": null,
      "platforms": [
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "Snipping Tool scores 38 out of 100 (grade F) on the screenshots and screen recording criteria. It meets 3 of 6 criteria: no ads or data sales, saved locally by default and no account needed. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/screen-recording/snipping-tool/",
      "markdown": "https://privacyratings.com/screen-recording/snipping-tool/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/windows/privacy/configure-windows-diagnostic-data-in-your-organization",
          "note": "Required Windows diagnostic data is sent to Microsoft and can only be turned off on Enterprise, Education and Server editions."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement#mainadvertisingmodule",
          "note": "No ads in the app, which is included with Windows. Microsoft states it does not use personal files, photos or documents to target ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_by_default": {
          "title": "Saved locally by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.microsoft.com/en-us/windows/apps/use-snipping-tool-to-capture-screenshots",
          "note": "Snips are saved automatically to the local Screenshots folder."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://support.microsoft.com/en-us/windows/apps/use-snipping-tool-to-capture-screenshots",
          "note": "No account is needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:30.832Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "spectacle",
      "category": "screen-recording",
      "name": "Spectacle",
      "description": "KDE's screenshot and screen recording app for Linux. It captures the desktop, a monitor, a window or a region, with annotation tools, and saves, copies or shares the result.",
      "website": "https://apps.kde.org/spectacle/",
      "source": "https://invent.kde.org/plasma/spectacle",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "Spectacle scores 85 out of 100 (grade B) on the screenshots and screen recording criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, saved locally by default and no account needed. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/screen-recording/spectacle/",
      "markdown": "https://privacyratings.com/screen-recording/spectacle/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://invent.kde.org/plasma/spectacle/-/tree/master/LICENSES",
          "note": "GPL-2.0-or-later and LGPL, with some files under BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kde.org/privacypolicy/",
          "note": "No third-party trackers, and KDE app telemetry is opt-in. KDE websites use self-hosted Matomo with cookies disabled and IP addresses anonymized."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kde.org/donate/",
          "note": "Free open-source app with no ads, funded by donations to KDE e.V."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_by_default": {
          "title": "Saved locally by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kde.org/privacypolicy-apps/",
          "note": "Captures are saved locally. KDE apps only send data as a result of an explicit user action, such as sharing a capture."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://apps.kde.org/spectacle/",
          "note": "No account is needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:33.146Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "xbox-game-bar",
      "category": "screen-recording",
      "name": "Xbox Game Bar",
      "description": "Gaming overlay built into Windows for recording game clips and screenshots, with widgets for performance monitoring, audio control and Xbox social features.",
      "website": "https://apps.microsoft.com/detail/9nzkpstsnw4p",
      "license": null,
      "platforms": [
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Xbox Game Bar scores 35 out of 100 (grade F) on the screenshots and screen recording criteria. It meets 2 of 6 criteria: no ads or data sales and saved locally by default. It partly meets no account needed. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/screen-recording/xbox-game-bar/",
      "markdown": "https://privacyratings.com/screen-recording/xbox-game-bar/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/windows/privacy/configure-windows-diagnostic-data-in-your-organization",
          "note": "Required Windows diagnostic data is sent to Microsoft and can only be turned off on Enterprise, Education and Server editions."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement#mainadvertisingmodule",
          "note": "No ads in the overlay, which is included with Windows. Microsoft states it does not use personal files, photos or documents to target ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_by_default": {
          "title": "Saved locally by default",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.microsoft.com/en-us/accessibility/windows/use-a-screen-reader-to-record-your-screen-with-xbox-game-bar",
          "note": "Recordings and screenshots are saved to the local Captures folder under Videos."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://support.microsoft.com/en-us/accessibility/windows/use-a-screen-reader-to-record-your-screen-with-xbox-game-bar",
          "note": "Recording and screenshots work without signing in. Xbox social features such as friends and chat need a Microsoft account."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:31.251Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "adobe-acrobat-sign",
      "category": "e-signatures",
      "name": "Adobe Acrobat Sign",
      "description": "Adobe's electronic signature service for sending, signing and tracking documents, with integrations for Microsoft 365, Salesforce and other business apps.",
      "website": "https://www.adobe.com/acrobat/business/sign.html",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "Adobe Acrobat Sign scores 38 out of 100 (grade F) on the electronic signatures criteria. It meets 3 of 8 criteria: transparency report, tells users about requests and TLS configuration. It partly meets independent audit. It does not meet open source, no trackers or telemetry, no ads or data sales and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade D+.",
      "url": "https://privacyratings.com/e-signatures/adobe-acrobat-sign/",
      "markdown": "https://privacyratings.com/e-signatures/adobe-acrobat-sign/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.adobe.echosign/latest/",
          "note": "The Android app includes 6 trackers, including Facebook Analytics, Demdex and Google Firebase Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.adobe.com/privacy/policy.html",
          "note": "Funded by subscriptions, but Adobe discloses information about actions in its websites and apps to social media and advertising partners."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.adobe.com/trust/compliance/compliance-list.html",
          "note": "Adobe lists SOC 2 Type 2 among its compliance attestations. SOC 2 reports are shared with customers only under NDA."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.adobe.com/trust/transparency/government-requests.html",
          "note": "Publishes a yearly report with counts of government requests for user data."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.adobe.com/trust/transparency/government-requests.html",
          "note": "Adobe gives advance notice to users targeted by a legal request unless a nondisclosure order prohibits it, and notifies them when the order expires."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=secure.adobesign.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=secure.adobesign.com",
          "note": "Grade D+ (40/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "D+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:39:16.005Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "documenso",
      "category": "e-signatures",
      "name": "Documenso",
      "description": "Open-source electronic signature platform for sending and signing documents, available as a hosted service or for self-hosting.",
      "website": "https://documenso.com",
      "source": "https://github.com/documenso/documenso",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": true,
      "pick_reason": "Open-source document signing, hosted or self-hosted, as a replacement for DocuSign. The core is AGPL-3.0, and self-hosted instances keep signed documents on your own server.",
      "disclosure": null,
      "grade": "D",
      "score": 56,
      "coverage": 100,
      "summary": "Documenso scores 56 out of 100 (grade D) on the electronic signatures criteria. It meets 3 of 8 criteria: open source, no ads or data sales and TLS configuration. It partly meets no trackers or telemetry and security headers. It does not meet independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/e-signatures/documenso/",
      "markdown": "https://privacyratings.com/e-signatures/documenso/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/documenso/documenso/blob/main/LICENSE",
          "note": "All code is public. The core is AGPL-3.0 and enterprise features in packages/ee use the source-available Documenso Commercial License."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://documenso.com/privacy",
          "note": "The website uses Plausible analytics, and self-hosted instances send anonymous telemetry by default, which can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://documenso.com/privacy",
          "note": "Funded by paid plans. The privacy policy states that personal information is not sold or rented."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.documenso.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.documenso.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:55.066Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "docuseal",
      "category": "e-signatures",
      "name": "DocuSeal",
      "description": "Open-source platform for creating fillable PDF forms and collecting electronic signatures, available as a hosted service or for self-hosting.",
      "website": "https://www.docuseal.com",
      "source": "https://github.com/docusealco/docuseal",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 53,
      "coverage": 100,
      "summary": "DocuSeal scores 53 out of 100 (grade D) on the electronic signatures criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It partly meets open source, no trackers or telemetry, independent audit and security headers. It does not meet transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/e-signatures/docuseal/",
      "markdown": "https://privacyratings.com/e-signatures/docuseal/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/docusealco/docuseal/blob/master/LICENSE",
          "note": "The core is AGPL-3.0. Pro features in the hosted service and the paid self-hosted edition are closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.docuseal.com/privacy",
          "note": "No tracking or analytics cookies. The hosted service sends error logs to Rollbar."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.docuseal.com/privacy",
          "note": "Funded by paid plans. The privacy policy states that personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.docuseal.com/security",
          "note": "DocuSeal Cloud has a SOC 2 Type II audit. The report is only available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.docuseal.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.docuseal.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:55.175Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "docusign",
      "category": "e-signatures",
      "name": "Docusign",
      "description": "Electronic signature service for sending, signing and tracking agreements, part of Docusign's agreement management platform.",
      "website": "https://www.docusign.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "Docusign scores 38 out of 100 (grade F) on the electronic signatures criteria. It meets 2 of 8 criteria: tells users about requests and TLS configuration. It partly meets no ads or data sales, independent audit and transparency report. It does not meet open source, no trackers or telemetry and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B-.",
      "url": "https://privacyratings.com/e-signatures/docusign/",
      "markdown": "https://privacyratings.com/e-signatures/docusign/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.docusign.ink/latest/",
          "note": "The Android app includes 7 trackers, including AppsFlyer, Mixpanel and Google Firebase Analytics, and the website uses Google Tag Manager and Optimizely."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.docusign.com/privacy",
          "note": "Funded by subscriptions, but Docusign discloses personal information to advertising partners in ways that may count as a sale or targeted advertising under US state laws."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.docusign.com/trust/compliance/certifications",
          "note": "Docusign has SOC 1 Type II and SOC 2 Type II audits. The reports are only available through the Docusign Trust Portal."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.docusign.com/legal/law-enforcement",
          "note": "Publishes law enforcement guidelines. The annual transparency report is only given to data protection authorities on request."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.docusign.com/legal/law-enforcement",
          "note": "Docusign notifies customers whose data is requested unless a non-disclosure order or statute prohibits it."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=apps.docusign.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=apps.docusign.com",
          "note": "Grade B- (65/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:55.293Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "dropbox-sign",
      "category": "e-signatures",
      "name": "Dropbox Sign",
      "description": "Electronic signature service from Dropbox, formerly HelloSign, for sending and signing documents online, with an API for adding signatures to other apps.",
      "website": "https://sign.dropbox.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Dropbox Sign scores 50 out of 100 (grade D) on the electronic signatures criteria. It meets 4 of 8 criteria: transparency report, tells users about requests, TLS configuration and security headers. It partly meets no ads or data sales and independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A.",
      "url": "https://privacyratings.com/e-signatures/dropbox-sign/",
      "markdown": "https://privacyratings.com/e-signatures/dropbox-sign/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://sign.dropbox.com/about/privacy",
          "note": "Uses Google Analytics, Heap and Google advertising features such as remarketing."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://sign.dropbox.com/about/privacy",
          "note": "Funded by subscriptions. The privacy policy states that information is not sold, although the website uses remarketing to advertise Dropbox Sign."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://trust.dropbox.com/",
          "note": "Dropbox Sign has SOC 2 Type II and ISO 27001 audits. The reports are only available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://help.dropbox.com/transparency",
          "note": "Dropbox publishes counts of government requests for user data. The report does not list Dropbox Sign separately."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://help.dropbox.com/transparency",
          "note": "Dropbox states that it gives users notice of government requests for their information unless a non-disclosure order prohibits it."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.hellosign.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.hellosign.com",
          "note": "Grade A (95/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google DoubleClick",
            "host": "pubads.g.doubleclick.net",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:55.346Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "opensign",
      "category": "e-signatures",
      "name": "OpenSign",
      "description": "Open-source electronic signature platform for preparing, sending and signing PDF documents, offered as a hosted service or for self-hosting.",
      "website": "https://www.opensignlabs.com",
      "source": "https://github.com/OpenSignLabs/OpenSign",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "IN",
        "name": "India",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 44,
      "coverage": 100,
      "summary": "OpenSign scores 44 out of 100 (grade D) on the electronic signatures criteria. It meets 3 of 8 criteria: open source, no ads or data sales and TLS configuration. It does not meet no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in India: Not in the Five, Nine or Fourteen Eyes. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/e-signatures/opensign/",
      "markdown": "https://privacyratings.com/e-signatures/opensign/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/OpenSignLabs/OpenSign/blob/main/LICENSE",
          "note": "All code is public. Most is AGPL-3.0, and one server directory (apps/OpenSignServer/cloud/customRoute) uses a separate source-available license that is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.opensignlabs.com/",
          "note": "The website loads Google Tag Manager and Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.opensignlabs.com/plans-pricing",
          "note": "Funded by paid plans, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.opensignlabs.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.opensignlabs.com",
          "note": "Grade D- (25/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Sentry",
            "host": "browser.sentry-cdn.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:55.407Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "pandadoc",
      "category": "e-signatures",
      "name": "PandaDoc",
      "description": "Document automation and electronic signature service for proposals, quotes and contracts, run by PandaDoc, Inc. in San Francisco. Data can be stored in the US or the EU.",
      "website": "https://www.pandadoc.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "PandaDoc scores 25 out of 100 (grade F) on the electronic signatures criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales and independent audit. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B-.",
      "url": "https://privacyratings.com/e-signatures/pandadoc/",
      "markdown": "https://privacyratings.com/e-signatures/pandadoc/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.pandadoc.com/privacy-notice/",
          "note": "The privacy notice names Google Analytics and describes behavior-based advertising by third parties that collect information about website use."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.pandadoc.com/privacy-notice/",
          "note": "Funded by subscriptions, and personal information is not sold or shared for marketing without consent, but third parties collect website data for behavior-based advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.pandadoc.com/security/",
          "note": "PandaDoc has a SOC 2 Type II report, available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.pandadoc.com/privacy-notice/",
          "note": "No transparency report is published. The privacy notice only says information may be disclosed in response to subpoenas, warrants or court orders."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.pandadoc.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.pandadoc.com",
          "note": "Grade B- (65/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:31:56.956Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "signnow",
      "category": "e-signatures",
      "name": "SignNow",
      "description": "Electronic signature service from airSlate, Inc. in the United States, for sending, signing and tracking documents, with an API for other apps.",
      "website": "https://www.signnow.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "SignNow scores 25 out of 100 (grade F) on the electronic signatures criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales and independent audit. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/e-signatures/signnow/",
      "markdown": "https://privacyratings.com/e-signatures/signnow/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://legal.signnow.com/privacy-notice",
          "note": "The privacy notice describes sharing personal information with advertising partners for cross-context behavioral advertising, and the website loads Google Tag Manager and Intercom."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://legal.signnow.com/privacy-notice",
          "note": "Funded by subscriptions, and personal information is not sold, but it is shared with third-party advertising partners to target advertising, with an opt-out."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.signnow.com/security",
          "note": "SignNow has a SOC 2 Type II report, available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://legal.signnow.com/privacy-notice",
          "note": "No transparency report is published. The privacy notice only says information may be shared to respond to court orders, subpoenas or search warrants."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.signnow.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.signnow.com",
          "note": "Grade F (10/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Intercom",
            "host": "widget.intercom.io",
            "effect": "none"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:31:47.817Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "signwell",
      "category": "e-signatures",
      "name": "SignWell",
      "description": "Electronic signature service from Docsketch, LLC in the United States, for sending and signing documents, with templates and an API.",
      "website": "https://www.signwell.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "SignWell scores 25 out of 100 (grade F) on the electronic signatures criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales and independent audit. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/e-signatures/signwell/",
      "markdown": "https://privacyratings.com/e-signatures/signwell/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.signwell.com/privacy/",
          "note": "The privacy policy names Google Analytics, Amplitude and Google and Facebook remarketing, and the website loads Hotjar and HubSpot."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.signwell.com/privacy/",
          "note": "Funded by paid plans with no ads in the product, but conversion data and hashed identifiers are shared with advertising platforms for remarketing and custom audiences."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.signwell.com/security/",
          "note": "States SOC 2 Type II compliance. The report is available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.signwell.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.signwell.com",
          "note": "Grade F (10/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Crazy Egg",
            "host": "script.crazyegg.com",
            "effect": "no"
          },
          {
            "name": "Fathom",
            "host": "cdn.usefathom.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Hotjar",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          },
          {
            "name": "Meta Pixel",
            "host": "www.facebook.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:38:14.091Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "youtrust",
      "category": "e-signatures",
      "name": "Youtrust",
      "description": "Electronic signature and identity verification service from Youtrust SAS in Caen, France, formerly Yousign. The platform is hosted in France.",
      "website": "https://youtrust.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 22,
      "coverage": 100,
      "summary": "Youtrust scores 22 out of 100 (grade F) on the electronic signatures criteria. It partly meets no ads or data sales, independent audit, TLS configuration and security headers. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/e-signatures/youtrust/",
      "markdown": "https://privacyratings.com/e-signatures/youtrust/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://youtrust.com/privacy",
          "note": "The privacy policy says cookies and trackers on the website and platform collect data for visitor statistics and targeted advertising campaigns."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://youtrust.com/privacy",
          "note": "Funded by subscriptions with no ads in the product, but visitor data is used for targeted advertising campaigns for Youtrust."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://youtrust.com/security",
          "note": "Holds eIDAS certifications and has annual technical audits by independent experts, but the audit reports are not published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://youtrust.com/privacy",
          "note": "No transparency report is published. The privacy policy only lists handling requests from authorities as a purpose."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=yousign.app&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=yousign.app",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:31:57.081Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "zoho-sign",
      "category": "e-signatures",
      "name": "Zoho Sign",
      "description": "Electronic signature service from Zoho for sending, signing and tracking documents, with integrations into other Zoho apps.",
      "website": "https://www.zoho.com/sign/",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "IN",
        "name": "India",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 41,
      "coverage": 100,
      "summary": "Zoho Sign scores 41 out of 100 (grade D) on the electronic signatures criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It partly meets no trackers or telemetry and independent audit. It does not meet open source, transparency report, tells users about requests and security headers. It is based in India: Not in the Five, Nine or Fourteen Eyes. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B-.",
      "url": "https://privacyratings.com/e-signatures/zoho-sign/",
      "markdown": "https://privacyratings.com/e-signatures/zoho-sign/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.zoho.com/privacy.html",
          "note": "Zoho states it does not use third-party tracking on its websites, but it uses first-party cookies to track visitor activity."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.zoho.com/privacy.html",
          "note": "Funded by subscriptions. The privacy policy states that Zoho does not sell personal information or earn money from advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.zoho.com/compliance.html",
          "note": "Zoho has SOC 2 Type 2 audits by an independent firm. The reports are available to customers, not publicly."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=sign.zoho.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=sign.zoho.com",
          "note": "Grade B- (65/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:31:57.126Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cognito-forms",
      "category": "forms",
      "name": "Cognito Forms",
      "description": "Online form builder with calculations, payments, workflows and document generation, run by Cognito Forms in the United States.",
      "website": "https://www.cognitoforms.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Cognito Forms scores 25 out of 100 (grade F) on the forms and surveys criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales and independent audit. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/forms/cognito-forms/",
      "markdown": "https://privacyratings.com/forms/cognito-forms/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.cognitoforms.com/legal/privacy",
          "note": "The privacy policy states that the website uses Google Analytics. Public and embedded forms do not include it unless the form owner connects their own account."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.cognitoforms.com/legal/privacy",
          "note": "Funded by paid plans, and the privacy policy states that data is not sold or mined. The website loads the Microsoft Advertising tag."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.cognitoforms.com/support/285/faq/how-do-i-get-a-copy-of-the-cognito-forms-soc-2-audit-report",
          "note": "Has a SOC 2 Type 2 report, available to paid and prospective Enterprise customers under a non-disclosure agreement."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.cognitoforms.com/legal/privacy",
          "note": "No transparency report is published. The privacy policy only says data may be disclosed in response to lawful requests by public authorities."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.cognitoforms.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.cognitoforms.com",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "www.trustpilot.com",
            "effect": "none"
          },
          {
            "name": "VWO",
            "host": "dev.visualwebsiteoptimizer.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:31:57.190Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fillout",
      "category": "forms",
      "name": "Fillout",
      "description": "Online form, survey and quiz builder from Zite, with scheduling, payments and PDF generation. Form responses can be stored in the EU on request.",
      "website": "https://www.fillout.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 34,
      "coverage": 100,
      "summary": "Fillout scores 34 out of 100 (grade F) on the forms and surveys criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It partly meets independent audit and security headers. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/forms/fillout/",
      "markdown": "https://privacyratings.com/forms/fillout/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.fillout.com/help/subprocessors",
          "note": "The subprocessor list includes Amplitude for analytics, Segment as an event pipeline, and Sentry and Datadog for monitoring."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.fillout.com/privacy",
          "note": "Funded by paid plans. The privacy policy states that data is not sold and users are not tracked across other websites for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.fillout.com/help/security",
          "note": "States SOC 2 Type 2 compliance, but no report is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.fillout.com/privacy",
          "note": "No transparency report is published. The privacy policy only says information may be shared with law enforcement to comply with legal process."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=build.fillout.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=build.fillout.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:31:57.292Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "formbricks",
      "category": "forms",
      "name": "Formbricks",
      "description": "Open-source survey and form platform for link, website and in-app surveys, from Formbricks GmbH in Germany. Available as a hosted cloud service or self-hosted with Docker.",
      "website": "https://formbricks.com",
      "source": "https://github.com/formbricks/formbricks",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": true,
      "pick_reason": "Open-source surveys and forms for links, websites and apps, as a replacement for Typeform, SurveyMonkey and Google Forms. Made by a company in Germany, with a hosted service or self-hosting with Docker.",
      "disclosure": null,
      "grade": "D",
      "score": 53,
      "coverage": 100,
      "summary": "Formbricks scores 53 out of 100 (grade D) on the forms and surveys criteria. It meets 3 of 8 criteria: open source, no ads or data sales and TLS configuration. It partly meets independent audit and security headers. It does not meet no trackers or telemetry, transparency report and tells users about requests. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/forms/formbricks/",
      "markdown": "https://privacyratings.com/forms/formbricks/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/formbricks/formbricks/main/LICENSE",
          "note": "All code is public. The core is AGPL-3.0, and enterprise features in the ee directory of the same repository use a source-available commercial license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://formbricks.com/privacy-policy",
          "note": "The cloud service uses PostHog for product analytics and Sentry for error tracking. Self-hosted instances send telemetry unless it is disabled."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://formbricks.com/privacy-policy",
          "note": "Funded by paid plans and enterprise licenses. The privacy policy states personal data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://formbricks.com/soc2",
          "note": "Reports SOC 2 Type II compliance and annual penetration tests. The reports are only shared through its Trust Center."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.formbricks.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.formbricks.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "PostHog",
            "host": "eu.i.posthog.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:55.472Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "framaforms",
      "category": "forms",
      "name": "Framaforms",
      "description": "Free online form and survey service run by the French nonprofit Framasoft on the open-source Yakforms software. Forms expire after six months by default.",
      "website": "https://framaforms.org",
      "source": "https://framagit.org/yakforms/yakforms",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 53,
      "coverage": 100,
      "summary": "Framaforms scores 53 out of 100 (grade D) on the forms and surveys criteria. It meets 3 of 8 criteria: open source, no ads or data sales and TLS configuration. It partly meets no trackers or telemetry. It does not meet independent audit, transparency report, tells users about requests and security headers. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/forms/framaforms/",
      "markdown": "https://privacyratings.com/forms/framaforms/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://framagit.org/yakforms/yakforms/-/raw/master/LICENSE.txt",
          "note": "Runs Yakforms, which is licensed under GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://framasoft.org/en/legals/",
          "note": "Framasoft measures traffic with its own Matomo instance, which sets a cookie. Data is not shared with third parties."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://framasoft.org/fr/cgu/",
          "note": "Free service funded by donations to Framasoft. The terms state personal data is not sold or passed on."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=framaforms.org&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=framaforms.org",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:20:55.703Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "google-forms",
      "category": "forms",
      "name": "Google Forms",
      "description": "Google's online form and survey builder, part of Google Workspace. Responses are stored in the creator's Google account and can be exported to Google Sheets.",
      "website": "https://workspace.google.com/products/forms/",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "Google Forms scores 38 out of 100 (grade F) on the forms and surveys criteria. It meets 3 of 8 criteria: transparency report, tells users about requests and security headers. It partly meets independent audit and TLS configuration. It does not meet open source, no trackers or telemetry and no ads or data sales. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/forms/google-forms/",
      "markdown": "https://privacyratings.com/forms/google-forms/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Google collects activity data across its services and uses it for analytics and personalized ads."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Free for personal accounts and funded by Google's advertising business, which uses activity data across services."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cloud.google.com/security/compliance/soc-3",
          "note": "Google Workspace, which includes Forms, has third-party SOC 2 audits. Only the SOC 3 summary report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://transparencyreport.google.com/user-data/overview",
          "note": "Publishes counts of government requests for user data and how often data is disclosed, updated twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://policies.google.com/terms/information-requests",
          "note": "Google emails the user before disclosing information unless legally prohibited or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=docs.google.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=docs.google.com",
          "note": "Grade A+ (110/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:55.558Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "heyform",
      "category": "forms",
      "name": "HeyForm",
      "description": "Open-source conversational form builder from EarlyBird, Inc., available as a hosted service or self-hosted.",
      "website": "https://heyform.net",
      "source": "https://github.com/heyform/heyform",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "HeyForm scores 25 out of 100 (grade F) on the forms and surveys criteria. It meets 1 of 8 criteria: open source. It partly meets TLS configuration. It does not meet no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/forms/heyform/",
      "markdown": "https://privacyratings.com/forms/heyform/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/heyform/heyform/main/LICENSE",
          "note": "Licensed under AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://docs.heyform.net/legal/privacy",
          "note": "The privacy policy states cookies are used for advertising and traffic analysis, with data shared with social media, advertising and analytics partners."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://docs.heyform.net/legal/privacy",
          "note": "Funded by paid plans, but site usage data and email addresses are shared with advertising partners, and purchased marketing data is used for tailored advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=my.heyform.net&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=my.heyform.net",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:55.617Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "jotform",
      "category": "forms",
      "name": "Jotform",
      "description": "Online form builder from Jotform Inc. in San Francisco, with templates, payments, approvals and PDF tools. Form data can be stored on EU servers.",
      "website": "https://www.jotform.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 34,
      "coverage": 100,
      "summary": "Jotform scores 34 out of 100 (grade F) on the forms and surveys criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales, independent audit, transparency report and security headers. It does not meet open source, no trackers or telemetry and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/forms/jotform/",
      "markdown": "https://privacyratings.com/forms/jotform/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.jotform.com/privacy/",
          "note": "The privacy policy describes web traffic analytics tools and advertising networks that use cookies and page tags, and the website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.jotform.com/privacy/",
          "note": "Funded by paid plans, and the privacy policy states that personal information and form data are not sold. Advertising networks use cookies to show Jotform ads on other websites."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.jotform.com/security/",
          "note": "States a SOC 2 environment for Enterprise customers and periodic penetration tests, but no report is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.jotform.com/privacy/",
          "note": "The privacy policy describes how legal and law enforcement requests are reviewed and what data may be produced, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.jotform.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.jotform.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:31:57.340Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "limesurvey",
      "category": "forms",
      "name": "LimeSurvey",
      "description": "Open-source survey software from LimeSurvey GmbH in Hamburg. It can be self-hosted for free or used as the paid LimeSurvey Cloud service hosted in Germany.",
      "website": "https://www.limesurvey.org",
      "source": "https://github.com/LimeSurvey/LimeSurvey",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 47,
      "coverage": 100,
      "summary": "LimeSurvey scores 47 out of 100 (grade D) on the forms and surveys criteria. It meets 3 of 8 criteria: open source, no ads or data sales and TLS configuration. It partly meets security headers. It does not meet no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/forms/limesurvey/",
      "markdown": "https://privacyratings.com/forms/limesurvey/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/LimeSurvey/LimeSurvey/master/LICENSE",
          "note": "Licensed under GPL-2.0 or later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.limesurvey.org/privacy-notice",
          "note": "The website uses Google Analytics, Google Tag Manager and Zoho PageSense."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.limesurvey.org/pricing",
          "note": "Funded by LimeSurvey Cloud subscriptions and services. The privacy notice states no external marketing providers are involved."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=account.limesurvey.org&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=account.limesurvey.org",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:55.705Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "microsoft-forms",
      "category": "forms",
      "name": "Microsoft Forms",
      "description": "Microsoft's online form, survey and quiz builder, included with Microsoft 365 and free with a Microsoft account. Responses can be exported to Excel.",
      "website": "https://www.microsoft.com/en-us/microsoft-365/online-surveys-polls-quizzes",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "Microsoft Forms scores 38 out of 100 (grade F) on the forms and surveys criteria. It meets 3 of 8 criteria: transparency report, tells users about requests and TLS configuration. It partly meets independent audit. It does not meet open source, no trackers or telemetry, no ads or data sales and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B-.",
      "url": "https://privacyratings.com/forms/microsoft-forms/",
      "markdown": "https://privacyratings.com/forms/microsoft-forms/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "Microsoft collects usage and diagnostic data and uses data about users for personalized advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement#mainadvertisingmodule",
          "note": "Forms shows no ads, but Microsoft uses data about users of its services for personalized advertising. Document contents are excluded."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2",
          "note": "Forms is in scope of Microsoft's SOC 2 Type 2 audits. The full reports are only available through the Service Trust Portal after sign-in."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Publishes counts of government requests for customer data twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Microsoft gives prior notice to users whose data is requested, except where prohibited by law or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=forms.cloud.microsoft&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=forms.cloud.microsoft",
          "note": "Grade B- (65/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:55.764Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "nextcloud-forms",
      "category": "forms",
      "name": "Nextcloud Forms",
      "description": "Survey and questionnaire app for self-hosted Nextcloud servers. Responses stay on the server running Nextcloud.",
      "website": "https://apps.nextcloud.com/apps/forms",
      "source": "https://github.com/nextcloud/forms",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Nextcloud Forms scores 80 out of 100 (grade B) on the forms and surveys criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/forms/nextcloud-forms/",
      "markdown": "https://privacyratings.com/forms/nextcloud-forms/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/nextcloud/forms/main/LICENSE",
          "note": "Licensed under AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nextcloud/forms",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://nextcloud.com/pricing/",
          "note": "Free app funded by Nextcloud GmbH enterprise subscriptions. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:47.905Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "opnform",
      "category": "forms",
      "name": "OpnForm",
      "description": "Open-source form builder with logic, file uploads and integrations, available as a hosted service or self-hosted.",
      "website": "https://opnform.com",
      "source": "https://github.com/OpnForm/OpnForm",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "OpnForm scores 38 out of 100 (grade F) on the forms and surveys criteria. It meets 2 of 8 criteria: open source and TLS configuration. It partly meets no ads or data sales. It does not meet no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/forms/opnform/",
      "markdown": "https://privacyratings.com/forms/opnform/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/OpnForm/OpnForm/blob/main/LICENSE",
          "note": "All code is public. Most is AGPL-3.0, and enterprise features in api/app/Enterprise use the source-available OpnForm Enterprise Edition license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://opnform.com/privacy-policy",
          "note": "The privacy policy describes cookies, beacons and scripts used to track activity, and the website is configured with Amplitude, Microsoft Clarity, Crisp and Sentry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://opnform.com/privacy-policy",
          "note": "Funded by paid plans, and the privacy policy states that personal information is not sold. Email addresses may be used for custom audience advertising on sites like Facebook."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://opnform.com/privacy-policy",
          "note": "No transparency report is published. The privacy policy only says data may be disclosed when required by law or public authorities."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=opnform.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=opnform.com",
          "note": "Grade C (55/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "www.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:31:57.389Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "paperform",
      "category": "forms",
      "name": "Paperform",
      "description": "Online form builder from Paperform Pty Ltd in Australia that combines forms with document-style pages, payments and bookings.",
      "website": "https://paperform.co",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "AU",
        "name": "Australia",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Paperform scores 25 out of 100 (grade F) on the forms and surveys criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales and independent audit. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and security headers. It is based in Australia: Five Eyes member; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/forms/paperform/",
      "markdown": "https://privacyratings.com/forms/paperform/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://paperform.co/privacy/",
          "note": "The privacy policy describes cookies, pixel tags and third parties that provide advertising, and the website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://paperform.co/privacy/",
          "note": "Funded by paid plans with no ads in forms, but the privacy policy describes remarketing through Google and Facebook and processing of personal data for targeted advertising, with an opt-out."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://paperform.co/blog/paperform-has-achieved-soc-2-compliance/",
          "note": "Completed a SOC 2 audit. The report is shared with customers, not published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://paperform.co/privacy/",
          "note": "No transparency report is published. The privacy policy only says data may be disclosed in response to legal requirements or law enforcement requests."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=paperform.co&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=paperform.co",
          "note": "Grade D- (25/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "G2",
            "host": "tracking.g2crowd.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Intercom",
            "host": "widget.intercom.io",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:31:57.482Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "qualtrics",
      "category": "forms",
      "name": "Qualtrics",
      "description": "Survey and experience management platform for research, customer and employee feedback, run by Qualtrics LLC in the United States.",
      "website": "https://www.qualtrics.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 28,
      "coverage": 100,
      "summary": "Qualtrics scores 28 out of 100 (grade F) on the forms and surveys criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales, independent audit and security headers. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/forms/qualtrics/",
      "markdown": "https://privacyratings.com/forms/qualtrics/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.qualtrics.com/privacy-statement/",
          "note": "The privacy statement says third-party advertising companies collect information on the website through cookies, and the website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.qualtrics.com/privacy-statement/",
          "note": "Funded by subscriptions, and the privacy statement says personal information is not sold. It is shared with advertising partners, such as Google, that show targeted Qualtrics ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.qualtrics.com/platform/security/",
          "note": "States SOC 2 Type 2, ISO 27001 and HITRUST certifications and FedRAMP High authorization, but the reports are not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.qualtrics.com/privacy-statement/",
          "note": "No transparency report is published. The privacy statement only lists law enforcement and government authorities as possible recipients."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=login.qualtrics.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=login.qualtrics.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          },
          {
            "name": "VWO",
            "host": "dev.visualwebsiteoptimizer.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:32:52.839Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "surveymonkey",
      "category": "forms",
      "name": "SurveyMonkey",
      "description": "Online survey platform from SurveyMonkey Inc. in the US for building surveys and forms and analyzing responses.",
      "website": "https://www.surveymonkey.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 22,
      "coverage": 100,
      "summary": "SurveyMonkey scores 22 out of 100 (grade F) on the forms and surveys criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets independent audit and security headers. It does not meet open source, no trackers or telemetry, no ads or data sales, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/forms/surveymonkey/",
      "markdown": "https://privacyratings.com/forms/surveymonkey/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.surveymonkey.com/mp/legal/privacy/",
          "note": "The privacy notice describes cookies and tracking by advertising and analytics partners across websites and devices."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.surveymonkey.com/mp/legal/privacy/",
          "note": "The standard survey end page can show advertising, and data is used with partners to tailor ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.surveymonkey.com/learn/trust-center/",
          "note": "Holds SOC 2 Type II and ISO 27001 certifications from third-party audits. The reports are not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.surveymonkey.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.surveymonkey.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:55.825Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "tally",
      "category": "forms",
      "name": "Tally",
      "description": "Online form builder operated by Tally BV in Belgium, with forms created in a document-style editor. Form data is hosted in the EU.",
      "website": "https://tally.so",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "BE",
        "name": "Belgium",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Tally scores 25 out of 100 (grade F) on the forms and surveys criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in Belgium: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/forms/tally/",
      "markdown": "https://privacyratings.com/forms/tally/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://tally.so/help/gdpr",
          "note": "The subprocessor list includes Mixpanel and Tinybird for analytics and Sentry for error monitoring."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tally.so/help/privacy-policy",
          "note": "Funded by paid plans. The privacy notice states personal data is not sold or rented to third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=tally.so&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=tally.so",
          "note": "Grade C (55/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:55.889Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "typeform",
      "category": "forms",
      "name": "Typeform",
      "description": "Online form and survey builder that presents questions one at a time, run by Typeform SL in Barcelona.",
      "website": "https://www.typeform.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "ES",
        "name": "Spain",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 28,
      "coverage": 100,
      "summary": "Typeform scores 28 out of 100 (grade F) on the forms and surveys criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales, transparency report and security headers. It does not meet open source, no trackers or telemetry, independent audit and tells users about requests. It is based in Spain: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/forms/typeform/",
      "markdown": "https://privacyratings.com/forms/typeform/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.typeform.com/legal/privacy-policy",
          "note": "The privacy policy describes profiling, analytics and audience building through cookies, shared with third-party analytics providers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.typeform.com/legal/ccpa-notice",
          "note": "Funded by subscriptions with no ads in forms. Third-party partners may collect website data through cookies for personalized advertising, with an opt-out."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cdn.prod.website-files.com/66ffe2174aa8e8d5661c2708/67acb3af2f60d1b3864acedc_Typeform%20-%20Transparency%20Report%202024.pdf",
          "note": "Publishes a content moderation report with counts of authority orders about content, but no counts of requests for user data."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=admin.typeform.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=admin.typeform.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          },
          {
            "name": "PartnerStack",
            "host": "js.partnerstack.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:55.950Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "zoho-forms",
      "category": "forms",
      "name": "Zoho Forms",
      "description": "Online form builder from Zoho with approvals, payments, offline mobile apps and integrations with other Zoho apps.",
      "website": "https://www.zoho.com/forms/",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "IN",
        "name": "India",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 41,
      "coverage": 100,
      "summary": "Zoho Forms scores 41 out of 100 (grade D) on the forms and surveys criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It partly meets no trackers or telemetry and independent audit. It does not meet open source, transparency report, tells users about requests and security headers. It is based in India: Not in the Five, Nine or Fourteen Eyes. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/forms/zoho-forms/",
      "markdown": "https://privacyratings.com/forms/zoho-forms/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.zoho.com/privacy.html",
          "note": "Zoho states it does not use third-party tracking on its websites, but it uses first-party cookies to track visitor activity."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.zoho.com/privacy.html",
          "note": "Funded by subscriptions. The privacy policy states that Zoho does not sell personal information or earn money from advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.zoho.com/compliance.html",
          "note": "Zoho has SOC 2 Type 2 audits by an independent firm. The reports are available to customers, not publicly."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=forms.zoho.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=forms.zoho.com",
          "note": "Grade F (10/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:31:58.206Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "apple-books",
      "category": "ebook-readers",
      "name": "Apple Books",
      "description": "Apple's e-book and audiobook store and reading app for iPhone, iPad and Mac. Purchases and reading progress sync through the user's Apple Account.",
      "website": "https://www.apple.com/apple-books/",
      "license": null,
      "platforms": [
        "macos",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Apple Books scores 25 out of 100 (grade F) on the ebook readers criteria. It partly meets no trackers or telemetry and no ads or data sales. It does not meet open source and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/ebook-readers/apple-books/",
      "markdown": "https://privacyratings.com/ebook-readers/apple-books/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/apple-books/",
          "note": "No third-party trackers, but Apple collects reading and usage data by default under random identifiers not linked to the Apple Account."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/apple-books/",
          "note": "The app shows no ads, but store purchases and downloads can be used for Apple's ads in the App Store, Apple News and Stocks if personalized ads are on."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:47.832Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "calibre",
      "category": "ebook-readers",
      "name": "Calibre",
      "description": "Free and open-source e-book manager for organizing, converting and reading e-books, with a built-in viewer, editor and device syncing.",
      "website": "https://calibre-ebook.com",
      "source": "https://github.com/kovidgoyal/calibre",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Calibre scores 50 out of 100 (grade D) on the ebook readers criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/ebook-readers/calibre/",
      "markdown": "https://privacyratings.com/ebook-readers/calibre/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/kovidgoyal/calibre/master/LICENSE",
          "note": "Licensed under GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://calibre-ebook.com",
          "note": "The website loads Google Analytics. The desktop app has no analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://calibre-ebook.com/donate",
          "note": "Free software funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:48.026Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "foliate",
      "category": "ebook-readers",
      "name": "Foliate",
      "description": "Open-source e-book reader for Linux built with GTK, supporting EPUB, MOBI, AZW3, FB2, CBZ and PDF.",
      "website": "https://johnfactotum.github.io/foliate/",
      "source": "https://github.com/johnfactotum/foliate",
      "license": "GPL-3.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Foliate scores 80 out of 100 (grade B) on the ebook readers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/ebook-readers/foliate/",
      "markdown": "https://privacyratings.com/ebook-readers/foliate/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/johnfactotum/foliate/gtk4/COPYING",
          "note": "Licensed under GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/johnfactotum/foliate",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://johnfactotum.github.io/foliate/",
          "note": "Free volunteer-developed software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:47.935Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "google-play-books",
      "category": "ebook-readers",
      "name": "Google Play Books",
      "description": "Google's e-book and audiobook store and reading app. Purchases, notes and reading progress sync through the user's Google account.",
      "website": "https://play.google.com/store/books",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Google Play Books scores 0 out of 100 (grade F) on the ebook readers criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/ebook-readers/google-play-books/",
      "markdown": "https://privacyratings.com/ebook-readers/google-play-books/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "The Exodus report finds no third-party trackers, but Google collects activity data across its services and uses it for analytics and personalized ads."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Google uses activity data across its services, including purchases, for personalized advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:47.905Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "kindle",
      "category": "ebook-readers",
      "name": "Kindle",
      "description": "Amazon's e-book store, reading apps and E Ink e-readers. Books bought from Amazon use DRM and sync reading progress and notes through the user's Amazon account.",
      "website": "https://www.amazon.com/kindle-dbs/fd/kcp",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Kindle scores 0 out of 100 (grade F) on the ebook readers criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/ebook-readers/kindle/",
      "markdown": "https://privacyratings.com/ebook-readers/kindle/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.amazon.kindle/latest/",
          "note": "The Android app contains Amazon Advertisement, Amazon Analytics, Bugsnag and Google Crashlytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.amazon.kindle/latest/",
          "note": "The Android app includes Amazon's advertising SDK, and Kindle e-readers sold with Special Offers show ads on the lock screen."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:00.109Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kobo",
      "category": "ebook-readers",
      "name": "Kobo",
      "description": "E-book and audiobook store, reading apps and E Ink e-readers from Rakuten Kobo Inc. in Toronto. Supports EPUB and syncs reading progress through a Kobo account.",
      "website": "https://www.kobo.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Kobo scores 0 out of 100 (grade F) on the ebook readers criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in Canada: Five Eyes member.",
      "url": "https://privacyratings.com/ebook-readers/kobo/",
      "markdown": "https://privacyratings.com/ebook-readers/kobo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.kobobooks.android/latest/",
          "note": "The Android app contains Google Firebase Analytics and Facebook SDKs."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://authorize.kobo.com/terms/privacypolicy",
          "note": "The privacy policy describes personalized advertising and sharing email addresses and site activity with third parties for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:48.047Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "koreader",
      "category": "ebook-readers",
      "name": "KOReader",
      "description": "Open-source document and e-book reader for E Ink devices such as Kindle, Kobo and PocketBook, also available for Android and Linux. Supports EPUB, PDF, DjVu, CBZ and more.",
      "website": "https://koreader.rocks",
      "source": "https://github.com/koreader/koreader",
      "license": "AGPL-3.0",
      "platforms": [
        "android",
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "KOReader scores 80 out of 100 (grade B) on the ebook readers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/ebook-readers/koreader/",
      "markdown": "https://privacyratings.com/ebook-readers/koreader/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/koreader/koreader/master/COPYING",
          "note": "Licensed under AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.koreader.launcher/latest/",
          "note": "The Exodus report finds no trackers in the Android app, and the source code contains no analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/koreader/koreader/master/README.md",
          "note": "Free volunteer-developed software funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:48.483Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "librera-reader",
      "category": "ebook-readers",
      "name": "Librera Reader",
      "description": "Open-source Android reader for EPUB, PDF, DjVu, MOBI, FB2 and other formats. A free ad-supported version, a paid PRO version and an F-Droid build are available.",
      "website": "https://librera.mobi",
      "source": "https://github.com/foobnix/LibreraReader",
      "license": null,
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Librera Reader scores 30 out of 100 (grade F) on the ebook readers criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/ebook-readers/librera-reader/",
      "markdown": "https://privacyratings.com/ebook-readers/librera-reader/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/foobnix/LibreraReader/master/LICENSE.txt",
          "note": "Licensed under GPL-3.0 or later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.foobnix.pdf.reader/latest/",
          "note": "The free Google Play version contains Google AdMob and Firebase Analytics. The F-Droid build has no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.foobnix.pdf.reader/latest/",
          "note": "The free Google Play version shows ads through Google AdMob. The paid PRO and F-Droid versions have no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:48.401Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "readest",
      "category": "ebook-readers",
      "name": "Readest",
      "description": "Open-source e-book reader for desktop, mobile and web, with optional cloud sync of books, progress and notes.",
      "website": "https://readest.com",
      "source": "https://github.com/readest/readest",
      "license": "AGPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Readest scores 50 out of 100 (grade D) on the ebook readers criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/ebook-readers/readest/",
      "markdown": "https://privacyratings.com/ebook-readers/readest/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/readest/readest/main/LICENSE",
          "note": "Licensed under AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.bilingify.readest/latest/",
          "note": "The Android app includes Sentry crash reporting, usage analytics are on until turned off, and the website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://readest.com/privacy-policy",
          "note": "No ads. The privacy policy states data is not sold to third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:48.450Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "thorium-reader",
      "category": "ebook-readers",
      "name": "Thorium Reader",
      "description": "Open-source desktop reader for EPUB, PDF, audiobooks and comics from EDRLab, a French nonprofit. It supports LCP-protected library loans, read aloud and screen readers.",
      "website": "https://www.edrlab.org/software/thorium-reader/",
      "source": "https://github.com/edrlab/thorium-reader",
      "license": "BSD-3-Clause",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Thorium Reader scores 50 out of 100 (grade D) on the ebook readers criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/ebook-readers/thorium-reader/",
      "markdown": "https://privacyratings.com/ebook-readers/thorium-reader/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/edrlab/thorium-reader/develop/LICENSE",
          "note": "Licensed under BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://raw.githubusercontent.com/edrlab/thorium-reader/develop/src/main/analytics/measurementProtocol.ts",
          "note": "The app sends Google Analytics telemetry unless disabled in settings, and the website loads Google Tag Manager and Matomo Cloud."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.edrlab.org/about/",
          "note": "Free software developed by EDRLab, a nonprofit association funded by its members. No ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Matomo Cloud",
            "host": "cdn.matomo.cloud",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:49.291Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "apertium",
      "category": "translation",
      "name": "Apertium",
      "description": "Free and open-source rule-based machine translation platform, focused on related and lesser-resourced languages. Usable on apertium.org or installed locally for offline translation.",
      "website": "https://www.apertium.org",
      "source": "https://github.com/apertium/apertium",
      "license": "GPL-2.0",
      "platforms": [
        "web",
        "linux",
        "windows",
        "macos",
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 77,
      "coverage": 100,
      "summary": "Apertium scores 77 out of 100 (grade B) on the translation criteria. It meets 4 of 6 criteria: open source, no ads or data sales, works offline and text not kept. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/translation/apertium/",
      "markdown": "https://privacyratings.com/translation/apertium/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/apertium/apertium/main/COPYING",
          "note": "Licensed under GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://raw.githubusercontent.com/apertium/apertium-html-tools/master/src/App.tsx",
          "note": "No third-party trackers. The apertium.org web interface records page views with a self-hosted Matomo instance."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://wiki.apertium.org/wiki/Main_Page",
          "note": "Volunteer-run open-source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://wiki.apertium.org/wiki/Installation",
          "note": "Can be installed on desktop, Android or your own server to translate offline."
        },
        "no_retention": {
          "title": "Text not kept",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://wiki.apertium.org/wiki/Installation",
          "note": "Rule-based translation with no model training on user text. Local installs keep text on the device."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:48.961Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "deepl",
      "category": "translation",
      "name": "DeepL",
      "description": "Machine translation service from DeepL SE in Cologne, with a free web translator, paid DeepL Pro plans, an API, and desktop and mobile apps.",
      "website": "https://www.deepl.com",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 31,
      "coverage": 100,
      "summary": "DeepL scores 31 out of 100 (grade F) on the translation criteria. It meets 2 of 10 criteria: no ads or data sales and TLS configuration. It partly meets independent audit, security headers and text not kept. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and works offline. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/translation/deepl/",
      "markdown": "https://privacyratings.com/translation/deepl/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.deepl.com/en/privacy",
          "note": "With consent, marketing cookies and conversion pixels from LinkedIn, Google, Microsoft, Meta, Reddit and others are loaded on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.deepl.com/en/pro",
          "note": "Funded by DeepL Pro and API subscriptions. The translator shows no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://assets.ctfassets.net/pplyeawnfzc7/6ME8nhfxNMIx54UhI88rNg/aa65dbf11f0a6979750babccb8f2336d/Audit_Verdict_DeepL_SOC_2_Type_2.pdf",
          "note": "Only the auditor's opinion from a SOC 2 Type 2 audit is public, not the full report."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.deepl.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.deepl.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "offline": {
          "title": "Works offline",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Online only. Translation runs on DeepL's servers."
        },
        "no_retention": {
          "title": "Text not kept",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.deepl.com/en/privacy",
          "note": "Texts sent to the free translator are kept for a limited time and used to train DeepL's models. With DeepL Pro, texts are deleted after translation and not used for training."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:22:39.432Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "firefox-translations",
      "category": "translation",
      "name": "Firefox Translations",
      "description": "Built-in Firefox feature that translates web pages on the device with local machine translation models, without sending text to a cloud service.",
      "website": "https://support.mozilla.org/en-US/kb/website-translation",
      "source": "https://github.com/mozilla-firefox/firefox",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 63,
      "coverage": 100,
      "summary": "Firefox Translations scores 63 out of 100 (grade C) on the translation criteria. It meets 3 of 6 criteria: open source, works offline and text not kept. It partly meets no trackers or telemetry. It does not meet no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/translation/firefox-translations/",
      "markdown": "https://privacyratings.com/translation/firefox-translations/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/mozilla-firefox/firefox/main/LICENSE",
          "note": "Part of Firefox, licensed under MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.mozilla.org/en-US/privacy/firefox/",
          "note": "No third-party trackers in the feature, but Firefox sends technical and interaction telemetry by default. Telemetry can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.mozilla.org/en-US/privacy/firefox/",
          "note": "Part of Firefox, which shows sponsored content on the New Tab page by default and is mainly funded by search engine deals."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://support.mozilla.org/en-US/kb/website-translation",
          "note": "Translation runs entirely on the device, and text is not sent to cloud servers."
        },
        "no_retention": {
          "title": "Text not kept",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.mozilla.org/en-US/kb/website-translation",
          "note": "Text is translated locally and never leaves the device."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:48.612Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "google-translate",
      "category": "translation",
      "name": "Google Translate",
      "description": "Google's machine translation service for text, documents, websites, speech and images, available on the web and as mobile apps.",
      "website": "https://translate.google.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 31,
      "coverage": 100,
      "summary": "Google Translate scores 31 out of 100 (grade F) on the translation criteria. It meets 2 of 10 criteria: transparency report and tells users about requests. It partly meets TLS configuration, works offline and text not kept. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/translation/google-translate/",
      "markdown": "https://privacyratings.com/translation/google-translate/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Google collects activity data across its services and uses it for analytics and personalized ads."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Free service funded by Google's advertising business, which uses activity data across services."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://transparencyreport.google.com/user-data/overview",
          "note": "Publishes counts of government requests for user data and how often data is disclosed, updated twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://policies.google.com/terms/information-requests",
          "note": "Google emails the user before disclosing information unless legally prohibited or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=translate.google.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=translate.google.com",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "offline": {
          "title": "Works offline",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://support.google.com/translate/answer/6142473",
          "note": "The mobile apps can download languages for offline use. The website and default app mode translate online."
        },
        "no_retention": {
          "title": "Text not kept",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.google.com/translate/answer/6142480",
          "note": "When signed in, translations are saved to cloud history and My Activity by default. History can be cleared, or avoided by signing out."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:56:31.652Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "kagi-translate",
      "category": "translation",
      "name": "Kagi Translate",
      "description": "Translation service from Kagi Inc. that uses large language models from several providers to translate text, documents and web pages. Free to use on the web and in mobile apps.",
      "website": "https://translate.kagi.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "Kagi Translate scores 38 out of 100 (grade F) on the translation criteria. It meets 2 of 10 criteria: no trackers or telemetry and no ads or data sales. It partly meets transparency report, TLS configuration and text not kept. It does not meet open source, independent audit, tells users about requests, security headers and works offline. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B-.",
      "url": "https://privacyratings.com/translation/kagi-translate/",
      "markdown": "https://privacyratings.com/translation/kagi-translate/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kagi.com/privacy",
          "note": "Kagi's privacy policy states its websites load no analytics or telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kagi.com/pricing",
          "note": "Funded by Kagi's paid subscriptions. Kagi Translate shows no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://kagi.com/privacy",
          "note": "The privacy policy includes a warrant canary, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=translate.kagi.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=translate.kagi.com",
          "note": "Grade B- (65/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "offline": {
          "title": "Works offline",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Online only. Translation runs on third-party language models through Kagi's servers."
        },
        "no_retention": {
          "title": "Text not kept",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://help.kagi.com/kagi/ai/llms-privacy.html",
          "note": "Model providers do not train on the text, but most keep API requests for up to 30 days."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:39:09.264Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "libretranslate",
      "category": "translation",
      "name": "LibreTranslate",
      "description": "Open-source machine translation API built on Argos Translate that can be self-hosted. A hosted instance at libretranslate.com offers a free web translator and paid API keys.",
      "website": "https://libretranslate.com",
      "source": "https://github.com/LibreTranslate/LibreTranslate",
      "license": "AGPL-3.0",
      "platforms": [
        "web",
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 67,
      "coverage": 100,
      "summary": "LibreTranslate scores 67 out of 100 (grade C) on the translation criteria. It meets 5 of 10 criteria: open source, no trackers or telemetry, no ads or data sales, works offline and text not kept. It partly meets TLS configuration. It does not meet independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/translation/libretranslate/",
      "markdown": "https://privacyratings.com/translation/libretranslate/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/LibreTranslate/LibreTranslate/main/LICENSE",
          "note": "Licensed under AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://portal.libretranslate.com/privacy.html",
          "note": "The privacy policy states no tracking technologies are used."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://portal.libretranslate.com/privacy.html",
          "note": "Funded by paid API keys. The privacy policy states personal information is not shared."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=libretranslate.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=libretranslate.com",
          "note": "Grade F (10/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "offline": {
          "title": "Works offline",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/LibreTranslate/LibreTranslate",
          "note": "Can be self-hosted so translation runs entirely on your own server with local models."
        },
        "no_retention": {
          "title": "Text not kept",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://portal.libretranslate.com/privacy.html",
          "note": "The hosted service does not store or log translation texts. IP addresses and API keys are kept for two days for abuse prevention."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:39:09.372Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "microsoft-translator",
      "category": "translation",
      "name": "Microsoft Translator",
      "description": "Microsoft's machine translation service for text, speech, images and conversations, available as Bing Translator on the web, as mobile and Windows apps, and built into Edge and Microsoft 365.",
      "website": "https://www.microsoft.com/en-us/translator/",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 33,
      "coverage": 100,
      "summary": "Microsoft Translator scores 33 out of 100 (grade F) on the translation criteria. It meets 3 of 10 criteria: transparency report, tells users about requests and TLS configuration. It partly meets security headers and works offline. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit and text not kept. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/translation/microsoft-translator/",
      "markdown": "https://privacyratings.com/translation/microsoft-translator/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "Microsoft collects usage and diagnostic data and uses data about users for personalized advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement#mainadvertisingmodule",
          "note": "Free service from Microsoft, which uses data about users of its services for personalized advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit of the consumer translator is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Publishes counts of government requests for customer data twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Microsoft gives prior notice to users whose data is requested, except where prohibited by law or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.bing.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.bing.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "offline": {
          "title": "Works offline",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.microsoft.com/en-us/translator/apps/",
          "note": "The mobile apps can download offline translation packs. Online translation is the default."
        },
        "no_retention": {
          "title": "Text not kept",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement#mainMicrosoftTranslatormodule",
          "note": "Submitted text and audio are processed to improve Microsoft's products, with random samples kept after de-identification. No opt-out is described."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:39:09.537Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "translatelocally",
      "category": "translation",
      "name": "TranslateLocally",
      "description": "Open-source desktop app that translates text on the device with downloadable neural models from the Bergamot project, originally built at the University of Edinburgh. Browser extensions are also available.",
      "website": "https://translatelocally.com/downloads/",
      "source": "https://github.com/XapaJIaMnu/translateLocally",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 87,
      "coverage": 100,
      "summary": "TranslateLocally scores 87 out of 100 (grade B) on the translation criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, works offline and text not kept. It does not meet independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/translation/translatelocally/",
      "markdown": "https://privacyratings.com/translation/translatelocally/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/XapaJIaMnu/translateLocally/master/LICENCE.md",
          "note": "Licensed under the MIT License."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/XapaJIaMnu/translateLocally",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://translatelocally.com/downloads/",
          "note": "Free download from Efficient Translation Limited, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "offline": {
          "title": "Works offline",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/XapaJIaMnu/translateLocally/master/README.md",
          "note": "Translation runs locally. The internet is only used to list and download language models."
        },
        "no_retention": {
          "title": "Text not kept",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://raw.githubusercontent.com/XapaJIaMnu/translateLocally/master/README.md",
          "note": "Text is translated on the device with local models and is not sent to a server."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:49.112Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "anarlog",
      "category": "speech-to-text",
      "name": "Anarlog",
      "description": "Open-source, local-first meeting notepad, formerly Hyprnote, that records device audio without a bot and creates transcripts and AI summaries. Transcription can run on the device on supported Macs or through a chosen cloud provider.",
      "website": "https://anarlog.so",
      "source": "https://github.com/fastrepl/anarlog",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 57,
      "coverage": 100,
      "summary": "Anarlog scores 57 out of 100 (grade D) on the dictation and transcription criteria. It meets 3 of 6 criteria: open source, no ads or data sales and no training on recordings. It partly meets runs on the device. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/speech-to-text/anarlog/",
      "markdown": "https://privacyratings.com/speech-to-text/anarlog/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/fastrepl/anarlog/blob/main/LICENSE",
          "note": "The app, including the optional hosted services, is MIT-licensed; separate enterprise components are commercially licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://anarlog.so/privacy",
          "note": "The policy lists PostHog, Google Analytics and Microsoft Clarity for analytics, including website session replay."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://anarlog.so/privacy",
          "note": "Funded by paid plans; the policy states data is not sold or shared for behavioral advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "runs_locally": {
          "title": "Runs on the device",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://docs.anarlog.so/models-and-providers",
          "note": "On-device transcription is available only on supported Macs; other platforms use a cloud or custom transcription provider."
        },
        "no_training": {
          "title": "No training on recordings",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://anarlog.so/privacy",
          "note": "The policy states notes, transcripts and audio are never used to train AI models."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:32.592Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "apple-dictation",
      "category": "speech-to-text",
      "name": "Apple Dictation",
      "description": "Speech-to-text feature built into macOS, iOS and iPadOS that types dictated text in any app. Supported languages are processed on the device; others are sent to Apple servers.",
      "website": "https://support.apple.com/guide/mac-help/use-dictation-mh40584/mac",
      "license": null,
      "platforms": [
        "macos",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 47,
      "coverage": 100,
      "summary": "Apple Dictation scores 47 out of 100 (grade D) on the dictation and transcription criteria. It meets 2 of 6 criteria: no ads or data sales and no training on recordings. It partly meets no trackers or telemetry and runs on the device. It does not meet open source and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/speech-to-text/apple-dictation/",
      "markdown": "https://privacyratings.com/speech-to-text/apple-dictation/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/ask-siri-dictation/",
          "note": "No third-party trackers, but Apple collects request data such as device configuration and performance statistics by default, under a rotating random identifier."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/data/en/ask-siri-dictation/",
          "note": "No ads in Dictation; Apple states dictation data is not used to build marketing profiles and is never sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "runs_locally": {
          "title": "Runs on the device",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/ask-siri-dictation/",
          "note": "Supported languages and devices process dictation on the device; otherwise audio is sent to Apple servers."
        },
        "no_training": {
          "title": "No training on recordings",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/data/en/ask-siri-dictation/",
          "note": "Dictated audio and text are stored and used to improve Apple models only if the user opts in to Improve Siri and Dictation."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:33.145Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "aqua-voice",
      "category": "speech-to-text",
      "name": "Aqua Voice",
      "description": "Voice dictation app that sends speech to the cloud for transcription with its own Avalon model and inserts formatted text into any app, with optional screen context for accuracy.",
      "website": "https://aquavoice.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "ios",
        "android"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 24,
      "coverage": 100,
      "summary": "Aqua Voice scores 24 out of 100 (grade F) on the dictation and transcription criteria. It meets 1 of 10 criteria: TLS configuration. It partly meets no ads or data sales, independent audit and no training on recordings. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests, security headers and runs on the device. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/speech-to-text/aqua-voice/",
      "markdown": "https://privacyratings.com/speech-to-text/aqua-voice/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://aquavoice.com/info/privacy",
          "note": "The website loads Google tags, HubSpot and Cookiebot, and the policy describes advertising attribution through Branch and ad platforms."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://aquavoice.com/info/privacy",
          "note": "Funded by subscriptions and does not sell data, but hashed emails and conversion events are shared with ad platforms such as Google and Meta to measure its own ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://aquavoice.com/info/privacy",
          "note": "A SOC 2 Type II audit by Advantage Partners is claimed, but the report is only available through the Trust Center."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=aquavoice.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=aquavoice.com",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "runs_locally": {
          "title": "Runs on the device",
          "weight": 3,
          "answer": "no",
          "evidence": "https://aquavoice.com/llms.txt",
          "note": "Audio is processed in the cloud."
        },
        "no_training": {
          "title": "No training on recordings",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://aquavoice.com/info/privacy",
          "note": "With Privacy Mode off, the default, transcripts may be stored to improve the product; Privacy Mode turns this off."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cookiebot",
            "host": "consent.cookiebot.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:31:58.383Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "buzz",
      "category": "speech-to-text",
      "name": "Buzz",
      "description": "Desktop app that transcribes and translates audio and video files or live microphone input offline using Whisper models. It can optionally use the OpenAI Whisper API instead.",
      "website": "https://buzzcaptions.com",
      "source": "https://github.com/chidiwilliams/buzz",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 87,
      "coverage": 100,
      "summary": "Buzz scores 87 out of 100 (grade B) on the dictation and transcription criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, runs on the device and no training on recordings. It does not meet independent audit.",
      "url": "https://privacyratings.com/speech-to-text/buzz/",
      "markdown": "https://privacyratings.com/speech-to-text/buzz/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/chidiwilliams/buzz/blob/main/LICENSE",
          "note": "MIT license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/chidiwilliams/buzz",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://buzzcaptions.com",
          "note": "Free open-source app, with a paid Mac App Store edition and no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "runs_locally": {
          "title": "Runs on the device",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://buzzcaptions.com",
          "note": "Transcription runs offline with local Whisper models; the OpenAI Whisper API is an optional alternative."
        },
        "no_training": {
          "title": "No training on recordings",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://buzzcaptions.com",
          "note": "Transcription is local by default, so recordings are not sent to the developer."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:32.613Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fireflies-ai",
      "category": "speech-to-text",
      "name": "Fireflies.ai",
      "description": "Cloud AI meeting assistant that joins video calls as a bot or records through its apps, then transcribes, summarizes and searches the conversations. It also offers dictation.",
      "website": "https://fireflies.ai",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "ios",
        "android"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 31,
      "coverage": 100,
      "summary": "Fireflies.ai scores 31 out of 100 (grade F) on the dictation and transcription criteria. It meets 2 of 10 criteria: TLS configuration and no training on recordings. It partly meets no ads or data sales, independent audit and security headers. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and runs on the device. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/speech-to-text/fireflies-ai/",
      "markdown": "https://privacyratings.com/speech-to-text/fireflies-ai/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://fireflies.ai/privacy-policy",
          "note": "The website loads Google tags, and the policy describes third-party analytics and ad-targeting cookies and pixels."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://fireflies.ai/privacy-policy",
          "note": "Funded by subscriptions, but personal data is shared with advertising partners to target Fireflies ads, which the policy says may count as a sale."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://fireflies.ai/security",
          "note": "SOC 2 Type II compliance is claimed, but the report is only available through the Trust Center."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.fireflies.ai&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.fireflies.ai",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "runs_locally": {
          "title": "Runs on the device",
          "weight": 3,
          "answer": "no",
          "evidence": "https://fireflies.ai/privacy-policy",
          "note": "Recordings are transcribed on Fireflies servers and by its speech-to-text providers."
        },
        "no_training": {
          "title": "No training on recordings",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://fireflies.ai/privacy-policy",
          "note": "The policy states personal information is not used for AI model training and vendors are barred from training on it."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:31:58.337Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "granola",
      "category": "speech-to-text",
      "name": "Granola",
      "description": "AI notepad for meetings that captures computer audio without a bot joining the call, transcribes it through cloud providers, and turns the user's notes and the transcript into meeting summaries.",
      "website": "https://www.granola.ai",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 26,
      "coverage": 100,
      "summary": "Granola scores 26 out of 100 (grade F) on the dictation and transcription criteria. It meets 1 of 10 criteria: TLS configuration. It partly meets no ads or data sales, independent audit, security headers and no training on recordings. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and runs on the device. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/speech-to-text/granola/",
      "markdown": "https://privacyratings.com/speech-to-text/granola/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://docs.granola.ai/help-center/policies/privacy-policy",
          "note": "The policy allows authorized third parties to use cookies, pixels and tags for analytics and targeted advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://docs.granola.ai/help-center/policies/privacy-policy",
          "note": "Funded by subscriptions and does not sell personal data, but third-party cookies are used to target Granola's own advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.granola.ai/security",
          "note": "A SOC 2 Type 2 audit is claimed, but the report is not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.granola.ai&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.granola.ai",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "runs_locally": {
          "title": "Runs on the device",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.granola.ai/security",
          "note": "Audio is sent to cloud transcription providers such as Deepgram and AssemblyAI."
        },
        "no_training": {
          "title": "No training on recordings",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://docs.granola.ai/help-center/policies/privacy-policy",
          "note": "De-identified data is used for model training unless the user opts out in account settings; enterprise workspaces are opted out by default."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:31:58.432Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "handy",
      "category": "speech-to-text",
      "name": "Handy",
      "description": "Free, open-source desktop app for push-to-talk dictation. Speech is transcribed offline on the device with local Whisper or Parakeet models and typed into the active text field.",
      "website": "https://handy.computer",
      "source": "https://github.com/cjpais/Handy",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 87,
      "coverage": 100,
      "summary": "Handy scores 87 out of 100 (grade B) on the dictation and transcription criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, runs on the device and no training on recordings. It does not meet independent audit.",
      "url": "https://privacyratings.com/speech-to-text/handy/",
      "markdown": "https://privacyratings.com/speech-to-text/handy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cjpais/Handy/blob/main/LICENSE",
          "note": "MIT license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://handy.computer/privacy",
          "note": "The app has no analytics or tracking telemetry, and the website has no analytics or tracking cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://handy.computer/privacy",
          "note": "Free and funded by donations; the policy states no advertising and no sale of personal information."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "runs_locally": {
          "title": "Runs on the device",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://handy.computer/privacy",
          "note": "Speech recognition models run on the device; audio is not sent to Handy servers."
        },
        "no_training": {
          "title": "No training on recordings",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://handy.computer/privacy",
          "note": "Transcription is local, so recordings are not sent to the maintainers for training."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:33.430Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "macwhisper",
      "category": "speech-to-text",
      "name": "MacWhisper",
      "description": "macOS app that transcribes audio and video files, meeting audio and dictation with local Whisper-based models, including speaker labels and subtitle export.",
      "website": "https://www.macwhisper.com",
      "license": null,
      "platforms": [
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 57,
      "coverage": 100,
      "summary": "MacWhisper scores 57 out of 100 (grade D) on the dictation and transcription criteria. It meets 3 of 6 criteria: no ads or data sales, runs on the device and no training on recordings. It partly meets no trackers or telemetry. It does not meet open source and independent audit.",
      "url": "https://privacyratings.com/speech-to-text/macwhisper/",
      "markdown": "https://privacyratings.com/speech-to-text/macwhisper/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.macwhisper.com/legal/privacy-policy",
          "note": "The app sends anonymous analytics events about license status; no other analytics are described."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.macwhisper.com",
          "note": "Funded by paid Pro licenses, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "runs_locally": {
          "title": "Runs on the device",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.macwhisper.com/legal/privacy-policy",
          "note": "The policy states all processing happens on the device and no audio or text leaves it."
        },
        "no_training": {
          "title": "No training on recordings",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.macwhisper.com/legal/privacy-policy",
          "note": "Processing is entirely local."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:33.576Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "meetily",
      "category": "speech-to-text",
      "name": "Meetily",
      "description": "Desktop meeting assistant that records meeting audio without a bot, transcribes it on the device with Whisper or Parakeet models, and generates summaries with local or user-chosen AI models.",
      "website": "https://meetily.ai",
      "source": "https://github.com/Zackriya-Solutions/meeting-minutes",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 57,
      "coverage": 100,
      "summary": "Meetily scores 57 out of 100 (grade D) on the dictation and transcription criteria. It meets 3 of 6 criteria: no ads or data sales, runs on the device and no training on recordings. It partly meets open source. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/speech-to-text/meetily/",
      "markdown": "https://privacyratings.com/speech-to-text/meetily/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/Zackriya-Solutions/meeting-minutes/blob/main/LICENSE.md",
          "note": "The Community edition is MIT-licensed; features in the paid Pro edition are not in the public repository."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://meetily.ai/privacy",
          "note": "The meetily.ai website uses PostHog analytics; app analytics are off by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://meetily.ai/pricing",
          "note": "Funded by paid Pro and Enterprise licenses, with a free Community edition and no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "runs_locally": {
          "title": "Runs on the device",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://meetily.ai/privacy",
          "note": "Transcription runs on the device by default; audio does not leave the computer."
        },
        "no_training": {
          "title": "No training on recordings",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://meetily.ai/privacy",
          "note": "Audio stays on the device, and transcripts are sent only to a summary provider the user chooses."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "PostHog",
            "host": "us.i.posthog.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:33.516Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "otter-ai",
      "category": "speech-to-text",
      "name": "Otter.ai",
      "description": "Cloud AI meeting assistant that records and transcribes meetings and conversations, joins video calls as a bot or captures audio from its apps, and generates summaries and action items.",
      "website": "https://otter.ai",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "ios",
        "android"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 24,
      "coverage": 100,
      "summary": "Otter.ai scores 24 out of 100 (grade F) on the dictation and transcription criteria. It meets 1 of 10 criteria: tells users about requests. It partly meets no ads or data sales, independent audit, transparency report and TLS configuration. It does not meet open source, no trackers or telemetry, security headers, runs on the device and no training on recordings. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/speech-to-text/otter-ai/",
      "markdown": "https://privacyratings.com/speech-to-text/otter-ai/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://otter.ai/privacy-policy",
          "note": "The policy lists Google Analytics, Amplitude and Facebook advertising cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://otter.ai/privacy-policy",
          "note": "Funded by subscriptions, but device and cookie data are shared with advertising partners to advertise Otter, which the policy says may count as a sale."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://otter.ai/privacy-security",
          "note": "A SOC 2 Type 2 report exists, but it is not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://otter.ai/data-request-policy",
          "note": "A data request policy is published, with no request counts."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://otter.ai/data-request-policy",
          "note": "The policy promises to notify the customer before disclosure unless legally prohibited, and afterward when a gag order expires."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=otter.ai&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=otter.ai",
          "note": "Grade D- (25/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "runs_locally": {
          "title": "Runs on the device",
          "weight": 3,
          "answer": "no",
          "evidence": "https://otter.ai/privacy-policy",
          "note": "Audio is processed on Otter's servers."
        },
        "no_training": {
          "title": "No training on recordings",
          "weight": 2,
          "answer": "no",
          "evidence": "https://otter.ai/privacy-security",
          "note": "De-identified recordings and transcripts are used to train Otter's models automatically, with no opt-out described."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Amplitude",
            "host": "cdn.amplitude.com",
            "effect": "no"
          },
          {
            "name": "Drift",
            "host": "js.driftt.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:31:58.481Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "superwhisper",
      "category": "speech-to-text",
      "name": "Superwhisper",
      "description": "Dictation app that turns speech into text in any app, with optional AI formatting. It offers local Whisper, Parakeet and Cohere models as well as cloud voice and language models.",
      "website": "https://superwhisper.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "ios",
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 43,
      "coverage": 100,
      "summary": "Superwhisper scores 43 out of 100 (grade D) on the dictation and transcription criteria. It meets 2 of 6 criteria: no ads or data sales and no training on recordings. It partly meets independent audit and runs on the device. It does not meet open source and no trackers or telemetry.",
      "url": "https://privacyratings.com/speech-to-text/superwhisper/",
      "markdown": "https://privacyratings.com/speech-to-text/superwhisper/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Tag Manager and PostHog."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://superwhisper.com/docs/billing/plans",
          "note": "Funded by paid Pro subscriptions and licenses, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://superwhisper.com/docs/security/compliance",
          "note": "SOC 2 and penetration test reports are available only on request through the Trust Center."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "runs_locally": {
          "title": "Runs on the device",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://superwhisper.com/docs/get-started/choose-your-model",
          "note": "Local voice models are available, but the default mode uses Superwhisper cloud models."
        },
        "no_training": {
          "title": "No training on recordings",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://superwhisper.com/docs/security/sensitive-data",
          "note": "Audio and text are not used to train models, and cloud providers operate under zero-data-retention terms."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:33.780Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "tl-dv",
      "category": "speech-to-text",
      "name": "tl;dv",
      "description": "Cloud meeting recorder that joins Google Meet, Zoom and Microsoft Teams calls as a bot, then records, transcribes and summarizes them and can sync notes to CRMs.",
      "website": "https://tldv.io",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 29,
      "coverage": 100,
      "summary": "tl;dv scores 29 out of 100 (grade F) on the dictation and transcription criteria. It meets 3 of 10 criteria: no ads or data sales, TLS configuration and no training on recordings. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests, security headers and runs on the device. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/speech-to-text/tl-dv/",
      "markdown": "https://privacyratings.com/speech-to-text/tl-dv/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://tldv.io/privacy/",
          "note": "The website loads Google Tag Manager, and the policy lists usage data collected for marketing and attribution."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tldv.io/privacy/",
          "note": "Funded by paid plans; the policy states data is not sold to third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=tldv.io&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=tldv.io",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "runs_locally": {
          "title": "Runs on the device",
          "weight": 3,
          "answer": "no",
          "evidence": "https://tldv.io/privacy/",
          "note": "Recordings are processed and stored on tl;dv's cloud infrastructure."
        },
        "no_training": {
          "title": "No training on recordings",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tldv.io/privacy/",
          "note": "The policy states customer recordings, transcripts and notes are not used to train AI models, by tl;dv or its AI providers."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:31:58.534Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "voiceink",
      "category": "speech-to-text",
      "name": "VoiceInk",
      "description": "Dictation app for macOS and iOS that transcribes speech with local Whisper, Parakeet or Apple models and inserts the text into any app. Cloud transcription and AI text enhancement are optional.",
      "website": "https://tryvoiceink.com",
      "source": "https://github.com/Beingpax/VoiceInk",
      "license": null,
      "platforms": [
        "macos",
        "ios"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 57,
      "coverage": 100,
      "summary": "VoiceInk scores 57 out of 100 (grade D) on the dictation and transcription criteria. It meets 3 of 6 criteria: no ads or data sales, runs on the device and no training on recordings. It partly meets open source. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/speech-to-text/voiceink/",
      "markdown": "https://privacyratings.com/speech-to-text/voiceink/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/Beingpax/VoiceInk/blob/main/LICENSE",
          "note": "The macOS app is GPL-3.0; the iOS app source is not published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tryvoiceink.com/pricing",
          "note": "Funded by paid licenses, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "runs_locally": {
          "title": "Runs on the device",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://tryvoiceink.com/privacy",
          "note": "Transcription runs on the device with local models by default; cloud providers are opt-in."
        },
        "no_training": {
          "title": "No training on recordings",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tryvoiceink.com/privacy",
          "note": "Local processing is the default and transcriptions are not stored on VoiceInk servers."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:34.446Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "whisper-cpp",
      "category": "speech-to-text",
      "name": "whisper.cpp",
      "description": "C/C++ port of OpenAI's Whisper speech recognition model that runs transcription on the CPU or GPU of the local device. Used as a library and command-line tool, and as the engine inside many dictation apps.",
      "website": "https://github.com/ggml-org/whisper.cpp",
      "source": "https://github.com/ggml-org/whisper.cpp",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 87,
      "coverage": 100,
      "summary": "whisper.cpp scores 87 out of 100 (grade B) on the dictation and transcription criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, runs on the device and no training on recordings. It does not meet independent audit.",
      "url": "https://privacyratings.com/speech-to-text/whisper-cpp/",
      "markdown": "https://privacyratings.com/speech-to-text/whisper-cpp/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ggml-org/whisper.cpp/blob/master/LICENSE",
          "note": "MIT license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ggml-org/whisper.cpp",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/ggml-org/whisper.cpp",
          "note": "Free open-source software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "runs_locally": {
          "title": "Runs on the device",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ggml-org/whisper.cpp",
          "note": "Inference runs entirely on the local device."
        },
        "no_training": {
          "title": "No training on recordings",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/ggml-org/whisper.cpp",
          "note": "Processing is entirely local."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:33.216Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "whisper",
      "category": "speech-to-text",
      "name": "Whisper",
      "description": "Open-source speech recognition model and Python command-line tool from OpenAI that transcribes and translates audio in many languages on the local computer.",
      "website": "https://github.com/openai/whisper",
      "source": "https://github.com/openai/whisper",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 87,
      "coverage": 100,
      "summary": "Whisper scores 87 out of 100 (grade B) on the dictation and transcription criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, runs on the device and no training on recordings. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/speech-to-text/whisper/",
      "markdown": "https://privacyratings.com/speech-to-text/whisper/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/openai/whisper/blob/main/LICENSE",
          "note": "Code and model weights are MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/openai/whisper",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/openai/whisper",
          "note": "Free open-source software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "runs_locally": {
          "title": "Runs on the device",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/openai/whisper",
          "note": "The model runs on the local computer; audio is not sent to a server."
        },
        "no_training": {
          "title": "No training on recordings",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/openai/whisper",
          "note": "Processing is entirely local."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:33.216Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "windows-voice-typing",
      "category": "speech-to-text",
      "name": "Windows Voice Typing",
      "description": "Dictation feature built into Windows 11, opened with Windows key + H, that converts speech to text in any text field using Microsoft's online speech recognition.",
      "website": "https://support.microsoft.com/en-us/accessibility/windows/use-voice-typing-to-talk-instead-of-type-on-your-pc",
      "license": null,
      "platforms": [
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 13,
      "coverage": 100,
      "summary": "Windows Voice Typing scores 13 out of 100 (grade F) on the dictation and transcription criteria. It meets 1 of 6 criteria: no training on recordings. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit and runs on the device. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/speech-to-text/windows-voice-typing/",
      "markdown": "https://privacyratings.com/speech-to-text/windows-voice-typing/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/windows/privacy/configure-windows-diagnostic-data-in-your-organization",
          "note": "Required Windows diagnostic data is sent to Microsoft and can only be turned off on Enterprise, Education and Server editions."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement#mainadvertisingmodule",
          "note": "Windows has an advertising ID, and Microsoft uses product usage data for personalized advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "runs_locally": {
          "title": "Runs on the device",
          "weight": 3,
          "answer": "no",
          "evidence": "https://support.microsoft.com/en-us/accessibility/windows/use-voice-typing-to-talk-instead-of-type-on-your-pc",
          "note": "Voice typing uses online speech recognition powered by Azure Speech services and needs an internet connection."
        },
        "no_training": {
          "title": "No training on recordings",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement#mainspeechinkingtypingmodule",
          "note": "Voice clips are contributed for product improvement only if the user opts in; otherwise Microsoft does not store or sample the recordings."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:33.840Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "wispr-flow",
      "category": "speech-to-text",
      "name": "Wispr Flow",
      "description": "Voice dictation app that transcribes speech in the cloud and inserts AI-formatted text into any app. It also includes a meeting notetaker.",
      "website": "https://wisprflow.ai",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "ios",
        "android"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 26,
      "coverage": 100,
      "summary": "Wispr Flow scores 26 out of 100 (grade F) on the dictation and transcription criteria. It meets 1 of 10 criteria: TLS configuration. It partly meets no ads or data sales, independent audit, security headers and no training on recordings. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and runs on the device. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/speech-to-text/wispr-flow/",
      "markdown": "https://privacyratings.com/speech-to-text/wispr-flow/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://wisprflow.ai/privacy-policy",
          "note": "The website loads PostHog and Google Tag Manager, and the policy describes third-party analytics including Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://wisprflow.ai/privacy-policy",
          "note": "Funded by subscriptions and does not sell data, but uses cookies and ad networks such as LinkedIn to advertise its own product."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://docs.wisprflow.ai/articles/3467817258-security-and-compliance-faq",
          "note": "SOC 2 Type II and ISO 27001 reports are available only through the Trust Center after approval and an NDA."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=wisprflow.ai&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=wisprflow.ai",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "runs_locally": {
          "title": "Runs on the device",
          "weight": 3,
          "answer": "no",
          "evidence": "https://wisprflow.ai/data-controls",
          "note": "Transcription always occurs in the cloud."
        },
        "no_training": {
          "title": "No training on recordings",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://docs.wisprflow.ai/articles/9609615338-private-cloud-sync-and-data-sharing-preferences-in-wispr-flow",
          "note": "Audio, transcripts and edits are used to improve models by default on Free and Pro plans, with an opt-out; Enterprise is excluded."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "PostHog",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:31:58.703Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "brave-leo",
      "category": "ai-assistants",
      "name": "Brave Leo",
      "description": "AI assistant built into the Brave browser for chat, page summaries and writing help. Works without an account and can also use local or self-chosen models.",
      "website": "https://brave.com/leo/",
      "source": "https://github.com/brave/brave-core",
      "license": "MPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 61,
      "coverage": 100,
      "summary": "Brave Leo scores 61 out of 100 (grade C) on the AI assistants criteria. It meets 3 of 8 criteria: no training on your data, limited chat retention and no account needed. It partly meets open source, no trackers or telemetry, no ads or data sales and runs locally. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/ai-assistants/brave-leo/",
      "markdown": "https://privacyratings.com/ai-assistants/brave-leo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/brave/brave-core/blob/master/LICENSE",
          "note": "The browser code, including Leo, is open source under MPL-2.0. The Leo server is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://brave.com/privacy/browser/",
          "note": "Privacy-preserving product and query analytics are on by default and can be turned off. No third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://brave.com/privacy/browser/",
          "note": "Leo has no ads and is funded by a Premium subscription, but Brave Ads can appear in the browser by default and can be turned off."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "no_training": {
          "title": "No training on your data",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://brave.com/privacy/browser/",
          "note": "Conversations are not used for model training."
        },
        "runs_locally": {
          "title": "Runs locally",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://brave.com/leo/",
          "note": "Bring Your Own Model can connect Leo to local models, but it uses Brave's hosted models by default."
        },
        "chat_retention": {
          "title": "Limited chat retention",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://brave.com/privacy/browser/",
          "note": "Prompts and responses are not stored on Brave's servers. History is stored locally on the device."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://brave.com/leo/",
          "note": "No account or login is needed for the free version."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:49.421Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "chatgpt",
      "category": "ai-assistants",
      "name": "ChatGPT",
      "description": "AI chatbot from OpenAI for writing, questions, coding, image generation and voice conversations. Available on the web and as desktop and mobile apps, with free and paid plans.",
      "website": "https://chatgpt.com",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 42,
      "coverage": 100,
      "summary": "ChatGPT scores 42 out of 100 (grade D) on the AI assistants criteria. It meets 3 of 12 criteria: transparency report, TLS configuration and limited chat retention. It partly meets independent audit, tells users about requests, security headers, no training on your data and no account needed. It does not meet open source, no trackers or telemetry, no ads or data sales and runs locally. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/ai-assistants/chatgpt/",
      "markdown": "https://privacyratings.com/ai-assistants/chatgpt/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.openai.chatgpt/latest/",
          "note": "The Android app includes Segment and Sentry, and the privacy policy describes cookies and web analytics services."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://openai.com/policies/us-privacy-policy/",
          "note": "Free and Go plans show ads that can be personalized using ad interests and activity, subject to settings."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://openai.com/security-and-privacy/",
          "note": "OpenAI holds ISO 42001 certification covering consumer products and SOC 2 for business services, but the full reports are not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://openai.com/trust-and-transparency/",
          "note": "Publishes counts of government requests for user data every six months."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://cdn.openai.com/trust-and-transparency/openai-law-enforcement-policy-v2024.07.pdf",
          "note": "The law enforcement policy says OpenAI may give users prior notice unless prohibited by law, without a firm commitment."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=chatgpt.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=chatgpt.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_training": {
          "title": "No training on your data",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://help.openai.com/en/articles/7730893-data-controls-faq",
          "note": "Chats are used for training by default. The Improve the model for everyone setting turns this off."
        },
        "runs_locally": {
          "title": "Runs locally",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Hosted only."
        },
        "chat_retention": {
          "title": "Limited chat retention",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://help.openai.com/en/articles/8809935-how-to-delete-and-archive-chats-in-chatgpt",
          "note": "Chats are kept until deleted, then removed within 30 days unless needed for security or legal obligations."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://help.openai.com/en/articles/7730893-data-controls-faq",
          "note": "ChatGPT can be used without signing in, with fewer features."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:39:09.645Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "claude",
      "category": "ai-assistants",
      "name": "Claude",
      "description": "AI assistant from Anthropic for writing, analysis, coding and research, available on the web and as desktop and mobile apps, with free and paid plans.",
      "website": "https://claude.ai",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 44,
      "coverage": 100,
      "summary": "Claude scores 44 out of 100 (grade D) on the AI assistants criteria. It meets 5 of 12 criteria: no ads or data sales, transparency report, tells users about requests, TLS configuration and limited chat retention. It partly meets no training on your data. It does not meet open source, no trackers or telemetry, independent audit, security headers, runs locally and no account needed. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C+.",
      "url": "https://privacyratings.com/ai-assistants/claude/",
      "markdown": "https://privacyratings.com/ai-assistants/claude/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://privacy.claude.com/en/articles/10023541-what-cookies-does-anthropic-use",
          "note": "The website and claude.ai use Google Analytics, LinkedIn and other third-party analytics and marketing cookies, and the Android app includes Segment and Sentry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.anthropic.com/news/claude-is-a-space-to-think",
          "note": "Funded by subscriptions and API sales. Anthropic states Claude will remain ad-free."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Anthropic's SOC 2 and ISO certifications cover its commercial products, not consumer Claude plans, and the reports are not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.anthropic.com/transparency/system-trust-reporting",
          "note": "Publishes counts of government requests for user data every six months."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://privacy.claude.com/en/articles/10023650-what-is-anthropic-s-policy-for-handling-governmental-requests-for-user-information",
          "note": "Anthropic notifies users when their data is requested unless legally prohibited or in rare exceptions such as emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=claude.ai&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=claude.ai",
          "note": "Grade C+ (60/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_training": {
          "title": "No training on your data",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://privacy.claude.com/en/articles/10023580-is-my-data-used-for-model-training",
          "note": "Chats are used for training when the model improvement setting is on, and chats flagged for safety review may be used to train safety systems."
        },
        "runs_locally": {
          "title": "Runs locally",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Hosted only."
        },
        "chat_retention": {
          "title": "Limited chat retention",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://privacy.claude.com/en/articles/10023548-how-long-do-you-store-my-data",
          "note": "Deleted chats are removed from back-end storage within 30 days. Chats flagged for policy violations are kept for up to 2 years."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "An account is required."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:39:09.702Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "duck-ai",
      "category": "ai-assistants",
      "name": "Duck.ai",
      "description": "AI chat from DuckDuckGo that relays prompts to third-party models without identifying the user, with no account needed and recent chats saved only on the device.",
      "website": "https://duck.ai",
      "source": "https://github.com/duckduckgo/Android",
      "license": "Apache-2.0",
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 60,
      "coverage": 100,
      "summary": "Duck.ai scores 60 out of 100 (grade C) on the AI assistants criteria. It meets 5 of 12 criteria: no trackers or telemetry, tells users about requests, no training on your data, limited chat retention and no account needed. It partly meets open source, no ads or data sales, transparency report and TLS configuration. It does not meet independent audit, security headers and runs locally. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade B-.",
      "url": "https://privacyratings.com/ai-assistants/duck-ai/",
      "markdown": "https://privacyratings.com/ai-assistants/duck-ai/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/duckduckgo/Android/blob/develop/LICENSE",
          "note": "DuckDuckGo's apps, which include Duck.ai, are open source under Apache-2.0. The Duck.ai service is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://duckduckgo.com/privacy",
          "note": "No third-party trackers or tracking cookies, and the Android app has no known trackers in its Exodus report."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://duckduckgo.com/privacy",
          "note": "DuckDuckGo is funded by search ads based only on the current search, not a profile, and by subscriptions."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://duckduckgo.com/privacy",
          "note": "The privacy policy states how legal requests are handled, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://duckduckgo.com/privacy",
          "note": "Users with an email address on file are notified of legal disclosures by email unless legally forbidden."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=duck.ai&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=duck.ai",
          "note": "Grade B- (65/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_training": {
          "title": "No training on your data",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://duckduckgo.com/duckai/privacy-terms",
          "note": "Agreements with model providers prohibit using prompts and outputs to train or improve models."
        },
        "runs_locally": {
          "title": "Runs locally",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Hosted only."
        },
        "chat_retention": {
          "title": "Limited chat retention",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://duckduckgo.com/duckai/privacy-terms",
          "note": "Recent chats are saved only on the device, and model providers delete data within 30 days, with limited exceptions for safety and legal compliance."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://duckduckgo.com/duckai/privacy-terms",
          "note": "No account is needed. Requests are sent without identifying metadata such as the IP address."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "B-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:39:09.758Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "google-gemini",
      "category": "ai-assistants",
      "name": "Google Gemini",
      "description": "AI assistant from Google for questions, writing, coding and image generation, connected to Google services such as Gmail and Drive. Available on the web and in Android and iOS apps.",
      "website": "https://gemini.google.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Google Gemini scores 35 out of 100 (grade F) on the AI assistants criteria. It meets 3 of 11 criteria: no ads or data sales, transparency report and tells users about requests. It partly meets TLS configuration, no training on your data and no account needed. It does not meet open source, no trackers or telemetry, independent audit, runs locally and limited chat retention. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B.",
      "url": "https://privacyratings.com/ai-assistants/google-gemini/",
      "markdown": "https://privacyratings.com/ai-assistants/google-gemini/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Google collects activity, device and usage data across its services, including Gemini, and this cannot be fully turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.google.com/gemini/answer/13594961",
          "note": "No ads are shown in Gemini, and Google states chats are not used to show ads, though it says it will announce any change."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit of the consumer Gemini app is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://transparencyreport.google.com/user-data/overview",
          "note": "Google publishes counts of government requests for user data and how it responds, updated twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://policies.google.com/terms/information-requests",
          "note": "Google emails the user before disclosing data in response to a government request, unless prohibited by law."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=gemini.google.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_training": {
          "title": "No training on your data",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://support.google.com/gemini/answer/13594961",
          "note": "With Keep Activity on, which is the default, chats are used to train models. Turning it off stops this."
        },
        "runs_locally": {
          "title": "Runs locally",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Hosted only."
        },
        "chat_retention": {
          "title": "Limited chat retention",
          "weight": 2,
          "answer": "no",
          "evidence": "https://support.google.com/gemini/answer/13594961",
          "note": "Activity is kept for 18 months by default, and chats reviewed by human reviewers are kept for up to three years even after deletion."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://support.google.com/gemini/answer/13594961",
          "note": "Gemini can be used without signing in to a Google account, with fewer features."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:39:21.905Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "gpt4all",
      "category": "ai-assistants",
      "name": "GPT4All",
      "description": "Open-source desktop app from Nomic for running large language models locally, including chatting with local documents.",
      "website": "https://www.nomic.ai/gpt4all",
      "source": "https://github.com/nomic-ai/gpt4all",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 72,
      "coverage": 100,
      "summary": "GPT4All scores 72 out of 100 (grade C) on the AI assistants criteria. It meets 6 of 8 criteria: open source, no ads or data sales, no training on your data, runs locally, limited chat retention and no account needed. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/ai-assistants/gpt4all/",
      "markdown": "https://privacyratings.com/ai-assistants/gpt4all/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nomic-ai/gpt4all/blob/main/LICENSE.txt",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.nomic.ai/gpt4all",
          "note": "The website loads Google Analytics and HubSpot."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/nomic-ai/gpt4all",
          "note": "Free and open source, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "no_training": {
          "title": "No training on your data",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://docs.gpt4all.io/gpt4all_desktop/settings.html",
          "note": "Chats stay on the device. Sharing them with the GPT4All datalake is opt-in and off by default."
        },
        "runs_locally": {
          "title": "Runs locally",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/nomic-ai/gpt4all",
          "note": "Runs models locally on the user's computer, with no internet connection needed."
        },
        "chat_retention": {
          "title": "Limited chat retention",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.gpt4all.io/gpt4all_desktop/settings.html",
          "note": "Chats are stored only on the device."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/nomic-ai/gpt4all",
          "note": "No account is needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "snap.licdn.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:49.803Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "jan",
      "category": "ai-assistants",
      "name": "Jan",
      "description": "Open-source desktop app for running large language models offline on a local computer, with optional connections to remote AI APIs.",
      "website": "https://www.jan.ai",
      "source": "https://github.com/janhq/jan",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 89,
      "coverage": 100,
      "summary": "Jan scores 89 out of 100 (grade B) on the AI assistants criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, no training on your data, runs locally, limited chat retention and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/ai-assistants/jan/",
      "markdown": "https://privacyratings.com/ai-assistants/jan/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/janhq/jan/blob/main/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/janhq/jan/blob/main/web-app/src/containers/analytics/AnalyticConsent.tsx",
          "note": "Product analytics are off until the user agrees, and no third-party trackers were found on the website."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.jan.ai/privacy",
          "note": "Free and open source, with no ads. Personal information is not shared with third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "no_training": {
          "title": "No training on your data",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.jan.ai/privacy",
          "note": "Conversations stay on the user's computer. Remote APIs, when chosen, follow their own policies."
        },
        "runs_locally": {
          "title": "Runs locally",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.jan.ai/privacy",
          "note": "Runs fully offline on the user's own computer."
        },
        "chat_retention": {
          "title": "Limited chat retention",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.jan.ai/privacy",
          "note": "Conversation history is stored locally and never leaves the computer."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.jan.ai/privacy",
          "note": "No account is needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:49.871Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "kagi-assistant",
      "category": "ai-assistants",
      "name": "Kagi Assistant",
      "description": "AI assistant from Kagi that combines several third-party language models with Kagi Search results, available with a Kagi account.",
      "website": "https://assistant.kagi.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 54,
      "coverage": 100,
      "summary": "Kagi Assistant scores 54 out of 100 (grade D) on the AI assistants criteria. It meets 5 of 12 criteria: no trackers or telemetry, no ads or data sales, security headers, no training on your data and limited chat retention. It partly meets transparency report and TLS configuration. It does not meet open source, independent audit, tells users about requests, runs locally and no account needed. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/ai-assistants/kagi-assistant/",
      "markdown": "https://privacyratings.com/ai-assistants/kagi-assistant/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kagi.com/privacy",
          "note": "The site loads no analytics or telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kagi.com/pricing",
          "note": "Funded by paid subscriptions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://kagi.com/privacy",
          "note": "The privacy policy includes a warrant canary, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=assistant.kagi.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=assistant.kagi.com",
          "note": "Grade A+ (105/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_training": {
          "title": "No training on your data",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kagi.com/privacy",
          "note": "Kagi does not train on chats and uses third-party providers that do not save data or train on it whenever possible."
        },
        "runs_locally": {
          "title": "Runs locally",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Hosted only."
        },
        "chat_retention": {
          "title": "Limited chat retention",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kagi.com/privacy",
          "note": "Threads are deleted automatically after one day by default, and can be deleted immediately. Reported threads are kept longer."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "no",
          "evidence": "https://kagi.com/pricing",
          "note": "A Kagi account is required."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:39:10.012Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "llama-cpp",
      "category": "ai-assistants",
      "name": "llama.cpp",
      "description": "Open-source C/C++ library and command-line tools for running large language model inference locally on CPUs and GPUs, including a built-in web server and chat interface.",
      "website": "https://github.com/ggml-org/llama.cpp",
      "source": "https://github.com/ggml-org/llama.cpp",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 89,
      "coverage": 100,
      "summary": "llama.cpp scores 89 out of 100 (grade B) on the AI assistants criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, no training on your data, runs locally, limited chat retention and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/ai-assistants/llama-cpp/",
      "markdown": "https://privacyratings.com/ai-assistants/llama-cpp/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ggml-org/llama.cpp/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ggml-org/llama.cpp",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/ggml-org/llama.cpp",
          "note": "Free and open source, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "no_training": {
          "title": "No training on your data",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ggml-org/llama.cpp",
          "note": "Runs entirely on the user's hardware, so prompts are never sent anywhere."
        },
        "runs_locally": {
          "title": "Runs locally",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/ggml-org/llama.cpp",
          "note": "Runs models locally on the user's own hardware."
        },
        "chat_retention": {
          "title": "Limited chat retention",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/ggml-org/llama.cpp",
          "note": "No server copy exists; everything stays on the user's machine."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/ggml-org/llama.cpp",
          "note": "No account is needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:49.803Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "lm-studio",
      "category": "ai-assistants",
      "name": "LM Studio",
      "description": "Desktop app for finding, downloading and running large language models locally, with a chat interface and a local API server.",
      "website": "https://lmstudio.ai",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 72,
      "coverage": 100,
      "summary": "LM Studio scores 72 out of 100 (grade C) on the AI assistants criteria. It meets 6 of 8 criteria: no trackers or telemetry, no ads or data sales, no training on your data, runs locally, limited chat retention and no account needed. It does not meet open source and independent audit.",
      "url": "https://privacyratings.com/ai-assistants/lm-studio/",
      "markdown": "https://privacyratings.com/ai-assistants/lm-studio/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. The lms command-line tool and SDKs are open source, but the app is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://lmstudio.ai/app-privacy",
          "note": "No third-party trackers, and the app contacts LM Studio only for updates and model downloads. The website's Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://lmstudio.ai/enterprise",
          "note": "Free to use, funded by paid enterprise plans, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "no_training": {
          "title": "No training on your data",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://lmstudio.ai/app-privacy",
          "note": "Prompts and responses stay on the device and are not retained by LM Studio."
        },
        "runs_locally": {
          "title": "Runs locally",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://lmstudio.ai/app-privacy",
          "note": "Models run entirely on the user's own computer and can work offline."
        },
        "chat_retention": {
          "title": "Limited chat retention",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://lmstudio.ai/app-privacy",
          "note": "Chats are stored only on the device."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://lmstudio.ai/app-privacy",
          "note": "No account is needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:38:50.250Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "lumo",
      "category": "ai-assistants",
      "name": "Lumo",
      "description": "AI assistant from Proton that runs open-weight models on Proton's servers, with no logs of chats and zero-access encrypted chat history.",
      "website": "https://proton.me/lumo",
      "source": "https://github.com/ProtonMail/WebClients",
      "license": "GPL-3.0",
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 73,
      "coverage": 100,
      "summary": "Lumo scores 73 out of 100 (grade C) on the AI assistants criteria. It meets 7 of 12 criteria: no ads or data sales, transparency report, tells users about requests, TLS configuration, security headers, no training on your data and limited chat retention. It partly meets open source, no trackers or telemetry, independent audit and no account needed. It does not meet runs locally. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/ai-assistants/lumo/",
      "markdown": "https://privacyratings.com/ai-assistants/lumo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/ProtonMail/WebClients/blob/main/LICENSE",
          "note": "Apps are open source under GPL-3.0. The server is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/me.proton.android.lumo/latest/",
          "note": "Website analytics are self-hosted, and the Android app includes Sentry crash reporting."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://proton.me/lumo/pricing",
          "note": "Funded by paid plans, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://proton.me/blog/soc-2",
          "note": "Proton completed a SOC 2 Type II audit, but the report is not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://proton.me/legal/transparency",
          "note": "Publishes yearly counts of legal orders received, complied with and contested."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://proton.me/legal/law-enforcement",
          "note": "Targeted users are notified of data requests, with delays only when Swiss law, a court order or a risk to life requires it."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=lumo.proton.me&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=lumo.proton.me",
          "note": "Grade A+ (115/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_training": {
          "title": "No training on your data",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://proton.me/support/lumo-privacy",
          "note": "Chats are not used to train models, except anonymized feedback that users choose to share for one model."
        },
        "runs_locally": {
          "title": "Runs locally",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Hosted only."
        },
        "chat_retention": {
          "title": "Limited chat retention",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://proton.me/support/lumo-privacy",
          "note": "Chats are erased from servers after each response. Saved history is zero-access encrypted and only readable by the user."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://proton.me/lumo",
          "note": "Guest access works without an account, with usage limits."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:39:10.075Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "meta-ai",
      "category": "ai-assistants",
      "name": "Meta AI",
      "description": "AI assistant from Meta built into Facebook, Instagram, WhatsApp and Messenger, and available on the web and as a standalone app.",
      "website": "https://www.meta.ai",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 27,
      "coverage": 100,
      "summary": "Meta AI scores 27 out of 100 (grade F) on the AI assistants criteria. It meets 3 of 12 criteria: transparency report, tells users about requests and TLS configuration. It partly meets limited chat retention and no account needed. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, security headers, no training on your data and runs locally. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/ai-assistants/meta-ai/",
      "markdown": "https://privacyratings.com/ai-assistants/meta-ai/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. Meta publishes some Llama model weights, but the Meta AI service is not open source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.facebook.com/privacy/policy/",
          "note": "Meta collects activity and device data across its products, including Meta AI, and uses it for personalization and ads."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://about.fb.com/news/2025/10/improving-your-recommendations-apps-ai-meta/",
          "note": "Interactions with Meta AI are used to personalize ads across Meta's apps."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://transparency.meta.com/reports/government-data-requests/",
          "note": "Publishes counts of government requests for user data twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.facebook.com/safety/groups/law/guidelines/",
          "note": "Meta's policy is to notify people of requests for their information before disclosure, unless prohibited by law or in exceptional circumstances."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.meta.ai&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.meta.ai",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_training": {
          "title": "No training on your data",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.facebook.com/privacy/genai/",
          "note": "Interactions with AI features are used to train Meta's models, with no general opt-out setting."
        },
        "runs_locally": {
          "title": "Runs locally",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Hosted only."
        },
        "chat_retention": {
          "title": "Limited chat retention",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.facebook.com/privacy/policy/",
          "note": "Chats are kept until deleted. The privacy policy sets retention case by case, with no fixed deletion period."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.meta.ai",
          "note": "The web version offers limited chat before logging in; most features need a Meta account."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:39:10.131Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "microsoft-copilot",
      "category": "ai-assistants",
      "name": "Microsoft Copilot",
      "description": "Consumer AI assistant from Microsoft for chat, search, writing and image generation, built into Windows and Edge and available on the web and in mobile apps.",
      "website": "https://copilot.microsoft.com",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 29,
      "coverage": 100,
      "summary": "Microsoft Copilot scores 29 out of 100 (grade F) on the AI assistants criteria. It meets 2 of 12 criteria: transparency report and tells users about requests. It partly meets TLS configuration, no training on your data, limited chat retention and no account needed. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, security headers and runs locally. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B-.",
      "url": "https://privacyratings.com/ai-assistants/microsoft-copilot/",
      "markdown": "https://privacyratings.com/ai-assistants/microsoft-copilot/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.microsoft.copilot/latest/",
          "note": "The Android app includes Adjust and Sentry, and Microsoft collects diagnostic data that cannot be fully turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://support.microsoft.com/en-us/microsoft-copilot/privacy-faq-for-microsoft-copilot",
          "note": "Microsoft shows ads to Copilot users, and with personalization on, Copilot conversation history is used to personalize them."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit of consumer Copilot is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Publishes counts of government requests for consumer data twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Microsoft gives prior notice to consumers whose data is requested, except where prohibited by law or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=copilot.microsoft.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=copilot.microsoft.com",
          "note": "Grade B- (65/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_training": {
          "title": "No training on your data",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://support.microsoft.com/en-us/microsoft-copilot/privacy-faq-for-microsoft-copilot",
          "note": "Conversations of signed-in users are used for model training by default, with an opt-out setting."
        },
        "runs_locally": {
          "title": "Runs locally",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Hosted only."
        },
        "chat_retention": {
          "title": "Limited chat retention",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.microsoft.com/en-us/microsoft-copilot/privacy-faq-for-microsoft-copilot",
          "note": "Conversations are stored for 18 months by default and can be deleted at any time."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://support.microsoft.com/en-us/microsoft-copilot/privacy-faq-for-microsoft-copilot",
          "note": "Copilot can be used without signing in, with fewer features."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:39:10.193Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "mistral-vibe",
      "category": "ai-assistants",
      "name": "Mistral Vibe",
      "description": "AI assistant from French company Mistral AI, formerly called Le Chat, for chat, research, documents and coding tasks. Available on the web and in mobile apps.",
      "website": "https://mistral.ai/products/vibe/",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 33,
      "coverage": 100,
      "summary": "Mistral Vibe scores 33 out of 100 (grade F) on the AI assistants criteria. It meets 2 of 12 criteria: no ads or data sales and TLS configuration. It partly meets independent audit, security headers, no training on your data and limited chat retention. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests, runs locally and no account needed. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/ai-assistants/mistral-vibe/",
      "markdown": "https://privacyratings.com/ai-assistants/mistral-vibe/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. Some Mistral models are published with open weights, but the assistant is not open source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://help.mistral.ai/en/articles/347616-do-you-use-cookies-at-mistral-and-why",
          "note": "The website uses analytics cookies and partner marketing cookies, and the Android app includes Sentry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://help.mistral.ai/en/articles/347633-do-you-use-my-conversations-with-vibe-to-show-me-ads",
          "note": "Funded by subscriptions and business sales. Conversations are not used for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://help.mistral.ai/en/articles/347638-do-you-have-soc-2-or-iso-27001-certification",
          "note": "Mistral has SOC 2 Type II and ISO 27001 audits, but the reports are only available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=chat.mistral.ai&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=chat.mistral.ai",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_training": {
          "title": "No training on your data",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://help.mistral.ai/en/articles/455207-can-i-opt-out-of-my-input-or-output-data-being-used-for-training",
          "note": "Chats on Free and Pro plans are used for training by default, with an opt-out setting."
        },
        "runs_locally": {
          "title": "Runs locally",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Hosted only."
        },
        "chat_retention": {
          "title": "Limited chat retention",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://help.mistral.ai/en/articles/347613-can-i-delete-a-chat-conversation",
          "note": "Chats are kept until deleted. Deleted data may be retained in backend systems for policy enforcement or legal reasons."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "A Mistral account is required."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:39:10.265Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "ollama",
      "category": "ai-assistants",
      "name": "Ollama",
      "description": "Open-source tool for downloading and running large language models on a local computer through a command line, API and desktop app. Optional cloud-hosted models are also offered.",
      "website": "https://ollama.com",
      "source": "https://github.com/ollama/ollama",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 81,
      "coverage": 100,
      "summary": "Ollama scores 81 out of 100 (grade B) on the AI assistants criteria. It meets 6 of 8 criteria: open source, no ads or data sales, no training on your data, runs locally, limited chat retention and no account needed. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/ai-assistants/ollama/",
      "markdown": "https://privacyratings.com/ai-assistants/ollama/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ollama/ollama/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://ollama.com/privacy",
          "note": "No third-party trackers, but Ollama collects limited device and usage metadata such as app version and request counts, without prompt content."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ollama.com/pricing",
          "note": "Free to run locally, with paid plans for cloud models. The privacy policy states data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "no_training": {
          "title": "No training on your data",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://ollama.com/privacy",
          "note": "Local prompts never reach Ollama, and prompts sent to cloud models are not used for training."
        },
        "runs_locally": {
          "title": "Runs locally",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ollama.com/privacy",
          "note": "Models run on the user's own computer by default."
        },
        "chat_retention": {
          "title": "Limited chat retention",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ollama.com/privacy",
          "note": "Local chats are not sent to Ollama's servers. Cloud model prompts are processed transiently."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://ollama.com/privacy",
          "note": "No account is needed to run models locally. An account is only needed for cloud models."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:50.657Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "open-webui",
      "category": "ai-assistants",
      "name": "Open WebUI",
      "description": "Self-hosted web interface for large language models that works with Ollama and OpenAI-compatible APIs, with multi-user support.",
      "website": "https://openwebui.com",
      "source": "https://github.com/open-webui/open-webui",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 72,
      "coverage": 100,
      "summary": "Open WebUI scores 72 out of 100 (grade C) on the AI assistants criteria. It meets 6 of 8 criteria: open source, no ads or data sales, no training on your data, runs locally, limited chat retention and no account needed. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/ai-assistants/open-webui/",
      "markdown": "https://privacyratings.com/ai-assistants/open-webui/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/open-webui/open-webui/blob/main/LICENSE",
          "note": "All code is public under the Open WebUI License, a source-available BSD-3-Clause variant with a branding clause that is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/open-webui/open-webui/blob/main/Dockerfile",
          "note": "The Docker image turns off library telemetry, but the openwebui.com website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.openwebui.com/enterprise/",
          "note": "Free to self-host, funded by enterprise licenses, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "no_training": {
          "title": "No training on your data",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://docs.openwebui.com/",
          "note": "Self-hosted, so chats stay on the user's server unless an external model API is connected."
        },
        "runs_locally": {
          "title": "Runs locally",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.openwebui.com/",
          "note": "Runs on the user's own server and works with local models through Ollama."
        },
        "chat_retention": {
          "title": "Limited chat retention",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.openwebui.com/",
          "note": "Chats are stored only on the user's own server."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.openwebui.com/",
          "note": "No account with the project is needed. Accounts exist only on the user's own instance."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:38:50.999Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "perplexity",
      "category": "ai-assistants",
      "name": "Perplexity",
      "description": "AI answer engine that searches the web and summarizes results with cited sources, available on the web and as desktop and mobile apps.",
      "website": "https://www.perplexity.ai",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 27,
      "coverage": 100,
      "summary": "Perplexity scores 27 out of 100 (grade F) on the AI assistants criteria. It meets 1 of 12 criteria: TLS configuration. It partly meets no ads or data sales, security headers, no training on your data, limited chat retention and no account needed. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and runs locally. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/ai-assistants/perplexity/",
      "markdown": "https://privacyratings.com/ai-assistants/perplexity/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/ai.perplexity.app.android/latest/",
          "note": "The Android app includes Google Firebase Analytics, Crashlytics and Singular."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.perplexity.ai/hub/blog/why-we-re-experimenting-with-advertising",
          "note": "Sponsored follow-up questions and ads can appear next to answers. Perplexity states queries are not sent to advertisers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit of the consumer service is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.perplexity.ai&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.perplexity.ai",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_training": {
          "title": "No training on your data",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.perplexity.ai/help-center/en/articles/10354855-what-data-does-perplexity-collect-about-me",
          "note": "Searches are used to improve the service by default. The AI Data Usage setting turns this off."
        },
        "runs_locally": {
          "title": "Runs locally",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Hosted only."
        },
        "chat_retention": {
          "title": "Limited chat retention",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.perplexity.ai/help-center/en/articles/10354873-how-long-does-perplexity-retain-my-search-history-profile-data-and-personal-information",
          "note": "Search history is kept while the account is active and can be deleted. Account data is removed within 30 days of account deletion."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://www.perplexity.ai/help-center/en/articles/10354855-what-data-does-perplexity-collect-about-me",
          "note": "Search works without an account, with fewer features."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:39:10.326Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "venice",
      "category": "ai-assistants",
      "name": "Venice",
      "description": "AI chat and image generation service that proxies prompts to open and third-party models, keeping conversation history only in the browser.",
      "website": "https://venice.ai",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 42,
      "coverage": 100,
      "summary": "Venice scores 42 out of 100 (grade D) on the AI assistants criteria. It meets 4 of 12 criteria: no ads or data sales, TLS configuration, no training on your data and limited chat retention. It partly meets security headers and no account needed. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and runs locally. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/ai-assistants/venice/",
      "markdown": "https://privacyratings.com/ai-assistants/venice/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://venice.ai/legal/privacy-policy",
          "note": "The privacy policy lists Google Analytics and third-party analytics and advertising partners."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://venice.ai/pricing",
          "note": "Funded by Pro subscriptions and API sales, with no ads in the service."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=venice.ai&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=venice.ai",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_training": {
          "title": "No training on your data",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://venice.ai/privacy",
          "note": "In the default Private mode, prompts are not stored by Venice or its inference providers. Anonymous mode sends prompts to third-party providers that may keep them."
        },
        "runs_locally": {
          "title": "Runs locally",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "Hosted only."
        },
        "chat_retention": {
          "title": "Limited chat retention",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://venice.ai/privacy",
          "note": "Conversation history is stored only on the device, and prompts are relayed without being stored."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://venice.ai/legal/privacy-policy",
          "note": "Venice can be used without an account, with limits."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:39:10.414Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "box",
      "category": "cloud-storage",
      "name": "Box",
      "description": "Cloud content management and file sharing service for businesses and individuals, with desktop, mobile and web apps. Files are encrypted at rest with keys Box holds, not end-to-end.",
      "website": "https://www.box.com",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 34,
      "coverage": 100,
      "summary": "Box scores 34 out of 100 (grade F) on the encrypted cloud storage criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It partly meets independent audit and security headers. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/cloud-storage/box/",
      "markdown": "https://privacyratings.com/cloud-storage/box/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.box.android/latest/",
          "note": "The Android app includes Amplitude, Google Firebase Analytics, Crashlytics and Pendo."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.box.com/legal/privacypolicy",
          "note": "Funded by paid plans, with no ads in the service. Box states it does not share personal information or content with third parties without permission."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.box.com/trust",
          "note": "Box has SOC 1, SOC 2 and SOC 3 audits and ISO certifications. The ISO certificates are public, but the SOC reports are only shared under NDA."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.box.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.box.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "TrustArc",
            "host": "cpm-form.trustarc.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:39:10.470Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "dropbox",
      "category": "cloud-storage",
      "name": "Dropbox",
      "description": "Cloud storage and file sync service with desktop, mobile and web apps. Files are encrypted at rest with keys Dropbox holds, not end-to-end.",
      "website": "https://www.dropbox.com",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 53,
      "coverage": 100,
      "summary": "Dropbox scores 53 out of 100 (grade D) on the encrypted cloud storage criteria. It meets 4 of 8 criteria: no ads or data sales, transparency report, tells users about requests and TLS configuration. It partly meets independent audit and security headers. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/cloud-storage/dropbox/",
      "markdown": "https://privacyratings.com/cloud-storage/dropbox/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.dropbox.android/latest/",
          "note": "The Android app includes Adjust, Amplitude, Google Firebase Analytics and Sentry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.dropbox.com/privacy",
          "note": "Funded by paid plans, with no ads in the service. Dropbox states it does not sell user information to advertisers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.dropbox.com/business/trust/compliance/certifications-compliance",
          "note": "Dropbox has third-party SOC 2 audits and ISO certifications. Only the SOC 3 summary report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://help.dropbox.com/transparency",
          "note": "Publishes counts of government requests for user data and its responses twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://help.dropbox.com/transparency",
          "note": "Dropbox's principles commit to notifying users of government requests unless a non-disclosure order prohibits it."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.dropbox.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.dropbox.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:40:51.041Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "filen",
      "category": "cloud-storage",
      "name": "Filen",
      "description": "End-to-end encrypted cloud storage from Germany, with open source web, desktop, mobile and CLI clients. Offers a free tier and paid plans.",
      "website": "https://filen.io",
      "source": "https://github.com/FilenCloudDienste/filen-desktop",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 63,
      "coverage": 100,
      "summary": "Filen scores 63 out of 100 (grade C) on the encrypted cloud storage criteria. It meets 3 of 8 criteria: no trackers or telemetry, no ads or data sales and TLS configuration. It partly meets open source, transparency report and security headers. It does not meet independent audit and tells users about requests. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/cloud-storage/filen/",
      "markdown": "https://privacyratings.com/cloud-storage/filen/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/FilenCloudDienste/filen-desktop/blob/main/LICENSE",
          "note": "Apps are open source. The server is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/io.filen.app/latest/",
          "note": "Exodus finds no trackers in the Android app, and the website uses self-hosted Plausible analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://filen.io/pricing",
          "note": "Funded by paid storage plans, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://filen.io/warrant-canary",
          "note": "Publishes a signed warrant canary, but no request counts."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=filen.io&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=filen.io",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:36.721Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "google-drive",
      "category": "cloud-storage",
      "name": "Google Drive",
      "description": "Cloud storage and file sharing from Google, integrated with Docs, Sheets and other Google services. Files are encrypted at rest with keys Google holds, not end-to-end.",
      "website": "https://workspace.google.com/products/drive/",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 44,
      "coverage": 100,
      "summary": "Google Drive scores 44 out of 100 (grade D) on the encrypted cloud storage criteria. It meets 3 of 8 criteria: no ads or data sales, transparency report and tells users about requests. It partly meets independent audit and TLS configuration. It does not meet open source, no trackers or telemetry and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B-.",
      "url": "https://privacyratings.com/cloud-storage/google-drive/",
      "markdown": "https://privacyratings.com/cloud-storage/google-drive/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Google collects activity, device and usage data across its services, including Drive, and this cannot be fully turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://support.google.com/drive/answer/10375054",
          "note": "No ads in Drive, and Google states Drive content is never used for advertising. Extra storage is sold as a subscription."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cloud.google.com/security/compliance/soc-3",
          "note": "Google Workspace, which includes Drive, has third-party SOC 2 audits. Only the SOC 3 summary report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://transparencyreport.google.com/user-data/overview",
          "note": "Google publishes counts of government requests for user data and how it responds, updated twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://policies.google.com/terms/information-requests",
          "note": "Google emails the user before disclosing data in response to a government request, unless prohibited by law."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=drive.google.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=drive.google.com",
          "note": "Grade B- (65/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:39:49.033Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "icedrive",
      "category": "cloud-storage",
      "name": "Icedrive",
      "description": "Cloud storage service with desktop, mobile and web apps, a free tier, and optional client-side encryption of a private folder on paid plans.",
      "website": "https://icedrive.net",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "GI",
        "name": "Gibraltar",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 19,
      "coverage": 100,
      "summary": "Icedrive scores 19 out of 100 (grade F) on the encrypted cloud storage criteria. It meets 1 of 8 criteria: no ads or data sales. It partly meets TLS configuration. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in Gibraltar: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/cloud-storage/icedrive/",
      "markdown": "https://privacyratings.com/cloud-storage/icedrive/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.icedrive.app/latest/",
          "note": "Exodus finds Google Firebase Analytics in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://icedrive.net/plans",
          "note": "Funded by paid storage plans, with no ads in the service."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=icedrive.net&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=icedrive.net",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:36.773Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "icloud-drive",
      "category": "cloud-storage",
      "name": "iCloud Drive",
      "description": "Apple's cloud storage for files across Apple devices, Windows and the web. Files are end-to-end encrypted only with the optional Advanced Data Protection setting, which is off by default.",
      "website": "https://www.icloud.com/iclouddrive",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 75,
      "coverage": 100,
      "summary": "iCloud Drive scores 75 out of 100 (grade B) on the encrypted cloud storage criteria. It meets 6 of 8 criteria: no trackers or telemetry, no ads or data sales, transparency report, tells users about requests, TLS configuration and security headers. It partly meets independent audit. It does not meet open source. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/cloud-storage/icloud-drive/",
      "markdown": "https://privacyratings.com/cloud-storage/icloud-drive/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/data/en/device-analytics/",
          "note": "Device and iCloud analytics are only shared with Apple if the user agrees, and no third-party trackers are included."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/en-ww/",
          "note": "Funded by iCloud+ subscriptions and device sales, with no ads in iCloud Drive. Apple states it does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.apple.com/guide/certifications/apple-internet-services-security-apc34d2c0468b/web",
          "note": "Apple's internet services, including iCloud, have yearly ISO 27001 and 27018 certification audits, but only the certificates are public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/transparency/",
          "note": "Publishes counts of government requests for customer data twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/law-enforcement-guidelines-us.pdf",
          "note": "Apple notifies customers when their account information is sought by legal process, unless prohibited or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.icloud.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.icloud.com",
          "note": "Grade A+ (130/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:39:49.183Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "infomaniak-kdrive",
      "category": "cloud-storage",
      "name": "Infomaniak kDrive",
      "description": "Cloud storage from Swiss company Infomaniak, hosted in its own data centers in Switzerland, with open-source desktop and mobile apps.",
      "website": "https://www.infomaniak.com/en/ksuite/kdrive",
      "source": "https://github.com/Infomaniak/desktop-kDrive",
      "license": "GPL-3.0",
      "platforms": [
        "web",
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 41,
      "coverage": 100,
      "summary": "Infomaniak kDrive scores 41 out of 100 (grade D) on the encrypted cloud storage criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It partly meets open source and independent audit. It does not meet no trackers or telemetry, transparency report, tells users about requests and security headers. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C-.",
      "url": "https://privacyratings.com/cloud-storage/infomaniak-kdrive/",
      "markdown": "https://privacyratings.com/cloud-storage/infomaniak-kdrive/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/Infomaniak/desktop-kDrive/blob/master/LICENSE",
          "note": "Desktop and mobile apps are open source under GPL-3.0. The server is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.infomaniak.com/en/legal/confidentiality-policy",
          "note": "Traffic is measured with self-hosted Matomo, but with consent the website also loads Google Ads and other advertising partners' tracking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.infomaniak.com/en/ksuite/kdrive/prices",
          "note": "Funded by paid plans, with no ads in the service."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.infomaniak.com/en/certifications",
          "note": "Infomaniak is ISO 27001 certified, but only the certificate is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=kdrive.infomaniak.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=kdrive.infomaniak.com",
          "note": "Grade C- (45/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:39:49.252Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "internxt",
      "category": "cloud-storage",
      "name": "Internxt",
      "description": "End-to-end encrypted cloud storage from Spain, with open source web, desktop and mobile clients. Offers a free tier and paid plans.",
      "website": "https://internxt.com",
      "source": "https://github.com/internxt/drive-desktop",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": {
        "code": "ES",
        "name": "Spain",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 41,
      "coverage": 100,
      "summary": "Internxt scores 41 out of 100 (grade D) on the encrypted cloud storage criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It partly meets open source and independent audit. It does not meet no trackers or telemetry, transparency report, tells users about requests and security headers. It is based in Spain: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/cloud-storage/internxt/",
      "markdown": "https://privacyratings.com/cloud-storage/internxt/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/internxt/drive-desktop/blob/main/LICENSE",
          "note": "Apps are open source. The server is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://internxt.com/legal",
          "note": "The website loads Google Analytics and Google Tag Manager, and Exodus finds Google AdMob in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://internxt.com/pricing",
          "note": "Funded by paid storage plans, with no ads in the service."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://blog.internxt.com/internxt-updated-security-audit/",
          "note": "Securitum audited the apps and backend, but only a summary of the findings is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=internxt.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=internxt.com",
          "note": "Grade D- (25/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Intercom",
            "host": "widget.intercom.io",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:36.823Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "koofr",
      "category": "cloud-storage",
      "name": "Koofr",
      "description": "Cloud storage from Slovenia with web, desktop, mobile, WebDAV and rclone access. Offers optional open source client-side encryption through Koofr Vault and can connect other cloud accounts.",
      "website": "https://koofr.eu",
      "source": "https://github.com/koofr/vault",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": {
        "code": "SI",
        "name": "Slovenia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 47,
      "coverage": 100,
      "summary": "Koofr scores 47 out of 100 (grade D) on the encrypted cloud storage criteria. It meets 2 of 8 criteria: no trackers or telemetry and no ads or data sales. It partly meets open source and TLS configuration. It does not meet independent audit, transparency report, tells users about requests and security headers. It is based in Slovenia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade C+.",
      "url": "https://privacyratings.com/cloud-storage/koofr/",
      "markdown": "https://privacyratings.com/cloud-storage/koofr/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/koofr/vault/blob/main/LICENSE",
          "note": "Only some clients and libraries are open source. The service is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://koofr.eu/privacy/",
          "note": "The privacy policy states no third-party tracking tools are used on the websites or in the services, and only a login cookie is set."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://koofr.eu/pricing/",
          "note": "Funded by paid storage plans. The privacy policy states data is never sold or given to advertisers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=koofr.eu&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=koofr.eu",
          "note": "Grade C+ (60/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "C+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:06:02.826Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mega",
      "category": "cloud-storage",
      "name": "MEGA",
      "description": "End-to-end encrypted cloud storage and file sharing service with desktop, mobile and web apps and source-available clients.",
      "website": "https://mega.io",
      "source": "https://github.com/meganz/android",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "HU",
        "name": "Hungary",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "MEGA scores 38 out of 100 (grade F) on the encrypted cloud storage criteria. It meets 2 of 8 criteria: transparency report and TLS configuration. It partly meets open source and security headers. It does not meet no trackers or telemetry, no ads or data sales, independent audit and tells users about requests. It is based in Hungary: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/cloud-storage/mega/",
      "markdown": "https://privacyratings.com/cloud-storage/mega/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/meganz/android/blob/master/LICENCE.md",
          "note": "Client source is published under the MEGA Limited Code Review Licence, which is not OSI-approved. The server is closed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/mega.privacy.android.app/latest/",
          "note": "The Android app includes Google AdMob, Firebase Analytics and Crashlytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://mega.io/privacy",
          "note": "MEGA may serve ads in its services through third-party advertising companies and uses usage data for marketing."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mega.io/transparency",
          "note": "Publishes a yearly transparency report with counts of legal orders and other requests."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mega.nz&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mega.nz",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:39:49.356Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "microsoft-onedrive",
      "category": "cloud-storage",
      "name": "Microsoft OneDrive",
      "description": "Cloud storage from Microsoft, built into Windows and Microsoft 365, with desktop, mobile and web apps. Files are encrypted at rest with keys Microsoft holds, not end-to-end.",
      "website": "https://www.microsoft.com/en-us/microsoft-365/onedrive/online-cloud-storage",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 44,
      "coverage": 100,
      "summary": "Microsoft OneDrive scores 44 out of 100 (grade D) on the encrypted cloud storage criteria. It meets 4 of 8 criteria: no ads or data sales, transparency report, tells users about requests and TLS configuration. It does not meet open source, no trackers or telemetry, independent audit and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/cloud-storage/microsoft-onedrive/",
      "markdown": "https://privacyratings.com/cloud-storage/microsoft-onedrive/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "Microsoft collects required diagnostic and usage data that cannot be turned off, and uses data about users for personalized advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "No ads in OneDrive, and Microsoft states it does not use files stored in cloud storage to target ads. Extra storage is sold as a subscription."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit of consumer OneDrive is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Publishes counts of government requests for consumer data, including OneDrive, twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Microsoft gives prior notice to consumers whose data is requested, except where prohibited by law or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=onedrive.live.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=onedrive.live.com",
          "note": "Grade D- (25/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:39:49.422Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "pcloud",
      "category": "cloud-storage",
      "name": "pCloud",
      "description": "Cloud storage from Switzerland with desktop, mobile and web apps. Client-side encryption covers only a separate encrypted folder that needs the paid pCloud Encryption add-on.",
      "website": "https://www.pcloud.com",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "pCloud scores 25 out of 100 (grade F) on the encrypted cloud storage criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/cloud-storage/pcloud/",
      "markdown": "https://privacyratings.com/cloud-storage/pcloud/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.pcloud.pcloud/latest/",
          "note": "The Android app includes Google Firebase Analytics and Crashlytics, and the privacy policy mentions advertising and analytics partners."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.pcloud.com/privacy_policy.html",
          "note": "Funded by paid storage plans, with no ads in the service. pCloud states it does not sell personal information."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=my.pcloud.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=my.pcloud.com",
          "note": "Grade F (20/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:39:49.545Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "peergos",
      "category": "cloud-storage",
      "name": "Peergos",
      "description": "Peer-to-peer, end-to-end encrypted file storage and sharing platform with fine-grained access control. Use the hosted peergos.net service or self-host the open source server.",
      "website": "https://peergos.org",
      "source": "https://github.com/Peergos/Peergos",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 75,
      "coverage": 100,
      "summary": "Peergos scores 75 out of 100 (grade B) on the encrypted cloud storage criteria. It meets 5 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, independent audit and TLS configuration. It does not meet transparency report, tells users about requests and security headers. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/cloud-storage/peergos/",
      "markdown": "https://privacyratings.com/cloud-storage/peergos/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Peergos/Peergos/blob/master/Licence.txt",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://peergos.net/privacy.html",
          "note": "The privacy policy states no cookies or local data are set in the browser, and only data needed to run the account is collected."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://peergos.org/about",
          "note": "Non-profit funded by subscriptions, donations and grants, with no investors or advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Peergos/Peergos/blob/master/audits/Peergos%20penetration%20test%20report%202024%201.0.pdf",
          "note": "Radically Open Security published a full penetration test report. An earlier Cure53 audit is also public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=peergos.org&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=peergos.org",
          "note": "Grade C (55/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:03:54.681Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "proton-drive",
      "category": "cloud-storage",
      "name": "Proton Drive",
      "description": "End-to-end encrypted cloud storage from Swiss company Proton, with open-source apps for web, desktop and mobile.",
      "website": "https://proton.me/drive",
      "source": "https://github.com/ProtonMail/WebClients",
      "license": "GPL-3.0",
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 75,
      "coverage": 100,
      "summary": "Proton Drive scores 75 out of 100 (grade B) on the encrypted cloud storage criteria. It meets 5 of 8 criteria: no ads or data sales, transparency report, tells users about requests, TLS configuration and security headers. It partly meets open source, no trackers or telemetry and independent audit. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/cloud-storage/proton-drive/",
      "markdown": "https://privacyratings.com/cloud-storage/proton-drive/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/ProtonMail/WebClients/blob/main/LICENSE",
          "note": "Apps are open source under GPL-3.0. The server is not."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://proton.me/legal/privacy",
          "note": "Website analytics are self-hosted. The apps include crash reporting, such as Sentry in the Android app, which is on by default and can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://proton.me/drive/pricing",
          "note": "Funded by paid plans, with no ads on any plan."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://proton.me/drive/security",
          "note": "Securitum audited the Proton Drive apps and Proton links the report, but its date could not be confirmed. Proton's SOC 2 Type II report is not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://proton.me/legal/transparency",
          "note": "Publishes yearly counts of legal orders received, complied with and contested."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://proton.me/legal/law-enforcement",
          "note": "Targeted users are notified of data requests, with delays only when Swiss law, a court order or a risk to life requires it."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=drive.proton.me&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=drive.proton.me",
          "note": "Grade A+ (115/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:39:49.598Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "sync-com",
      "category": "cloud-storage",
      "name": "Sync.com",
      "description": "End-to-end encrypted cloud storage and file sharing from Canada, with desktop, mobile and web apps.",
      "website": "https://www.sync.com",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 38,
      "coverage": 100,
      "summary": "Sync.com scores 38 out of 100 (grade F) on the encrypted cloud storage criteria. It meets 3 of 8 criteria: no ads or data sales, tells users about requests and TLS configuration. It partly meets transparency report. It does not meet open source, no trackers or telemetry, independent audit and security headers. It is based in Canada: Five Eyes member. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C-.",
      "url": "https://privacyratings.com/cloud-storage/sync-com/",
      "markdown": "https://privacyratings.com/cloud-storage/sync-com/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.sync.mobileapp/latest/",
          "note": "The Android app includes Google Firebase Analytics, Crashlytics, Mixpanel and Sentry, and the website loads Google and Facebook advertising tags."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.sync.com/pricing-individual/",
          "note": "Funded by paid plans, with no ads in the service."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.sync.com/privacy/",
          "note": "The privacy policy explains how legal requests are verified and answered, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.sync.com/privacy/",
          "note": "Sync commits to reasonable efforts to notify users before their information is disclosed, within the bounds of the law."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=cp.sync.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=cp.sync.com",
          "note": "Grade C- (45/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "no-cache.hubspot.com",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "snap.licdn.com",
            "effect": "no"
          },
          {
            "name": "Meta Pixel",
            "host": "www.facebook.com",
            "effect": "no"
          },
          {
            "name": "Reddit Pixel",
            "host": "www.redditstatic.com",
            "effect": "no"
          },
          {
            "name": "X (Twitter) Pixel",
            "host": "static.ads-twitter.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:39:49.667Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "tresorit",
      "category": "cloud-storage",
      "name": "Tresorit",
      "description": "End-to-end encrypted cloud storage, file sync and sharing service based in Switzerland, with desktop, mobile and web apps aimed mainly at businesses.",
      "website": "https://tresorit.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 44,
      "coverage": 100,
      "summary": "Tresorit scores 44 out of 100 (grade D) on the encrypted cloud storage criteria. It meets 3 of 8 criteria: no ads or data sales, TLS configuration and security headers. It partly meets independent audit and transparency report. It does not meet open source, no trackers or telemetry and tells users about requests. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/cloud-storage/tresorit/",
      "markdown": "https://privacyratings.com/cloud-storage/tresorit/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Analytics, Google Tag Manager, Hotjar and Meta Pixel."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tresorit.com/legal/privacy-policy",
          "note": "Funded by paid subscriptions. The privacy policy states personal data is never sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://tresorit.com/security",
          "note": "Certified to ISO 27001 by TÜV Rheinland, but no full audit report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://tresorit.com/blog/tresorits-updated-transparency-report-from-january-2019-to-november-2021",
          "note": "A transparency report with request counts was published, but it is not updated every year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=tresorit.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=tresorit.com",
          "note": "Grade A+ (105/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Hotjar",
            "host": "script.hotjar.com",
            "effect": "no"
          },
          {
            "name": "Meta Pixel",
            "host": "www.facebook.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:03:54.764Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "croc",
      "category": "file-sharing",
      "name": "croc",
      "description": "Open source command-line tool for sending files and folders between two computers using a short code phrase, with end-to-end encryption and a relay server.",
      "website": "https://github.com/schollz/croc",
      "source": "https://github.com/schollz/croc",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "croc scores 80 out of 100 (grade B) on the file sharing criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-sharing/croc/",
      "markdown": "https://privacyratings.com/file-sharing/croc/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/schollz/croc/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/schollz/croc/blob/main/src/publicrelay/umami.go",
          "note": "No third-party trackers, and the client sends no telemetry. Relay servers can report aggregate event counts to Umami, without IP addresses or client identifiers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/schollz",
          "note": "Free software funded by GitHub Sponsors donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:52.118Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "localsend",
      "category": "file-sharing",
      "name": "LocalSend",
      "description": "Open source app for sending files and messages between nearby devices over the local network, without an internet connection or account.",
      "website": "https://localsend.org",
      "source": "https://github.com/localsend/localsend",
      "license": "Apache-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "LocalSend scores 80 out of 100 (grade B) on the file sharing criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-sharing/localsend/",
      "markdown": "https://privacyratings.com/file-sharing/localsend/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/localsend/localsend/blob/main/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://localsend.org/privacy",
          "note": "The privacy policy states the app does not collect any personal or non-personal data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://localsend.org/donate",
          "note": "Free software funded by donations through GitHub Sponsors and in-app donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:52.307Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "lufi",
      "category": "file-sharing",
      "name": "Lufi",
      "description": "Self-hosted web app for uploading and sharing files with end-to-end encryption in the browser, with expiring download links. Written in Perl.",
      "website": "https://framagit.org/fiat-tux/hat-softwares/lufi",
      "source": "https://framagit.org/fiat-tux/hat-softwares/lufi",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Lufi scores 80 out of 100 (grade B) on the file sharing criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-sharing/lufi/",
      "markdown": "https://privacyratings.com/file-sharing/lufi/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://framagit.org/fiat-tux/hat-softwares/lufi/-/blob/master/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://framagit.org/fiat-tux/hat-softwares/lufi/-/blob/master/lufi.conf.template",
          "note": "No telemetry in the source code. A Matomo image tracker is available only if the operator enables it, and is off by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://framagit.org/fiat-tux/hat-softwares/lufi",
          "note": "Free software supported by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:52.266Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "magic-wormhole",
      "category": "file-sharing",
      "name": "Magic Wormhole",
      "description": "Open source Python library and command-line tool for sending files, folders and text between computers using short one-time codes, with end-to-end encryption.",
      "website": "https://magic-wormhole.readthedocs.io/en/latest/",
      "source": "https://github.com/magic-wormhole/magic-wormhole",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Magic Wormhole scores 80 out of 100 (grade B) on the file sharing criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-sharing/magic-wormhole/",
      "markdown": "https://privacyratings.com/file-sharing/magic-wormhole/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/magic-wormhole/magic-wormhole/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/magic-wormhole/magic-wormhole",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/magic-wormhole/magic-wormhole",
          "note": "Free volunteer-maintained software with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:52.356Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "onionshare",
      "category": "file-sharing",
      "name": "OnionShare",
      "description": "Open source desktop and mobile tool that shares files, hosts websites and runs chat rooms over Tor onion services, directly from the user's device.",
      "website": "https://onionshare.org",
      "source": "https://github.com/onionshare/onionshare",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 90,
      "coverage": 100,
      "summary": "OnionShare scores 90 out of 100 (grade A) on the file sharing criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It partly meets independent audit. Automated tests: Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/file-sharing/onionshare/",
      "markdown": "https://privacyratings.com/file-sharing/onionshare/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/onionshare/onionshare/blob/main/LICENSE.txt",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://onionshare.org/privacy/",
          "note": "The desktop and mobile apps collect no analytics, and website logs exclude IP addresses."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/lockdown-systems",
          "note": "Free software funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/onionshare/onionshare/blob/main/security/2021%20Penetration%20Test%20Report.pdf",
          "note": "A full penetration test report by Radically Open Security is public but older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:28.438Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "pairdrop",
      "category": "file-sharing",
      "name": "PairDrop",
      "description": "Open source web app for sending files and text between devices on the same network or paired devices over WebRTC, usable at pairdrop.net or self-hosted. A fork of Snapdrop.",
      "website": "https://pairdrop.net",
      "source": "https://github.com/schlagmichdoch/PairDrop",
      "license": "GPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "PairDrop scores 80 out of 100 (grade B) on the file sharing criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-sharing/pairdrop/",
      "markdown": "https://privacyratings.com/file-sharing/pairdrop/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/schlagmichdoch/PairDrop/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/schlagmichdoch/PairDrop",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://buymeacoffee.com/pairdrop",
          "note": "Free software funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:52.926Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "send",
      "category": "file-sharing",
      "name": "Send",
      "description": "Self-hosted web app for sharing files with end-to-end encryption through expiring links. A community-maintained fork of Mozilla's discontinued Firefox Send.",
      "website": "https://gitlab.com/timvisee/send",
      "source": "https://gitlab.com/timvisee/send",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Send scores 80 out of 100 (grade B) on the file sharing criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-sharing/send/",
      "markdown": "https://privacyratings.com/file-sharing/send/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/timvisee/send/-/blob/master/LICENSE",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/timvisee/send/-/blob/master/server/config.js",
          "note": "No analytics in the source code. Sentry error reporting only runs if the operator configures it."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://timvisee.com/donate/",
          "note": "Free software funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:38:52.356Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "swisstransfer",
      "category": "file-sharing",
      "name": "SwissTransfer",
      "description": "Free file transfer service from Infomaniak for sending large files by link or email without an account, with files stored in Switzerland for a limited time.",
      "website": "https://www.swisstransfer.com/en",
      "source": "https://github.com/Infomaniak/android-SwissTransfer",
      "license": "GPL-3.0",
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 47,
      "coverage": 100,
      "summary": "SwissTransfer scores 47 out of 100 (grade D) on the file sharing criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It partly meets open source, no trackers or telemetry and security headers. It does not meet independent audit, transparency report and tells users about requests. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/file-sharing/swisstransfer/",
      "markdown": "https://privacyratings.com/file-sharing/swisstransfer/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/Infomaniak/android-SwissTransfer/blob/main/LICENSE",
          "note": "The mobile apps are GPL-3.0, but the server is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.infomaniak.swisstransfer/latest/",
          "note": "The Android app includes Matomo analytics and Sentry crash reporting, and the website uses Matomo, which Infomaniak hosts on its own servers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.infomaniak.com/en/legal/confidentiality-policy",
          "note": "Funded by Infomaniak's paid services. The site promotes Infomaniak products but shows no third-party ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.swisstransfer.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.swisstransfer.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:39:49.742Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "wetransfer",
      "category": "file-sharing",
      "name": "WeTransfer",
      "description": "Hosted service for sending large files by email or download link, with accounts for storing and managing transfers. Owned by Bending Spoons.",
      "website": "https://wetransfer.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 28,
      "coverage": 100,
      "summary": "WeTransfer scores 28 out of 100 (grade F) on the file sharing criteria. It meets 2 of 8 criteria: TLS configuration and security headers. It partly meets transparency report and tells users about requests. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the Netherlands: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/file-sharing/wetransfer/",
      "markdown": "https://privacyratings.com/file-sharing/wetransfer/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://wetransfer.com/explore/legal/privacy",
          "note": "The privacy policy says WeTransfer and its advertising partners place advertising cookies, pixels and SDKs."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://wetransfer.com/explore/legal/privacy",
          "note": "The service shows ads, including personalized ads when users consent, and shares data with advertising partners."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://wetransfer.com/explore/legal/law-enforcement",
          "note": "Publishes guidelines for law enforcement requests, but no request counts."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://wetransfer.com/explore/legal/law-enforcement",
          "note": "The guidelines say WeTransfer may notify users when permitted or required, without a firm promise."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=wetransfer.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=wetransfer.com",
          "note": "Grade A+ (115/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:39:49.805Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "wormhole",
      "category": "file-sharing",
      "name": "Wormhole",
      "description": "Web service for sending files with end-to-end encryption through a share link, transferred peer-to-peer or through temporary server storage. Run by WebTorrent, LLC.",
      "website": "https://wormhole.app",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Wormhole scores 50 out of 100 (grade D) on the file sharing criteria. It meets 4 of 8 criteria: no trackers or telemetry, no ads or data sales, TLS configuration and security headers. It does not meet open source, independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/file-sharing/wormhole/",
      "markdown": "https://privacyratings.com/file-sharing/wormhole/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://wormhole.app/security",
          "note": "Closed source. Only the encryption library, wormhole-crypto, is published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://wormhole.app/security",
          "note": "The security page states there are no ads and no tracking in Wormhole."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://wormhole.app/legal",
          "note": "No ads, and the terms state Wormhole does not sell, rent or monetize personal data or content."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=wormhole.app&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=wormhole.app",
          "note": "Grade A+ (145/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:39:49.868Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "beaver-habit-tracker",
      "category": "habit-trackers",
      "name": "Beaver Habit Tracker",
      "description": "Open source web app for tracking daily habits without goals or streak targets, available as a paid hosted service or self-hosted with Docker.",
      "website": "https://beaverhabits.com",
      "source": "https://github.com/daya0576/beaverhabits",
      "license": "BSD-3-Clause",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Beaver Habit Tracker scores 80 out of 100 (grade B) on the habit trackers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/habit-trackers/beaver-habit-tracker/",
      "markdown": "https://privacyratings.com/habit-trackers/beaver-habit-tracker/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/daya0576/beaverhabits/blob/main/LICENSE",
          "note": "BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/daya0576/beaverhabits/blob/main/beaverhabits/frontend/layout.py",
          "note": "No third-party trackers. The hosted service's Umami analytics are cookieless and aggregate-only, and self-hosted instances have none unless the operator adds them."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/daya0576/beaverhabits",
          "note": "Funded by paid plans for the hosted service, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:53.482Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "habitica",
      "category": "habit-trackers",
      "name": "Habitica",
      "description": "Habit and task tracker that presents habits, dailies and to-dos as a role-playing game, with avatars, rewards and group challenges. Run by HabitRPG, Inc.",
      "website": "https://habitica.com",
      "source": "https://github.com/HabitRPG/habitica",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Habitica scores 30 out of 100 (grade F) on the habit trackers criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/habit-trackers/habitica/",
      "markdown": "https://privacyratings.com/habit-trackers/habitica/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/HabitRPG/habitica/blob/develop/LICENSE",
          "note": "GPL-3.0 for the server, web app and mobile apps."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://habitica.com/static/privacy",
          "note": "The privacy policy lists Google Analytics and Amplitude, and the Exodus report finds Google Crashlytics in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://habitica.com/static/privacy",
          "note": "Funded by subscriptions and in-app purchases, but the privacy policy says personal information is used for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:53.303Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "loop-habit-tracker",
      "category": "habit-trackers",
      "name": "Loop Habit Tracker",
      "description": "Open source Android app for tracking habits with reminders, charts and statistics. Data is stored only on the device.",
      "website": "https://loophabits.org",
      "source": "https://github.com/iSoron/uhabits",
      "license": "GPL-3.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Loop Habit Tracker scores 80 out of 100 (grade B) on the habit trackers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/habit-trackers/loop-habit-tracker/",
      "markdown": "https://privacyratings.com/habit-trackers/loop-habit-tracker/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/iSoron/uhabits/blob/master/LICENSE.txt",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://loophabits.org/privacy",
          "note": "The privacy policy states the app includes no advertising libraries or third-party analytics, and the Exodus report finds no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://loophabits.org/privacy",
          "note": "Free software with no advertising libraries, and data is not shared with third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:53.890Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "openhabittracker",
      "category": "habit-trackers",
      "name": "OpenHabitTracker",
      "description": "Open source habit tracker with notes and tasks for web, desktop and mobile. Data stays on the device, with optional sync through a self-hosted Docker server and no account required.",
      "website": "https://openhabittracker.net",
      "source": "https://github.com/Jinjinov/OpenHabitTracker",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "OpenHabitTracker scores 50 out of 100 (grade D) on the habit trackers criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/habit-trackers/openhabittracker/",
      "markdown": "https://privacyratings.com/habit-trackers/openhabittracker/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Jinjinov/OpenHabitTracker/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics and Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://openhabittracker.net/",
          "note": "Free app with no ads, no account and no subscription."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:09.350Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "streaks",
      "category": "habit-trackers",
      "name": "Streaks",
      "description": "Paid habit-forming to-do list for Apple devices that tracks daily task streaks, with Apple Health integration and iCloud sync. Made by Crunchy Bagel.",
      "website": "https://streaksapp.com",
      "license": null,
      "platforms": [
        "ios",
        "macos"
      ],
      "jurisdiction": {
        "code": "AU",
        "name": "Australia",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Streaks scores 20 out of 100 (grade F) on the habit trackers criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in Australia: Five Eyes member; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/habit-trackers/streaks/",
      "markdown": "https://privacyratings.com/habit-trackers/streaks/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://streaksapp.com/privacy.html",
          "note": "The privacy policy says anonymous data is sent to an external crash reporting service, and the only way to opt out is to uninstall the app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://apps.apple.com/us/app/streaks/id963034692",
          "note": "Paid app with no ads, and the privacy policy says data is not shared with third parties beyond crash reporting."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:38:53.745Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "apple-maps",
      "category": "maps",
      "name": "Apple Maps",
      "description": "Apple's built-in mapping and navigation app for Apple devices, with turn-by-turn directions, transit, place information and a web version.",
      "website": "https://www.apple.com/maps/",
      "license": null,
      "platforms": [
        "ios",
        "macos",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Apple Maps scores 25 out of 100 (grade F) on the maps and navigation criteria. It partly meets no trackers or telemetry and no ads or data sales. It does not meet open source and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/maps/apple-maps/",
      "markdown": "https://privacyratings.com/maps/apple-maps/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/apple-maps/",
          "note": "No third-party trackers, but Apple collects usage metrics by default with identifiers not tied to the Apple Account."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/apple-maps/",
          "note": "Maps shows Apple-delivered ads selected from contextual information such as search terms and map view, not tied to the Apple Account."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:38:53.681Z"
      },
      "last_modified": "2026-10-01T06:56:31Z"
    },
    {
      "slug": "comaps",
      "category": "maps",
      "name": "CoMaps",
      "description": "Community-run, non-profit offline maps and navigation app built on OpenStreetMap data. Search and routing run on the device.",
      "website": "https://www.comaps.app",
      "source": "https://codeberg.org/comaps/comaps",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "CoMaps scores 80 out of 100 (grade B) on the maps and navigation criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/maps/comaps/",
      "markdown": "https://privacyratings.com/maps/comaps/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/comaps/comaps/src/branch/main/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.comaps.app/privacy/",
          "note": "The policy states the app does not track users or collect personal data, and the Exodus report finds no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.comaps.app/donate/",
          "note": "Non-profit project funded by donations, with no advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:08.273Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "google-maps",
      "category": "maps",
      "name": "Google Maps",
      "description": "Google's mapping and navigation service with traffic, public transit, Street View, business listings and reviews, available on the web and as mobile apps.",
      "website": "https://www.google.com/maps",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Google Maps scores 0 out of 100 (grade F) on the maps and navigation criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/maps/google-maps/",
      "markdown": "https://privacyratings.com/maps/google-maps/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.google.android.apps.maps/latest/",
          "note": "The Exodus report finds Google Firebase Analytics in the Android app, and Google's privacy policy covers collection of location and activity data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Funded by advertising. The privacy policy says Google uses collected data to show personalized ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:38.491Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "here-wego",
      "category": "maps",
      "name": "HERE WeGo",
      "description": "Free maps and navigation app from HERE Technologies, with driving, transit and walking directions, offline maps and a web version.",
      "website": "https://wego.here.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "HERE WeGo scores 0 out of 100 (grade F) on the maps and navigation criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the Netherlands: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/maps/here-wego/",
      "markdown": "https://privacyratings.com/maps/here-wego/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.here.app.maps/latest/",
          "note": "The Exodus report finds Facebook Login and Google Crashlytics, and the privacy supplement describes third-party analytics and advertising cookies and SDKs."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.here.com/en-gb/privacy/here-wego-here-application-or-here-maps-privacy-supplement-updated",
          "note": "The privacy supplement says collected data, including advertiser IDs, is used to serve and measure advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:38.622Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "magic-earth",
      "category": "maps",
      "name": "Magic Earth",
      "description": "Navigation app using OpenStreetMap data, with offline maps, traffic, public transit and activity recording, and paid premium features. Run by Magic Lane International B.V.",
      "website": "https://www.magicearth.com",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Magic Earth scores 35 out of 100 (grade F) on the maps and navigation criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets no trackers or telemetry. It does not meet open source and independent audit. It is based in the Netherlands: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/maps/magic-earth/",
      "markdown": "https://privacyratings.com/maps/magic-earth/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.generalmagic.magicearth/latest/",
          "note": "The Exodus report finds no trackers, but the terms say location data and device identifiers are used for analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.magicearth.com/terms-and-conditions",
          "note": "Funded by premium licenses, and the privacy policy says information is not sold or rented to marketers or third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:39.478Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mapy-com",
      "category": "maps",
      "name": "Mapy.com",
      "description": "Map and navigation service from the Czech company Seznam.cz, formerly Mapy.cz, with offline maps, tourist and cycling routes, and a web version. Coverage is most detailed in Central Europe.",
      "website": "https://mapy.com/en/",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "CZ",
        "name": "Czechia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Mapy.com scores 0 out of 100 (grade F) on the maps and navigation criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in Czechia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/maps/mapy-com/",
      "markdown": "https://privacyratings.com/maps/mapy-com/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/cz.seznam.mapy/latest/",
          "note": "The Exodus report finds AppsFlyer, Google Firebase Analytics, Google Crashlytics, Huawei Mobile Services and OneSignal in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://o-seznam.cz/pravni-informace/ochrana-udaju/",
          "note": "Seznam's privacy policy covers personalized advertising, and the website loads Seznam's ad platform scripts."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:39.063Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "openstreetmap",
      "category": "maps",
      "name": "OpenStreetMap",
      "description": "Collaborative world map built by volunteers and published as open data under the ODbL. The website offers map browsing, search, directions and editing, and the data powers many other map apps.",
      "website": "https://www.openstreetmap.org",
      "source": "https://github.com/openstreetmap/openstreetmap-website",
      "license": "GPL-2.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "OpenStreetMap scores 65 out of 100 (grade C) on the maps and navigation criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/maps/openstreetmap/",
      "markdown": "https://privacyratings.com/maps/openstreetmap/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/openstreetmap/openstreetmap-website/blob/master/LICENSE",
          "note": "GPL-2.0 for the website software. Map data is under the ODbL."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://osmfoundation.org/wiki/Privacy_Policy",
          "note": "No third-party trackers, but the website runs self-hosted Matomo analytics with shortened IP addresses."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://supporting.openstreetmap.org/",
          "note": "Run by the non-profit OpenStreetMap Foundation, funded by donations and membership, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:39.087Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "organic-maps",
      "category": "maps",
      "name": "Organic Maps",
      "description": "Offline maps and navigation app built on OpenStreetMap data, run by Organic Maps OÜ in Estonia. Governance disputes among contributors led to the CoMaps fork.",
      "website": "https://organicmaps.app",
      "source": "https://github.com/organicmaps/organicmaps",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "EE",
        "name": "Estonia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Organic Maps scores 80 out of 100 (grade B) on the maps and navigation criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Estonia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/maps/organic-maps/",
      "markdown": "https://privacyratings.com/maps/organic-maps/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/organicmaps/organicmaps/blob/master/LICENSES/Apache-2.0.txt",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://organicmaps.app/privacy/",
          "note": "No third-party trackers, and the app collects no data. The website's Cloudflare Web Analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://organicmaps.app/donate/",
          "note": "Funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:59:38.714Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "osmand",
      "category": "maps",
      "name": "OsmAnd",
      "description": "Offline maps and navigation app built on OpenStreetMap data, with routing for driving, cycling and hiking, contour lines, GPX tracks and plugins. Developed by OsmAnd BV.",
      "website": "https://osmand.net",
      "source": "https://github.com/osmandapp/OsmAnd",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "OsmAnd scores 50 out of 100 (grade D) on the maps and navigation criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source and no trackers or telemetry. It does not meet independent audit. It is based in the Netherlands: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/maps/osmand/",
      "markdown": "https://privacyratings.com/maps/osmand/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/osmandapp/OsmAnd/blob/master/LICENSE",
          "note": "Code is GPL-3.0, but UI design and layouts are CC BY-NC-ND and some resources are proprietary."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://osmand.net/docs/legal/privacy-policy/",
          "note": "No third-party trackers, and the Exodus report finds none, but the app collects aggregated usage statistics, configurable in settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://osmand.net/docs/legal/privacy-policy/",
          "note": "Funded by paid features and subscriptions. The privacy policy states user data is not shared or sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:39.365Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "waze",
      "category": "maps",
      "name": "Waze",
      "description": "Community-driven navigation app owned by Google, with live traffic, hazard and police reports shared by drivers, route suggestions and fuel prices.",
      "website": "https://www.waze.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "IL",
        "name": "Israel",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Waze scores 0 out of 100 (grade F) on the maps and navigation criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in Israel: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/maps/waze/",
      "markdown": "https://privacyratings.com/maps/waze/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.waze/latest/",
          "note": "The Exodus report finds Google Crashlytics in the Android app, and the privacy policy covers collection of location, device and ad interaction data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://support.google.com/waze/answer/12075406",
          "note": "Funded by advertising. The privacy policy says data is collected to show relevant ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:39.148Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dragon",
      "category": "accessibility",
      "name": "Dragon",
      "description": "Commercial speech recognition software for dictation and voice control of the computer, sold as Dragon Professional for Windows and Dragon Anywhere for mobile. Made by Nuance, a Microsoft company.",
      "website": "https://dragon.nuance.com/en-us/dragon.html",
      "license": null,
      "platforms": [
        "windows",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Dragon scores 0 out of 100 (grade F) on the accessibility criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/accessibility/dragon/",
      "markdown": "https://privacyratings.com/accessibility/dragon/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://dragon.nuance.com/en-us/cookies.html",
          "note": "The cookie statement says third-party analytics and advertising network cookies are used on Nuance websites."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://dragon.nuance.com/en-us/cookies.html",
          "note": "Sold as paid software, but the cookie statement says third-party advertising networks use cookies to target Nuance ads to visitors on other sites."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:39.223Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "espeak-ng",
      "category": "accessibility",
      "name": "eSpeak NG",
      "description": "Open source speech synthesizer supporting more than 100 languages and accents, used as a text-to-speech engine by screen readers such as NVDA and Orca.",
      "website": "https://github.com/espeak-ng/espeak-ng",
      "source": "https://github.com/espeak-ng/espeak-ng",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "eSpeak NG scores 80 out of 100 (grade B) on the accessibility criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/accessibility/espeak-ng/",
      "markdown": "https://privacyratings.com/accessibility/espeak-ng/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/espeak-ng/espeak-ng/blob/master/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/espeak-ng/espeak-ng",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/espeak-ng/espeak-ng",
          "note": "Free volunteer-maintained software with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:59:39.063Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nvda",
      "category": "accessibility",
      "name": "NVDA",
      "description": "Free, open source screen reader for Windows that reads screen content aloud by speech or braille display. Developed by the Australian non-profit NV Access.",
      "website": "https://www.nvaccess.org",
      "source": "https://github.com/nvaccess/nvda",
      "license": null,
      "platforms": [
        "windows"
      ],
      "jurisdiction": {
        "code": "AU",
        "name": "Australia",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "NVDA scores 80 out of 100 (grade B) on the accessibility criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Australia: Five Eyes member; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/accessibility/nvda/",
      "markdown": "https://privacyratings.com/accessibility/nvda/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nvaccess/nvda/blob/master/copying.txt",
          "note": "GPL-2.0-or-later, with two exceptions for linking."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://download.nvaccess.org/documentation/userGuide.html#UsageStatsDialog",
          "note": "Usage statistics are only sent if the user agrees in a dialog on first start, and can be turned off in settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.nvaccess.org/support-us/",
          "note": "Developed by a non-profit funded by donations, training sales and grants, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:40.104Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "orca",
      "category": "accessibility",
      "name": "Orca",
      "description": "Free, open source screen reader for Linux desktops that gives access to applications through speech and braille, using the AT-SPI accessibility framework. Part of the GNOME project.",
      "website": "https://orca.gnome.org",
      "source": "https://gitlab.gnome.org/GNOME/orca",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Orca scores 80 out of 100 (grade B) on the accessibility criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/accessibility/orca/",
      "markdown": "https://privacyratings.com/accessibility/orca/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/GNOME/orca/blob/main/COPYING",
          "note": "LGPL-2.1."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/GNOME/orca",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://donate.gnome.org/en/",
          "note": "Part of the GNOME project, supported by donations to the non-profit GNOME Foundation, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:40.351Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "speech-note",
      "category": "accessibility",
      "name": "Speech Note",
      "description": "Open source Linux app for taking, reading and translating notes with offline speech-to-text, text-to-speech and machine translation. Processing runs locally on the computer.",
      "website": "https://github.com/mkiol/dsnote",
      "source": "https://github.com/mkiol/dsnote",
      "license": "MPL-2.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Speech Note scores 80 out of 100 (grade B) on the accessibility criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/accessibility/speech-note/",
      "markdown": "https://privacyratings.com/accessibility/speech-note/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mkiol/dsnote/blob/main/LICENSE",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mkiol/dsnote",
          "note": "The README states text and voice processing runs offline and no data is sent to the internet."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/mkiol/dsnote",
          "note": "Free software supported by donations through Ko-fi and Liberapay, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:59:39.149Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vocalinux",
      "category": "accessibility",
      "name": "Vocalinux",
      "description": "Offline voice dictation for Linux on X11 and Wayland that types speech into the focused app. Speech recognition runs locally with engines such as whisper.cpp and VOSK.",
      "website": "https://vocalinux.com",
      "source": "https://github.com/VocaHQ/vocalinux",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Vocalinux scores 50 out of 100 (grade D) on the accessibility criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/accessibility/vocalinux/",
      "markdown": "https://privacyratings.com/accessibility/vocalinux/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/VocaHQ/vocalinux/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/VocaHQ/vocalinux/blob/main/README.md",
          "note": "Free AGPL-licensed desktop app with no ads or account."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:08.143Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bitbucket",
      "category": "code-hosting",
      "name": "Bitbucket",
      "description": "Git hosting service from Atlassian with pull requests, Bitbucket Pipelines CI/CD and integration with Jira and other Atlassian products.",
      "website": "https://bitbucket.org",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "AU",
        "name": "Australia",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 47,
      "coverage": 100,
      "summary": "Bitbucket scores 47 out of 100 (grade D) on the code hosting criteria. It meets 3 of 8 criteria: transparency report, tells users about requests and TLS configuration. It partly meets no ads or data sales, independent audit and security headers. It does not meet open source and no trackers or telemetry. It is based in Australia: Five Eyes member; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/code-hosting/bitbucket/",
      "markdown": "https://privacyratings.com/code-hosting/bitbucket/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.atlassian.com/legal/privacy-policy",
          "note": "The privacy policy says Atlassian and third-party advertising and analytics partners use cookies, pixels and device identifiers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.atlassian.com/legal/privacy-policy",
          "note": "Funded by subscriptions, but the privacy policy describes targeted advertising with third-party advertising partners."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.atlassian.com/trust/compliance/resources/soc2",
          "note": "Bitbucket Cloud has SOC 2 reports from an independent CPA firm, available only through Atlassian's Trust Portal."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.atlassian.com/trust/privacy/transparency-report",
          "note": "Publishes an annual transparency report with counts of government requests for user data and content removal."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.atlassian.com/trust/privacy/guidelines-for-law-enforcement",
          "note": "Policy is to notify customers of requests for their information 7 to 10 days before disclosure unless prohibited by law."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=bitbucket.org&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=bitbucket.org",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:43.750Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "codeberg",
      "category": "code-hosting",
      "name": "Codeberg",
      "description": "Non-profit Git hosting run by Codeberg e.V. in Berlin on the open source Forgejo software, with issues, pull requests, CI and static page hosting.",
      "website": "https://codeberg.org",
      "source": "https://codeberg.org/forgejo/forgejo",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 66,
      "coverage": 100,
      "summary": "Codeberg scores 66 out of 100 (grade C) on the code hosting criteria. It meets 4 of 8 criteria: open source, no trackers or telemetry, no ads or data sales and TLS configuration. It partly meets security headers. It does not meet independent audit, transparency report and tells users about requests. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/code-hosting/codeberg/",
      "markdown": "https://privacyratings.com/code-hosting/codeberg/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/forgejo/forgejo/src/branch/forgejo/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/codeberg/org/src/branch/main/PrivacyPolicy.md",
          "note": "The privacy policy states Codeberg does not use cookies or other techniques for user-targeted analytics or advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.codeberg.org/improving-codeberg/donate/",
          "note": "Run by a non-profit association funded by donations and membership fees, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=codeberg.org&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=codeberg.org",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:08.461Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "forgejo",
      "category": "code-hosting",
      "name": "Forgejo",
      "description": "Self-hosted Git forge with issues, pull requests, package registries and CI through Forgejo Actions. A community fork of Gitea, with its domains held by the non-profit Codeberg e.V.",
      "website": "https://forgejo.org",
      "source": "https://codeberg.org/forgejo/forgejo",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Forgejo scores 80 out of 100 (grade B) on the code hosting criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/code-hosting/forgejo/",
      "markdown": "https://privacyratings.com/code-hosting/forgejo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/forgejo/forgejo/src/branch/forgejo/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/forgejo/forgejo",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://forgejo.org/faq/",
          "note": "Funded by volunteer contributions, grants and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:40.611Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gitea",
      "category": "code-hosting",
      "name": "Gitea",
      "description": "Lightweight self-hosted Git service written in Go, with issues, pull requests, packages and CI through Gitea Actions. Maintained with commercial backing from CommitGo.",
      "website": "https://about.gitea.com",
      "source": "https://github.com/go-gitea/gitea",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Gitea scores 30 out of 100 (grade F) on the code hosting criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/code-hosting/gitea/",
      "markdown": "https://privacyratings.com/code-hosting/gitea/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/go-gitea/gitea/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Tag Manager and HubSpot (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://about.gitea.com/privacy-policy/",
          "note": "The software is sold with commercial support, but the website privacy policy lets third-party companies track visitors to tailor advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:28.521Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "github",
      "category": "code-hosting",
      "name": "GitHub",
      "description": "Git hosting service owned by Microsoft, with pull requests, issues, Actions CI/CD, package hosting, Pages static sites and Copilot AI features.",
      "website": "https://github.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "GitHub scores 50 out of 100 (grade D) on the code hosting criteria. It meets 4 of 8 criteria: transparency report, tells users about requests, TLS configuration and security headers. It partly meets no ads or data sales and independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
      "url": "https://privacyratings.com/code-hosting/github/",
      "markdown": "https://privacyratings.com/code-hosting/github/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. Some tools, such as GitHub Desktop and GitHub CLI, are open source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement",
          "note": "The privacy statement allows third-party cookies for interest-based advertising, and the Exodus report finds Google Firebase Analytics and Crashlytics in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement",
          "note": "Funded by subscriptions, but the privacy statement says third-party cookies may gather data for interest-based advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://docs.github.com/en/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/accessing-compliance-reports-for-your-organization",
          "note": "SOC reports and ISO/IEC 27001 certification are only available to organization owners in account settings."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://transparencycenter.github.com/",
          "note": "Publishes a transparency report with counts of requests for user information, disclosures and takedowns, with data in the github/transparency repository."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.github.com/en/site-policy/other-site-policies/guidelines-for-legal-requests-of-user-data",
          "note": "Policy is to notify affected users about requests for their account information unless prohibited by law or court order."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=github.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=github.com",
          "note": "Grade A+ (115/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "A+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:06:27.169Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gitlab",
      "category": "code-hosting",
      "name": "GitLab",
      "description": "Git hosting with CI/CD, issue tracking and project management, offered as the hosted GitLab.com service or as software to self-host.",
      "website": "https://gitlab.com",
      "source": "https://gitlab.com/gitlab-org/gitlab",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 63,
      "coverage": 100,
      "summary": "GitLab scores 63 out of 100 (grade C) on the code hosting criteria. It meets 4 of 8 criteria: open source, transparency report, tells users about requests and TLS configuration. It partly meets no ads or data sales and independent audit. It does not meet no trackers or telemetry and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/code-hosting/gitlab/",
      "markdown": "https://privacyratings.com/code-hosting/gitlab/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/gitlab-org/gitlab/-/blob/master/LICENSE",
          "note": "All code is public, including the ee directory used by GitLab.com. The Community Edition is MIT and the Enterprise Edition code uses the source-available GitLab Enterprise Edition license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Optimizely (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://about.gitlab.com/privacy/",
          "note": "Funded by subscriptions, but the privacy statement says cookies are used for interest-based advertising based on online activity."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://trust.gitlab.com/",
          "note": "SOC 2 reports and penetration test summaries from independent auditors are only available on request through the Trust Center."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://handbook.gitlab.com/handbook/legal/privacy/transparency-reports/",
          "note": "Publishes yearly law enforcement reports with request counts by type."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://handbook.gitlab.com/handbook/legal/privacy/transparency-reports/",
          "note": "Policy is to notify users of requests for their data unless prohibited by law or a court order."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=gitlab.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=gitlab.com",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          },
          {
            "name": "Optimizely",
            "host": "cdn.optimizely.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:19:54.497Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gogs",
      "category": "code-hosting",
      "name": "Gogs",
      "description": "Lightweight self-hosted Git service written in Go, with a web interface for repositories, issues, pull requests and wikis.",
      "website": "https://gogs.io",
      "source": "https://github.com/gogs/gogs",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Gogs scores 80 out of 100 (grade B) on the code hosting criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. Automated tests: Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/code-hosting/gogs/",
      "markdown": "https://privacyratings.com/code-hosting/gogs/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gogs/gogs/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gogs/gogs",
          "note": "No telemetry or analytics in the source code. The website uses Plausible, a cookieless analytics service, and no advertising trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gogs.io/getting-started/introduction",
          "note": "Free software supported by sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:00.937Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "radicle",
      "category": "code-hosting",
      "name": "Radicle",
      "description": "Open source peer-to-peer code collaboration stack built on Git, where repositories, issues and patches are replicated between nodes and signed with cryptographic identities, with no central server.",
      "website": "https://radicle.dev",
      "source": "https://radicle.network/nodes/seed.radicle.dev/rad%3Az3gqcJUoA1n9HaHKufZs5FCSGazv5",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Radicle scores 80 out of 100 (grade B) on the code hosting criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/code-hosting/radicle/",
      "markdown": "https://privacyratings.com/code-hosting/radicle/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://radicle.network/nodes/seed.radicle.dev/rad%3Az3gqcJUoA1n9HaHKufZs5FCSGazv5/tree/LICENSE-MIT",
          "note": "MIT or Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://radicle.dev",
          "note": "No third-party trackers, and the software has no telemetry. The radicle.dev website's Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://radicle.dev/faq",
          "note": "Funded by grants from Radworks, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:59:40.292Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sourcehut",
      "category": "code-hosting",
      "name": "SourceHut",
      "description": "Git and Mercurial hosting with ticket tracking, mailing lists, wikis and a CI build service. Can be self-hosted, or used through the hosted instance at sr.ht.",
      "website": "https://sourcehut.org",
      "source": "https://git.sr.ht/~sircmpwn/git.sr.ht",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 75,
      "coverage": 100,
      "summary": "SourceHut scores 75 out of 100 (grade B) on the code hosting criteria. It meets 5 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, tells users about requests and TLS configuration. It partly meets transparency report. It does not meet independent audit and security headers. It is based in the Netherlands: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/code-hosting/sourcehut/",
      "markdown": "https://privacyratings.com/code-hosting/sourcehut/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://git.sr.ht/~sircmpwn/git.sr.ht/tree/master/item/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://man.sr.ht/privacy.md",
          "note": "The privacy policy lists no analytics and states no user information is shared with third parties apart from payment processing."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://sourcehut.org/pricing/",
          "note": "Funded by paid subscriptions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://man.sr.ht/privacy.md",
          "note": "The privacy policy describes how court orders for account data are handled, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://man.sr.ht/privacy.md",
          "note": "The privacy policy promises to notify users of court orders for their data unless the order prohibits it."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=sourcehut.org&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=sourcehut.org",
          "note": "Grade D (35/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:03:55.197Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cursor",
      "category": "code-editors",
      "name": "Cursor",
      "description": "AI code editor from Anysphere, built on a fork of VS Code, with AI chat, code completion and coding agents.",
      "website": "https://cursor.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Cursor scores 30 out of 100 (grade F) on the code editors criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/code-editors/cursor/",
      "markdown": "https://privacyratings.com/code-editors/cursor/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://cursor.com/privacy",
          "note": "The website loads Google Tag Manager and Google Analytics, and the privacy policy lists analytics providers among its vendors."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cursor.com/privacy",
          "note": "Funded by paid plans. The privacy policy states personal data is not sold, shared for cross-context behavioral advertising or used for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cursor.com/security",
          "note": "Holds a SOC 2 Type II attestation and ISO 27001 certification, but reports are only available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:40.509Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gnu-emacs",
      "category": "code-editors",
      "name": "GNU Emacs",
      "description": "Extensible text editor from the GNU Project, programmable in Emacs Lisp, with packages for code editing, Org mode, email, Git and more.",
      "website": "https://www.gnu.org/software/emacs/",
      "source": "https://savannah.gnu.org/projects/emacs",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "GNU Emacs scores 80 out of 100 (grade B) on the code editors criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/code-editors/gnu-emacs/",
      "markdown": "https://privacyratings.com/code-editors/gnu-emacs/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://cgit.git.savannah.gnu.org/cgit/emacs.git/tree/COPYING",
          "note": "GPL-3.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://savannah.gnu.org/projects/emacs",
          "note": "No telemetry or analytics in the source code, and the gnu.org website loads no third-party scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://my.fsf.org/donate",
          "note": "GNU project supported by the Free Software Foundation through donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:41.091Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "helix",
      "category": "code-editors",
      "name": "Helix",
      "description": "Modal terminal text editor written in Rust, inspired by Kakoune, with multiple selections, built-in LSP support and Tree-sitter syntax highlighting.",
      "website": "https://helix-editor.com",
      "source": "https://github.com/helix-editor/helix",
      "license": "MPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Helix scores 80 out of 100 (grade B) on the code editors criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/code-editors/helix/",
      "markdown": "https://privacyratings.com/code-editors/helix/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/helix-editor/helix/blob/master/LICENSE",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/helix-editor/helix",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/helix-editor",
          "note": "Community project funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:41.116Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "intellij-idea",
      "category": "code-editors",
      "name": "IntelliJ IDEA",
      "description": "IDE from JetBrains for Java, Kotlin and other JVM languages, with code analysis, refactoring, debugging and AI features. Some features require a paid subscription.",
      "website": "https://www.jetbrains.com/idea/",
      "source": "https://github.com/JetBrains/intellij-community",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "CZ",
        "name": "Czechia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "IntelliJ IDEA scores 25 out of 100 (grade F) on the code editors criteria. It partly meets open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Czechia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/code-editors/intellij-idea/",
      "markdown": "https://privacyratings.com/code-editors/intellij-idea/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/JetBrains/intellij-community/blob/master/LICENSE.txt",
          "note": "The core platform is Apache 2.0 and available as open-source builds, but the standard IntelliJ IDEA distribution includes proprietary features."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.jetbrains.com/legal/docs/privacy/privacy/#how-we-collect-data",
          "note": "The website loads Google Tag Manager and shares data with third-party advertising partners. In the IDE, anonymous usage statistics are opt-in."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.jetbrains.com/idea/buy/",
          "note": "Funded by paid subscriptions, with no ads in the IDE. The privacy policy allows sharing website data with advertising partners to market JetBrains products."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:41.359Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kate",
      "category": "code-editors",
      "name": "Kate",
      "description": "Text and code editor from KDE with tabs, split views, LSP support, a built-in terminal and plugins.",
      "website": "https://kate-editor.org",
      "source": "https://invent.kde.org/utilities/kate",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Kate scores 80 out of 100 (grade B) on the code editors criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/code-editors/kate/",
      "markdown": "https://privacyratings.com/code-editors/kate/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://apps.kde.org/kate/",
          "note": "LGPL-2.1-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kde.org/privacypolicy/",
          "note": "No third-party trackers, and KDE app telemetry is opt-in. KDE websites use self-hosted Matomo with cookies disabled and IP addresses anonymized."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kde.org/donate/",
          "note": "KDE community project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:41.710Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "neovim",
      "category": "code-editors",
      "name": "Neovim",
      "description": "Fork of Vim focused on extensibility, with a Lua plugin API, a built-in LSP client, Tree-sitter support and an embeddable editor core.",
      "website": "https://neovim.io",
      "source": "https://github.com/neovim/neovim",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Neovim scores 80 out of 100 (grade B) on the code editors criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/code-editors/neovim/",
      "markdown": "https://privacyratings.com/code-editors/neovim/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/neovim/neovim/blob/master/LICENSE.txt",
          "note": "Apache 2.0, with parts inherited from Vim under the Vim license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/neovim/neovim",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://neovim.io/sponsors/",
          "note": "Community project funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:59:41.232Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "pulsar",
      "category": "code-editors",
      "name": "Pulsar",
      "description": "Community-maintained continuation of the Atom editor, hackable through JavaScript packages and themes, with its own package registry.",
      "website": "https://pulsar-edit.dev",
      "source": "https://github.com/pulsar-edit/pulsar",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Pulsar scores 80 out of 100 (grade B) on the code editors criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/code-editors/pulsar/",
      "markdown": "https://privacyratings.com/code-editors/pulsar/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pulsar-edit/pulsar/blob/master/LICENSE.md",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://pulsar-edit.dev/privacy",
          "note": "The editor collects no telemetry and the website runs no analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://pulsar-edit.dev/donate",
          "note": "Community project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:41.457Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sublime-text",
      "category": "code-editors",
      "name": "Sublime Text",
      "description": "Cross-platform text and code editor with multiple selections, a command palette, Git integration and a Python plugin API. Free to evaluate, with a paid license for continued use.",
      "website": "https://www.sublimetext.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "AU",
        "name": "Australia",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Sublime Text scores 50 out of 100 (grade D) on the code editors criteria. It meets 2 of 4 criteria: no trackers or telemetry and no ads or data sales. It does not meet open source and independent audit. It is based in Australia: Five Eyes member; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/code-editors/sublime-text/",
      "markdown": "https://privacyratings.com/code-editors/sublime-text/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.sublimetext.com/eula",
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.sublimetext.com",
          "note": "The website loads no third-party scripts and the editor has no known telemetry beyond update and license checks. No privacy policy is published."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.sublimehq.com/store/text",
          "note": "Funded by paid licenses, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:43.375Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vim",
      "category": "code-editors",
      "name": "Vim",
      "description": "Modal text editor for the terminal and GUI, configurable through Vim script and plugins. Distributed as charityware that asks users to donate to a children's charity in Uganda.",
      "website": "https://www.vim.org",
      "source": "https://github.com/vim/vim",
      "license": "Vim",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Vim scores 40 out of 100 (grade D) on the code editors criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/code-editors/vim/",
      "markdown": "https://privacyratings.com/code-editors/vim/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/vim/vim/blob/master/LICENSE",
          "note": "Vim license, a free software license that also allows modified versions to be distributed under the GPL v2 or later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.vim.org",
          "note": "The vim.org website loads Google AdSense. The editor itself has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.vim.org/sponsor/index.php",
          "note": "The editor has no ads and is funded by donations, but the vim.org website shows Google AdSense ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:43.424Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "visual-studio-code",
      "category": "code-editors",
      "name": "Visual Studio Code",
      "description": "Microsoft's code editor with built-in Git support, debugging, AI features and an extension marketplace. Built from the MIT-licensed Code - OSS repository, with Microsoft branding and proprietary components.",
      "website": "https://code.visualstudio.com",
      "source": "https://github.com/microsoft/vscode",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Visual Studio Code scores 50 out of 100 (grade D) on the code editors criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source and no trackers or telemetry. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/code-editors/visual-studio-code/",
      "markdown": "https://privacyratings.com/code-editors/visual-studio-code/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://code.visualstudio.com/docs/supporting/faq#_what-is-the-difference-between-the-vscode-repository-and-the-microsoft-visual-studio-code-distribution",
          "note": "The Code - OSS source is MIT, but Microsoft's Visual Studio Code builds add proprietary components under a Microsoft product license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://code.visualstudio.com/docs/configure/telemetry",
          "note": "Crash reports, error telemetry and usage data are sent to Microsoft by default and can be turned off with the telemetry.telemetryLevel setting. Extensions may send their own telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://code.visualstudio.com/docs/supporting/faq#_is-vs-code-free",
          "note": "Free product from Microsoft with no ads in the editor."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:43.731Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vscodium",
      "category": "code-editors",
      "name": "VSCodium",
      "description": "Community builds of Microsoft's VS Code source under the MIT license, without Microsoft branding and with telemetry turned off. Uses the Open VSX extension registry by default.",
      "website": "https://vscodium.com",
      "source": "https://github.com/VSCodium/vscodium",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "VSCodium scores 80 out of 100 (grade B) on the code editors criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/code-editors/vscodium/",
      "markdown": "https://privacyratings.com/code-editors/vscodium/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/VSCodium/vscodium/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/VSCodium/vscodium/blob/master/docs/telemetry.md",
          "note": "Builds are made without Microsoft telemetry and all telemetry settings are off by default. Some third-party extensions may send their own telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/VSCodium/vscodium/blob/master/LICENSE",
          "note": "Free community project under the MIT license, with no ads or paid features."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:08.465Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "zed",
      "category": "code-editors",
      "name": "Zed",
      "description": "Code editor written in Rust with GPU-accelerated rendering, real-time collaboration and built-in AI agent features.",
      "website": "https://zed.dev",
      "source": "https://github.com/zed-industries/zed",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Zed scores 50 out of 100 (grade D) on the code editors criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/code-editors/zed/",
      "markdown": "https://privacyratings.com/code-editors/zed/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/zed-industries/zed/blob/main/LICENSE-GPL",
          "note": "GPL-3.0-or-later, with some components under Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://zed.dev/privacy-policy",
          "note": "The website uses Amplitude analytics, and the editor sends crash reports and usage metrics by default, which can be turned off in settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://zed.dev/privacy-policy#how-we-disclose-the-personal-data-we-collect",
          "note": "Funded by paid plans. The privacy policy states personal data is not sold or shared for cross-context advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:43.645Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "alacritty",
      "category": "terminals",
      "name": "Alacritty",
      "description": "Cross-platform, GPU-accelerated terminal emulator configured through a TOML file, with a vi mode, regex search and hints for opening URLs.",
      "website": "https://alacritty.org",
      "source": "https://github.com/alacritty/alacritty",
      "license": "Apache-2.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Alacritty scores 80 out of 100 (grade B) on the terminals criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/terminals/alacritty/",
      "markdown": "https://privacyratings.com/terminals/alacritty/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/alacritty/alacritty/blob/master/LICENSE-APACHE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/alacritty/alacritty",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/alacritty/alacritty/blob/master/LICENSE-APACHE",
          "note": "Free software under the Apache-2.0 and MIT licenses, with no ads or paid features."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:09.325Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "foot",
      "category": "terminals",
      "name": "foot",
      "description": "Lightweight terminal emulator for Wayland with a server mode, Sixel image support and low resource use.",
      "website": "https://codeberg.org/dnkl/foot",
      "source": "https://codeberg.org/dnkl/foot",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "foot scores 80 out of 100 (grade B) on the terminals criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/terminals/foot/",
      "markdown": "https://privacyratings.com/terminals/foot/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/dnkl/foot/src/branch/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/dnkl/foot",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://codeberg.org/dnkl/foot/src/branch/master/LICENSE",
          "note": "Free MIT-licensed project supported by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:59:41.457Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ghostty",
      "category": "terminals",
      "name": "Ghostty",
      "description": "GPU-accelerated terminal emulator written in Zig, using native UI toolkits on each platform.",
      "website": "https://ghostty.org",
      "source": "https://github.com/ghostty-org/ghostty",
      "license": "MIT",
      "platforms": [
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Ghostty scores 80 out of 100 (grade B) on the terminals criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/terminals/ghostty/",
      "markdown": "https://privacyratings.com/terminals/ghostty/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ghostty-org/ghostty/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ghostty-org/ghostty",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/ghostty-org/ghostty/blob/main/LICENSE",
          "note": "Free MIT-licensed project with no ads or paid features."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:43.599Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "iterm2",
      "category": "terminals",
      "name": "iTerm2",
      "description": "Terminal emulator for macOS with split panes, search, autocomplete, tmux integration and a Python scripting API.",
      "website": "https://iterm2.com",
      "source": "https://github.com/gnachman/iTerm2",
      "license": "GPL-2.0",
      "platforms": [
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "iTerm2 scores 80 out of 100 (grade B) on the terminals criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/terminals/iterm2/",
      "markdown": "https://privacyratings.com/terminals/iterm2/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gnachman/iTerm2/blob/master/LICENSE",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gnachman/iTerm2",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://iterm2.com/donate.html",
          "note": "Funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:59:43.446Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kitty",
      "category": "terminals",
      "name": "kitty",
      "description": "GPU-accelerated terminal emulator with tabs, split layouts, a graphics protocol for images in the terminal and extensions called kittens.",
      "website": "https://sw.kovidgoyal.net/kitty/",
      "source": "https://github.com/kovidgoyal/kitty",
      "license": "GPL-3.0",
      "platforms": [
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "kitty scores 50 out of 100 (grade D) on the terminals criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/terminals/kitty/",
      "markdown": "https://privacyratings.com/terminals/kitty/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/kovidgoyal/kitty/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://sw.kovidgoyal.net/kitty/",
          "note": "The website loads Google Analytics through Google Tag Manager. The terminal itself has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://sw.kovidgoyal.net/kitty/support/",
          "note": "Funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:44.053Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "konsole",
      "category": "terminals",
      "name": "Konsole",
      "description": "Terminal emulator from KDE with tabs, split views, profiles, bookmarks and search.",
      "website": "https://apps.kde.org/konsole/",
      "source": "https://invent.kde.org/utilities/konsole",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Konsole scores 80 out of 100 (grade B) on the terminals criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/terminals/konsole/",
      "markdown": "https://privacyratings.com/terminals/konsole/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://apps.kde.org/konsole/",
          "note": "GPL-2.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kde.org/privacypolicy/",
          "note": "No third-party trackers, and KDE app telemetry is opt-in. KDE websites use self-hosted Matomo with cookies disabled and IP addresses anonymized."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kde.org/donate/",
          "note": "KDE community project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:45.091Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "warp",
      "category": "terminals",
      "name": "Warp",
      "description": "Terminal from Warp with block-based command output, a built-in editor, AI agents and team features such as shared workflows. Some features require an account.",
      "website": "https://www.warp.dev",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Warp scores 20 out of 100 (grade F) on the terminals criteria. It partly meets no ads or data sales and independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/terminals/warp/",
      "markdown": "https://privacyratings.com/terminals/warp/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/warpdotdev/Warp/blob/main/LICENSE",
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://docs.warp.dev/support-and-community/privacy-and-security/privacy",
          "note": "The website loads Google Tag Manager, Meta and HubSpot scripts, and the app sends analytics through RudderStack by default, which can be turned off in settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.warp.dev/pricing",
          "note": "Funded by paid plans, with no ads in the app. The privacy policy allows sharing personal information with advertising partners to market Warp."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.warp.dev/legal/security",
          "note": "Has a SOC 2 Type 2 attestation, but the report is only available on request."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "snap.licdn.com",
            "effect": "no"
          },
          {
            "name": "Meta Pixel",
            "host": "www.facebook.com",
            "effect": "no"
          },
          {
            "name": "Reddit Pixel",
            "host": "www.redditstatic.com",
            "effect": "no"
          },
          {
            "name": "VWO",
            "host": "dev.visualwebsiteoptimizer.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:45.173Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "wezterm",
      "category": "terminals",
      "name": "WezTerm",
      "description": "GPU-accelerated terminal emulator and multiplexer written in Rust, configured in Lua, with tabs, panes and SSH and serial connections.",
      "website": "https://wezterm.org",
      "source": "https://github.com/wezterm/wezterm",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "WezTerm scores 80 out of 100 (grade B) on the terminals criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/terminals/wezterm/",
      "markdown": "https://privacyratings.com/terminals/wezterm/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/wezterm/wezterm/blob/main/LICENSE.md",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/wezterm/wezterm",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://wezterm.org/sponsor.html",
          "note": "Funded by sponsorships, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:45.058Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "windows-terminal",
      "category": "terminals",
      "name": "Windows Terminal",
      "description": "Microsoft's terminal application for Windows, with tabs, panes, profiles for PowerShell, Command Prompt and WSL, and GPU-accelerated text rendering.",
      "website": "https://learn.microsoft.com/en-us/windows/terminal/",
      "source": "https://github.com/microsoft/terminal",
      "license": "MIT",
      "platforms": [
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Windows Terminal scores 65 out of 100 (grade C) on the terminals criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/terminals/windows-terminal/",
      "markdown": "https://privacyratings.com/terminals/windows-terminal/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/microsoft/terminal/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/microsoft/terminal/blob/main/src/cascadia/TerminalApp/AppLogic.cpp",
          "note": "Sends usage events to Microsoft through the Windows diagnostic data pipeline, controlled by the Windows optional diagnostic data setting."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/microsoft/terminal/blob/main/LICENSE",
          "note": "Free MIT-licensed app from Microsoft, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:45.097Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bruno",
      "category": "developer-tools",
      "name": "Bruno",
      "description": "Local-first API client that stores collections as plain text files in the filesystem, so they can be versioned with Git. Supports REST, GraphQL, gRPC and WebSocket requests.",
      "website": "https://www.usebruno.com",
      "source": "https://github.com/usebruno/bruno",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Bruno scores 25 out of 100 (grade F) on the developer tools criteria. It partly meets open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/developer-tools/bruno/",
      "markdown": "https://privacyratings.com/developer-tools/bruno/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/usebruno/bruno/blob/main/license.md",
          "note": "Open core. The main app is MIT licensed, but features in the paid Pro and Ultimate editions are proprietary."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics, Google Tag Manager, HubSpot, LinkedIn Insight, Reddit Pixel and X (Twitter) Pixel (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.usebruno.com/privacy-policy",
          "note": "Funded by paid licenses, but the privacy policy lists Google AdWords and other tracking for interest-based advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hsforms.net",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "snap.licdn.com",
            "effect": "no"
          },
          {
            "name": "Reddit Pixel",
            "host": "www.redditstatic.com",
            "effect": "no"
          },
          {
            "name": "X (Twitter) Pixel",
            "host": "static.ads-twitter.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:09.064Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "devtoys",
      "category": "developer-tools",
      "name": "DevToys",
      "description": "Offline desktop toolbox for developers with utilities for JSON, YAML, hashes, JWTs, Base64, text comparison and more, so data does not need to be pasted into online tools.",
      "website": "https://devtoys.app",
      "source": "https://github.com/DevToys-app/DevToys",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "DevToys scores 50 out of 100 (grade D) on the developer tools criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/developer-tools/devtoys/",
      "markdown": "https://privacyratings.com/developer-tools/devtoys/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/DevToys-app/DevToys/blob/main/LICENSE.md",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics and Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/DevToys-app/DevToys/blob/main/PRIVACY-POLICY.md",
          "note": "Free MIT-licensed app with no ads. The privacy policy states usage data stays on the device."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:09.178Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gitgost",
      "category": "developer-tools",
      "name": "gitGost",
      "description": "Relay for contributing to Git repositories anonymously: add it as a Git remote and it opens a pull request from a shared bot account with author name, email and commit metadata removed.",
      "website": "https://gitgost.livrasand.com",
      "source": "https://github.com/livrasand/gitGost",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "gitGost scores 80 out of 100 (grade B) on the developer tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/developer-tools/gitgost/",
      "markdown": "https://privacyratings.com/developer-tools/gitgost/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/livrasand/gitGost/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/livrasand/gitGost/blob/main/web/ethicalmetrics.js",
          "note": "No third-party trackers. The website counts page views with first-party analytics that set no cookies, store no IP addresses or identifiers, and respect Do Not Track."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/livrasand",
          "note": "Free service funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:09.612Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hoppscotch",
      "category": "developer-tools",
      "name": "Hoppscotch",
      "description": "API development tool for REST, GraphQL, WebSocket and other requests, available as a web app, desktop app and self-hostable server.",
      "website": "https://hoppscotch.com",
      "source": "https://github.com/hoppscotch/hoppscotch",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Hoppscotch scores 40 out of 100 (grade D) on the developer tools criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/developer-tools/hoppscotch/",
      "markdown": "https://privacyratings.com/developer-tools/hoppscotch/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hoppscotch/hoppscotch/blob/main/LICENSE",
          "note": "MIT, including the self-hostable backend."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://docs.hoppscotch.io/support/privacy",
          "note": "The privacy policy lists Google Analytics and PostHog, and the hosted app loads them."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://hoppscotch.com/pricing",
          "note": "Funded by paid plans, with no ads in the app. The privacy policy allows third-party advertising partners to use cookies to market Hoppscotch."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:45.047Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "insomnia",
      "category": "developer-tools",
      "name": "Insomnia",
      "description": "API client from Kong for REST, GraphQL, gRPC and WebSocket requests, with API design and testing tools. Data can be stored locally, in Git, or synced to Kong's cloud.",
      "website": "https://insomnia.rest",
      "source": "https://github.com/Kong/insomnia",
      "license": "Apache-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "Insomnia scores 45 out of 100 (grade D) on the developer tools criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source and independent audit. It does not meet no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/developer-tools/insomnia/",
      "markdown": "https://privacyratings.com/developer-tools/insomnia/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/Kong/insomnia/blob/develop/LICENSE",
          "note": "The desktop app is Apache 2.0, but the cloud sync service is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://insomnia.rest/privacy",
          "note": "The privacy policy lists Segment, Sentry and Google Analytics for the website and apps."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://insomnia.rest/pricing",
          "note": "Funded by paid plans, with no ads in the app."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://insomnia.rest/pricing",
          "note": "SOC 2 reports and security testing results are only shared with Enterprise customers."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Segment",
            "host": "cdn.segment.com",
            "effect": "no"
          },
          {
            "name": "VWO",
            "host": "dev.visualwebsiteoptimizer.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:45.179Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "postman",
      "category": "developer-tools",
      "name": "Postman",
      "description": "API platform for designing, testing and documenting APIs, with collections, environments, mock servers and team workspaces synced to Postman's cloud.",
      "website": "https://www.postman.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Postman scores 30 out of 100 (grade F) on the developer tools criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/developer-tools/postman/",
      "markdown": "https://privacyratings.com/developer-tools/postman/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.postman.com",
          "note": "The website loads Google Tag Manager, the Meta pixel and HubSpot."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.postman.com/pricing/",
          "note": "Funded by paid plans, with no ads in the app."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.postman.com/security/",
          "note": "Holds SOC 2 Type II and ISO 27001 certifications, but reports are only available on request through its trust portal."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Facebook SDK",
            "host": "connect.facebook.net",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "snap.licdn.com",
            "effect": "no"
          },
          {
            "name": "Meta Pixel",
            "host": "www.facebook.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:45.610Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "yaak",
      "category": "developer-tools",
      "name": "Yaak",
      "description": "Offline-first desktop API client for REST, GraphQL, gRPC, WebSocket and server-sent events, storing data locally with optional Git sync. Free for personal use, with a license required for commercial use.",
      "website": "https://yaak.app",
      "source": "https://github.com/mountain-loop/yaak",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Yaak scores 65 out of 100 (grade C) on the developer tools criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/developer-tools/yaak/",
      "markdown": "https://privacyratings.com/developer-tools/yaak/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mountain-loop/yaak/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://yaak.app/privacy",
          "note": "The app has no telemetry beyond update and license checks, but the website uses first-party analytics stored by Yaak."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://yaak.app/pricing",
          "note": "Funded by license sales and sponsors. The privacy policy states data is not sold or shared with third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:45.641Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "adonisjs",
      "category": "node-frameworks",
      "name": "AdonisJS",
      "description": "TypeScript-first MVC web framework for Node.js that includes routing, an ORM, authentication and validation.",
      "website": "https://adonisjs.com",
      "source": "https://github.com/adonisjs/core",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "AdonisJS scores 50 out of 100 (grade D) on the Node.js frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/node-frameworks/adonisjs/",
      "markdown": "https://privacyratings.com/node-frameworks/adonisjs/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/adonisjs/core/blob/7.x/LICENSE.md",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://adonisjs.com/",
          "note": "The adonisjs.com website loads PostHog analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/thetutlage",
          "note": "Funded by sponsors through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:44.812Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "elysia",
      "category": "node-frameworks",
      "name": "Elysia",
      "description": "TypeScript web framework designed for the Bun runtime, with end-to-end type safety and schema validation.",
      "website": "https://elysiajs.com",
      "source": "https://github.com/elysiajs/elysia",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Elysia scores 80 out of 100 (grade B) on the Node.js frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/node-frameworks/elysia/",
      "markdown": "https://privacyratings.com/node-frameworks/elysia/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/elysiajs/elysia/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://elysiajs.com/",
          "note": "No third-party trackers, and the framework has no telemetry. The website's Cloudflare Web Analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/SaltyAom",
          "note": "Funded by sponsors through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:44.831Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "encore-ts",
      "category": "node-frameworks",
      "name": "Encore.ts",
      "description": "TypeScript backend framework with a Rust-based runtime, where APIs and infrastructure such as databases, queues and cron jobs are declared in code.",
      "website": "https://encore.dev",
      "source": "https://github.com/encoredev/encore",
      "license": "MPL-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "SE",
        "name": "Sweden",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Encore.ts scores 50 out of 100 (grade D) on the Node.js frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Sweden: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/node-frameworks/encore-ts/",
      "markdown": "https://privacyratings.com/node-frameworks/encore-ts/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/encoredev/encore/blob/main/LICENSE",
          "note": "MPL-2.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://encore.dev/docs/cli/telemetry",
          "note": "The Encore CLI sends usage telemetry by default until disabled, and encore.dev loads Google Analytics and Microsoft Clarity."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://encore.dev/pricing",
          "note": "Developed by Encoretivity AB and funded by its paid Encore Cloud platform, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "px.ads.linkedin.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Clarity",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:03.458Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "express",
      "category": "node-frameworks",
      "name": "Express",
      "description": "Minimal web framework for Node.js that provides routing and middleware for building web applications and APIs.",
      "website": "https://expressjs.com",
      "source": "https://github.com/expressjs/express",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 100,
      "coverage": 100,
      "summary": "Express scores 100 out of 100 (grade A) on the Node.js frameworks criteria. It meets 4 of 4 criteria: open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/node-frameworks/express/",
      "markdown": "https://privacyratings.com/node-frameworks/express/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/expressjs/express/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/expressjs/expressjs.com",
          "note": "The framework has no telemetry, and the website source loads no analytics or trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/express",
          "note": "OpenJS Foundation project funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ostif.org/wp-content/uploads/2024/10/expressjs-2024-security-audit-report.pdf",
          "note": "Security audit by Ada Logics through OSTIF, with the full report published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:44.964Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fastify",
      "category": "node-frameworks",
      "name": "Fastify",
      "description": "Web framework for Node.js focused on low overhead, with a plugin system and JSON schema based validation and serialization.",
      "website": "https://fastify.dev",
      "source": "https://github.com/fastify/fastify",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 100,
      "coverage": 100,
      "summary": "Fastify scores 100 out of 100 (grade A) on the Node.js frameworks criteria. It meets 4 of 4 criteria: open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/node-frameworks/fastify/",
      "markdown": "https://privacyratings.com/node-frameworks/fastify/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/fastify/fastify/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/fastify/website",
          "note": "The framework has no telemetry, and the website source loads no analytics or trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/fastify",
          "note": "OpenJS Foundation project funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ostif.org/wp-content/uploads/2024/07/fastify-security-audit-updated-15th-May-2024.pdf",
          "note": "Security audit by Ada Logics through OSTIF, with the full report published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:44.979Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "feathers",
      "category": "node-frameworks",
      "name": "Feathers",
      "description": "TypeScript and JavaScript framework for building real-time applications and REST APIs on Node.js.",
      "website": "https://feathersjs.com",
      "source": "https://github.com/feathersjs/feathers",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Feathers scores 50 out of 100 (grade D) on the Node.js frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/node-frameworks/feathers/",
      "markdown": "https://privacyratings.com/node-frameworks/feathers/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/feathersjs/feathers/blob/dove/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/feathersjs/feathers/blob/dove/docs/.vitepress/theme/index.ts",
          "note": "The feathersjs.com website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/feathers",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:45.021Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hapi",
      "category": "node-frameworks",
      "name": "Hapi",
      "description": "Web framework for Node.js for building applications and services, with built-in input validation, caching and authentication support.",
      "website": "https://hapi.dev",
      "source": "https://github.com/hapijs/hapi",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Hapi scores 40 out of 100 (grade D) on the Node.js frameworks criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/node-frameworks/hapi/",
      "markdown": "https://privacyratings.com/node-frameworks/hapi/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hapijs/hapi/blob/master/LICENSE.md",
          "note": "BSD-3-Clause licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/hapijs/hapi.dev/blob/master/components/CarbonAds.vue",
          "note": "The hapi.dev website loads the Carbon Ads ad network script."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/hapijs/hapi.dev/blob/master/components/CarbonAds.vue",
          "note": "The framework has no ads, but the documentation website shows contextual Carbon Ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:45.465Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hono",
      "category": "node-frameworks",
      "name": "Hono",
      "description": "Small web framework built on Web Standards that runs on Node.js, Bun, Deno, Cloudflare Workers and other JavaScript runtimes.",
      "website": "https://hono.dev",
      "source": "https://github.com/honojs/hono",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Hono scores 80 out of 100 (grade B) on the Node.js frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/node-frameworks/hono/",
      "markdown": "https://privacyratings.com/node-frameworks/hono/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/honojs/hono/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/honojs/website",
          "note": "The framework has no telemetry, and the website source loads no analytics or trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/yusukebe",
          "note": "Funded by sponsors through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:45.019Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "koa",
      "category": "node-frameworks",
      "name": "Koa",
      "description": "Minimal web framework for Node.js from the team behind Express, built around async middleware functions.",
      "website": "https://koajs.com",
      "source": "https://github.com/koajs/koa",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": true,
      "pick_reason": "A small core built on async middleware, from the team behind Express. MIT licensed, with no telemetry.",
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Koa scores 50 out of 100 (grade D) on the Node.js frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/node-frameworks/koa/",
      "markdown": "https://privacyratings.com/node-frameworks/koa/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/koajs/koa/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://koajs.com/",
          "note": "The koajs.com website loads Segment analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/koajs",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:45.401Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "loopback",
      "category": "node-frameworks",
      "name": "LoopBack",
      "description": "TypeScript framework for Node.js for building REST APIs and microservices, with OpenAPI support, dependency injection and database connectors.",
      "website": "https://loopback.io",
      "source": "https://github.com/loopbackio/loopback-next",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "LoopBack scores 50 out of 100 (grade D) on the Node.js frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/node-frameworks/loopback/",
      "markdown": "https://privacyratings.com/node-frameworks/loopback/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/loopbackio/loopback-next/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://loopback.io/",
          "note": "The framework and CLI have no telemetry, but the loopback.io website loads Google Analytics through Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://openjsf.org/projects",
          "note": "An OpenJS Foundation project maintained by IBM and community contributors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:04.314Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "meteor",
      "category": "node-frameworks",
      "name": "Meteor",
      "description": "Full-stack JavaScript platform for building web and mobile applications with real-time data on Node.js.",
      "website": "https://www.meteor.com",
      "source": "https://github.com/meteor/meteor",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Meteor scores 50 out of 100 (grade D) on the Node.js frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/node-frameworks/meteor/",
      "markdown": "https://privacyratings.com/node-frameworks/meteor/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/meteor/meteor/blob/devel/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.meteor.com/",
          "note": "The meteor.com website loads Google Tag Manager and Plausible analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.meteor.com/pricing",
          "note": "Funded by Meteor Software's paid Galaxy hosting, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:45.408Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "moleculer",
      "category": "node-frameworks",
      "name": "Moleculer",
      "description": "Microservices framework for Node.js with service discovery, load balancing, fault tolerance and pluggable message transporters.",
      "website": "https://moleculer.services",
      "source": "https://github.com/moleculerjs/moleculer",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Moleculer scores 50 out of 100 (grade D) on the Node.js frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/node-frameworks/moleculer/",
      "markdown": "https://privacyratings.com/node-frameworks/moleculer/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/moleculerjs/moleculer/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://moleculer.services/",
          "note": "The framework has no telemetry, but the moleculer.services website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/moleculer",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:04.457Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nestjs",
      "category": "node-frameworks",
      "name": "NestJS",
      "description": "TypeScript framework for building server-side Node.js applications, using modules, dependency injection and decorators on top of Express or Fastify.",
      "website": "https://nestjs.com",
      "source": "https://github.com/nestjs/nest",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "NestJS scores 50 out of 100 (grade D) on the Node.js frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/node-frameworks/nestjs/",
      "markdown": "https://privacyratings.com/node-frameworks/nestjs/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nestjs/nest/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://nestjs.com/",
          "note": "The nestjs.com website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/nest",
          "note": "Funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:46.306Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nitro",
      "category": "node-frameworks",
      "name": "Nitro",
      "description": "Server toolkit for building web servers and APIs in JavaScript and TypeScript, built on h3 and deployable to many hosting platforms and runtimes.",
      "website": "https://nitro.build",
      "source": "https://github.com/nitrojs/nitro",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Nitro scores 80 out of 100 (grade B) on the Node.js frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/node-frameworks/nitro/",
      "markdown": "https://privacyratings.com/node-frameworks/nitro/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nitrojs/nitro/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nitrojs/nitro",
          "note": "No telemetry in the source code, and the nitro.build website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/pi0",
          "note": "Funded by sponsorships through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:04.164Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "oak",
      "category": "node-frameworks",
      "name": "Oak",
      "description": "Middleware framework for HTTP servers on Deno, Node.js, Bun and Cloudflare Workers, modeled on Koa, with a built-in router.",
      "website": "https://oakserver.org",
      "source": "https://github.com/oakserver/oak",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Oak scores 80 out of 100 (grade B) on the Node.js frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/node-frameworks/oak/",
      "markdown": "https://privacyratings.com/node-frameworks/oak/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/oakserver/oak/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/oakserver/oak",
          "note": "No telemetry or analytics in the source code, and oakserver.org loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/oakserver/oak",
          "note": "Volunteer-maintained open-source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:07.127Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "restify",
      "category": "node-frameworks",
      "name": "Restify",
      "description": "Node.js web service framework for building REST APIs, with a focus on observability and correctness.",
      "website": "https://restify.com",
      "source": "https://github.com/restify/node-restify",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Restify scores 80 out of 100 (grade B) on the Node.js frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/node-frameworks/restify/",
      "markdown": "https://privacyratings.com/node-frameworks/restify/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/restify/node-restify/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/restify/restify.github.io",
          "note": "The framework has no telemetry, and the website source loads no analytics or trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/restify/node-restify",
          "note": "Volunteer-maintained open-source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:45.515Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sails",
      "category": "node-frameworks",
      "name": "Sails",
      "description": "MVC web framework for Node.js built on Express, with auto-generated REST APIs, WebSocket support and the Waterline ORM.",
      "website": "https://sailsjs.com",
      "source": "https://github.com/balderdashy/sails",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Sails scores 40 out of 100 (grade D) on the Node.js frameworks criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/node-frameworks/sails/",
      "markdown": "https://privacyratings.com/node-frameworks/sails/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/balderdashy/sails/blob/master/LICENSE.md",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://sailsjs.com/",
          "note": "The sailsjs.com website loads Google Analytics and the Facebook pixel."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://sailsjs.com/",
          "note": "No ads in the framework, but the website loads the Facebook pixel for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Facebook SDK",
            "host": "connect.facebook.net",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Meta Pixel",
            "host": "www.facebook.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:45.538Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "total-js",
      "category": "node-frameworks",
      "name": "Total.js",
      "description": "Node.js framework for building web applications, REST services and real-time apps, with no third-party dependencies in its core and built-in NoSQL storage.",
      "website": "https://www.totaljs.com",
      "source": "https://github.com/totaljs/framework5",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "SK",
        "name": "Slovakia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Total.js scores 50 out of 100 (grade D) on the Node.js frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Slovakia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/node-frameworks/total-js/",
      "markdown": "https://privacyratings.com/node-frameworks/total-js/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/totaljs/framework5/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.totaljs.com/",
          "note": "The framework has no telemetry, but the totaljs.com website loads Google Analytics through Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.totaljs.com/support/",
          "note": "Funded by donations, paid services and cloud hosting, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:05.278Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "trpc",
      "category": "node-frameworks",
      "name": "tRPC",
      "description": "TypeScript library for building end-to-end type-safe APIs, sharing types between server and client without schemas or code generation.",
      "website": "https://trpc.io",
      "source": "https://github.com/trpc/trpc",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "tRPC scores 50 out of 100 (grade D) on the Node.js frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/node-frameworks/trpc/",
      "markdown": "https://privacyratings.com/node-frameworks/trpc/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/trpc/trpc/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://trpc.io/",
          "note": "No telemetry in the library, but the trpc.io website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/trpc",
          "note": "Funded by sponsors through GitHub Sponsors and Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:04.840Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "alpine-js",
      "category": "web-frameworks",
      "name": "Alpine.js",
      "description": "Lightweight JavaScript framework that adds reactive behavior to HTML through attributes written directly in the markup.",
      "website": "https://alpinejs.dev",
      "source": "https://github.com/alpinejs/alpine",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Alpine.js scores 80 out of 100 (grade B) on the front-end and full-stack frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/web-frameworks/alpine-js/",
      "markdown": "https://privacyratings.com/web-frameworks/alpine-js/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/alpinejs/alpine/blob/main/LICENSE.md",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://alpinejs.dev/",
          "note": "No third-party trackers, and the library has no telemetry. The alpinejs.dev website's Fathom analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://alpinejs.dev/components",
          "note": "Funded by paid UI components and GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Fathom",
            "host": "cdn.usefathom.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:04.912Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "analog",
      "category": "web-frameworks",
      "name": "Analog",
      "description": "Full-stack meta-framework for Angular built on Vite, with file-based routing, server-side rendering, static generation and API routes.",
      "website": "https://analogjs.org",
      "source": "https://github.com/analogjs/analog",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Analog scores 50 out of 100 (grade D) on the front-end and full-stack frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/web-frameworks/analog/",
      "markdown": "https://privacyratings.com/web-frameworks/analog/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/analogjs/analog/blob/beta/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://analogjs.org/",
          "note": "The framework has no telemetry, but analogjs.org loads Google Tag Manager and Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://analogjs.org/docs/sponsoring",
          "note": "Funded by sponsorships, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:05.196Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "angular",
      "category": "web-frameworks",
      "name": "Angular",
      "description": "TypeScript-based web application framework from Google, with components, dependency injection, routing and a CLI.",
      "website": "https://angular.dev",
      "source": "https://github.com/angular/angular",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Angular scores 50 out of 100 (grade D) on the front-end and full-stack frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/web-frameworks/angular/",
      "markdown": "https://privacyratings.com/web-frameworks/angular/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/angular/angular/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://angular.dev/cli/analytics",
          "note": "CLI usage analytics are opt-in, but the angular.dev website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/angular/angular/blob/main/LICENSE",
          "note": "Developed and funded by Google, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:45.728Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "astro",
      "category": "web-frameworks",
      "name": "Astro",
      "description": "Web framework for content-driven websites that renders pages to HTML and loads JavaScript only for interactive components.",
      "website": "https://astro.build",
      "source": "https://github.com/withastro/astro",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Astro scores 65 out of 100 (grade C) on the front-end and full-stack frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/web-frameworks/astro/",
      "markdown": "https://privacyratings.com/web-frameworks/astro/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/withastro/astro/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://astro.build/telemetry/",
          "note": "The CLI sends anonymous telemetry by default until disabled, and astro.build uses Fathom analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/astrodotbuild",
          "note": "Funded by Cloudflare and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Fathom",
            "host": "cdn.usefathom.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:45.915Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "aurelia",
      "category": "web-frameworks",
      "name": "Aurelia",
      "description": "JavaScript and TypeScript front-end framework for building web applications with standards-based components, data binding and dependency injection.",
      "website": "https://aurelia.io",
      "source": "https://github.com/aurelia/aurelia",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Aurelia scores 50 out of 100 (grade D) on the front-end and full-stack frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/web-frameworks/aurelia/",
      "markdown": "https://privacyratings.com/web-frameworks/aurelia/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/aurelia/aurelia/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://aurelia.io/",
          "note": "The framework has no telemetry, but the aurelia.io website loads Google Analytics through Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/aurelia",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:05.176Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "backbone-js",
      "category": "web-frameworks",
      "name": "Backbone.js",
      "description": "Lightweight JavaScript library that gives web applications structure with models, collections, views and a router.",
      "website": "https://backbonejs.org",
      "source": "https://github.com/jashkenas/backbone",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Backbone.js scores 80 out of 100 (grade B) on the front-end and full-stack frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/web-frameworks/backbone-js/",
      "markdown": "https://privacyratings.com/web-frameworks/backbone-js/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jashkenas/backbone/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jashkenas/backbone",
          "note": "No telemetry in the source code, and the backbonejs.org website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://backbonejs.org/",
          "note": "Maintained by volunteers, with no ads on the website or in the library."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:05.316Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "blitz-js",
      "category": "web-frameworks",
      "name": "Blitz.js",
      "description": "Full-stack toolkit for Next.js that adds authentication, a zero-API data layer and code generation.",
      "website": "https://blitzjs.com",
      "source": "https://github.com/blitz-js/blitz",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Blitz.js scores 80 out of 100 (grade B) on the front-end and full-stack frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/web-frameworks/blitz-js/",
      "markdown": "https://privacyratings.com/web-frameworks/blitz-js/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/blitz-js/blitz/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://blitzjs.com/",
          "note": "No third-party trackers, and the framework has no telemetry. The blitzjs.com website's Fathom analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/blitzjs",
          "note": "Funded by donations through Open Collective and GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:05.212Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ember-js",
      "category": "web-frameworks",
      "name": "Ember.js",
      "description": "JavaScript framework for building web applications, with conventions, a CLI, routing and a data layer.",
      "website": "https://emberjs.com",
      "source": "https://github.com/emberjs/ember.js",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Ember.js scores 50 out of 100 (grade D) on the front-end and full-stack frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/web-frameworks/ember-js/",
      "markdown": "https://privacyratings.com/web-frameworks/ember-js/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/emberjs/ember.js/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://emberjs.com/",
          "note": "The emberjs.com website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/emberjs",
          "note": "Funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:46.143Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fresh",
      "category": "web-frameworks",
      "name": "Fresh",
      "description": "Web framework for Deno from Deno Land that renders pages on the server with Preact and ships JavaScript only for interactive islands.",
      "website": "https://usefresh.dev",
      "source": "https://github.com/denoland/fresh",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Fresh scores 50 out of 100 (grade D) on the front-end and full-stack frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/web-frameworks/fresh/",
      "markdown": "https://privacyratings.com/web-frameworks/fresh/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/denoland/fresh/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/denoland/fresh/blob/main/www/routes/_middleware.ts",
          "note": "The framework has no telemetry, but the usefresh.dev website sends page views with visitor IP addresses to Google Analytics from its server."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://deno.com/deploy/pricing",
          "note": "Developed by Deno Land and funded by its paid Deno Deploy hosting, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:05.469Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gatsby",
      "category": "web-frameworks",
      "name": "Gatsby",
      "description": "React-based framework for building static websites and apps, with a GraphQL data layer and plugins for content sources.",
      "website": "https://www.gatsbyjs.com",
      "source": "https://github.com/gatsbyjs/gatsby",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Gatsby scores 50 out of 100 (grade D) on the front-end and full-stack frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/web-frameworks/gatsby/",
      "markdown": "https://privacyratings.com/web-frameworks/gatsby/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gatsbyjs/gatsby/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.gatsbyjs.com/docs/telemetry/",
          "note": "The CLI sends telemetry by default until disabled, and gatsbyjs.com loads Google Tag Manager and Segment."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/gatsbyjs/gatsby/blob/master/LICENSE",
          "note": "Free MIT-licensed framework maintained by Netlify, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Segment",
            "host": "cdn.segment.io",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:46.159Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "htmx",
      "category": "web-frameworks",
      "name": "htmx",
      "description": "JavaScript library that lets HTML elements issue HTTP requests and swap in server-rendered HTML through attributes, without writing JavaScript.",
      "website": "https://htmx.org",
      "source": "https://github.com/bigskysoftware/htmx",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "htmx scores 80 out of 100 (grade B) on the front-end and full-stack frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/web-frameworks/htmx/",
      "markdown": "https://privacyratings.com/web-frameworks/htmx/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bigskysoftware/htmx/blob/master/LICENSE",
          "note": "Zero-Clause BSD licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bigskysoftware/htmx",
          "note": "No telemetry or analytics in the source code, and htmx.org loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/bigskysoftware",
          "note": "Funded by sponsorships through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:05.629Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hydrogen",
      "category": "web-frameworks",
      "name": "Hydrogen",
      "description": "React framework from Shopify for building custom storefronts on the Shopify commerce platform, based on React Router.",
      "website": "https://hydrogen.shopify.dev",
      "source": "https://github.com/Shopify/hydrogen",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Hydrogen scores 35 out of 100 (grade F) on the front-end and full-stack frameworks criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source. It does not meet no trackers or telemetry and independent audit. It is based in Canada: Five Eyes member.",
      "url": "https://privacyratings.com/web-frameworks/hydrogen/",
      "markdown": "https://privacyratings.com/web-frameworks/hydrogen/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/Shopify/hydrogen/blob/main/LICENSE.md",
          "note": "The framework is MIT-licensed, but storefronts built with it need Shopify's proprietary commerce platform."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://shopify.dev/docs/api/shopify-cli",
          "note": "The Shopify CLI used with Hydrogen collects anonymous usage statistics by default until disabled, and hydrogen.shopify.dev loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.shopify.com/pricing",
          "note": "Developed by Shopify and funded by its paid commerce plans, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:05.661Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "inferno",
      "category": "web-frameworks",
      "name": "Inferno",
      "description": "JavaScript library for building user interfaces with a virtual DOM and a React-style component API.",
      "website": "https://www.infernojs.org",
      "source": "https://github.com/infernojs/inferno",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Inferno scores 80 out of 100 (grade B) on the front-end and full-stack frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/web-frameworks/inferno/",
      "markdown": "https://privacyratings.com/web-frameworks/inferno/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/infernojs/inferno/blob/master/LICENSE.md",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/infernojs/inferno",
          "note": "No telemetry in the source code, and the infernojs.org website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/inferno",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:06.901Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "jquery",
      "category": "web-frameworks",
      "name": "jQuery",
      "description": "JavaScript library for DOM manipulation, event handling and Ajax, maintained under the OpenJS Foundation.",
      "website": "https://jquery.com",
      "source": "https://github.com/jquery/jquery",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "jQuery scores 80 out of 100 (grade B) on the front-end and full-stack frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/web-frameworks/jquery/",
      "markdown": "https://privacyratings.com/web-frameworks/jquery/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jquery/jquery/blob/main/LICENSE.txt",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jquery/jquery",
          "note": "No telemetry in the source code, and the jquery.com website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://openjsf.org/projects",
          "note": "Hosted by the OpenJS Foundation, which is funded by member organizations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:05.515Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "lit",
      "category": "web-frameworks",
      "name": "Lit",
      "description": "Library for building Web Components with reactive properties and declarative templates.",
      "website": "https://lit.dev",
      "source": "https://github.com/lit/lit",
      "license": "BSD-3-Clause",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Lit scores 50 out of 100 (grade D) on the front-end and full-stack frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/web-frameworks/lit/",
      "markdown": "https://privacyratings.com/web-frameworks/lit/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/lit/lit/blob/main/LICENSE",
          "note": "BSD-3-Clause licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://lit.dev/",
          "note": "The lit.dev website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://lit.dev/",
          "note": "OpenJS Foundation project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:46.181Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "marko",
      "category": "web-frameworks",
      "name": "Marko",
      "description": "HTML-based UI language and framework for JavaScript, originally from eBay, that compiles components for streaming server rendering and partial hydration in the browser.",
      "website": "https://markojs.com",
      "source": "https://github.com/marko-js/marko",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Marko scores 80 out of 100 (grade B) on the front-end and full-stack frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/web-frameworks/marko/",
      "markdown": "https://privacyratings.com/web-frameworks/marko/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/marko-js/marko/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/marko-js/marko",
          "note": "No telemetry or analytics in the source code, and markojs.com loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/marko-js",
          "note": "Funded by eBay and donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:05.948Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mithril-js",
      "category": "web-frameworks",
      "name": "Mithril.js",
      "description": "Small client-side JavaScript framework for building single-page applications, with a virtual DOM and built-in routing and HTTP utilities.",
      "website": "https://mithril.js.org",
      "source": "https://github.com/MithrilJS/mithril.js",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Mithril.js scores 80 out of 100 (grade B) on the front-end and full-stack frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/web-frameworks/mithril-js/",
      "markdown": "https://privacyratings.com/web-frameworks/mithril-js/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/MithrilJS/mithril.js/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/MithrilJS/mithril.js",
          "note": "No telemetry in the source code, and the mithril.js.org website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/mithriljs",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:05.928Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "next-js",
      "category": "web-frameworks",
      "name": "Next.js",
      "description": "React framework from Vercel for building web applications with server-side rendering, static generation and API routes.",
      "website": "https://nextjs.org",
      "source": "https://github.com/vercel/next.js",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Next.js scores 50 out of 100 (grade D) on the front-end and full-stack frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/web-frameworks/next-js/",
      "markdown": "https://privacyratings.com/web-frameworks/next-js/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/vercel/next.js/blob/canary/license.md",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://nextjs.org/telemetry",
          "note": "The CLI sends anonymous telemetry by default until disabled, and nextjs.org loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://vercel.com/pricing",
          "note": "Developed by Vercel and funded by its paid hosting platform, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:46.316Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nuxt",
      "category": "web-frameworks",
      "name": "Nuxt",
      "description": "Vue-based framework for building web applications with server-side rendering, static generation and file-based routing.",
      "website": "https://nuxt.com",
      "source": "https://github.com/nuxt/nuxt",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Nuxt scores 80 out of 100 (grade B) on the front-end and full-stack frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/web-frameworks/nuxt/",
      "markdown": "https://privacyratings.com/web-frameworks/nuxt/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nuxt/nuxt/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nuxt/nuxt.com/blob/main/nuxt.config.ts",
          "note": "No third-party trackers, and CLI telemetry asks for consent first. Vercel Web Analytics and Speed Insights on nuxt.com are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/nuxtjs",
          "note": "Funded by sponsors and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:46.281Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "preact",
      "category": "web-frameworks",
      "name": "Preact",
      "description": "Small JavaScript library with a React-compatible component API for building user interfaces.",
      "website": "https://preactjs.com",
      "source": "https://github.com/preactjs/preact",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Preact scores 50 out of 100 (grade D) on the front-end and full-stack frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/web-frameworks/preact/",
      "markdown": "https://privacyratings.com/web-frameworks/preact/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/preactjs/preact/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://preactjs.com/",
          "note": "The preactjs.com website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/preact",
          "note": "Funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:46.393Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "qwik",
      "category": "web-frameworks",
      "name": "Qwik",
      "description": "Web framework that serializes application state into HTML so pages resume in the browser without hydration.",
      "website": "https://qwik.dev",
      "source": "https://github.com/QwikDev/qwik",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Qwik scores 50 out of 100 (grade D) on the front-end and full-stack frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/web-frameworks/qwik/",
      "markdown": "https://privacyratings.com/web-frameworks/qwik/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/QwikDev/qwik/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://qwik.dev/",
          "note": "The qwik.dev website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/qwikdev",
          "note": "Funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:46.771Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "react-router",
      "category": "web-frameworks",
      "name": "React Router",
      "description": "Routing library and full-stack framework for React, whose framework mode continues the Remix framework.",
      "website": "https://reactrouter.com",
      "source": "https://github.com/remix-run/react-router",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "React Router scores 80 out of 100 (grade B) on the front-end and full-stack frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/web-frameworks/react-router/",
      "markdown": "https://privacyratings.com/web-frameworks/react-router/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/remix-run/react-router/blob/main/LICENSE.md",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/remix-run/react-router-website",
          "note": "The framework has no telemetry, and the website source loads no analytics or trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/remix-run/react-router/blob/main/LICENSE.md",
          "note": "Free MIT-licensed library maintained by Shopify's Remix team, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:46.435Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "react",
      "category": "web-frameworks",
      "name": "React",
      "description": "JavaScript library for building user interfaces from components, used for web and native applications.",
      "website": "https://react.dev",
      "source": "https://github.com/facebook/react",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "React scores 50 out of 100 (grade D) on the front-end and full-stack frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/web-frameworks/react/",
      "markdown": "https://privacyratings.com/web-frameworks/react/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/facebook/react/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://react.dev/",
          "note": "The react.dev website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://react.dev/blog/2025/10/07/introducing-the-react-foundation",
          "note": "Developed by Meta and member companies of the React Foundation, with no ads in the library."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:46.594Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "redwoodsdk",
      "category": "web-frameworks",
      "name": "RedwoodSDK",
      "description": "Full-stack React framework from the RedwoodJS team that runs on Cloudflare Workers, built as a Vite plugin with server components, server-side rendering and realtime features.",
      "website": "https://rwsdk.com",
      "source": "https://github.com/redwoodjs/sdk",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "RedwoodSDK scores 80 out of 100 (grade B) on the front-end and full-stack frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/web-frameworks/redwoodsdk/",
      "markdown": "https://privacyratings.com/web-frameworks/redwoodsdk/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/redwoodjs/sdk/blob/main/LICENSE.md",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/redwoodjs/sdk",
          "note": "No telemetry or analytics in the source code, and rwsdk.com loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/redwoodjs/sdk",
          "note": "Open-source project developed by RedwoodJS Inc, with no ads in the framework or on its website."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:06.223Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "remix",
      "category": "web-frameworks",
      "name": "Remix",
      "description": "Full-stack web framework for JavaScript and TypeScript from Shopify, built on web standards such as the Fetch API and HTML forms. Its earlier React-based version continues as the framework mode of React Router.",
      "website": "https://remix.run",
      "source": "https://github.com/remix-run/remix",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Remix scores 80 out of 100 (grade B) on the front-end and full-stack frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Canada: Five Eyes member.",
      "url": "https://privacyratings.com/web-frameworks/remix/",
      "markdown": "https://privacyratings.com/web-frameworks/remix/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/remix-run/remix/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://remix.run/",
          "note": "No third-party trackers, and the framework has no telemetry. The remix.run website's Fathom analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.shopify.com/pricing",
          "note": "Developed by Shopify and funded by its paid commerce platform, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:06.126Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "solidjs",
      "category": "web-frameworks",
      "name": "SolidJS",
      "description": "JavaScript library for building user interfaces with JSX and fine-grained reactivity, updating the DOM directly without a virtual DOM.",
      "website": "https://www.solidjs.com",
      "source": "https://github.com/solidjs/solid",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "SolidJS scores 80 out of 100 (grade B) on the front-end and full-stack frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/web-frameworks/solidjs/",
      "markdown": "https://privacyratings.com/web-frameworks/solidjs/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/solidjs/solid/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/solidjs/solid",
          "note": "No telemetry or analytics in the source code, and solidjs.com loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/solid",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:06.115Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "solidstart",
      "category": "web-frameworks",
      "name": "SolidStart",
      "description": "Full-stack framework for SolidJS, a reactive UI library, with routing, server functions and server-side rendering.",
      "website": "https://start.solidjs.com",
      "source": "https://github.com/solidjs/solid-start",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "SolidStart scores 80 out of 100 (grade B) on the front-end and full-stack frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/web-frameworks/solidstart/",
      "markdown": "https://privacyratings.com/web-frameworks/solidstart/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/solidjs/solid-start/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/solidjs/solid-start/tree/main/apps/landing-page",
          "note": "The framework has no telemetry, and the website source loads no analytics or trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/solid",
          "note": "Funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:46.524Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "stencil",
      "category": "web-frameworks",
      "name": "Stencil",
      "description": "Compiler from Ionic for building reusable web components with TypeScript and JSX that work with any front-end framework or none.",
      "website": "https://stenciljs.com",
      "source": "https://github.com/stenciljs/core",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Stencil scores 50 out of 100 (grade D) on the front-end and full-stack frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/web-frameworks/stencil/",
      "markdown": "https://privacyratings.com/web-frameworks/stencil/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/stenciljs/core/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://stenciljs.com/docs/telemetry",
          "note": "The CLI sends anonymous usage telemetry by default until disabled, and stenciljs.com loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ionic.io/",
          "note": "Developed by Ionic, an OutSystems company, and funded by its commercial products, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:06.364Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "svelte",
      "category": "web-frameworks",
      "name": "Svelte",
      "description": "Component framework for JavaScript and TypeScript that compiles components into JavaScript at build time instead of using a virtual DOM.",
      "website": "https://svelte.dev",
      "source": "https://github.com/sveltejs/svelte",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": true,
      "pick_reason": "Compiles components to small, fast JavaScript with no virtual DOM and no telemetry, and works well with TypeScript. The Forward Email webmail and apps use Svelte and TypeScript on Tauri (github.com/forwardemail/mail.forwardemail.net).",
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Svelte scores 80 out of 100 (grade B) on the front-end and full-stack frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/web-frameworks/svelte/",
      "markdown": "https://privacyratings.com/web-frameworks/svelte/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sveltejs/svelte/blob/main/LICENSE.md",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sveltejs/svelte.dev/blob/main/apps/svelte.dev/src/routes/+layout.svelte",
          "note": "No third-party trackers, and the compiler and CLI have no telemetry. Vercel Web Analytics and Speed Insights on svelte.dev are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/svelte",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:06.279Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sveltekit",
      "category": "web-frameworks",
      "name": "SvelteKit",
      "description": "Framework for building web applications with Svelte, a compiler-based UI framework, with routing, server-side rendering and static site generation.",
      "website": "https://svelte.dev",
      "source": "https://github.com/sveltejs/kit",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "SvelteKit scores 80 out of 100 (grade B) on the front-end and full-stack frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/web-frameworks/sveltekit/",
      "markdown": "https://privacyratings.com/web-frameworks/sveltekit/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sveltejs/kit/blob/version-3/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sveltejs/svelte.dev/blob/main/apps/svelte.dev/package.json",
          "note": "No third-party trackers, and the framework has no telemetry. Vercel Speed Insights on svelte.dev is cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/svelte",
          "note": "Funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:46.640Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "tanstack-start",
      "category": "web-frameworks",
      "name": "TanStack Start",
      "description": "Full-stack React and Solid framework built on TanStack Router and Vite, with type-safe routing, server functions and server-side rendering.",
      "website": "https://tanstack.com/start/latest",
      "source": "https://github.com/TanStack/router",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "TanStack Start scores 50 out of 100 (grade D) on the front-end and full-stack frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/web-frameworks/tanstack-start/",
      "markdown": "https://privacyratings.com/web-frameworks/tanstack-start/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TanStack/router/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://tanstack.com/start/latest",
          "note": "The framework has no telemetry, but tanstack.com loads Google Analytics through a first-party proxy and a namethathost.com tracker."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tanstack.com/ads",
          "note": "Funded by partnerships and sponsors; third-party ads were removed from the site."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:06.865Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vike",
      "category": "web-frameworks",
      "name": "Vike",
      "description": "Vite-based framework for building web applications with server-side rendering, static generation and routing, used with UI libraries such as React, Vue or Solid.",
      "website": "https://vike.dev",
      "source": "https://github.com/vikejs/vike",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Vike scores 50 out of 100 (grade D) on the front-end and full-stack frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/web-frameworks/vike/",
      "markdown": "https://privacyratings.com/web-frameworks/vike/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/vikejs/vike/blob/main/LICENSE.md",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://vike.dev/",
          "note": "The framework has no telemetry, but the vike.dev website loads Google Analytics through Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://vike.dev/pricing",
          "note": "Funded by sponsors and planned paid license keys for larger organizations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:06.524Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vue",
      "category": "web-frameworks",
      "name": "Vue",
      "description": "Progressive JavaScript framework for building user interfaces with reactive, component-based templates.",
      "website": "https://vuejs.org",
      "source": "https://github.com/vuejs/core",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Vue scores 40 out of 100 (grade D) on the front-end and full-stack frameworks criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/web-frameworks/vue/",
      "markdown": "https://privacyratings.com/web-frameworks/vue/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/vuejs/core/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/vuejs/docs/blob/main/.vitepress/config.ts",
          "note": "The vuejs.org website loads Fathom analytics, a third-party promotional banner script and Carbon Ads."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/vuejs/docs/blob/main/.vitepress/config.ts",
          "note": "The framework has no ads, but the documentation website shows contextual Carbon Ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Fathom",
            "host": "cdn.usefathom.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:46.810Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "waku",
      "category": "web-frameworks",
      "name": "Waku",
      "description": "Minimal React framework for building web applications with React Server Components, server-side rendering and static generation.",
      "website": "https://waku.gg",
      "source": "https://github.com/wakujs/waku",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Waku scores 50 out of 100 (grade D) on the front-end and full-stack frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/web-frameworks/waku/",
      "markdown": "https://privacyratings.com/web-frameworks/waku/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/wakujs/waku/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://waku.gg/",
          "note": "The framework has no telemetry, but the waku.gg website loads Google Analytics through Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/dai-shi",
          "note": "Funded by sponsorships through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:06.662Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bun",
      "category": "build-tools",
      "name": "Bun",
      "description": "JavaScript runtime, package manager, test runner and bundler in a single executable, built on JavaScriptCore and written in Zig.",
      "website": "https://bun.com",
      "source": "https://github.com/oven-sh/bun",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Bun scores 65 out of 100 (grade C) on the bundlers and build tools criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/build-tools/bun/",
      "markdown": "https://privacyratings.com/build-tools/bun/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/oven-sh/bun/blob/main/LICENSE.md",
          "note": "MIT, with the statically linked JavaScriptCore under LGPL-2."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://bun.com/docs/runtime/bunfig",
          "note": "Anonymous crash reports are on by default and can be turned off, and the website uses Plausible analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://bun.com/blog/bun-joins-anthropic",
          "note": "Free MIT-licensed software backed by Anthropic, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:46.805Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "esbuild",
      "category": "build-tools",
      "name": "esbuild",
      "description": "JavaScript and TypeScript bundler and minifier written in Go, with a command-line tool and APIs for JavaScript and Go.",
      "website": "https://esbuild.github.io",
      "source": "https://github.com/evanw/esbuild",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "esbuild scores 80 out of 100 (grade B) on the bundlers and build tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/build-tools/esbuild/",
      "markdown": "https://privacyratings.com/build-tools/esbuild/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/evanw/esbuild/blob/main/LICENSE.md",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/evanw/esbuild",
          "note": "No telemetry or analytics in the source code, and the website loads no known trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/evanw/esbuild/blob/main/LICENSE.md",
          "note": "Free MIT-licensed software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:46.660Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "parcel",
      "category": "build-tools",
      "name": "Parcel",
      "description": "Zero-configuration bundler for web applications that builds JavaScript, CSS, HTML and other assets, with a Rust-based compiler and built-in development server.",
      "website": "https://parceljs.org",
      "source": "https://github.com/parcel-bundler/parcel",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Parcel scores 50 out of 100 (grade D) on the bundlers and build tools criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/build-tools/parcel/",
      "markdown": "https://privacyratings.com/build-tools/parcel/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/parcel-bundler/parcel/blob/v2/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Analytics. The bundler itself has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/parcel",
          "note": "Free software funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:47.314Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "rolldown",
      "category": "build-tools",
      "name": "Rolldown",
      "description": "JavaScript and TypeScript bundler written in Rust with a Rollup-compatible API, developed as the bundler for Vite.",
      "website": "https://rolldown.rs",
      "source": "https://github.com/rolldown/rolldown",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Rolldown scores 80 out of 100 (grade B) on the bundlers and build tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/build-tools/rolldown/",
      "markdown": "https://privacyratings.com/build-tools/rolldown/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rolldown/rolldown/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rolldown/rolldown",
          "note": "No telemetry or analytics in the source code, and the website loads no known trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/rolldown/rolldown/blob/main/LICENSE",
          "note": "Free MIT-licensed software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:46.969Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "rollup",
      "category": "build-tools",
      "name": "Rollup",
      "description": "Module bundler for JavaScript that compiles ES modules into bundles for libraries and applications, with tree shaking and a plugin API.",
      "website": "https://rollupjs.org",
      "source": "https://github.com/rollup/rollup",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Rollup scores 80 out of 100 (grade B) on the bundlers and build tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/build-tools/rollup/",
      "markdown": "https://privacyratings.com/build-tools/rollup/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rollup/rollup/blob/master/LICENSE.md",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rollup/rollup",
          "note": "No telemetry or analytics in the source code, and the website loads no known trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/rollup",
          "note": "Free software funded by sponsors and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:47.310Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "rspack",
      "category": "build-tools",
      "name": "Rspack",
      "description": "JavaScript bundler written in Rust that is compatible with the webpack configuration and plugin API, developed by the ByteDance web infrastructure team.",
      "website": "https://rspack.rs",
      "source": "https://github.com/web-infra-dev/rspack",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Rspack scores 50 out of 100 (grade D) on the bundlers and build tools criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/build-tools/rspack/",
      "markdown": "https://privacyratings.com/build-tools/rspack/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/web-infra-dev/rspack/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Analytics. The bundler itself has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/web-infra-dev/rspack/blob/main/LICENSE",
          "note": "Free MIT-licensed software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:47.367Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "turbopack",
      "category": "build-tools",
      "name": "Turbopack",
      "description": "Incremental bundler written in Rust and built into Next.js, used by the Next.js development server and production builds.",
      "website": "https://nextjs.org/docs/app/api-reference/turbopack",
      "source": "https://github.com/vercel/next.js",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Turbopack scores 40 out of 100 (grade D) on the bundlers and build tools criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/build-tools/turbopack/",
      "markdown": "https://privacyratings.com/build-tools/turbopack/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/vercel/next.js/blob/canary/license.md",
          "note": "MIT, developed in the Next.js repository."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://vercel.com/legal/privacy-notice",
          "note": "Next.js sends anonymous usage telemetry by default with an opt-out, and the Vercel privacy notice says its sites use cookies for analytics and targeted advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://vercel.com/legal/privacy-notice",
          "note": "Free software with no ads, but Vercel shares site data with advertising networks to promote its own services."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:47.459Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vite",
      "category": "build-tools",
      "name": "Vite",
      "description": "Frontend build tool with a fast development server using native ES modules and hot module replacement, and a production bundler for web applications.",
      "website": "https://vite.dev",
      "source": "https://github.com/vitejs/vite",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Vite scores 80 out of 100 (grade B) on the bundlers and build tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/build-tools/vite/",
      "markdown": "https://privacyratings.com/build-tools/vite/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/vitejs/vite/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/vitejs/vite",
          "note": "No telemetry or analytics in the source code, and the website loads no known trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/vite",
          "note": "Free software funded by sponsors and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:47.400Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "webpack",
      "category": "build-tools",
      "name": "webpack",
      "description": "Module bundler for JavaScript applications that builds a dependency graph and packages code and assets into bundles, extensible through loaders and plugins.",
      "website": "https://webpack.js.org",
      "source": "https://github.com/webpack/webpack",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "webpack scores 50 out of 100 (grade D) on the bundlers and build tools criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/build-tools/webpack/",
      "markdown": "https://privacyratings.com/build-tools/webpack/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/webpack/webpack/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Analytics. The bundler itself has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/webpack",
          "note": "Free software funded by sponsors and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:47.346Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bridgetown",
      "category": "static-site-generators",
      "name": "Bridgetown",
      "description": "Ruby web framework and static site generator that builds sites from Markdown, Ruby templates and components, with optional server-side rendering through Roda.",
      "website": "https://www.bridgetownrb.com",
      "source": "https://github.com/bridgetownrb/bridgetown",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Bridgetown scores 80 out of 100 (grade B) on the static site generators criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/static-site-generators/bridgetown/",
      "markdown": "https://privacyratings.com/static-site-generators/bridgetown/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bridgetownrb/bridgetown/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bridgetownrb/bridgetown",
          "note": "No telemetry or analytics in the source code, and bridgetownrb.com loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/jaredcwhite",
          "note": "Funded by sponsorships through GitHub Sponsors and Liberapay, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:06.579Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "docusaurus",
      "category": "static-site-generators",
      "name": "Docusaurus",
      "description": "Static site generator from Meta, built on React, for documentation websites with versioning, search and translations.",
      "website": "https://docusaurus.io",
      "source": "https://github.com/facebook/docusaurus",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Docusaurus scores 50 out of 100 (grade D) on the static site generators criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/static-site-generators/docusaurus/",
      "markdown": "https://privacyratings.com/static-site-generators/docusaurus/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/facebook/docusaurus/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://docusaurus.io/",
          "note": "The docusaurus.io website loads Google Analytics through Google Tag Manager. The Docusaurus CLI has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/docusaurus",
          "note": "Developed by Meta and supported by Open Collective donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:07.002Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "eleventy",
      "category": "static-site-generators",
      "name": "Eleventy",
      "description": "Static site generator for Node.js that works with many template languages and outputs plain HTML. Maintained by Font Awesome and being renamed Build Awesome.",
      "website": "https://www.11ty.dev",
      "source": "https://github.com/11ty/eleventy",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Eleventy scores 80 out of 100 (grade B) on the static site generators criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/static-site-generators/eleventy/",
      "markdown": "https://privacyratings.com/static-site-generators/eleventy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/11ty/eleventy/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/11ty/eleventy",
          "note": "No telemetry or analytics in the source code, and the 11ty.dev website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.11ty.dev/blog/build-awesome/",
          "note": "Funded by Font Awesome through a paid Pro tier, crowdfunding and Open Collective donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Trustpilot",
            "host": "au.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:06.762Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hexo",
      "category": "static-site-generators",
      "name": "Hexo",
      "description": "Blog framework and static site generator for Node.js that renders Markdown posts using themes and plugins.",
      "website": "https://hexo.io",
      "source": "https://github.com/hexojs/hexo",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Hexo scores 50 out of 100 (grade D) on the static site generators criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/static-site-generators/hexo/",
      "markdown": "https://privacyratings.com/static-site-generators/hexo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hexojs/hexo/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://hexo.io/",
          "note": "The hexo.io website loads Google Analytics. The hexo command has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/hexo",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:06.818Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hugo",
      "category": "static-site-generators",
      "name": "Hugo",
      "description": "Static site generator written in Go that builds websites from Markdown content and Go templates, distributed as a single binary.",
      "website": "https://gohugo.io",
      "source": "https://github.com/gohugoio/hugo",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Hugo scores 50 out of 100 (grade D) on the static site generators criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/static-site-generators/hugo/",
      "markdown": "https://privacyratings.com/static-site-generators/hugo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gohugoio/hugo/blob/master/LICENSE",
          "note": "Apache 2.0 licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://gohugo.io/",
          "note": "The gohugo.io website loads Google Analytics through Google Tag Manager. The hugo command has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/gohugoio/hugo#sponsors",
          "note": "Funded by sponsors listed in the repository, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:07.213Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "jekyll",
      "category": "static-site-generators",
      "name": "Jekyll",
      "description": "Static site generator written in Ruby that turns Markdown and Liquid templates into websites and blogs. It powers GitHub Pages.",
      "website": "https://jekyllrb.com",
      "source": "https://github.com/jekyll/jekyll",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Jekyll scores 50 out of 100 (grade D) on the static site generators criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/static-site-generators/jekyll/",
      "markdown": "https://privacyratings.com/static-site-generators/jekyll/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jekyll/jekyll/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://jekyllrb.com/",
          "note": "The jekyllrb.com website loads Google Analytics. The jekyll command has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/jekyll",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:07.081Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "lume",
      "category": "static-site-generators",
      "name": "Lume",
      "description": "Static site generator for Deno that supports many template languages and processes assets through plugins.",
      "website": "https://lume.land",
      "source": "https://github.com/lumeland/lume",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Lume scores 80 out of 100 (grade B) on the static site generators criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/static-site-generators/lume/",
      "markdown": "https://privacyratings.com/static-site-generators/lume/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/lumeland/lume/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/lumeland/lume",
          "note": "No telemetry or analytics in the source code, and the lume.land website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/lume",
          "note": "Funded by donations through Open Collective and GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:07.481Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "material-for-mkdocs",
      "category": "static-site-generators",
      "name": "Material for MkDocs",
      "description": "Documentation theme for MkDocs with search, navigation and many Markdown extensions. The project is in maintenance mode and receives only critical bug and security fixes.",
      "website": "https://squidfunk.github.io/mkdocs-material/",
      "source": "https://github.com/squidfunk/mkdocs-material",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Material for MkDocs scores 50 out of 100 (grade D) on the static site generators criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/static-site-generators/material-for-mkdocs/",
      "markdown": "https://privacyratings.com/static-site-generators/material-for-mkdocs/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/squidfunk/mkdocs-material/blob/master/LICENSE",
          "note": "MIT-licensed, including all former sponsor-only features."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://squidfunk.github.io/mkdocs-material/",
          "note": "The documentation website loads Google Analytics through Google Tag Manager. The theme has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://squidfunk.github.io/mkdocs-material/blog/2025/11/11/insiders-now-free-for-everyone/",
          "note": "Funded by sponsorships and now by the maintainers' work on Zensical, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:07.135Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mdbook",
      "category": "static-site-generators",
      "name": "mdBook",
      "description": "Command-line tool written in Rust that builds online books from Markdown files, with search, themes and a preprocessor system.",
      "website": "https://rust-lang.github.io/mdBook/",
      "source": "https://github.com/rust-lang/mdBook",
      "license": "MPL-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "mdBook scores 80 out of 100 (grade B) on the static site generators criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/static-site-generators/mdbook/",
      "markdown": "https://privacyratings.com/static-site-generators/mdbook/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rust-lang/mdBook/blob/main/LICENSE",
          "note": "MPL-2.0 licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rust-lang/mdBook",
          "note": "No telemetry or analytics in the source code, and the documentation site loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://rustfoundation.org/",
          "note": "Maintained by the Rust project, which is supported by the Rust Foundation, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:07.181Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mkdocs",
      "category": "static-site-generators",
      "name": "MkDocs",
      "description": "Static site generator written in Python for project documentation, built from Markdown files and a single YAML configuration file.",
      "website": "https://www.mkdocs.org",
      "source": "https://github.com/mkdocs/mkdocs",
      "license": "BSD-2-Clause",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "MkDocs scores 50 out of 100 (grade D) on the static site generators criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/static-site-generators/mkdocs/",
      "markdown": "https://privacyratings.com/static-site-generators/mkdocs/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mkdocs/mkdocs/blob/master/LICENSE",
          "note": "BSD 2-Clause licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.mkdocs.org/",
          "note": "The mkdocs.org website loads Google Analytics through Google Tag Manager. The mkdocs command has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/mkdocs",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:07.436Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nextra",
      "category": "static-site-generators",
      "name": "Nextra",
      "description": "Static site and documentation framework built on Next.js and React, which turns Markdown and MDX files into websites with themes for docs and blogs.",
      "website": "https://nextra.site",
      "source": "https://github.com/shuding/nextra",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Nextra scores 65 out of 100 (grade C) on the static site generators criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/static-site-generators/nextra/",
      "markdown": "https://privacyratings.com/static-site-generators/nextra/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/shuding/nextra/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://nextjs.org/telemetry",
          "note": "The nextra.site website has no third-party trackers, but Nextra sites are built with the Next.js CLI, which sends anonymous telemetry by default until disabled."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://nextra.site/sponsors",
          "note": "Funded by sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:07.374Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nikola",
      "category": "static-site-generators",
      "name": "Nikola",
      "description": "Static site generator written in Python that builds blogs and websites from reStructuredText, Markdown, Jupyter notebooks and other formats.",
      "website": "https://getnikola.com",
      "source": "https://github.com/getnikola/nikola",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Nikola scores 50 out of 100 (grade D) on the static site generators criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/static-site-generators/nikola/",
      "markdown": "https://privacyratings.com/static-site-generators/nikola/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/getnikola/nikola/blob/master/LICENSE.txt",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://getnikola.com/",
          "note": "The tool has no telemetry, but getnikola.com loads StatCounter analytics and Twitter widgets."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/nikola",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:07.503Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "pelican",
      "category": "static-site-generators",
      "name": "Pelican",
      "description": "Static site generator written in Python that builds websites from Markdown or reStructuredText content with Jinja templates.",
      "website": "https://getpelican.com",
      "source": "https://github.com/getpelican/pelican",
      "license": "AGPL-3.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Pelican scores 80 out of 100 (grade B) on the static site generators criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/static-site-generators/pelican/",
      "markdown": "https://privacyratings.com/static-site-generators/pelican/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/getpelican/pelican/blob/main/LICENSE",
          "note": "AGPL-3.0 licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/getpelican/pelican",
          "note": "No telemetry or analytics in the source code, and the getpelican.com website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/justinmayer",
          "note": "Funded by donations through GitHub Sponsors and Liberapay, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:07.858Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sphinx",
      "category": "static-site-generators",
      "name": "Sphinx",
      "description": "Documentation generator written in Python that builds HTML, PDF, ePub and other formats from reStructuredText or Markdown, with cross-references and API docs extracted from code.",
      "website": "https://www.sphinx-doc.org",
      "source": "https://github.com/sphinx-doc/sphinx",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 55,
      "coverage": 100,
      "summary": "Sphinx scores 55 out of 100 (grade D) on the static site generators criteria. It meets 1 of 4 criteria: open source. It partly meets no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/static-site-generators/sphinx/",
      "markdown": "https://privacyratings.com/static-site-generators/sphinx/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sphinx-doc/sphinx/blob/master/LICENSE.rst",
          "note": "BSD-2-Clause licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://docs.readthedocs.com/platform/stable/traffic-analytics.html",
          "note": "The tool has no telemetry, but sphinx-doc.org is hosted on Read the Docs, whose script records page views for Read the Docs traffic analytics and loads EthicalAds."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://docs.readthedocs.com/platform/stable/advertising/ethical-advertising.html",
          "note": "The documentation site on Read the Docs shows contextual EthicalAds; the software itself has no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:07.953Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "starlight",
      "category": "static-site-generators",
      "name": "Starlight",
      "description": "Documentation website framework built on Astro, with navigation, search, internationalization and theming included.",
      "website": "https://starlight.astro.build",
      "source": "https://github.com/withastro/starlight",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Starlight scores 65 out of 100 (grade C) on the static site generators criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/static-site-generators/starlight/",
      "markdown": "https://privacyratings.com/static-site-generators/starlight/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/withastro/starlight/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://astro.build/telemetry/",
          "note": "Astro, which Starlight runs on, sends anonymous CLI telemetry by default until disabled, and the website uses Fathom, a cookieless analytics service."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/astrodotbuild",
          "note": "Developed by the Astro team at Cloudflare and supported by Open Collective donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Fathom",
            "host": "cdn.usefathom.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:07.675Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vitepress",
      "category": "static-site-generators",
      "name": "VitePress",
      "description": "Static site generator built on Vite and Vue for documentation sites written in Markdown.",
      "website": "https://vitepress.dev",
      "source": "https://github.com/vuejs/vitepress",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "VitePress scores 80 out of 100 (grade B) on the static site generators criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/static-site-generators/vitepress/",
      "markdown": "https://privacyratings.com/static-site-generators/vitepress/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/vuejs/vitepress/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://vitepress.dev/",
          "note": "No third-party trackers, and the CLI has no telemetry. The vitepress.dev website's Fathom analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://vuejs.org/sponsor/",
          "note": "Funded by Vue.js sponsors and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Fathom",
            "host": "cdn.usefathom.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:07.759Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "zola",
      "category": "static-site-generators",
      "name": "Zola",
      "description": "Static site generator written in Rust, shipped as a single binary with templates, Sass compilation, syntax highlighting and search built in.",
      "website": "https://www.getzola.org",
      "source": "https://github.com/getzola/zola",
      "license": "EUPL-1.2",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Zola scores 80 out of 100 (grade B) on the static site generators criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/static-site-generators/zola/",
      "markdown": "https://privacyratings.com/static-site-generators/zola/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/getzola/zola/blob/master/LICENSE",
          "note": "Licensed under the EUPL-1.2, with older code under the MIT license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/getzola/zola",
          "note": "No telemetry or analytics in the source code, and the getzola.org website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/getzola/zola",
          "note": "Developed by volunteers as an open-source project, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:07.868Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "apache-cordova",
      "category": "app-frameworks",
      "name": "Apache Cordova",
      "description": "Apache Software Foundation framework for building mobile apps with HTML, CSS and JavaScript, packaged in a native webview with plugins for device APIs.",
      "website": "https://cordova.apache.org",
      "source": "https://github.com/apache/cordova",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Apache Cordova scores 80 out of 100 (grade B) on the cross-platform app frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/app-frameworks/apache-cordova/",
      "markdown": "https://privacyratings.com/app-frameworks/apache-cordova/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/apache/cordova-cli/blob/master/LICENSE",
          "note": "Apache-2.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://privacy.apache.org/policies/privacy-policy-public.html",
          "note": "No third-party trackers, and the CLI has no telemetry. The Apache Software Foundation's self-hosted Matomo uses no cookies and anonymizes IP addresses."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apache.org/foundation/sponsorship.html",
          "note": "Developed under the Apache Software Foundation, funded by sponsorships and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:07.739Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "avalonia-ui",
      "category": "app-frameworks",
      "name": "Avalonia UI",
      "description": "Cross-platform UI framework for .NET that draws its own controls with XAML and C#, targeting Windows, macOS, Linux, Android, iOS and WebAssembly.",
      "website": "https://avaloniaui.net",
      "source": "https://github.com/AvaloniaUI/Avalonia",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "EE",
        "name": "Estonia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Avalonia UI scores 50 out of 100 (grade D) on the cross-platform app frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Estonia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/app-frameworks/avalonia-ui/",
      "markdown": "https://privacyratings.com/app-frameworks/avalonia-ui/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/AvaloniaUI/Avalonia/blob/main/licence.md",
          "note": "MIT-licensed. Some add-on controls and the XPF product are sold separately under proprietary licenses."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://avaloniaui.net/",
          "note": "The avaloniaui.net website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://avaloniaui.net/pricing",
          "note": "Funded by paid add-ons, enterprise products and support, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:08.568Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "beeware",
      "category": "app-frameworks",
      "name": "BeeWare",
      "description": "Collection of Python tools for building native apps, including the Toga GUI toolkit that uses each platform's native widgets and the Briefcase packaging tool.",
      "website": "https://beeware.org",
      "source": "https://github.com/beeware/toga",
      "license": "BSD-3-Clause",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "BeeWare scores 80 out of 100 (grade B) on the cross-platform app frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/app-frameworks/beeware/",
      "markdown": "https://privacyratings.com/app-frameworks/beeware/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/beeware/toga/blob/main/LICENSE",
          "note": "BSD-3-Clause-licensed, as is the Briefcase packaging tool."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/beeware/briefcase",
          "note": "No telemetry or analytics in the Toga or Briefcase source code, and beeware.org loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://beeware.org/membership/",
          "note": "Funded by memberships and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:08.314Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "capacitor",
      "category": "app-frameworks",
      "name": "Capacitor",
      "description": "Cross-platform native runtime for running web apps on Android and iOS and as progressive web apps, with a plugin API for native device features.",
      "website": "https://capacitorjs.com",
      "source": "https://github.com/ionic-team/capacitor",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Capacitor scores 50 out of 100 (grade D) on the cross-platform app frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/app-frameworks/capacitor/",
      "markdown": "https://privacyratings.com/app-frameworks/capacitor/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ionic-team/capacitor/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://capacitorjs.com/docs/cli/telemetry",
          "note": "The Capacitor CLI enrolls users in anonymous telemetry after its first command until turned off, and capacitorjs.com loads Google Tag Manager and HubSpot."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ionic.io/blog/important-announcement-the-future-of-ionics-commercial-products",
          "note": "Developed by Ionic, part of OutSystems, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:08.083Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "electrobun",
      "category": "app-frameworks",
      "name": "Electrobun",
      "description": "Framework for building desktop apps in TypeScript, with a native layer written in Zig, Objective-C and C++, compact bundles and built-in differential updates.",
      "website": "https://blackboard.sh/electrobun/",
      "source": "https://github.com/blackboardsh/electrobun",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Electrobun scores 50 out of 100 (grade D) on the cross-platform app frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/app-frameworks/electrobun/",
      "markdown": "https://privacyratings.com/app-frameworks/electrobun/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/blackboardsh/electrobun/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://blackboard.sh/electrobun/",
          "note": "No telemetry in the source code, but the Electrobun website loads Mixpanel."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/YoavCodes",
          "note": "Developed by Blackboard Technologies and funded by GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Mixpanel",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:08.337Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "electron",
      "category": "app-frameworks",
      "name": "Electron",
      "description": "Framework for building cross-platform desktop applications with JavaScript, HTML and CSS by bundling Chromium and Node.js.",
      "website": "https://www.electronjs.org",
      "source": "https://github.com/electron/electron",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Electron scores 50 out of 100 (grade D) on the cross-platform app frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/app-frameworks/electron/",
      "markdown": "https://privacyratings.com/app-frameworks/electron/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/electron/electron/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.electronjs.org/",
          "note": "The electronjs.org website loads Google Analytics; the framework itself has no built-in telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.electronjs.org/governance",
          "note": "A project of the OpenJS Foundation, funded by member organizations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:08.506Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "expo",
      "category": "app-frameworks",
      "name": "Expo",
      "description": "Framework and tooling built on React Native for building Android, iOS and web apps, with a CLI, SDK modules, file-based routing and optional cloud build services.",
      "website": "https://expo.dev",
      "source": "https://github.com/expo/expo",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Expo scores 50 out of 100 (grade D) on the cross-platform app frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/app-frameworks/expo/",
      "markdown": "https://privacyratings.com/app-frameworks/expo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/expo/expo/blob/main/LICENSE",
          "note": "MIT-licensed. The EAS cloud build and update services are separate hosted products."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://docs.expo.dev/more/expo-cli/#telemetry",
          "note": "The Expo CLI sends anonymous usage data by default until EXPO_NO_TELEMETRY is set, and expo.dev loads the RudderStack analytics SDK."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://expo.dev/pricing",
          "note": "Funded by paid Expo Application Services plans, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:08.332Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "flutter",
      "category": "app-frameworks",
      "name": "Flutter",
      "description": "Google's UI toolkit for building natively compiled mobile, web and desktop apps from one Dart codebase, drawing its own widgets with its rendering engine.",
      "website": "https://flutter.dev",
      "source": "https://github.com/flutter/flutter",
      "license": "BSD-3-Clause",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Flutter scores 50 out of 100 (grade D) on the cross-platform app frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/app-frameworks/flutter/",
      "markdown": "https://privacyratings.com/app-frameworks/flutter/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/flutter/flutter/blob/master/LICENSE",
          "note": "BSD-3-Clause licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://docs.flutter.dev/reference/crash-reporting",
          "note": "The flutter tool sends usage statistics and crash reports to Google by default until disabled, and flutter.dev loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://flutter.dev/",
          "note": "Developed and funded by Google, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:08.275Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "framework7",
      "category": "app-frameworks",
      "name": "Framework7",
      "description": "HTML and JavaScript framework for building mobile, desktop and web apps with an iOS and Material Design look, usable with Vue, React or Svelte.",
      "website": "https://framework7.io",
      "source": "https://github.com/framework7io/framework7",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Framework7 scores 50 out of 100 (grade D) on the cross-platform app frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/app-frameworks/framework7/",
      "markdown": "https://privacyratings.com/app-frameworks/framework7/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/framework7io/framework7/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://framework7.io/",
          "note": "No telemetry in the framework, but the framework7.io website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://sponsors.nolimits4web.com/",
          "note": "Funded by sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "au.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:09.156Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fyne",
      "category": "app-frameworks",
      "name": "Fyne",
      "description": "GUI toolkit for Go that builds desktop, mobile and web apps from a single codebase.",
      "website": "https://fyne.io",
      "source": "https://github.com/fyne-io/fyne",
      "license": "BSD-3-Clause",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Fyne scores 50 out of 100 (grade D) on the cross-platform app frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/app-frameworks/fyne/",
      "markdown": "https://privacyratings.com/app-frameworks/fyne/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/fyne-io/fyne/blob/develop/LICENSE",
          "note": "BSD 3-Clause licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://fyne.io/",
          "note": "The fyne.io website loads Google Analytics through Google Tag Manager. The toolkit itself has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://fyne.io/sponsor/",
          "note": "Funded by sponsors and donations through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:09.217Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gtk",
      "category": "app-frameworks",
      "name": "GTK",
      "description": "Toolkit for building graphical user interfaces, written in C with bindings for many languages. It is developed by the GNOME project.",
      "website": "https://www.gtk.org",
      "source": "https://gitlab.gnome.org/GNOME/gtk",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "GTK scores 80 out of 100 (grade B) on the cross-platform app frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/app-frameworks/gtk/",
      "markdown": "https://privacyratings.com/app-frameworks/gtk/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/GNOME/gtk/-/blob/main/COPYING",
          "note": "Licensed under the LGPL-2.1-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/GNOME/gtk",
          "note": "No telemetry or analytics in the source code, and the gtk.org website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://donate.gnome.org/en/",
          "note": "Supported by the GNOME Foundation through donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:09.285Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "iced",
      "category": "app-frameworks",
      "name": "Iced",
      "description": "Cross-platform GUI library for Rust based on the Elm architecture, focused on simplicity and type safety.",
      "website": "https://iced.rs",
      "source": "https://github.com/iced-rs/iced",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Iced scores 80 out of 100 (grade B) on the cross-platform app frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/app-frameworks/iced/",
      "markdown": "https://privacyratings.com/app-frameworks/iced/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/iced-rs/iced/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/iced-rs/iced",
          "note": "No telemetry or analytics in the source code, and the iced.rs website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/hecrj",
          "note": "Funded through GitHub Sponsors and company sponsorship, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:10.454Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ionic",
      "category": "app-frameworks",
      "name": "Ionic",
      "description": "UI toolkit of web components for building mobile, desktop and progressive web apps with HTML, CSS and JavaScript, usable with Angular, React or Vue.",
      "website": "https://ionicframework.com",
      "source": "https://github.com/ionic-team/ionic-framework",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Ionic scores 50 out of 100 (grade D) on the cross-platform app frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/app-frameworks/ionic/",
      "markdown": "https://privacyratings.com/app-frameworks/ionic/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ionic-team/ionic-framework/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://ionicframework.com/docs/cli/configuration",
          "note": "The Ionic CLI sends usage data by default until disabled, and ionicframework.com loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ionic.io/blog/important-announcement-the-future-of-ionics-commercial-products",
          "note": "Developed by Ionic, part of OutSystems, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:09.243Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "jetpack-compose",
      "category": "app-frameworks",
      "name": "Jetpack Compose",
      "description": "Google's declarative UI toolkit for Android apps, written in Kotlin, where interfaces are built from composable functions.",
      "website": "https://developer.android.com/compose",
      "source": "https://github.com/androidx/androidx",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Jetpack Compose scores 50 out of 100 (grade D) on the cross-platform app frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/app-frameworks/jetpack-compose/",
      "markdown": "https://privacyratings.com/app-frameworks/jetpack-compose/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/androidx/androidx/blob/androidx-main/LICENSE.txt",
          "note": "Apache-2.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://developer.android.com/compose",
          "note": "The developer.android.com website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/androidx/androidx/blob/androidx-main/LICENSE.txt",
          "note": "Developed and funded by Google, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:11.569Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kivy",
      "category": "app-frameworks",
      "name": "Kivy",
      "description": "Python framework for cross-platform apps with multi-touch support, drawing its own GPU-accelerated widgets and using the KV design language.",
      "website": "https://kivy.org",
      "source": "https://github.com/kivy/kivy",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android",
        "ios"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Kivy scores 80 out of 100 (grade B) on the cross-platform app frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/app-frameworks/kivy/",
      "markdown": "https://privacyratings.com/app-frameworks/kivy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/kivy/kivy/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/kivy/kivy",
          "note": "No telemetry or analytics in the source code, and kivy.org loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/kivy",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:10.555Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kotlin-multiplatform",
      "category": "app-frameworks",
      "name": "Kotlin Multiplatform",
      "description": "JetBrains technology for sharing Kotlin code across Android, iOS, desktop, web and server, with Compose Multiplatform for shared user interfaces.",
      "website": "https://kotlinlang.org/multiplatform/",
      "source": "https://github.com/JetBrains/kotlin",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "CZ",
        "name": "Czechia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Kotlin Multiplatform scores 50 out of 100 (grade D) on the cross-platform app frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Czechia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/app-frameworks/kotlin-multiplatform/",
      "markdown": "https://privacyratings.com/app-frameworks/kotlin-multiplatform/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/JetBrains/kotlin/blob/master/license/LICENSE.txt",
          "note": "Apache-2.0 licensed, as is Compose Multiplatform."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://kotlinlang.org/multiplatform/",
          "note": "The kotlinlang.org website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.jetbrains.com/store/",
          "note": "Developed by JetBrains and funded by its paid developer tools, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Optimizely",
            "host": "cdn.optimizely.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:10.893Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "lynx",
      "category": "app-frameworks",
      "name": "Lynx",
      "description": "Cross-platform framework for building native mobile and web interfaces with web technologies such as CSS and React, using a multi-threaded rendering engine.",
      "website": "https://lynxjs.org",
      "source": "https://github.com/lynx-family/lynx",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Lynx scores 50 out of 100 (grade D) on the cross-platform app frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/app-frameworks/lynx/",
      "markdown": "https://privacyratings.com/app-frameworks/lynx/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/lynx-family/lynx/blob/develop/LICENSE",
          "note": "Apache-2.0 licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://lynxjs.org/",
          "note": "The lynxjs.org website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://lynxjs.org/next/blog/lynx-unlock-native-for-more.html",
          "note": "Developed by the team behind TikTok, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:10.601Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nativescript",
      "category": "app-frameworks",
      "name": "NativeScript",
      "description": "Framework for building native Android and iOS apps with JavaScript or TypeScript, giving direct access to native platform APIs, usable with Angular, Vue, React, Svelte or Solid.",
      "website": "https://nativescript.org",
      "source": "https://github.com/NativeScript/NativeScript",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "NativeScript scores 80 out of 100 (grade B) on the cross-platform app frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/app-frameworks/nativescript/",
      "markdown": "https://privacyratings.com/app-frameworks/nativescript/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/NativeScript/NativeScript/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/NativeScript/nativescript-cli/blob/main/docs/man_pages/general/usage-reporting.md",
          "note": "No third-party trackers, and the CLI sends usage statistics only after consent. The website's Cloudflare Web Analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/nativescript",
          "note": "An OpenJS Foundation project funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:10.502Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "net-maui",
      "category": "app-frameworks",
      "name": ".NET MAUI",
      "description": "Microsoft's cross-platform UI framework for building native Android, iOS, macOS and Windows apps from a single C# and XAML codebase.",
      "website": "https://dotnet.microsoft.com/en-us/apps/maui",
      "source": "https://github.com/dotnet/maui",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": ".NET MAUI scores 50 out of 100 (grade D) on the cross-platform app frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/app-frameworks/net-maui/",
      "markdown": "https://privacyratings.com/app-frameworks/net-maui/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dotnet/maui/blob/main/LICENSE.txt",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/dotnet/core/tools/telemetry",
          "note": "The .NET SDK sends usage telemetry by default until opted out, and dotnet.microsoft.com loads Microsoft analytics and Adobe Target."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://dotnet.microsoft.com/en-us/apps/maui",
          "note": "Developed and funded by Microsoft, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:16.711Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "neutralinojs",
      "category": "app-frameworks",
      "name": "Neutralinojs",
      "description": "Lightweight framework for building desktop apps with JavaScript, HTML and CSS, using the operating system's webview and a small native server instead of a bundled browser.",
      "website": "https://neutralino.js.org",
      "source": "https://github.com/neutralinojs/neutralinojs",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Neutralinojs scores 40 out of 100 (grade D) on the cross-platform app frameworks criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/app-frameworks/neutralinojs/",
      "markdown": "https://privacyratings.com/app-frameworks/neutralinojs/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/neutralinojs/neutralinojs/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://neutralino.js.org/",
          "note": "The neutralino.js.org website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://opencollective.com/neutralinojs",
          "note": "Funded by donations through Open Collective, but the website shows EthicalAds."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:10.706Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nw-js",
      "category": "app-frameworks",
      "name": "NW.js",
      "description": "Runtime that combines Chromium and Node.js for building desktop apps with HTML and JavaScript, with Node.js modules callable from the DOM.",
      "website": "https://nwjs.io",
      "source": "https://github.com/nwjs/nw.js",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "NW.js scores 50 out of 100 (grade D) on the cross-platform app frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/app-frameworks/nw-js/",
      "markdown": "https://privacyratings.com/app-frameworks/nw-js/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nwjs/nw.js/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://nwjs.io/",
          "note": "The nwjs.io website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/nwjs/nw.js",
          "note": "Community-maintained open-source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:10.754Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "qt",
      "category": "app-frameworks",
      "name": "Qt",
      "description": "Cross-platform C++ application framework with the Qt Widgets and Qt Quick/QML user interface toolkits, for desktop, mobile and embedded devices.",
      "website": "https://www.qt.io",
      "source": "https://code.qt.io/cgit/qt/qtbase.git/",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "FI",
        "name": "Finland",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Qt scores 35 out of 100 (grade F) on the cross-platform app frameworks criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source. It does not meet no trackers or telemetry and independent audit. It is based in Finland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/app-frameworks/qt/",
      "markdown": "https://privacyratings.com/app-frameworks/qt/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://code.qt.io/cgit/qt/qtbase.git/tree/LICENSES/LGPL-3.0-only.txt",
          "note": "Available under LGPLv3 and GPL, or under a commercial license, but a few add-on modules and tools are commercial only."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.qt.io/",
          "note": "The qt.io website loads Google Tag Manager, HubSpot, Optimizely and Sentry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.qt.io/pricing",
          "note": "Funded by commercial licenses from The Qt Company, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js-eu1.hsforms.net",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          },
          {
            "name": "Sentry",
            "host": "js.sentry-cdn.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:11.871Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "quasar",
      "category": "app-frameworks",
      "name": "Quasar",
      "description": "Vue.js-based framework for building web, mobile and desktop apps from one codebase, with a Material component library and a CLI.",
      "website": "https://quasar.dev",
      "source": "https://github.com/quasarframework/quasar",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Quasar scores 50 out of 100 (grade D) on the cross-platform app frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/app-frameworks/quasar/",
      "markdown": "https://privacyratings.com/app-frameworks/quasar/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/quasarframework/quasar/blob/dev/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://quasar.dev/",
          "note": "No telemetry in the CLI, but the quasar.dev website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/rstoenescu",
          "note": "Funded by sponsors through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:11.040Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "react-native",
      "category": "app-frameworks",
      "name": "React Native",
      "description": "Framework from Meta for building native Android and iOS apps with React and JavaScript or TypeScript, rendering platform-native UI components.",
      "website": "https://reactnative.dev",
      "source": "https://github.com/facebook/react-native",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "React Native scores 50 out of 100 (grade D) on the cross-platform app frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/app-frameworks/react-native/",
      "markdown": "https://privacyratings.com/app-frameworks/react-native/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/facebook/react-native/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reactnative.dev/",
          "note": "The reactnative.dev website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://react.dev/blog/2025/10/07/introducing-the-react-foundation",
          "note": "Developed by Meta and member companies of the React Foundation, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:11.239Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "slint",
      "category": "app-frameworks",
      "name": "Slint",
      "description": "UI toolkit for building native user interfaces with a declarative markup language, with APIs for Rust, C++, JavaScript and Python, for desktop, mobile and embedded devices.",
      "website": "https://slint.dev",
      "source": "https://github.com/slint-ui/slint",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android",
        "web"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Slint scores 65 out of 100 (grade C) on the cross-platform app frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/app-frameworks/slint/",
      "markdown": "https://privacyratings.com/app-frameworks/slint/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/slint-ui/slint/blob/master/LICENSE.md",
          "note": "Available under GPLv3, a royalty-free license for proprietary desktop and mobile apps, or a commercial license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/slint-ui/slint/blob/master/editors/vscode/src/telemetry.ts",
          "note": "The VS Code extension sends usage data to slint.dev unless VS Code telemetry is turned off, and slint.dev uses Cloudflare Web Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://slint.dev/pricing",
          "note": "Funded by commercial licenses and support from SixtyFPS GmbH, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:11.138Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "swiftui",
      "category": "app-frameworks",
      "name": "SwiftUI",
      "description": "Apple's declarative UI framework for building apps in Swift across iOS, iPadOS, macOS, watchOS, tvOS and visionOS.",
      "website": "https://developer.apple.com/swiftui/",
      "license": null,
      "platforms": [
        "macos",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "SwiftUI scores 35 out of 100 (grade F) on the cross-platform app frameworks criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets no trackers or telemetry. It does not meet open source and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/app-frameworks/swiftui/",
      "markdown": "https://privacyratings.com/app-frameworks/swiftui/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. SwiftUI ships as a proprietary framework in Apple's SDKs."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/device-analytics/",
          "note": "No third-party trackers, and sharing device analytics with Apple is opt-in. Apple web pages load Apple's own analytics by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://developer.apple.com/programs/",
          "note": "Funded by Apple's hardware sales and paid developer program, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:11.395Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "tauri",
      "category": "app-frameworks",
      "name": "Tauri",
      "description": "Framework for building desktop and mobile applications with a web frontend and a Rust backend, using the operating system's webview.",
      "website": "https://tauri.app",
      "source": "https://github.com/tauri-apps/tauri",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": true,
      "pick_reason": "Small, fast apps for desktop and mobile from one web codebase, using the system web view instead of a bundled browser. A Rust core with a permission system, no telemetry, and a public independent audit. Pairs well with Svelte and TypeScript, as in the Forward Email apps (github.com/forwardemail/mail.forwardemail.net), which ship to Windows, macOS, Linux, Android and iOS from one Tauri, Svelte and TypeScript codebase.",
      "disclosure": null,
      "grade": "B",
      "score": 85,
      "coverage": 100,
      "summary": "Tauri scores 85 out of 100 (grade B) on the cross-platform app frameworks criteria. It meets 3 of 4 criteria: open source, no ads or data sales and independent audit. It partly meets no trackers or telemetry. It is based in the Netherlands: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/app-frameworks/tauri/",
      "markdown": "https://privacyratings.com/app-frameworks/tauri/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/tauri-apps/tauri/blob/dev/LICENSE.spdx",
          "note": "Dual-licensed under MIT and Apache 2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://tauri.app/",
          "note": "The framework and CLI have no telemetry, but tauri.app loads Netlify Real User Monitoring."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/tauri",
          "note": "Run by the Tauri Programme within the Commons Conservancy and funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/tauri-apps/tauri/blob/dev/audits/Radically_Open_Security-v2-report.pdf",
          "note": "Radically Open Security published a full penetration test report on Tauri 2.0."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:11.470Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "uno-platform",
      "category": "app-frameworks",
      "name": "Uno Platform",
      "description": "Cross-platform UI framework for .NET that runs C# and XAML apps on Windows, macOS, Linux, Android, iOS and WebAssembly, using WinUI APIs.",
      "website": "https://platform.uno",
      "source": "https://github.com/unoplatform/uno",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Uno Platform scores 50 out of 100 (grade D) on the cross-platform app frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Canada: Five Eyes member.",
      "url": "https://privacyratings.com/app-frameworks/uno-platform/",
      "markdown": "https://privacyratings.com/app-frameworks/uno-platform/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/unoplatform/uno/blob/master/License.md",
          "note": "Apache-2.0 licensed. Some design and productivity tools are sold separately."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://platform.uno/docs/articles/uno-toolchain-telemetry.html",
          "note": "The Uno Platform SDK collects build telemetry by default until opted out, and platform.uno loads Google Tag Manager, HubSpot, LinkedIn and X ad pixels."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://platform.uno/select-subscription/",
          "note": "Funded by paid subscriptions for its developer tools and support, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js-na1.hs-scripts.com",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "snap.licdn.com",
            "effect": "no"
          },
          {
            "name": "X (Twitter) Pixel",
            "host": "static.ads-twitter.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:11.606Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "wails",
      "category": "app-frameworks",
      "name": "Wails",
      "description": "Framework for building desktop apps with Go and web technologies, using the operating system's native webview for the frontend.",
      "website": "https://wails.io",
      "source": "https://github.com/wailsapp/wails",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Wails scores 80 out of 100 (grade B) on the cross-platform app frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/app-frameworks/wails/",
      "markdown": "https://privacyratings.com/app-frameworks/wails/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/wailsapp/wails/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/wailsapp/wails/blob/master/website/docusaurus.config.js",
          "note": "No telemetry in the source code, and the wails.io website configuration loads no analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/leaanthony",
          "note": "Funded by donations through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:11.938Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bottle",
      "category": "python-frameworks",
      "name": "Bottle",
      "description": "Single-file micro web framework for Python with no dependencies other than the standard library.",
      "website": "https://bottlepy.org",
      "source": "https://github.com/bottlepy/bottle",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Bottle scores 80 out of 100 (grade B) on the Python web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/python-frameworks/bottle/",
      "markdown": "https://privacyratings.com/python-frameworks/bottle/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bottlepy/bottle/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bottlepy/bottle",
          "note": "No telemetry in the source code, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/defnull",
          "note": "Funded by GitHub Sponsors and Liberapay donations to the maintainer, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:13.984Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "django-rest-framework",
      "category": "python-frameworks",
      "name": "Django REST framework",
      "description": "Toolkit for building web APIs with Django, providing serializers, viewsets, authentication, permissions and a browsable API.",
      "website": "https://www.django-rest-framework.org",
      "source": "https://github.com/encode/django-rest-framework",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Django REST framework scores 80 out of 100 (grade B) on the Python web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/python-frameworks/django-rest-framework/",
      "markdown": "https://privacyratings.com/python-frameworks/django-rest-framework/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/encode/django-rest-framework/blob/main/LICENSE.md",
          "note": "BSD-3-Clause-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/encode/django-rest-framework",
          "note": "No telemetry in the framework source code, and the website has no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://fund.django-rest-framework.org/topics/funding/",
          "note": "Funded by sponsorships and paid plans for companies, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:12.110Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "django",
      "category": "python-frameworks",
      "name": "Django",
      "description": "Batteries-included Python web framework with an ORM, admin interface, templates and authentication.",
      "website": "https://www.djangoproject.com",
      "source": "https://github.com/django/django",
      "license": "BSD-3-Clause",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Django scores 80 out of 100 (grade B) on the Python web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/python-frameworks/django/",
      "markdown": "https://privacyratings.com/python-frameworks/django/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/django/django/blob/main/LICENSE",
          "note": "BSD-3-Clause licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.djangoproject.com/",
          "note": "No third-party trackers, and the framework has no telemetry. The website's Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.djangoproject.com/fundraising/",
          "note": "Funded by donations and corporate members of the Django Software Foundation, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:12.063Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "falcon",
      "category": "python-frameworks",
      "name": "Falcon",
      "description": "Minimal Python framework for building REST APIs and microservices, supporting both WSGI and ASGI.",
      "website": "https://falconframework.org",
      "source": "https://github.com/falconry/falcon",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 70,
      "coverage": 100,
      "summary": "Falcon scores 70 out of 100 (grade C) on the Python web frameworks criteria. It meets 2 of 4 criteria: open source and no trackers or telemetry. It partly meets no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/python-frameworks/falcon/",
      "markdown": "https://privacyratings.com/python-frameworks/falcon/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/falconry/falcon/blob/master/LICENSE",
          "note": "Apache-2.0 licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/falconry/falcon",
          "note": "No telemetry in the source code, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://falcon.readthedocs.io/en/stable/",
          "note": "Funded by donations through Open Collective, but the documentation hosted on Read the Docs shows EthicalAds."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:12.319Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fastapi",
      "category": "python-frameworks",
      "name": "FastAPI",
      "description": "Python framework for building APIs with type hints, based on Starlette and Pydantic, with automatic request validation and OpenAPI documentation.",
      "website": "https://fastapi.tiangolo.com",
      "source": "https://github.com/fastapi/fastapi",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "FastAPI scores 80 out of 100 (grade B) on the Python web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/python-frameworks/fastapi/",
      "markdown": "https://privacyratings.com/python-frameworks/fastapi/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/fastapi/fastapi/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://fastapi.tiangolo.com/",
          "note": "No third-party trackers, and the framework and CLI have no telemetry. The website's Cloudflare Web Analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/tiangolo",
          "note": "Funded by sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:12.356Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "flask",
      "category": "python-frameworks",
      "name": "Flask",
      "description": "Lightweight WSGI web framework for Python, built on Werkzeug and Jinja, that leaves databases and other components to extensions.",
      "website": "https://flask.palletsprojects.com",
      "source": "https://github.com/pallets/flask",
      "license": "BSD-3-Clause",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 70,
      "coverage": 100,
      "summary": "Flask scores 70 out of 100 (grade C) on the Python web frameworks criteria. It meets 2 of 4 criteria: open source and no trackers or telemetry. It partly meets no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/python-frameworks/flask/",
      "markdown": "https://privacyratings.com/python-frameworks/flask/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pallets/flask/blob/main/LICENSE.txt",
          "note": "BSD-3-Clause licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pallets/flask",
          "note": "No telemetry in the source code, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://flask.palletsprojects.com/en/stable/",
          "note": "Funded by donations to Pallets, but the documentation hosted on Read the Docs shows EthicalAds."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:12.496Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gradio",
      "category": "python-frameworks",
      "name": "Gradio",
      "description": "Python library from Hugging Face for building web interfaces and demos for machine learning models and other Python functions.",
      "website": "https://gradio.app",
      "source": "https://github.com/gradio-app/gradio",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 70,
      "coverage": 100,
      "summary": "Gradio scores 70 out of 100 (grade C) on the Python web frameworks criteria. It meets 3 of 4 criteria: open source, no ads or data sales and independent audit. It does not meet no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/python-frameworks/gradio/",
      "markdown": "https://privacyratings.com/python-frameworks/gradio/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gradio-app/gradio/blob/main/LICENSE",
          "note": "Apache-2.0 licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://gradio.app/guides/environment-variables",
          "note": "Apps send basic telemetry to Hugging Face by default until GRADIO_ANALYTICS_ENABLED is set to False, and gradio.app loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://huggingface.co/pricing",
          "note": "Developed by Hugging Face and funded by its paid plans, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/trailofbits/publications/blob/master/reviews/2024-10-huggingface-gradio-securityreview.pdf",
          "note": "Trail of Bits published a full security review of Gradio 5."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:12.382Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "litestar",
      "category": "python-frameworks",
      "name": "Litestar",
      "description": "ASGI web framework for Python for building APIs, with dependency injection, data validation, ORM integration and OpenAPI documentation.",
      "website": "https://litestar.dev",
      "source": "https://github.com/litestar-org/litestar",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Litestar scores 80 out of 100 (grade B) on the Python web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/python-frameworks/litestar/",
      "markdown": "https://privacyratings.com/python-frameworks/litestar/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/litestar-org/litestar/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/litestar-org/litestar",
          "note": "No telemetry in the source code, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/litestar",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:12.508Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "masonite",
      "category": "python-frameworks",
      "name": "Masonite",
      "description": "Batteries-included Python web framework with an ORM, queues, mail, notifications and task scheduling, built around a service container.",
      "website": "https://www.masonite.dev",
      "source": "https://github.com/masonitedev/masonite",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Masonite scores 80 out of 100 (grade B) on the Python web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/python-frameworks/masonite/",
      "markdown": "https://privacyratings.com/python-frameworks/masonite/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/masonitedev/masonite/blob/5.0/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/masonitedev/masonite",
          "note": "No telemetry in the framework source code, and the website has no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/masonitedev/masonite/blob/5.0/.github/FUNDING.yml",
          "note": "Maintained by volunteers and funded through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:12.631Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nicegui",
      "category": "python-frameworks",
      "name": "NiceGUI",
      "description": "Python framework for building web-based user interfaces that run in the browser or as a desktop app.",
      "website": "https://nicegui.io",
      "source": "https://github.com/zauberzeug/nicegui",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "NiceGUI scores 80 out of 100 (grade B) on the Python web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/python-frameworks/nicegui/",
      "markdown": "https://privacyratings.com/python-frameworks/nicegui/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/zauberzeug/nicegui/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://nicegui.io/",
          "note": "No third-party trackers, and the framework has no telemetry. The website's Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/zauberzeug",
          "note": "Developed by Zauberzeug and funded by GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:12.749Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "pyramid",
      "category": "python-frameworks",
      "name": "Pyramid",
      "description": "Python web framework from the Pylons Project that scales from single-file apps to large applications, with a choice of templating and database layers.",
      "website": "https://trypyramid.com",
      "source": "https://github.com/Pylons/pyramid",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Pyramid scores 40 out of 100 (grade D) on the Python web frameworks criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/python-frameworks/pyramid/",
      "markdown": "https://privacyratings.com/python-frameworks/pyramid/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Pylons/pyramid/blob/main/LICENSE.txt",
          "note": "Licensed under the BSD-derived Repoze Public License."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://trypyramid.com/",
          "note": "No telemetry in the framework, but trypyramid.com loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://docs.pylonsproject.org/projects/pyramid/en/latest/",
          "note": "A volunteer project with no ads in the framework, but the documentation hosted on Read the Docs shows EthicalAds."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:12.685Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "quart",
      "category": "python-frameworks",
      "name": "Quart",
      "description": "Asynchronous Python web framework with the Flask API, built on ASGI.",
      "website": "https://quart.palletsprojects.com",
      "source": "https://github.com/pallets/quart",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 70,
      "coverage": 100,
      "summary": "Quart scores 70 out of 100 (grade C) on the Python web frameworks criteria. It meets 2 of 4 criteria: open source and no trackers or telemetry. It partly meets no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/python-frameworks/quart/",
      "markdown": "https://privacyratings.com/python-frameworks/quart/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pallets/quart/blob/main/LICENSE.txt",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pallets/quart",
          "note": "No telemetry in the source code, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://quart.palletsprojects.com/en/latest/",
          "note": "Funded by donations to Pallets, but the documentation hosted on Read the Docs shows EthicalAds."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:13.067Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "reflex",
      "category": "python-frameworks",
      "name": "Reflex",
      "description": "Framework for building full-stack web apps in pure Python, which compiles the frontend to a React app.",
      "website": "https://reflex.dev",
      "source": "https://github.com/reflex-dev/reflex",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Reflex scores 40 out of 100 (grade D) on the Python web frameworks criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/python-frameworks/reflex/",
      "markdown": "https://privacyratings.com/python-frameworks/reflex/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/reflex-dev/reflex/blob/main/LICENSE",
          "note": "Apache-2.0 licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reflex.dev/docs/api-reference/telemetry/",
          "note": "The CLI sends anonymous usage data to PostHog by default until disabled, and reflex.dev loads Google Analytics, the Meta Pixel, PostHog, HubSpot and Ahrefs analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://reflex.dev/pricing/",
          "note": "Funded by paid Reflex Cloud and enterprise plans, but reflex.dev shares visitor data with Meta and Google for advertising its own product."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Meta Pixel",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "PostHog",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:13.360Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sanic",
      "category": "python-frameworks",
      "name": "Sanic",
      "description": "Asynchronous Python web server and framework built on asyncio.",
      "website": "https://sanic.dev",
      "source": "https://github.com/sanic-org/sanic",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Sanic scores 80 out of 100 (grade B) on the Python web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/python-frameworks/sanic/",
      "markdown": "https://privacyratings.com/python-frameworks/sanic/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sanic-org/sanic/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://sanic.dev/en/",
          "note": "No third-party trackers, and the framework has no telemetry. The website's self-hosted Umami analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/sanic-org",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:13.367Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "starlette",
      "category": "python-frameworks",
      "name": "Starlette",
      "description": "Lightweight ASGI toolkit and framework for building asynchronous web services in Python.",
      "website": "https://starlette.dev",
      "source": "https://github.com/Kludex/starlette",
      "license": "BSD-3-Clause",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Starlette scores 50 out of 100 (grade D) on the Python web frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/python-frameworks/starlette/",
      "markdown": "https://privacyratings.com/python-frameworks/starlette/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Kludex/starlette/blob/main/LICENSE.md",
          "note": "BSD-3-Clause licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://starlette.dev",
          "note": "No telemetry in the framework, but starlette.dev loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/Kludex",
          "note": "Funded by GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:13.078Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "streamlit",
      "category": "python-frameworks",
      "name": "Streamlit",
      "description": "Python framework from Snowflake for turning data scripts into interactive web apps and dashboards.",
      "website": "https://streamlit.io",
      "source": "https://github.com/streamlit/streamlit",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Streamlit scores 50 out of 100 (grade D) on the Python web frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/python-frameworks/streamlit/",
      "markdown": "https://privacyratings.com/python-frameworks/streamlit/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/streamlit/streamlit/blob/develop/LICENSE",
          "note": "Apache-2.0 licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://docs.streamlit.io/develop/api-reference/configuration/config.toml",
          "note": "Apps send usage statistics to Streamlit by default (browser.gatherUsageStats), and streamlit.io loads Segment analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.snowflake.com/en/pricing-options/",
          "note": "Developed by Snowflake and funded by its paid data platform, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:13.695Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "tornado",
      "category": "python-frameworks",
      "name": "Tornado",
      "description": "Python web framework and asynchronous networking library, suited to long polling, WebSockets and other long-lived connections.",
      "website": "https://www.tornadoweb.org",
      "source": "https://github.com/tornadoweb/tornado",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Tornado scores 80 out of 100 (grade B) on the Python web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/python-frameworks/tornado/",
      "markdown": "https://privacyratings.com/python-frameworks/tornado/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/tornadoweb/tornado/blob/master/LICENSE",
          "note": "Apache-2.0 licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/tornadoweb/tornado",
          "note": "No telemetry in the source code, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.tornadoweb.org/en/stable/",
          "note": "A volunteer project with ad-free documentation."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:13.700Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "web2py",
      "category": "python-frameworks",
      "name": "web2py",
      "description": "Full-stack Python web framework with a database abstraction layer, a web-based development interface and security defaults, designed to run without installation.",
      "website": "https://web2py.com",
      "source": "https://github.com/web2py/web2py",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "web2py scores 80 out of 100 (grade B) on the Python web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/python-frameworks/web2py/",
      "markdown": "https://privacyratings.com/python-frameworks/web2py/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/web2py/web2py/blob/master/LICENSE.web2py.txt",
          "note": "LGPL-3.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/web2py/web2py",
          "note": "No telemetry in the framework source code, and the website has no third-party trackers. The scaffold app only loads analytics when a developer sets a tracking ID."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/web2py/web2py",
          "note": "Volunteer-maintained open-source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:13.722Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "grape",
      "category": "ruby-frameworks",
      "name": "Grape",
      "description": "Ruby framework for building REST-like APIs, with a DSL for versioning, parameter validation and response formatting, running on Rack or alongside Rails.",
      "website": "https://www.ruby-grape.org",
      "source": "https://github.com/ruby-grape/grape",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Grape scores 80 out of 100 (grade B) on the Ruby web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/ruby-frameworks/grape/",
      "markdown": "https://privacyratings.com/ruby-frameworks/grape/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ruby-grape/grape/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ruby-grape/grape",
          "note": "No telemetry in the framework source code, and the website has no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/ruby-grape/grape/blob/master/.github/FUNDING.yml",
          "note": "Funded through GitHub Sponsors and Tidelift, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:13.963Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hanami",
      "category": "ruby-frameworks",
      "name": "Hanami",
      "description": "Ruby web framework for structured, modular applications, with slices, actions, views and a repository-based database layer.",
      "website": "https://hanakai.org/hanami",
      "source": "https://github.com/hanami/hanami",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Hanami scores 80 out of 100 (grade B) on the Ruby web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/ruby-frameworks/hanami/",
      "markdown": "https://privacyratings.com/ruby-frameworks/hanami/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hanami/hanami/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hanami/hanami",
          "note": "No telemetry in the framework source code, and the website has no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://hanakai.org/hanami",
          "note": "Funded by company sponsors and individual patrons, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:14.318Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hotwire",
      "category": "ruby-frameworks",
      "name": "Hotwire",
      "description": "Approach from 37signals for building web applications by sending HTML instead of JSON over the wire, made up of the Turbo, Stimulus and Hotwire Native libraries.",
      "website": "https://hotwired.dev",
      "source": "https://github.com/hotwired/turbo",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Hotwire scores 80 out of 100 (grade B) on the Ruby web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/ruby-frameworks/hotwire/",
      "markdown": "https://privacyratings.com/ruby-frameworks/hotwire/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hotwired/turbo/blob/main/MIT-LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://hotwired.dev/",
          "note": "No third-party trackers, and the libraries have no telemetry. The website's Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://37signals.com/",
          "note": "Developed by 37signals and funded by its paid products, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:13.919Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "padrino",
      "category": "ruby-frameworks",
      "name": "Padrino",
      "description": "Ruby web framework built on Sinatra that adds generators, helpers, mailers, an admin interface and support for mounting several apps.",
      "website": "https://padrinorb.com",
      "source": "https://github.com/padrino/padrino-framework",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Padrino scores 80 out of 100 (grade B) on the Ruby web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/ruby-frameworks/padrino/",
      "markdown": "https://privacyratings.com/ruby-frameworks/padrino/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/padrino/padrino-framework/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/padrino/padrino-framework",
          "note": "No telemetry in the framework source code, and the website has no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/padrino/padrino-framework",
          "note": "Volunteer-maintained open-source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:14.289Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "roda",
      "category": "ruby-frameworks",
      "name": "Roda",
      "description": "Ruby web toolkit built around a routing tree, with a small core and features added through plugins.",
      "website": "https://roda.jeremyevans.net",
      "source": "https://github.com/jeremyevans/roda",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Roda scores 80 out of 100 (grade B) on the Ruby web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/ruby-frameworks/roda/",
      "markdown": "https://privacyratings.com/ruby-frameworks/roda/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jeremyevans/roda/blob/master/MIT-LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jeremyevans/roda",
          "note": "No telemetry in the framework source code, and the website has no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/jeremyevans/roda",
          "note": "Volunteer-maintained open-source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:14.383Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ruby-on-rails",
      "category": "ruby-frameworks",
      "name": "Ruby on Rails",
      "description": "Full-stack Ruby web framework following the model-view-controller pattern, with the Active Record ORM, conventions over configuration and built-in support for mail, background jobs and WebSockets.",
      "website": "https://rubyonrails.org",
      "source": "https://github.com/rails/rails",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 100,
      "coverage": 100,
      "summary": "Ruby on Rails scores 100 out of 100 (grade A) on the Ruby web frameworks criteria. It meets 4 of 4 criteria: open source, no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/ruby-frameworks/ruby-on-rails/",
      "markdown": "https://privacyratings.com/ruby-frameworks/ruby-on-rails/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rails/rails/blob/main/MIT-LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://rubyonrails.org/",
          "note": "No third-party trackers, and the framework has no telemetry. The website's Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://rubyonrails.org/foundation",
          "note": "Supported by the Rails Foundation, funded by member companies, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ostif.org/wp-content/uploads/2025/06/X41-Rails-Audit-Final-Report-PUBLIC.pdf",
          "note": "X41 D-Sec audited Rails through OSTIF and published the full report."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:14.447Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sinatra",
      "category": "ruby-frameworks",
      "name": "Sinatra",
      "description": "Minimal Ruby library for building web applications and APIs with a DSL that maps HTTP routes to blocks of code.",
      "website": "https://sinatrarb.com",
      "source": "https://github.com/sinatra/sinatra",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Sinatra scores 80 out of 100 (grade B) on the Ruby web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/ruby-frameworks/sinatra/",
      "markdown": "https://privacyratings.com/ruby-frameworks/sinatra/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sinatra/sinatra/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sinatra/sinatra",
          "note": "No telemetry in the framework source code, and the website has no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sinatra/sinatra",
          "note": "Volunteer-maintained open-source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:14.368Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cakephp",
      "category": "php-frameworks",
      "name": "CakePHP",
      "description": "PHP web framework following the model-view-controller pattern, with an ORM, code generation and conventions over configuration.",
      "website": "https://cakephp.org",
      "source": "https://github.com/cakephp/cakephp",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 60,
      "coverage": 100,
      "summary": "CakePHP scores 60 out of 100 (grade C) on the PHP frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets independent audit. It does not meet no trackers or telemetry.",
      "url": "https://privacyratings.com/php-frameworks/cakephp/",
      "markdown": "https://privacyratings.com/php-frameworks/cakephp/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cakephp/cakephp/blob/5.x/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://cakephp.org/",
          "note": "cakephp.org loads Google Analytics and the Facebook SDK."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cakephp.org/",
          "note": "Supported by the Cake Software Foundation, sponsors such as CakeDC, and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://wiki.mozilla.org/images/4/40/Cakephp-report.pdf",
          "note": "NCC Group audited CakePHP for the Mozilla Secure Open Source program; the full report is older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Facebook SDK",
            "host": "connect.facebook.net",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:14.562Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "codeigniter",
      "category": "php-frameworks",
      "name": "CodeIgniter",
      "description": "Lightweight PHP web framework following the model-view-controller pattern, with a small footprint and little configuration.",
      "website": "https://codeigniter.com",
      "source": "https://github.com/codeigniter4/CodeIgniter4",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "CodeIgniter scores 80 out of 100 (grade B) on the PHP frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/php-frameworks/codeigniter/",
      "markdown": "https://privacyratings.com/php-frameworks/codeigniter/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/codeigniter4/CodeIgniter4/blob/develop/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/codeigniter4/CodeIgniter4",
          "note": "No telemetry in the framework source code, and the website has no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/codeigniter4/CodeIgniter4",
          "note": "Volunteer-maintained open-source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:14.520Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "laminas",
      "category": "php-frameworks",
      "name": "Laminas",
      "description": "PHP framework and component collection, the successor to Zend Framework, with an MVC layer and the Mezzio middleware framework.",
      "website": "https://getlaminas.org",
      "source": "https://github.com/laminas/laminas-mvc",
      "license": "BSD-3-Clause",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Laminas scores 80 out of 100 (grade B) on the PHP frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/php-frameworks/laminas/",
      "markdown": "https://privacyratings.com/php-frameworks/laminas/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/laminas/laminas-mvc/blob/3.9.x/LICENSE.md",
          "note": "BSD 3-Clause licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/laminas/laminas-mvc",
          "note": "No telemetry in the framework source code, and getlaminas.org loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://crowdfunding.linuxfoundation.org/initiatives/laminas-project",
          "note": "A Linux Foundation project funded by member companies and crowdfunding, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:15.021Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "laravel",
      "category": "php-frameworks",
      "name": "Laravel",
      "description": "PHP web framework with the Eloquent ORM, Blade templates, queues and a set of first-party packages and tools.",
      "website": "https://laravel.com",
      "source": "https://github.com/laravel/framework",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Laravel scores 50 out of 100 (grade D) on the PHP frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/php-frameworks/laravel/",
      "markdown": "https://privacyratings.com/php-frameworks/laravel/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/laravel/framework/blob/13.x/LICENSE.md",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://laravel.com/",
          "note": "laravel.com loads Google Tag Manager, HubSpot, Ahrefs and Fathom analytics, and an OpenAI tracking script."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://laravel.com/cloud",
          "note": "Developed by Laravel and funded by its paid hosting and tooling products, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Fathom",
            "host": "cdn.usefathom.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:14.919Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "livewire",
      "category": "php-frameworks",
      "name": "Livewire",
      "description": "Full-stack framework for Laravel that builds dynamic interfaces from PHP components and Blade templates, updated from the server without writing JavaScript.",
      "website": "https://livewire.laravel.com",
      "source": "https://github.com/livewire/livewire",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Livewire scores 80 out of 100 (grade B) on the PHP frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/php-frameworks/livewire/",
      "markdown": "https://privacyratings.com/php-frameworks/livewire/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/livewire/livewire/blob/4.x/LICENSE.md",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://livewire.laravel.com/",
          "note": "No third-party trackers, and the framework has no telemetry. The website's Fathom analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/livewire",
          "note": "Funded by GitHub Sponsors and paid screencasts, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Fathom",
            "host": "cdn.usefathom.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:14.847Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "phalcon",
      "category": "php-frameworks",
      "name": "Phalcon",
      "description": "Full-stack PHP framework delivered as a C extension, with MVC components, an ORM and the Volt template engine.",
      "website": "https://phalcon.io",
      "source": "https://github.com/phalcon/cphalcon",
      "license": "BSD-3-Clause",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Phalcon scores 50 out of 100 (grade D) on the PHP frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/php-frameworks/phalcon/",
      "markdown": "https://privacyratings.com/php-frameworks/phalcon/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/phalcon/cphalcon/blob/master/LICENSE.txt",
          "note": "BSD 3-Clause licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://phalcon.io/en-us",
          "note": "The framework has no telemetry, but phalcon.io loads Google Analytics through Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/phalcon",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:14.961Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "slim",
      "category": "php-frameworks",
      "name": "Slim",
      "description": "PHP micro-framework for building web applications and APIs around PSR-7 requests, routing and middleware.",
      "website": "https://www.slimframework.com",
      "source": "https://github.com/slimphp/Slim",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Slim scores 50 out of 100 (grade D) on the PHP frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/php-frameworks/slim/",
      "markdown": "https://privacyratings.com/php-frameworks/slim/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/slimphp/Slim/blob/4.x/LICENSE.md",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.slimframework.com/",
          "note": "The framework has no telemetry, but slimframework.com loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/slimphp",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:14.870Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "spiral",
      "category": "php-frameworks",
      "name": "Spiral",
      "description": "PHP framework from Spiral Scout for long-running applications on the RoadRunner application server, with dependency injection, queues and gRPC support.",
      "website": "https://spiral.dev",
      "source": "https://github.com/spiral/framework",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Spiral scores 40 out of 100 (grade D) on the PHP frameworks criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/php-frameworks/spiral/",
      "markdown": "https://privacyratings.com/php-frameworks/spiral/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/spiral/framework/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://spiral.dev/",
          "note": "The framework has no telemetry, but spiral.dev loads Google Tag Manager and the LinkedIn Insight Tag."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/sponsors/spiral",
          "note": "Developed by Spiral Scout and funded by its services and sponsorships, with no ads; spiral.dev shares visit data with LinkedIn for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google reCAPTCHA",
            "host": "google.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "snap.licdn.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:15.478Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "symfony",
      "category": "php-frameworks",
      "name": "Symfony",
      "description": "PHP framework and set of reusable components for building web applications, APIs and console tools.",
      "website": "https://symfony.com",
      "source": "https://github.com/symfony/symfony",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 75,
      "coverage": 100,
      "summary": "Symfony scores 75 out of 100 (grade B) on the PHP frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry and independent audit. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/php-frameworks/symfony/",
      "markdown": "https://privacyratings.com/php-frameworks/symfony/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/symfony/symfony/blob/8.2/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://symfony.com/",
          "note": "No telemetry in the framework or Symfony CLI source code, but symfony.com loads the Blackfire real-user monitoring script."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://symfony.com/backers",
          "note": "Funded by SensioLabs and company backers, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://ostif.org/wp-content/uploads/2026/06/OSTIF-Symfony-YAML-Report-v1.2.pdf",
          "note": "Shielder audited only the YAML component through OSTIF and published the full report."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:15.844Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "yii",
      "category": "php-frameworks",
      "name": "Yii",
      "description": "Component-based PHP framework for web applications and APIs, with an Active Record ORM, the Gii code generator and caching support.",
      "website": "https://www.yiiframework.com",
      "source": "https://github.com/yiisoft/yii2",
      "license": "BSD-3-Clause",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Yii scores 50 out of 100 (grade D) on the PHP frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/php-frameworks/yii/",
      "markdown": "https://privacyratings.com/php-frameworks/yii/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/yiisoft/yii2/blob/master/LICENSE.md",
          "note": "BSD-3-Clause-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.yiiframework.com/",
          "note": "yiiframework.com loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/yiisoft",
          "note": "Funded by donations through Open Collective and GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:15.838Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "beego",
      "category": "go-frameworks",
      "name": "Beego",
      "description": "Full-stack web framework for Go with an MVC structure, ORM, caching, logging and the bee command-line tool for scaffolding.",
      "website": "https://github.com/beego/beego",
      "source": "https://github.com/beego/beego",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Beego scores 80 out of 100 (grade B) on the Go web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/go-frameworks/beego/",
      "markdown": "https://privacyratings.com/go-frameworks/beego/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/beego/beego/blob/master/LICENSE",
          "note": "Apache 2.0 licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/beego/beego",
          "note": "No telemetry in the framework or bee tool source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/beego/beego",
          "note": "Volunteer-maintained open-source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:14.961Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "buffalo",
      "category": "go-frameworks",
      "name": "Buffalo",
      "description": "Web development toolkit for Go that generates projects with routing, templates, the Pop database layer, migrations and a front-end asset pipeline.",
      "website": "https://gobuffalo.io",
      "source": "https://github.com/gobuffalo/buffalo",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Buffalo scores 80 out of 100 (grade B) on the Go web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/go-frameworks/buffalo/",
      "markdown": "https://privacyratings.com/go-frameworks/buffalo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gobuffalo/buffalo/blob/main/LICENSE.txt",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gobuffalo/cli",
          "note": "No telemetry in the framework or CLI source code, and gobuffalo.io loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gobuffalo.io/",
          "note": "Funded by sponsors and Patreon, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:15.834Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "chi",
      "category": "go-frameworks",
      "name": "Chi",
      "description": "Lightweight, composable router for building HTTP services in Go, built on the standard net/http package.",
      "website": "https://go-chi.io",
      "source": "https://github.com/go-chi/chi",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Chi scores 80 out of 100 (grade B) on the Go web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/go-frameworks/chi/",
      "markdown": "https://privacyratings.com/go-frameworks/chi/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/go-chi/chi/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/go-chi/chi",
          "note": "No telemetry in the source code, and go-chi.io loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/pkieltyka",
          "note": "Funded by GitHub Sponsors of its maintainer, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:15.677Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "echo",
      "category": "go-frameworks",
      "name": "Echo",
      "description": "Minimalist HTTP web framework for Go with an optimized router, middleware, data binding and rendering.",
      "website": "https://echo.labstack.com",
      "source": "https://github.com/labstack/echo",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Echo scores 50 out of 100 (grade D) on the Go web frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/go-frameworks/echo/",
      "markdown": "https://privacyratings.com/go-frameworks/echo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/labstack/echo/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://echo.labstack.com/",
          "note": "The framework has no telemetry, but echo.labstack.com loads Google Analytics through Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/labstack",
          "note": "Funded by GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:15.881Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "encore",
      "category": "go-frameworks",
      "name": "Encore",
      "description": "Backend framework for Go and TypeScript that declares APIs and infrastructure such as databases, queues and cron jobs in code, with a local development dashboard.",
      "website": "https://encore.dev",
      "source": "https://github.com/encoredev/encore",
      "license": "MPL-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "SE",
        "name": "Sweden",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Encore scores 40 out of 100 (grade D) on the Go web frameworks criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Sweden: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/go-frameworks/encore/",
      "markdown": "https://privacyratings.com/go-frameworks/encore/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/encoredev/encore/blob/main/LICENSE",
          "note": "Mozilla Public License 2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://encore.dev/docs/cli/telemetry",
          "note": "The CLI sends anonymous telemetry by default until disabled, and encore.dev loads Google Tag Manager, Microsoft Clarity, Ahrefs analytics and the LinkedIn Insight Tag."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://encore.dev/pricing",
          "note": "Funded by the paid Encore Cloud platform, with no ads in the framework; encore.dev shares visit data with Google Ads and LinkedIn for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "LinkedIn Insight",
            "host": "px.ads.linkedin.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Clarity",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:15.849Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fiber",
      "category": "go-frameworks",
      "name": "Fiber",
      "description": "Express-inspired web framework for Go built on the Fasthttp HTTP engine, with routing, middleware and templating.",
      "website": "https://gofiber.io",
      "source": "https://github.com/gofiber/fiber",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Fiber scores 80 out of 100 (grade B) on the Go web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/go-frameworks/fiber/",
      "markdown": "https://privacyratings.com/go-frameworks/fiber/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gofiber/fiber/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gofiber.io/",
          "note": "No third-party trackers, and the framework has no telemetry. The website's Simple Analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/gofiber",
          "note": "Funded by GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:16.313Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gin",
      "category": "go-frameworks",
      "name": "Gin",
      "description": "HTTP web framework for Go with a radix-tree router, middleware support, request binding and validation.",
      "website": "https://gin-gonic.com",
      "source": "https://github.com/gin-gonic/gin",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Gin scores 80 out of 100 (grade B) on the Go web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/go-frameworks/gin/",
      "markdown": "https://privacyratings.com/go-frameworks/gin/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gin-gonic/gin/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gin-gonic/gin",
          "note": "No telemetry in the framework source code, and gin-gonic.com loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/gin-gonic/gin",
          "note": "Volunteer-maintained open-source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:16.309Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gorilla-mux",
      "category": "go-frameworks",
      "name": "Gorilla Mux",
      "description": "HTTP request router for Go from the Gorilla web toolkit that matches routes by path, host, method, headers and query values, built on net/http.",
      "website": "https://gorilla.github.io",
      "source": "https://github.com/gorilla/mux",
      "license": "BSD-3-Clause",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Gorilla Mux scores 80 out of 100 (grade B) on the Go web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/go-frameworks/gorilla-mux/",
      "markdown": "https://privacyratings.com/go-frameworks/gorilla-mux/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gorilla/mux/blob/main/LICENSE",
          "note": "BSD 3-Clause licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gorilla/mux",
          "note": "No telemetry in the source code, and gorilla.github.io loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/gorilla/mux",
          "note": "Volunteer-maintained open-source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:16.265Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hertz",
      "category": "go-frameworks",
      "name": "Hertz",
      "description": "HTTP framework for Go from ByteDance's CloudWeGo project, designed for high-performance microservices, with the hz code generator.",
      "website": "https://www.cloudwego.io/docs/hertz/",
      "source": "https://github.com/cloudwego/hertz",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "CN",
        "name": "China",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Hertz scores 50 out of 100 (grade D) on the Go web frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in China: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/go-frameworks/hertz/",
      "markdown": "https://privacyratings.com/go-frameworks/hertz/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cloudwego/hertz/blob/main/LICENSE",
          "note": "Apache 2.0 licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.cloudwego.io/docs/hertz/",
          "note": "The framework has no telemetry, but cloudwego.io loads Google Analytics and Baidu Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.cloudwego.io/about/",
          "note": "Developed and funded by ByteDance's infrastructure team, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:16.327Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "iris",
      "category": "go-frameworks",
      "name": "Iris",
      "description": "Web framework for Go with routing, an MVC layer, sessions, WebSockets and view templating.",
      "website": "https://www.iris-go.com",
      "source": "https://github.com/kataras/iris",
      "license": "BSD-3-Clause",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Iris scores 80 out of 100 (grade B) on the Go web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/go-frameworks/iris/",
      "markdown": "https://privacyratings.com/go-frameworks/iris/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/kataras/iris/blob/main/LICENSE",
          "note": "BSD 3-Clause licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/kataras/iris",
          "note": "No telemetry in the source code, and iris-go.com loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/kataras",
          "note": "Funded by GitHub Sponsors of its author, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:16.541Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "revel",
      "category": "go-frameworks",
      "name": "Revel",
      "description": "Full-stack web framework for Go with routing, templates, hot code reload and a built-in test runner. No longer maintained.",
      "website": "https://revel.github.io",
      "source": "https://github.com/revel/revel",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Revel scores 50 out of 100 (grade D) on the Go web frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/go-frameworks/revel/",
      "markdown": "https://privacyratings.com/go-frameworks/revel/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/revel/revel/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://revel.github.io/",
          "note": "The revel.github.io website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/revel/revel",
          "note": "Volunteer-maintained open-source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:16.518Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "templ",
      "category": "go-frameworks",
      "name": "Templ",
      "description": "HTML templating language for Go that compiles components into type-safe Go code, with a command-line generator and a language server for editors.",
      "website": "https://templ.guide",
      "source": "https://github.com/a-h/templ",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Templ scores 80 out of 100 (grade B) on the Go web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/go-frameworks/templ/",
      "markdown": "https://privacyratings.com/go-frameworks/templ/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/a-h/templ/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/a-h/templ/tree/main/docs",
          "note": "The framework has no telemetry, and the website source loads no analytics or trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/a-h",
          "note": "Funded by sponsors through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:17.131Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "actix-web",
      "category": "rust-frameworks",
      "name": "Actix Web",
      "description": "Web framework for Rust built on Tokio, with routing, request extractors, middleware and support for HTTP/2 and WebSockets.",
      "website": "https://actix.rs",
      "source": "https://github.com/actix/actix-web",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Actix Web scores 80 out of 100 (grade B) on the Rust web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/rust-frameworks/actix-web/",
      "markdown": "https://privacyratings.com/rust-frameworks/actix-web/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/actix/actix-web/blob/main/LICENSE-MIT",
          "note": "Dual-licensed under MIT and Apache 2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/actix/actix-website",
          "note": "The framework has no telemetry, and the website source loads no analytics or trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/robjtede",
          "note": "Funded by sponsors of its maintainer through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:16.677Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "axum",
      "category": "rust-frameworks",
      "name": "Axum",
      "description": "Web application framework for Rust from the Tokio project, built on hyper and Tower middleware, with macro-free routing and request extractors.",
      "website": "https://github.com/tokio-rs/axum",
      "source": "https://github.com/tokio-rs/axum",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Axum scores 80 out of 100 (grade B) on the Rust web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/rust-frameworks/axum/",
      "markdown": "https://privacyratings.com/rust-frameworks/axum/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/tokio-rs/axum/blob/main/axum/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/tokio-rs/axum",
          "note": "The framework has no telemetry, and the project has no website beyond its repository and API documentation."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/tokio",
          "note": "Part of the Tokio project, funded by donations and sponsors through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:16.327Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dioxus",
      "category": "rust-frameworks",
      "name": "Dioxus",
      "description": "Rust framework for building user interfaces for web, desktop and mobile apps from one codebase, with components, signals and the dx command-line tool.",
      "website": "https://dioxuslabs.com",
      "source": "https://github.com/DioxusLabs/dioxus",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Dioxus scores 50 out of 100 (grade D) on the Rust web frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/rust-frameworks/dioxus/",
      "markdown": "https://privacyratings.com/rust-frameworks/dioxus/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/DioxusLabs/dioxus/blob/main/LICENSE-MIT",
          "note": "Dual-licensed under MIT and Apache 2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/DioxusLabs/dioxus/blob/main/packages/cli-telemetry/src/lib.rs",
          "note": "The dx CLI sends anonymous telemetry by default until disabled, and the dioxuslabs.com website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/dioxus-labs",
          "note": "Funded by Dioxus Labs and by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:16.572Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "leptos",
      "category": "rust-frameworks",
      "name": "Leptos",
      "description": "Full-stack web framework for Rust based on fine-grained reactivity, with server-side rendering, hydration and server functions, compiling to WebAssembly for the browser.",
      "website": "https://leptos.dev",
      "source": "https://github.com/leptos-rs/leptos",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Leptos scores 80 out of 100 (grade B) on the Rust web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/rust-frameworks/leptos/",
      "markdown": "https://privacyratings.com/rust-frameworks/leptos/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/leptos-rs/leptos/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://leptos.dev/",
          "note": "No third-party trackers, and the framework has no telemetry. The website's Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/gbj",
          "note": "Funded by sponsors of its maintainer through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:16.859Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "loco",
      "category": "rust-frameworks",
      "name": "Loco",
      "description": "Batteries-included web framework for Rust with code generators, a SeaORM database layer, background jobs, mailers and authentication.",
      "website": "https://loco.rs",
      "source": "https://github.com/loco-rs/loco",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Loco scores 80 out of 100 (grade B) on the Rust web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/rust-frameworks/loco/",
      "markdown": "https://privacyratings.com/rust-frameworks/loco/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/loco-rs/loco/blob/master/LICENSE",
          "note": "Apache 2.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/loco-rs/loco/tree/master/website",
          "note": "The framework has no telemetry, and the website source loads no analytics or trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/loco-rs",
          "note": "Funded by sponsors through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:17.040Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "poem",
      "category": "rust-frameworks",
      "name": "Poem",
      "description": "Web framework for Rust built on Tokio and hyper, with a companion crate that generates OpenAPI specifications from code.",
      "website": "https://github.com/poem-web/poem",
      "source": "https://github.com/poem-web/poem",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Poem scores 80 out of 100 (grade B) on the Rust web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/rust-frameworks/poem/",
      "markdown": "https://privacyratings.com/rust-frameworks/poem/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/poem-web/poem/blob/master/LICENSE-MIT",
          "note": "Dual-licensed under MIT and Apache 2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/poem-web/poem",
          "note": "The framework has no telemetry, and the project has no website beyond its repository and API documentation."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/sunli829",
          "note": "Funded by sponsors of its maintainer through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:16.573Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "rocket",
      "category": "rust-frameworks",
      "name": "Rocket",
      "description": "Web framework for Rust that uses code generation for type-safe routing, request guards and form handling, with templating and database support.",
      "website": "https://rocket.rs",
      "source": "https://github.com/rwf2/Rocket",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Rocket scores 80 out of 100 (grade B) on the Rust web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/rust-frameworks/rocket/",
      "markdown": "https://privacyratings.com/rust-frameworks/rocket/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rwf2/Rocket/blob/master/LICENSE-MIT",
          "note": "Dual-licensed under MIT and Apache 2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rwf2/Rocket",
          "note": "The framework has no telemetry, and the rocket.rs website loads no analytics or trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/rwf2",
          "note": "Funded by donations and sponsors through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:17.008Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "salvo",
      "category": "rust-frameworks",
      "name": "Salvo",
      "description": "Web framework for Rust built on Tokio and hyper, with a tree-based router, handlers that double as middleware, HTTP/3 support and OpenAPI generation.",
      "website": "https://salvo.rs",
      "source": "https://github.com/salvo-rs/salvo",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Salvo scores 80 out of 100 (grade B) on the Rust web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/rust-frameworks/salvo/",
      "markdown": "https://privacyratings.com/rust-frameworks/salvo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/salvo-rs/salvo/blob/main/LICENSE",
          "note": "Apache 2.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/salvo-rs/website",
          "note": "The framework has no telemetry, and the website source loads no analytics or trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/salvo",
          "note": "Funded by donations and sponsors through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:17.241Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "warp",
      "category": "rust-frameworks",
      "name": "Warp",
      "description": "Web server framework for Rust built on hyper, where routes and middleware are composed from reusable filters.",
      "website": "https://github.com/seanmonstar/warp",
      "source": "https://github.com/seanmonstar/warp",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Warp scores 80 out of 100 (grade B) on the Rust web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/rust-frameworks/warp/",
      "markdown": "https://privacyratings.com/rust-frameworks/warp/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/seanmonstar/warp/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/seanmonstar/warp",
          "note": "The framework has no telemetry, and the project has no website beyond its repository and API documentation."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/seanmonstar",
          "note": "Funded by sponsors of its maintainer through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:16.712Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "yew",
      "category": "rust-frameworks",
      "name": "Yew",
      "description": "Component-based Rust framework for building web front ends that compile to WebAssembly, with an HTML-like macro and optional server-side rendering.",
      "website": "https://yew.rs",
      "source": "https://github.com/yewstack/yew",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Yew scores 50 out of 100 (grade D) on the Rust web frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/rust-frameworks/yew/",
      "markdown": "https://privacyratings.com/rust-frameworks/yew/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/yewstack/yew/blob/master/LICENSE-MIT",
          "note": "Dual-licensed under MIT and Apache 2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://yew.rs/",
          "note": "The yew.rs website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/yew",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:17.229Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "apache-struts",
      "category": "jvm-frameworks",
      "name": "Apache Struts",
      "description": "Apache MVC framework for building Java web applications, based on actions, interceptors and result views.",
      "website": "https://struts.apache.org",
      "source": "https://github.com/apache/struts",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Apache Struts scores 50 out of 100 (grade D) on the Java and Kotlin frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/jvm-frameworks/apache-struts/",
      "markdown": "https://privacyratings.com/jvm-frameworks/apache-struts/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/apache/struts/blob/main/LICENSE",
          "note": "Apache 2.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://struts.apache.org/",
          "note": "The struts.apache.org website loads the Facebook SDK for a Like button, alongside the Apache self-hosted Matomo."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apache.org/foundation/sponsorship.html",
          "note": "Hosted by the Apache Software Foundation, which is funded by sponsors and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:17.280Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dropwizard",
      "category": "jvm-frameworks",
      "name": "Dropwizard",
      "description": "Java framework for building RESTful web services that bundles Jetty, Jersey and Jackson into one application package with built-in metrics and health checks.",
      "website": "https://www.dropwizard.io",
      "source": "https://github.com/dropwizard/dropwizard",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 70,
      "coverage": 100,
      "summary": "Dropwizard scores 70 out of 100 (grade C) on the Java and Kotlin frameworks criteria. It meets 2 of 4 criteria: open source and no trackers or telemetry. It partly meets no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/jvm-frameworks/dropwizard/",
      "markdown": "https://privacyratings.com/jvm-frameworks/dropwizard/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dropwizard/dropwizard/blob/release/5.0.x/LICENSE",
          "note": "Apache 2.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dropwizard/dropwizard",
          "note": "No telemetry in the source code, and the Read the Docs site has analytics turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.dropwizard.io/en/stable/",
          "note": "No ads in the framework, but the documentation site on Read the Docs shows EthicalAds contextual ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:17.911Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "eclipse-vert-x",
      "category": "jvm-frameworks",
      "name": "Eclipse Vert.x",
      "description": "Eclipse Foundation toolkit for building reactive, event-driven applications on the JVM with non-blocking I/O, usable from Java, Kotlin and other JVM languages.",
      "website": "https://vertx.io",
      "source": "https://github.com/eclipse-vertx/vert.x",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "BE",
        "name": "Belgium",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Eclipse Vert.x scores 80 out of 100 (grade B) on the Java and Kotlin frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Belgium: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/jvm-frameworks/eclipse-vert-x/",
      "markdown": "https://privacyratings.com/jvm-frameworks/eclipse-vert-x/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/eclipse-vertx/vert.x/blob/master/LICENSE.md",
          "note": "Dual-licensed under the Eclipse Public License 2.0 and Apache 2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/eclipse-vertx/vert.x",
          "note": "No telemetry in the source code, and vertx.io loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.eclipse.org/membership/",
          "note": "Hosted by the Eclipse Foundation, which is funded by member organizations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:17.861Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "grails",
      "category": "jvm-frameworks",
      "name": "Grails",
      "description": "Web application framework for the Groovy language built on Spring Boot, with convention over configuration, the GORM data layer and GSP templates.",
      "website": "https://grails.apache.org",
      "source": "https://github.com/apache/grails-core",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Grails scores 50 out of 100 (grade D) on the Java and Kotlin frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/jvm-frameworks/grails/",
      "markdown": "https://privacyratings.com/jvm-frameworks/grails/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/apache/grails-core/blob/8.0.x/LICENSE",
          "note": "Apache 2.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://grails.apache.org/",
          "note": "The grails.apache.org website loads the kapa.ai assistant widget with fingerprint-based analytics, alongside the Apache self-hosted Matomo."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apache.org/foundation/sponsorship.html",
          "note": "Hosted by the Apache Software Foundation, which is funded by sponsors and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:17.390Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "helidon",
      "category": "jvm-frameworks",
      "name": "Helidon",
      "description": "Java framework from Oracle for building microservices, offered as a lightweight functional API (Helidon SE) and a MicroProfile implementation (Helidon MP).",
      "website": "https://helidon.io",
      "source": "https://github.com/helidon-io/helidon",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Helidon scores 80 out of 100 (grade B) on the Java and Kotlin frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/jvm-frameworks/helidon/",
      "markdown": "https://privacyratings.com/jvm-frameworks/helidon/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/helidon-io/helidon/blob/main/LICENSE.txt",
          "note": "Apache 2.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/helidon-io/helidon",
          "note": "No telemetry in the framework or CLI source code, and helidon.io loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.oracle.com/a/ocom/docs/technical-brief--helidon-report.pdf",
          "note": "Developed and funded by Oracle, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:18.123Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "javalin",
      "category": "jvm-frameworks",
      "name": "Javalin",
      "description": "Lightweight web framework for Java and Kotlin built on the Jetty server, with a small handler-based API for REST APIs and WebSockets.",
      "website": "https://javalin.io",
      "source": "https://github.com/javalin/javalin",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Javalin scores 80 out of 100 (grade B) on the Java and Kotlin frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/jvm-frameworks/javalin/",
      "markdown": "https://privacyratings.com/jvm-frameworks/javalin/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/javalin/javalin/blob/master/LICENSE",
          "note": "Apache 2.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/javalin/javalin",
          "note": "No telemetry in the source code, and javalin.io loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/tipsy",
          "note": "Funded by donations through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:17.915Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ktor",
      "category": "jvm-frameworks",
      "name": "Ktor",
      "description": "Kotlin framework from JetBrains for building asynchronous servers and HTTP clients with coroutines, extended through plugins.",
      "website": "https://ktor.io",
      "source": "https://github.com/ktorio/ktor",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "CZ",
        "name": "Czechia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Ktor scores 50 out of 100 (grade D) on the Java and Kotlin frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Czechia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/jvm-frameworks/ktor/",
      "markdown": "https://privacyratings.com/jvm-frameworks/ktor/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ktorio/ktor/blob/main/LICENSE",
          "note": "Apache 2.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://ktor.io/",
          "note": "The ktor.io website loads Google Tag Manager and Optimizely."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.jetbrains.com/store/",
          "note": "Developed by JetBrains and funded by its paid developer tools, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Optimizely",
            "host": "cdn.optimizely.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:18.609Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "micronaut",
      "category": "jvm-frameworks",
      "name": "Micronaut",
      "description": "JVM framework for microservices and serverless applications in Java, Kotlin and Groovy, using compile-time dependency injection instead of reflection.",
      "website": "https://micronaut.io",
      "source": "https://github.com/micronaut-projects/micronaut-core",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Micronaut scores 50 out of 100 (grade D) on the Java and Kotlin frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/jvm-frameworks/micronaut/",
      "markdown": "https://privacyratings.com/jvm-frameworks/micronaut/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/micronaut-projects/micronaut-core/blob/5.3.x/LICENSE",
          "note": "Apache 2.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://micronaut.io/",
          "note": "The framework has no telemetry, but the micronaut.io website loads Google Analytics through Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://micronaut.io/support/",
          "note": "Commonhaus Foundation project supported by sponsors and commercial support providers, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:18.134Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "play-framework",
      "category": "jvm-frameworks",
      "name": "Play Framework",
      "description": "Web framework for Java and Scala with a stateless, non-blocking architecture, hot reloading during development and type-safe templates.",
      "website": "https://www.playframework.com",
      "source": "https://github.com/playframework/playframework",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Play Framework scores 80 out of 100 (grade B) on the Java and Kotlin frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/jvm-frameworks/play-framework/",
      "markdown": "https://privacyratings.com/jvm-frameworks/play-framework/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/playframework/playframework/blob/main/LICENSE",
          "note": "Apache 2.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/playframework/playframework",
          "note": "No telemetry in the source code, and playframework.com loads no analytics, only sponsor images from Open Collective, Clearbit and Gravatar."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/playframework",
          "note": "Funded by sponsors and donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:18.354Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "quarkus",
      "category": "jvm-frameworks",
      "name": "Quarkus",
      "description": "Java framework for cloud and Kubernetes applications, designed for fast startup and low memory use, with GraalVM native compilation and a live-reload dev mode.",
      "website": "https://quarkus.io",
      "source": "https://github.com/quarkusio/quarkus",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Quarkus scores 65 out of 100 (grade C) on the Java and Kotlin frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/jvm-frameworks/quarkus/",
      "markdown": "https://privacyratings.com/jvm-frameworks/quarkus/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/quarkusio/quarkus/blob/main/LICENSE",
          "note": "Apache 2.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://quarkus.io/guides/build-analytics/",
          "note": "Build analytics are opt-in, but the quarkus.io website uses Matomo analytics hosted at ossupstream.org and loads a Mailjet newsletter script."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/quarkus",
          "note": "Commonhaus Foundation project funded by sponsors and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:18.433Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "spring-boot",
      "category": "jvm-frameworks",
      "name": "Spring Boot",
      "description": "Java framework from the Spring project for building standalone applications, with auto-configuration, embedded web servers and starter dependencies.",
      "website": "https://spring.io/projects/spring-boot/",
      "source": "https://github.com/spring-projects/spring-boot",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Spring Boot scores 50 out of 100 (grade D) on the Java and Kotlin frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/jvm-frameworks/spring-boot/",
      "markdown": "https://privacyratings.com/jvm-frameworks/spring-boot/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/spring-projects/spring-boot/blob/main/LICENSE.txt",
          "note": "Apache 2.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://spring.io/projects/spring-boot/",
          "note": "The framework has no telemetry, but the spring.io website loads Google Tag Manager, OneTrust and Cloudflare Web Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://enterprise.spring.io/",
          "note": "Developed by Broadcom and funded by its paid Tanzu Spring support, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:18.381Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vaadin",
      "category": "jvm-frameworks",
      "name": "Vaadin",
      "description": "Java framework for building web application user interfaces, with server-side Java UI components (Flow) and React-based views (Hilla). Some components and tools are commercial.",
      "website": "https://vaadin.com",
      "source": "https://github.com/vaadin/flow",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "FI",
        "name": "Finland",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Vaadin scores 35 out of 100 (grade F) on the Java and Kotlin frameworks criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source. It does not meet no trackers or telemetry and independent audit. It is based in Finland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/jvm-frameworks/vaadin/",
      "markdown": "https://privacyratings.com/jvm-frameworks/vaadin/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://vaadin.com/licensing-faq-and-troubleshooting",
          "note": "The core framework is Apache 2.0-licensed, but some components and tools are under the proprietary Vaadin Commercial License."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://vaadin.com/docs/latest/flow/configuration/properties",
          "note": "Development mode collects usage statistics by default until disabled, and vaadin.com loads HubSpot analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://vaadin.com/pricing",
          "note": "Funded by commercial subscriptions and support, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:18.525Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "abp-framework",
      "category": "dotnet-frameworks",
      "name": "ABP Framework",
      "description": "Application framework for ASP.NET Core from Volosoft, with a modular architecture, domain-driven design building blocks, multi-tenancy and startup templates.",
      "website": "https://abp.io",
      "source": "https://github.com/abpframework/abp",
      "license": "LGPL-3.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "TR",
        "name": "Türkiye",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "ABP Framework scores 40 out of 100 (grade D) on the .NET web frameworks criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Türkiye: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/dotnet-frameworks/abp-framework/",
      "markdown": "https://privacyratings.com/dotnet-frameworks/abp-framework/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/abpframework/abp/blob/dev/LICENSE.md",
          "note": "The framework is LGPL-3.0-licensed; commercial modules and ABP Studio are sold separately."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/abpframework/abp/blob/dev/framework/src/Volo.Abp.Core/Volo/Abp/AbpApplicationBase.cs",
          "note": "Applications send telemetry to telemetry.abp.io in development unless Abp:Telemetry:IsEnabled is set to false, and abp.io loads Google Tag Manager and the Google Ads tag."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://abp.io/pricing",
          "note": "Funded by commercial licenses, with no ads in the framework, but abp.io loads the Google Ads tag to advertise the vendor's products."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:19.153Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "asp-net-core",
      "category": "dotnet-frameworks",
      "name": "ASP.NET Core",
      "description": "Microsoft framework for building web apps, APIs and real-time services in C# on .NET, with MVC, Razor Pages, minimal APIs and SignalR.",
      "website": "https://dotnet.microsoft.com/en-us/apps/aspnet",
      "source": "https://github.com/dotnet/aspnetcore",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "ASP.NET Core scores 50 out of 100 (grade D) on the .NET web frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/dotnet-frameworks/asp-net-core/",
      "markdown": "https://privacyratings.com/dotnet-frameworks/asp-net-core/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dotnet/aspnetcore/blob/main/LICENSE.txt",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/dotnet/core/tools/telemetry",
          "note": "The .NET SDK sends usage telemetry by default until disabled, and dotnet.microsoft.com loads Microsoft analytics scripts and connects to Adobe Target."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://dotnet.microsoft.com/en-us/platform/free",
          "note": "Free and funded by Microsoft, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:19.982Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "blazor",
      "category": "dotnet-frameworks",
      "name": "Blazor",
      "description": "Microsoft framework for building interactive web user interfaces in C# with Razor components, running on the server or in the browser through WebAssembly.",
      "website": "https://dotnet.microsoft.com/en-us/apps/aspnet/web-apps/blazor",
      "source": "https://github.com/dotnet/aspnetcore",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Blazor scores 50 out of 100 (grade D) on the .NET web frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/dotnet-frameworks/blazor/",
      "markdown": "https://privacyratings.com/dotnet-frameworks/blazor/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dotnet/aspnetcore/blob/main/LICENSE.txt",
          "note": "MIT-licensed as part of ASP.NET Core."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/dotnet/core/tools/telemetry",
          "note": "The .NET SDK sends usage telemetry by default until disabled, and dotnet.microsoft.com loads Microsoft analytics scripts and connects to Adobe Target."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://dotnet.microsoft.com/en-us/platform/free",
          "note": "Free and funded by Microsoft, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:19.986Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "carter",
      "category": "dotnet-frameworks",
      "name": "Carter",
      "description": "Library for ASP.NET Core that organizes minimal API routes into modules, with support for validation and content negotiation.",
      "website": "https://github.com/CarterCommunity/Carter",
      "source": "https://github.com/CarterCommunity/Carter",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Carter scores 80 out of 100 (grade B) on the .NET web frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/dotnet-frameworks/carter/",
      "markdown": "https://privacyratings.com/dotnet-frameworks/carter/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/CarterCommunity/Carter/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/CarterCommunity/Carter",
          "note": "No telemetry in the source code, and the project has no website beyond its repository."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/CarterCommunity/Carter",
          "note": "Volunteer-maintained open-source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:18.433Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fastendpoints",
      "category": "dotnet-frameworks",
      "name": "FastEndpoints",
      "description": "Library for building REST APIs on ASP.NET Core in which each endpoint is a class with its own request and response types (the REPR pattern).",
      "website": "https://fast-endpoints.com",
      "source": "https://github.com/FastEndpoints/FastEndpoints",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "FastEndpoints scores 50 out of 100 (grade D) on the .NET web frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/dotnet-frameworks/fastendpoints/",
      "markdown": "https://privacyratings.com/dotnet-frameworks/fastendpoints/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/FastEndpoints/FastEndpoints/blob/main/LICENSE.md",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://fast-endpoints.com/",
          "note": "The fast-endpoints.com website loads Google Analytics through Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/fast-endpoints",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:18.791Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "orchard-core",
      "category": "dotnet-frameworks",
      "name": "Orchard Core",
      "description": "Modular application framework and content management system built on ASP.NET Core, with multi-tenancy and a headless CMS mode.",
      "website": "https://orchardcore.net",
      "source": "https://github.com/OrchardCMS/OrchardCore",
      "license": "BSD-3-Clause",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 70,
      "coverage": 100,
      "summary": "Orchard Core scores 70 out of 100 (grade C) on the .NET web frameworks criteria. It meets 2 of 4 criteria: open source and no trackers or telemetry. It partly meets no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/dotnet-frameworks/orchard-core/",
      "markdown": "https://privacyratings.com/dotnet-frameworks/orchard-core/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/OrchardCMS/OrchardCore/blob/main/LICENSE",
          "note": "BSD 3-Clause-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/OrchardCMS/OrchardCore",
          "note": "No telemetry in the source code, and orchardcore.net and its Read the Docs documentation load no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://docs.orchardcore.net/en/latest/",
          "note": "A .NET Foundation project with no ads in the framework, but the documentation site on Read the Docs shows EthicalAds contextual ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:18.889Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "servicestack",
      "category": "dotnet-frameworks",
      "name": "ServiceStack",
      "description": "Framework for building message-based web services and APIs on .NET, with typed clients, an ORM and generated admin interfaces. Dual-licensed under the AGPL and a commercial license.",
      "website": "https://servicestack.net",
      "source": "https://github.com/ServiceStack/ServiceStack",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "ServiceStack scores 50 out of 100 (grade D) on the .NET web frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/dotnet-frameworks/servicestack/",
      "markdown": "https://privacyratings.com/dotnet-frameworks/servicestack/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ServiceStack/ServiceStack/blob/main/license.txt",
          "note": "AGPL-3.0-licensed with a FOSS exception, and a paid commercial license for closed-source use."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://servicestack.net/",
          "note": "The servicestack.net website loads Google Analytics through Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://account.servicestack.net/pricing",
          "note": "Funded by commercial licenses, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:18.800Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ash-framework",
      "category": "elixir-frameworks",
      "name": "Ash Framework",
      "description": "Declarative application framework for Elixir that models resources, actions and policies, and derives APIs and data layers from them.",
      "website": "https://ash-hq.org",
      "source": "https://github.com/ash-project/ash",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Ash Framework scores 80 out of 100 (grade B) on the Elixir, Erlang and Gleam frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/elixir-frameworks/ash-framework/",
      "markdown": "https://privacyratings.com/elixir-frameworks/ash-framework/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ash-project/ash/blob/main/LICENSES/MIT.txt",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://ash-hq.org/",
          "note": "No third-party trackers, and the framework has no telemetry. The website's Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/ash-framework",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:19.136Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cowboy",
      "category": "elixir-frameworks",
      "name": "Cowboy",
      "description": "Small HTTP server for Erlang/OTP with support for HTTP/1.1, HTTP/2, WebSocket and REST handlers.",
      "website": "https://ninenines.eu/",
      "source": "https://github.com/ninenines/cowboy",
      "license": "ISC",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Cowboy scores 80 out of 100 (grade B) on the Elixir, Erlang and Gleam frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/elixir-frameworks/cowboy/",
      "markdown": "https://privacyratings.com/elixir-frameworks/cowboy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ninenines/cowboy/blob/master/LICENSE",
          "note": "ISC-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ninenines/cowboy",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/essen",
          "note": "Funded by sponsors and paid consulting from the maintainer, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:19.045Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hologram",
      "category": "elixir-frameworks",
      "name": "Hologram",
      "description": "Full-stack Elixir web framework that compiles client-side Elixir code to JavaScript, so pages and components are written in Elixir.",
      "website": "https://hologram.page/",
      "source": "https://github.com/bartblast/hologram",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Hologram scores 50 out of 100 (grade D) on the Elixir, Erlang and Gleam frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/elixir-frameworks/hologram/",
      "markdown": "https://privacyratings.com/elixir-frameworks/hologram/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bartblast/hologram/blob/dev/LICENSE",
          "note": "Apache-2.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://hologram.page/",
          "note": "The framework has no telemetry, but hologram.page loads Google Analytics, Heap, Sentry and Plausible."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/bartblast",
          "note": "Funded by sponsors through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Sentry",
            "host": "js.sentry-cdn.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:19.139Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "lustre",
      "category": "elixir-frameworks",
      "name": "Lustre",
      "description": "Gleam framework for building web user interfaces with a model-view-update architecture, running in the browser or as server components.",
      "website": "https://lustre.hexdocs.pm/",
      "source": "https://github.com/lustre-labs/lustre",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Lustre scores 80 out of 100 (grade B) on the Elixir, Erlang and Gleam frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/elixir-frameworks/lustre/",
      "markdown": "https://privacyratings.com/elixir-frameworks/lustre/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/lustre-labs/lustre/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://lustre.hexdocs.pm/",
          "note": "No third-party trackers, and the framework has no telemetry. HexDocs uses Plausible analytics, which are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/hayleigh-dot-dev",
          "note": "Funded by sponsors through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:19.260Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nerves",
      "category": "elixir-frameworks",
      "name": "Nerves",
      "description": "Elixir platform for building and deploying embedded software on devices such as the Raspberry Pi, producing minimal Linux firmware images.",
      "website": "https://nerves-project.org",
      "source": "https://github.com/nerves-project/nerves",
      "license": null,
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Nerves scores 80 out of 100 (grade B) on the Elixir, Erlang and Gleam frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/elixir-frameworks/nerves/",
      "markdown": "https://privacyratings.com/elixir-frameworks/nerves/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nerves-project/nerves/blob/main/LICENSES/Apache-2.0.txt",
          "note": "Apache-2.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nerves-project/nerves",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/nerves-project",
          "note": "Funded by donations and sponsors through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:19.928Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nitrogen",
      "category": "elixir-frameworks",
      "name": "Nitrogen Web Framework",
      "description": "Event-driven web framework for Erlang that builds pages from Erlang records and updates them over Ajax or WebSocket.",
      "website": "https://nitrogenproject.com/",
      "source": "https://github.com/nitrogen/nitrogen",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Nitrogen Web Framework scores 50 out of 100 (grade D) on the Elixir, Erlang and Gleam frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/elixir-frameworks/nitrogen/",
      "markdown": "https://privacyratings.com/elixir-frameworks/nitrogen/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nitrogen/nitrogen/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://nitrogenproject.com/",
          "note": "The framework has no telemetry, but nitrogenproject.com loads Google Analytics through Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/nitrogen/nitrogen",
          "note": "Volunteer-maintained open-source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:19.489Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "phoenix",
      "category": "elixir-frameworks",
      "name": "Phoenix",
      "description": "Web framework for Elixir with a model-view-controller structure, LiveView for server-rendered interactive pages and channels for real-time communication.",
      "website": "https://www.phoenixframework.org",
      "source": "https://github.com/phoenixframework/phoenix",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Phoenix scores 80 out of 100 (grade B) on the Elixir, Erlang and Gleam frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/elixir-frameworks/phoenix/",
      "markdown": "https://privacyratings.com/elixir-frameworks/phoenix/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/phoenixframework/phoenix/blob/main/LICENSE.md",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/phoenixframework/phoenix",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/phoenixframework/phoenix",
          "note": "Community-maintained open-source framework with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:19.718Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "plug",
      "category": "elixir-frameworks",
      "name": "Plug",
      "description": "Specification and library for composable web modules in Elixir, with connection adapters for web servers and a router.",
      "website": "https://github.com/elixir-plug/plug",
      "source": "https://github.com/elixir-plug/plug",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Plug scores 80 out of 100 (grade B) on the Elixir, Erlang and Gleam frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/elixir-frameworks/plug/",
      "markdown": "https://privacyratings.com/elixir-frameworks/plug/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/elixir-plug/plug/blob/main/LICENSE",
          "note": "Apache-2.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/elixir-plug/plug",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/elixir-plug/plug",
          "note": "Community-maintained open-source library with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:19.261Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "wisp",
      "category": "elixir-frameworks",
      "name": "Wisp",
      "description": "Web framework for Gleam on the BEAM, built around request handler functions and middleware.",
      "website": "https://gleam-wisp.github.io/wisp/",
      "source": "https://github.com/gleam-wisp/wisp",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Wisp scores 80 out of 100 (grade B) on the Elixir, Erlang and Gleam frameworks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/elixir-frameworks/wisp/",
      "markdown": "https://privacyratings.com/elixir-frameworks/wisp/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gleam-wisp/wisp/blob/main/LICENCE",
          "note": "Apache-2.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gleam-wisp/wisp",
          "note": "No telemetry or analytics in the source code, and the website loads no scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/lpil",
          "note": "Funded by sponsors through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:19.565Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "biff",
      "category": "other-web-frameworks",
      "name": "Biff",
      "description": "Full-stack Clojure web framework for solo developers that bundles a database, authentication, server-side rendering with htmx and deployment tooling.",
      "website": "https://biffweb.com",
      "source": "https://github.com/jacobobryant/biff",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Biff scores 65 out of 100 (grade C) on the web frameworks for other languages criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/other-web-frameworks/biff/",
      "markdown": "https://privacyratings.com/other-web-frameworks/biff/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jacobobryant/biff/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://biffweb.com/",
          "note": "The framework has no telemetry, but biffweb.com loads self-hosted Plausible analytics and Google reCAPTCHA."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/jacobobryant",
          "note": "Funded by GitHub Sponsors donations to the maintainer, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:19.938Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "crow",
      "category": "other-web-frameworks",
      "name": "Crow",
      "description": "Microframework for building HTTP and WebSocket services in C++, with Flask-style routing.",
      "website": "https://crowcpp.org",
      "source": "https://github.com/CrowCpp/Crow",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Crow scores 80 out of 100 (grade B) on the web frameworks for other languages criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/other-web-frameworks/crow/",
      "markdown": "https://privacyratings.com/other-web-frameworks/crow/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/CrowCpp/Crow/blob/master/LICENSE",
          "note": "BSD-3-Clause-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/CrowCpp/Crow",
          "note": "No telemetry in the source code, and crowcpp.org loads no third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/crow",
          "note": "Funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:19.996Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dart-frog",
      "category": "other-web-frameworks",
      "name": "Dart Frog",
      "description": "Minimal backend framework for Dart with file-based routing, middleware and dependency injection, plus a CLI for development and builds.",
      "website": "https://dart-frog.dev/",
      "source": "https://github.com/dart-frog-dev/dart_frog",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Dart Frog scores 80 out of 100 (grade B) on the web frameworks for other languages criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/other-web-frameworks/dart-frog/",
      "markdown": "https://privacyratings.com/other-web-frameworks/dart-frog/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dart-frog-dev/dart_frog/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dart-frog-dev/dart_frog",
          "note": "No telemetry or analytics in the framework or CLI source code, and the website loads no third-party scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/dart-frog-dev/dart_frog",
          "note": "Community-maintained open-source framework with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:19.875Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dream",
      "category": "other-web-frameworks",
      "name": "Dream",
      "description": "Web framework for OCaml and ReasonML that bundles HTTP, WebSocket, sessions, templates and database access in one package.",
      "website": "https://camlworks.github.io/dream/",
      "source": "https://github.com/camlworks/dream",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Dream scores 80 out of 100 (grade B) on the web frameworks for other languages criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/other-web-frameworks/dream/",
      "markdown": "https://privacyratings.com/other-web-frameworks/dream/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/camlworks/dream/blob/master/LICENSE.md",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/camlworks/dream",
          "note": "No telemetry in the source code, and the documentation site loads no third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/aantron",
          "note": "Funded by GitHub Sponsors donations to the maintainer, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:20.166Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "drogon",
      "category": "other-web-frameworks",
      "name": "Drogon",
      "description": "HTTP application framework for C++ with an asynchronous, non-blocking I/O core, an ORM, WebSocket support and view templates.",
      "website": "https://drogon.org",
      "source": "https://github.com/drogonframework/drogon",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Drogon scores 80 out of 100 (grade B) on the web frameworks for other languages criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/other-web-frameworks/drogon/",
      "markdown": "https://privacyratings.com/other-web-frameworks/drogon/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/drogonframework/drogon/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/drogonframework/drogon",
          "note": "No telemetry in the source code, and drogon.org loads no third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/drogon",
          "note": "Funded by donations through Open Collective and GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:20.837Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hummingbird",
      "category": "other-web-frameworks",
      "name": "Hummingbird",
      "description": "Lightweight server framework for Swift built on SwiftNIO and Swift concurrency, with routing, middleware and optional extensions.",
      "website": "https://hummingbird.codes/",
      "source": "https://github.com/hummingbird-project/hummingbird",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Hummingbird scores 80 out of 100 (grade B) on the web frameworks for other languages criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/other-web-frameworks/hummingbird/",
      "markdown": "https://privacyratings.com/other-web-frameworks/hummingbird/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hummingbird-project/hummingbird/blob/main/LICENSE.txt",
          "note": "Apache-2.0-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hummingbird-project/hummingbird",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/hummingbird-project",
          "note": "Funded by sponsors through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:20.484Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ihp",
      "category": "other-web-frameworks",
      "name": "IHP",
      "description": "Batteries-included Haskell web framework from digitally induced with type-checked SQL, HSX templates and a development IDE. Some features require a paid IHP Pro or Business license.",
      "website": "https://ihp.digitallyinduced.com",
      "source": "https://github.com/digitallyinduced/ihp",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "IHP scores 25 out of 100 (grade F) on the web frameworks for other languages criteria. It partly meets open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/other-web-frameworks/ihp/",
      "markdown": "https://privacyratings.com/other-web-frameworks/ihp/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://ihp.digitallyinduced.com/Pricing",
          "note": "The core is MIT-licensed, but IHP Pro and Business features are sold under commercial licenses."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/digitallyinduced/ihp/blob/master/ihp-ide/IHP/Telemetry.hs",
          "note": "The development server sends telemetry by default until IHP_TELEMETRY_DISABLED is set, and the website loads the Reddit Pixel, Plausible and datakant analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://ihp.digitallyinduced.com/Pricing",
          "note": "Funded by paid IHP Pro and Business licenses, but the website loads the Reddit Pixel for ad retargeting."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "G2",
            "host": "images.g2crowd.com",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          },
          {
            "name": "Reddit Pixel",
            "host": "www.redditstatic.com",
            "effect": "no"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:20.937Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "jester",
      "category": "other-web-frameworks",
      "name": "Jester",
      "description": "Sinatra-style web framework for the Nim language, with routes defined through a small DSL.",
      "website": "https://github.com/dom96/jester",
      "source": "https://github.com/dom96/jester",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Jester scores 80 out of 100 (grade B) on the web frameworks for other languages criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/other-web-frameworks/jester/",
      "markdown": "https://privacyratings.com/other-web-frameworks/jester/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dom96/jester/blob/master/license.txt",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dom96/jester",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/dom96/jester",
          "note": "Community-developed open-source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:02:19.996Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kemal",
      "category": "other-web-frameworks",
      "name": "Kemal",
      "description": "Lightweight web framework for Crystal inspired by Sinatra, with routing, middleware and WebSocket support.",
      "website": "https://kemalcr.com/",
      "source": "https://github.com/kemalcr/kemal",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Kemal scores 50 out of 100 (grade D) on the web frameworks for other languages criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/other-web-frameworks/kemal/",
      "markdown": "https://privacyratings.com/other-web-frameworks/kemal/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/kemalcr/kemal/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://kemalcr.com/",
          "note": "The framework has no telemetry, but kemalcr.com loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/sdogruyol",
          "note": "Funded by sponsors through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:20.576Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kit",
      "category": "other-web-frameworks",
      "name": "Kit",
      "description": "Modular Clojure web framework built on Integrant and Aero, with a project template and optional libraries added as modules.",
      "website": "https://kit-clj.github.io",
      "source": "https://github.com/kit-clj/kit",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Kit scores 80 out of 100 (grade B) on the web frameworks for other languages criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/other-web-frameworks/kit/",
      "markdown": "https://privacyratings.com/other-web-frameworks/kit/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/kit-clj/kit/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/kit-clj/kit",
          "note": "No telemetry in the source code, and kit-clj.github.io loads no third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/kit-clj/kit",
          "note": "Community-developed open-source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:20.658Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "lucky",
      "category": "other-web-frameworks",
      "name": "Lucky",
      "description": "Full-stack web framework for the Crystal language with type-safe routing, database queries and HTML rendering checked at compile time.",
      "website": "https://luckyframework.org",
      "source": "https://github.com/luckyframework/lucky",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Lucky scores 80 out of 100 (grade B) on the web frameworks for other languages criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/other-web-frameworks/lucky/",
      "markdown": "https://privacyratings.com/other-web-frameworks/lucky/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/luckyframework/lucky/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/luckyframework/lucky",
          "note": "No telemetry in the source code, and luckyframework.org loads no third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/sponsors/jwoertink",
          "note": "Funded by GitHub Sponsors donations to core team members, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:21.076Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mojolicious",
      "category": "other-web-frameworks",
      "name": "Mojolicious",
      "description": "Real-time web framework for Perl with a non-blocking I/O web server, WebSocket support, templates and no dependencies beyond core Perl.",
      "website": "https://mojolicious.org",
      "source": "https://github.com/mojolicious/mojo",
      "license": "Artistic-2.0",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Mojolicious scores 80 out of 100 (grade B) on the web frameworks for other languages criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/other-web-frameworks/mojolicious/",
      "markdown": "https://privacyratings.com/other-web-frameworks/mojolicious/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mojolicious/mojo/blob/main/LICENSE",
          "note": "Licensed under the Artistic License 2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mojolicious/mojo",
          "note": "No telemetry in the source code, and mojolicious.org loads no third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/mojolicious/mojo",
          "note": "Community-developed open-source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:20.915Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "servant",
      "category": "other-web-frameworks",
      "name": "Servant",
      "description": "Haskell library for describing web APIs as types, from which servers, clients and documentation are derived.",
      "website": "https://www.servant.dev",
      "source": "https://github.com/haskell-servant/servant",
      "license": null,
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 70,
      "coverage": 100,
      "summary": "Servant scores 70 out of 100 (grade C) on the web frameworks for other languages criteria. It meets 2 of 4 criteria: open source and no trackers or telemetry. It partly meets no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/other-web-frameworks/servant/",
      "markdown": "https://privacyratings.com/other-web-frameworks/servant/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/haskell-servant/servant/blob/master/servant/LICENSE",
          "note": "BSD-3-Clause-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/haskell-servant/servant",
          "note": "No telemetry in the source code, and servant.dev loads no third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://docs.servant.dev/en/latest/",
          "note": "Community-developed, but the documentation on Read the Docs shows EthicalAds contextual ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:21.040Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "serverpod",
      "category": "other-web-frameworks",
      "name": "Serverpod",
      "description": "Backend framework for Dart and Flutter that generates client code for server endpoints, with an ORM, authentication, caching and file uploads.",
      "website": "https://serverpod.dev/",
      "source": "https://github.com/serverpod/serverpod",
      "license": "BSD-3-Clause",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": {
        "code": "SE",
        "name": "Sweden",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Serverpod scores 50 out of 100 (grade D) on the web frameworks for other languages criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Sweden: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/other-web-frameworks/serverpod/",
      "markdown": "https://privacyratings.com/other-web-frameworks/serverpod/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/serverpod/serverpod/blob/main/LICENSE",
          "note": "BSD-3-Clause-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/serverpod/serverpod/blob/main/tools/serverpod_cli/lib/src/analytics/cli_analytics.dart",
          "note": "The CLI sends analytics to PostHog unless run with --no-analytics, and serverpod.dev loads Google Tag Manager and PostHog."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://serverpod.dev/pricing",
          "note": "Developed by Serverpod AB and funded by its paid Serverpod Cloud hosting, with no ads in the framework."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "PostHog",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:21.496Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vapor",
      "category": "other-web-frameworks",
      "name": "Vapor",
      "description": "Server-side web framework for Swift built on SwiftNIO, with routing, middleware, the Fluent ORM and the Leaf templating language.",
      "website": "https://vapor.codes/",
      "source": "https://github.com/vapor/vapor",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Vapor scores 80 out of 100 (grade B) on the web frameworks for other languages criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/other-web-frameworks/vapor/",
      "markdown": "https://privacyratings.com/other-web-frameworks/vapor/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/vapor/vapor/blob/main/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/vapor/vapor",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/vapor",
          "note": "Funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:21.603Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "yesod",
      "category": "other-web-frameworks",
      "name": "Yesod",
      "description": "Haskell web framework for type-safe web applications, with compile-time checked routes and templates and the Persistent database library.",
      "website": "https://www.yesodweb.com",
      "source": "https://github.com/yesodweb/yesod",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos",
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Yesod scores 50 out of 100 (grade D) on the web frameworks for other languages criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/other-web-frameworks/yesod/",
      "markdown": "https://privacyratings.com/other-web-frameworks/yesod/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/yesodweb/yesod/blob/master/LICENSE",
          "note": "MIT-licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.yesodweb.com/",
          "note": "The yesodweb.com website loads Google Analytics; the framework itself has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/yesodweb/yesod",
          "note": "Community-developed open-source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:21.651Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cloudflare-web-analytics",
      "category": "web-analytics",
      "name": "Cloudflare Web Analytics",
      "description": "Free web analytics from Cloudflare that reports page views, visits and Core Web Vitals using a JavaScript beacon or Cloudflare's proxy, without cookies.",
      "website": "https://www.cloudflare.com/web-analytics/",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 61,
      "coverage": 100,
      "summary": "Cloudflare Web Analytics scores 61 out of 100 (grade C) on the website analytics criteria. It meets 6 of 11 criteria: no ads or data sales, transparency report, tells users about requests, TLS configuration, no cookies and no personal data. It partly meets independent audit and security headers. It does not meet open source, no trackers or telemetry and self-hostable. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/web-analytics/cloudflare-web-analytics/",
      "markdown": "https://privacyratings.com/web-analytics/cloudflare-web-analytics/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.cloudflare.com/privacypolicy/",
          "note": "The Cloudflare website loads Google Tag Manager and uses cookies for interest-based advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.cloudflare.com/web-analytics/",
          "note": "Funded by paid Cloudflare plans. The product page states visitor data is not used to retarget visitors with ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://developers.cloudflare.com/fundamentals/reference/policies-compliances/compliance-docs/",
          "note": "SOC 2, ISO 27001 and PCI reports exist but are only available to account administrators in the dashboard."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.cloudflare.com/transparency/",
          "note": "Semi-annual reports with counts of legal requests and responses."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://cf-assets.www.cloudflare.com/slt3lc6tev37/zItVXCvbb4LZpYG4Uh10R/7b27bba39755f0a4344acb946977704d/2H_2025_Cloudflare_s_Transparency_Report_Legal-v2.pdf",
          "note": "The transparency report states customers are notified of legal requests unless legally prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=dash.cloudflare.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=dash.cloudflare.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_cookies": {
          "title": "No cookies",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.cloudflare.com/web-analytics/",
          "note": "No client-side state such as cookies or localStorage is used, and visitors are not fingerprinted."
        },
        "no_personal_data": {
          "title": "No personal data",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://developers.cloudflare.com/web-analytics/about/",
          "note": "The documentation states Web Analytics does not collect or use visitors' personal data."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Hosted only."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:46.080Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fathom-analytics",
      "category": "web-analytics",
      "name": "Fathom Analytics",
      "description": "Hosted web analytics that counts visitors without cookies using a daily-salted hash, with a single-page dashboard and event tracking.",
      "website": "https://usefathom.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Fathom Analytics scores 50 out of 100 (grade D) on the website analytics criteria. It meets 4 of 11 criteria: no trackers or telemetry, no ads or data sales, TLS configuration and no cookies. It partly meets security headers and no personal data. It does not meet open source, independent audit, transparency report, tells users about requests and self-hostable. It is based in Canada: Five Eyes member. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/web-analytics/fathom-analytics/",
      "markdown": "https://privacyratings.com/web-analytics/fathom-analytics/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://usefathom.com/legal/privacy",
          "note": "No third-party trackers. The website uses Fathom's own analytics, which are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://usefathom.com/legal/privacy",
          "note": "Funded by subscriptions. The privacy policy states personal data is not rented or sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=usefathom.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=usefathom.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_cookies": {
          "title": "No cookies",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://usefathom.com/data",
          "note": "Visitors are counted with a hashed signature and a daily salt instead of cookies."
        },
        "no_personal_data": {
          "title": "No personal data",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://usefathom.com/data",
          "note": "IP addresses of ordinary visitors are hashed with a daily salt, but records of detected bot traffic keep IP addresses."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Hosted only."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:45.535Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "goatcounter",
      "category": "web-analytics",
      "name": "GoatCounter",
      "description": "Open source web analytics that shows aggregate visitor counts without cookies or stored IP addresses. Available as a hosted service at goatcounter.com or as a self-hosted binary.",
      "website": "https://www.goatcounter.com",
      "source": "https://github.com/arp242/goatcounter",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "IE",
        "name": "Ireland",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 73,
      "coverage": 100,
      "summary": "GoatCounter scores 73 out of 100 (grade C) on the website analytics criteria. It meets 7 of 11 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, no cookies, no personal data and self-hostable. It does not meet independent audit, transparency report, tells users about requests and security headers. It is based in Ireland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/web-analytics/goatcounter/",
      "markdown": "https://privacyratings.com/web-analytics/goatcounter/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/arp242/goatcounter/blob/master/LICENSE",
          "note": "EUPL-1.2, with a shortened list of compatible licenses."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.goatcounter.com/help/privacy",
          "note": "The website loads no third-party trackers, and the privacy policy states no information is shared with third parties."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.goatcounter.com/contribute",
          "note": "Funded by donations and paid plans, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.goatcounter.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.goatcounter.com",
          "note": "Grade F (15/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_cookies": {
          "title": "No cookies",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.goatcounter.com/help/privacy",
          "note": "Nothing is stored in the browser with cookies, localStorage, cache or other methods."
        },
        "no_personal_data": {
          "title": "No personal data",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.goatcounter.com/help/sessions",
          "note": "IP addresses and User-Agent headers are only held in memory for session counting and never stored to disk."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://github.com/arp242/goatcounter#self-hosting-goatcounter",
          "note": "Official binaries and instructions for self-hosting are provided."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:45.908Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "google-analytics",
      "category": "web-analytics",
      "name": "Google Analytics",
      "description": "Google's web and app analytics service (GA4) that measures traffic, events and conversions, and connects with Google Ads for audiences and ad measurement.",
      "website": "https://marketingplatform.google.com/about/analytics/",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 23,
      "coverage": 100,
      "summary": "Google Analytics scores 23 out of 100 (grade F) on the website analytics criteria. It meets 2 of 11 criteria: transparency report and tells users about requests. It partly meets independent audit and TLS configuration. It does not meet open source, no trackers or telemetry, no ads or data sales, security headers, no cookies, no personal data and self-hostable. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/web-analytics/google-analytics/",
      "markdown": "https://privacyratings.com/web-analytics/google-analytics/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Google's websites and the Analytics site use Google's own advertising and analytics cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://support.google.com/analytics/answer/1011397",
          "note": "Part of Google's advertising business. Analytics data can be shared with Google for its products and used with Google Ads for audiences and ad personalization."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.google.com/analytics/answer/6004245",
          "note": "Google Analytics is covered by Google's ISO 27001 certification, but no full audit report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://transparencyreport.google.com/user-data/overview",
          "note": "Publishes counts of government requests for user data and how often data is disclosed, updated twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://policies.google.com/terms/information-requests",
          "note": "Google emails the user before disclosing information unless legally prohibited or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=analytics.google.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=analytics.google.com",
          "note": "Grade C (55/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_cookies": {
          "title": "No cookies",
          "weight": 2,
          "answer": "no",
          "evidence": "https://support.google.com/analytics/answer/6004245",
          "note": "Uses first-party cookies on websites and app instance IDs in apps to identify users."
        },
        "no_personal_data": {
          "title": "No personal data",
          "weight": 3,
          "answer": "no",
          "evidence": "https://support.google.com/analytics/answer/6004245",
          "note": "IP addresses are not stored, but cookie and user identifiers are kept, and data can be used for advertising personalization."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Hosted only."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:45.544Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "matomo",
      "category": "web-analytics",
      "name": "Matomo",
      "description": "Open source web analytics platform, formerly Piwik, with detailed reports, goals, heatmaps and a tag manager. Can be self-hosted or used as the hosted Matomo Cloud.",
      "website": "https://matomo.org",
      "source": "https://github.com/matomo-org/matomo",
      "license": "GPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "NZ",
        "name": "New Zealand",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Matomo scores 50 out of 100 (grade D) on the website analytics criteria. It meets 4 of 11 criteria: open source, no ads or data sales, TLS configuration and self-hostable. It partly meets security headers, no cookies and no personal data. It does not meet no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in New Zealand: Five Eyes member. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/web-analytics/matomo/",
      "markdown": "https://privacyratings.com/web-analytics/matomo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/matomo-org/matomo/blob/5.x-dev/LEGALNOTICE",
          "note": "GPL-3.0-or-later. Some premium plugins are sold separately."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://matomo.org/privacy-policy/",
          "note": "The privacy policy lists Google Ads tracking on the website, with consent where required."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://matomo.org/privacy-policy/",
          "note": "Funded by Matomo Cloud subscriptions and paid plugins. The privacy policy states personal data is never sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published. Paid external penetration tests are mentioned but no report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=matomo.org&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=matomo.org",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_cookies": {
          "title": "No cookies",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://matomo.org/faq/general/faq_157/",
          "note": "The default tracking code sets first-party cookies, and a cookieless mode can be turned on."
        },
        "no_personal_data": {
          "title": "No personal data",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://matomo.org/faq/general/configure-privacy-settings-in-matomo/",
          "note": "IP masking is on by default, and full anonymization and data retention limits can be configured."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://matomo.org/faq/on-premise/installing-matomo/",
          "note": "Matomo On-Premise is officially supported for self-hosting."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "LinkedIn Insight",
            "host": "snap.licdn.com",
            "effect": "no"
          },
          {
            "name": "Matomo Cloud",
            "host": "cdn.matomo.cloud",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:59:45.768Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "microsoft-clarity",
      "category": "web-analytics",
      "name": "Microsoft Clarity",
      "description": "Free behavior analytics from Microsoft that records sessions and builds heatmaps of clicks and scrolling on websites and mobile apps.",
      "website": "https://clarity.microsoft.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 27,
      "coverage": 100,
      "summary": "Microsoft Clarity scores 27 out of 100 (grade F) on the website analytics criteria. It meets 3 of 11 criteria: transparency report, tells users about requests and TLS configuration. It partly meets no cookies. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, security headers, no personal data and self-hostable. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/web-analytics/microsoft-clarity/",
      "markdown": "https://privacyratings.com/web-analytics/microsoft-clarity/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The service is closed source. Only the tracking script is published under the MIT license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.microsoft.com/en-us/privacy/privacystatement",
          "note": "Microsoft collects usage data on its websites and uses data about users for personalized advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/clarity/faq",
          "note": "Free service from Microsoft. Clarity uses third-party cookies for purposes such as advertising, with opt-out through the Digital Advertising Alliance."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit of Clarity is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Microsoft publishes counts of government requests for customer data twice a year."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.microsoft.com/en-us/corporate-responsibility/reports/government-requests/customer-data",
          "note": "Microsoft gives prior notice to users of its consumer services whose data is requested, except where prohibited by law or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=clarity.microsoft.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=clarity.microsoft.com",
          "note": "Grade D (35/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_cookies": {
          "title": "No cookies",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://learn.microsoft.com/en-us/clarity/faq",
          "note": "First-party cookies store a persistent Clarity user ID by default. Without cookie consent, Clarity runs without cookies with fragmented sessions."
        },
        "no_personal_data": {
          "title": "No personal data",
          "weight": 3,
          "answer": "no",
          "evidence": "https://learn.microsoft.com/en-us/clarity/faq",
          "note": "Records sessions tied to a persistent user ID, and third-party cookies support advertising."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Hosted only."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:45.743Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "pirsch",
      "category": "web-analytics",
      "name": "Pirsch",
      "description": "Hosted web analytics from Germany that counts visitors without cookies using a daily hash, with server-side tracking options and a built-in link shortener.",
      "website": "https://pirsch.io",
      "source": "https://github.com/pirsch-analytics/pirsch",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 64,
      "coverage": 100,
      "summary": "Pirsch scores 64 out of 100 (grade C) on the website analytics criteria. It meets 5 of 11 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, no cookies and no personal data. It partly meets open source and self-hostable. It does not meet independent audit, transparency report, tells users about requests and security headers. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/web-analytics/pirsch/",
      "markdown": "https://privacyratings.com/web-analytics/pirsch/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/pirsch-analytics/pirsch/blob/master/LICENSE",
          "note": "The core tracking library is AGPL-3.0, but the dashboard and hosted service are closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://pirsch.io/privacy",
          "note": "No third-party trackers. The website uses Pirsch's own analytics, which are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.pirsch.io/privacy",
          "note": "Funded by subscriptions. The documentation states no information is sold to third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=pirsch.io&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=pirsch.io",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_cookies": {
          "title": "No cookies",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.pirsch.io/privacy",
          "note": "No cookies are used. Visitors are recognized for up to a day with a salted hash computed on the server."
        },
        "no_personal_data": {
          "title": "No personal data",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://docs.pirsch.io/privacy",
          "note": "The visitor's IP address is never stored or logged."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://pirsch.io/pricing",
          "note": "On-premise installation is only offered with the Enterprise plan."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:46.040Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "plausible-analytics",
      "category": "web-analytics",
      "name": "Plausible Analytics",
      "description": "Lightweight web analytics that counts visits without cookies and shows aggregate stats on a single dashboard. Available as a hosted service or as the self-hosted Community Edition.",
      "website": "https://plausible.io",
      "source": "https://github.com/plausible/analytics",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "EE",
        "name": "Estonia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 73,
      "coverage": 100,
      "summary": "Plausible Analytics scores 73 out of 100 (grade C) on the website analytics criteria. It meets 7 of 11 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, no cookies, no personal data and self-hostable. It does not meet independent audit, transparency report, tells users about requests and security headers. It is based in Estonia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/web-analytics/plausible-analytics/",
      "markdown": "https://privacyratings.com/web-analytics/plausible-analytics/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/plausible/analytics/blob/master/extra/COPYING.txt",
          "note": "All code is public. The Community Edition is AGPL-3.0, and code for hosted-only features in the extra directory of the same repository is published under a source-available proprietary notice."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://plausible.io/privacy",
          "note": "No third-party trackers. The website uses Plausible's own analytics, which are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://plausible.io/privacy",
          "note": "Funded by subscriptions. The privacy policy states data is never sold or used for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=plausible.io&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=plausible.io",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_cookies": {
          "title": "No cookies",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://plausible.io/data-policy",
          "note": "The script sets no cookies and generates no persistent visitor identifiers."
        },
        "no_personal_data": {
          "title": "No personal data",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://plausible.io/data-policy",
          "note": "Raw IP addresses and User-Agent strings are not stored, and a daily visitor hash is used instead."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://plausible.io/self-hosted-web-analytics",
          "note": "The Community Edition is officially offered for self-hosting."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:45.719Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "posthog",
      "category": "web-analytics",
      "name": "PostHog",
      "description": "Product analytics platform with web analytics, session replay, feature flags, experiments and surveys. Offered as PostHog Cloud or as an unsupported self-hosted deployment.",
      "website": "https://posthog.com",
      "source": "https://github.com/PostHog/posthog",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 48,
      "coverage": 100,
      "summary": "PostHog scores 48 out of 100 (grade D) on the website analytics criteria. It meets 4 of 11 criteria: open source, no ads or data sales, independent audit and TLS configuration. It partly meets no cookies and self-hostable. It does not meet no trackers or telemetry, transparency report, tells users about requests, security headers and no personal data. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/web-analytics/posthog/",
      "markdown": "https://privacyratings.com/web-analytics/posthog/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/PostHog/posthog/blob/master/LICENSE",
          "note": "All code is public. Most is MIT, and the ee directory in the same repository uses a source-available proprietary license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://posthog.com/privacy",
          "note": "The privacy policy describes marketing cookies and sharing account information with third-party advertising platforms such as LinkedIn."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://posthog.com/privacy",
          "note": "Funded by usage-based subscriptions. The privacy policy states customer data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://posthog.com/security/soc2-report-2026.pdf",
          "note": "The full SOC 2 Type 2 report from an independent service auditor is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=posthog.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=posthog.com",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_cookies": {
          "title": "No cookies",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://posthog.com/tutorials/cookieless-tracking",
          "note": "The script sets a first-party cookie and localStorage by default, and a cookieless mode can be turned on."
        },
        "no_personal_data": {
          "title": "No personal data",
          "weight": 3,
          "answer": "no",
          "evidence": "https://posthog.com/docs/privacy/data-collection",
          "note": "Client IP addresses are captured by default, except for EU organizations, and can be discarded in settings."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://posthog.com/docs/self-host",
          "note": "Self-hosting with Docker is possible but officially unsupported."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:45.948Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "simple-analytics",
      "category": "web-analytics",
      "name": "Simple Analytics",
      "description": "Hosted web analytics from the Netherlands that counts page views and unique visits without cookies, fingerprinting or IP addresses.",
      "website": "https://www.simpleanalytics.com",
      "source": "https://github.com/simpleanalytics/scripts",
      "license": "MIT",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 61,
      "coverage": 100,
      "summary": "Simple Analytics scores 61 out of 100 (grade C) on the website analytics criteria. It meets 5 of 11 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, no cookies and no personal data. It partly meets open source. It does not meet independent audit, transparency report, tells users about requests, security headers and self-hostable. It is based in the Netherlands: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B-.",
      "url": "https://privacyratings.com/web-analytics/simple-analytics/",
      "markdown": "https://privacyratings.com/web-analytics/simple-analytics/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/simpleanalytics/scripts/blob/main/LICENSE",
          "note": "The tracking scripts are MIT, but the hosted analytics service is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.simpleanalytics.com/privacy-policy",
          "note": "No third-party trackers. The website uses Simple Analytics' own analytics, which are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.simpleanalytics.com/privacy-policy",
          "note": "Funded by subscriptions. The privacy policy states data is never sold to third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.simpleanalytics.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.simpleanalytics.com",
          "note": "Grade B- (65/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_cookies": {
          "title": "No cookies",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.simpleanalytics.com/what-we-collect",
          "note": "No cookies, local storage, fingerprinting or IP hashing are used."
        },
        "no_personal_data": {
          "title": "No personal data",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://docs.simpleanalytics.com/what-we-collect",
          "note": "IP addresses are not collected or stored, and country is derived from the visitor's time zone."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "Hosted only."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Simple Analytics",
            "host": "scripts.simpleanalyticscdn.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:59:46.652Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "swetrix",
      "category": "web-analytics",
      "name": "Swetrix",
      "description": "Open source, cookieless web analytics with performance monitoring, error tracking and optional session replays. Available as Swetrix Cloud or as the self-hosted Community Edition.",
      "website": "https://swetrix.com",
      "source": "https://github.com/Swetrix/swetrix",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 73,
      "coverage": 100,
      "summary": "Swetrix scores 73 out of 100 (grade C) on the website analytics criteria. It meets 7 of 11 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, no cookies, no personal data and self-hostable. It does not meet independent audit, transparency report, tells users about requests and security headers. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C-.",
      "url": "https://privacyratings.com/web-analytics/swetrix/",
      "markdown": "https://privacyratings.com/web-analytics/swetrix/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Swetrix/swetrix/blob/main/backend/apps/cloud/COPYING.txt",
          "note": "All code is public. The Community Edition is AGPL-3.0, and the cloud-only features in backend/apps/cloud use a source-available proprietary license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://swetrix.com/privacy",
          "note": "No third-party trackers. The website uses Swetrix's own analytics, which are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://swetrix.com/privacy",
          "note": "Funded by subscriptions. The privacy policy states personal information is not sold or rented."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=swetrix.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=swetrix.com",
          "note": "Grade C- (45/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_cookies": {
          "title": "No cookies",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://swetrix.com/data-policy",
          "note": "No cookies or other client-side identifiers such as local storage are used for tracking."
        },
        "no_personal_data": {
          "title": "No personal data",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://swetrix.com/data-policy",
          "note": "IP addresses and User-Agent strings are only processed in memory to build a daily-salted session hash and are not stored."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://swetrix.com/docs/selfhosting/how-to",
          "note": "The Community Edition is officially documented for self-hosting with Docker."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:46.548Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "umami",
      "category": "web-analytics",
      "name": "Umami",
      "description": "Open source web analytics that tracks page views, referrers and events without cookies. Available as the hosted Umami Cloud or for self-hosting.",
      "website": "https://umami.is",
      "source": "https://github.com/umami-software/umami",
      "license": "MIT",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 61,
      "coverage": 100,
      "summary": "Umami scores 61 out of 100 (grade C) on the website analytics criteria. It meets 6 of 11 criteria: open source, no ads or data sales, TLS configuration, no cookies, no personal data and self-hostable. It partly meets security headers. It does not meet no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/web-analytics/umami/",
      "markdown": "https://privacyratings.com/web-analytics/umami/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/umami-software/umami/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google Ads conversion tracking (gtag)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://umami.is/privacy",
          "note": "Funded by Umami Cloud subscriptions. The privacy policy states personal information is not sold or shared."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=umami.is&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=umami.is",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "no_cookies": {
          "title": "No cookies",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.umami.is/docs/faq",
          "note": "The tracking code uses no cookies."
        },
        "no_personal_data": {
          "title": "No personal data",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://docs.umami.is/docs/faq",
          "note": "No personally identifiable information is stored and collected data is anonymized."
        },
        "self_hostable": {
          "title": "Self-hostable",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://docs.umami.is/docs/install",
          "note": "Official instructions for installing from source or with Docker."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:46.069Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bitly",
      "category": "url-shorteners",
      "name": "Bitly",
      "description": "Link management platform for creating short links, QR codes and landing pages, with click analytics and branded domains.",
      "website": "https://bitly.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 31,
      "coverage": 100,
      "summary": "Bitly scores 31 out of 100 (grade F) on the URL shorteners criteria. It meets 2 of 8 criteria: transparency report and TLS configuration. It partly meets independent audit. It does not meet open source, no trackers or telemetry, no ads or data sales, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/url-shorteners/bitly/",
      "markdown": "https://privacyratings.com/url-shorteners/bitly/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://bitly.com/pages/privacy",
          "note": "The website loads Google Tag Manager and Optimizely, and the privacy policy describes tracking pixels and third-party analytics providers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://bitly.com/pages/privacy",
          "note": "Link destination previews may include third-party advertising, and mobile advertising identifiers are collected."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://bitly.com/pages/trust",
          "note": "Bitly states it is SOC 2 Type 2 compliant, but the report is not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://bitly.com/pages/transparency-report",
          "note": "Publishes a yearly report with counts of court orders, subpoenas and foreign government requests and how many were answered."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=bitly.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=bitly.com",
          "note": "Grade F (20/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js-eu1.hs-scripts.com",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          },
          {
            "name": "Optimizely",
            "host": "cdn.optimizely.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:46.234Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dub",
      "category": "url-shorteners",
      "name": "Dub",
      "description": "Open source link management platform for short links, QR codes, conversion tracking and affiliate programs. Available as a hosted service or for self-hosting.",
      "website": "https://dub.co",
      "source": "https://github.com/dubinc/dub",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 63,
      "coverage": 100,
      "summary": "Dub scores 63 out of 100 (grade C) on the URL shorteners criteria. It meets 3 of 8 criteria: open source, no ads or data sales and TLS configuration. It partly meets no trackers or telemetry, independent audit and security headers. It does not meet transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/url-shorteners/dub/",
      "markdown": "https://privacyratings.com/url-shorteners/dub/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dubinc/dub/blob/main/LICENSE.md",
          "note": "All code is public. Most is AGPL-3.0, and code in the ee directories uses a separate source-available commercial license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://dub.co/legal/privacy",
          "note": "The website uses proxied Plausible analytics and Dub's own analytics, and the privacy policy states no third-party cookies are used."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://dub.co/legal/privacy",
          "note": "Funded by subscriptions. The privacy policy states personal information is not sold or rented."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://dub.co/security",
          "note": "Dub states it is SOC 2 Type II certified, but the report is not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=dub.co&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=dub.co",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Trustpilot",
            "host": "www.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:46.539Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kutt",
      "category": "url-shorteners",
      "name": "Kutt",
      "description": "Open source URL shortener with custom domains, password-protected and expiring links, and link statistics. Can be self-hosted, and the developers run a hosted instance at kutt.to.",
      "website": "https://kutt.to",
      "source": "https://github.com/thedevs-network/kutt",
      "license": "MIT",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 56,
      "coverage": 100,
      "summary": "Kutt scores 56 out of 100 (grade D) on the URL shorteners criteria. It meets 3 of 8 criteria: open source, no trackers or telemetry and no ads or data sales. It partly meets TLS configuration. It does not meet independent audit, transparency report, tells users about requests and security headers. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/url-shorteners/kutt/",
      "markdown": "https://privacyratings.com/url-shorteners/kutt/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/thedevs-network/kutt/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/thedevs-network/kutt",
          "note": "No telemetry or analytics in the source code, and kutt.to loads no third-party scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kutt.to/premium",
          "note": "Funded by premium plans and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=kutt.to&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=kutt.to",
          "note": "Grade D- (25/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:59:46.482Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "shlink",
      "category": "url-shorteners",
      "name": "Shlink",
      "description": "Self-hosted URL shortener with a REST API, command line tools, custom domains, QR codes and visit tracking. Managed through a separate web client or the API.",
      "website": "https://shlink.io",
      "source": "https://github.com/shlinkio/shlink",
      "license": "MIT",
      "platforms": [
        "linux",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Shlink scores 80 out of 100 (grade B) on the URL shorteners criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/url-shorteners/shlink/",
      "markdown": "https://privacyratings.com/url-shorteners/shlink/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/shlinkio/shlink/blob/develop/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/shlinkio/shlink",
          "note": "No telemetry or analytics in the source code. Forwarding visits to a Matomo instance is an optional integration."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/shlinkio/shlink/blob/develop/README.md",
          "note": "Free software funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:46.784Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "tinyurl",
      "category": "url-shorteners",
      "name": "TinyURL",
      "description": "Long-running URL shortener that creates short links without an account, with paid plans for custom aliases, branded domains and link analytics.",
      "website": "https://tinyurl.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 16,
      "coverage": 100,
      "summary": "TinyURL scores 16 out of 100 (grade F) on the URL shorteners criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets security headers. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/url-shorteners/tinyurl/",
      "markdown": "https://privacyratings.com/url-shorteners/tinyurl/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://tinyurl.com/app/privacy-policy",
          "note": "The website loads ad network scripts, and the privacy policy describes third-party analytics such as Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://tinyurl.com/app/privacy-policy",
          "note": "The free service shows ads, and the privacy policy lists ad networks among the recipients of personal information."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=tinyurl.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=tinyurl.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:46.657Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "yourls",
      "category": "url-shorteners",
      "name": "YOURLS",
      "description": "Self-hosted PHP URL shortener with a plugin system, an API, bookmarklets and click statistics for your own short domain.",
      "website": "https://yourls.org",
      "source": "https://github.com/YOURLS/YOURLS",
      "license": "MIT",
      "platforms": [
        "linux",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "YOURLS scores 65 out of 100 (grade C) on the URL shorteners criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/url-shorteners/yourls/",
      "markdown": "https://privacyratings.com/url-shorteners/yourls/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/YOURLS/YOURLS/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/YOURLS/YOURLS/blob/master/includes/functions-http.php",
          "note": "The update check sends usage statistics such as the site URL and link and click counts to api.yourls.org by default. It can be turned off with YOURLS_NO_VERSION_CHECK."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://yourls.org",
          "note": "Free software funded by sponsors through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:59:46.924Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "amazon-alexa",
      "category": "smart-home",
      "name": "Amazon Alexa",
      "description": "Amazon's voice assistant and smart home platform for Echo speakers and displays, controlled through the Alexa app. Voice requests are sent to Amazon's cloud for processing.",
      "website": "https://www.amazon.com/alexa",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Amazon Alexa scores 0 out of 100 (grade F) on the smart home criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/smart-home/amazon-alexa/",
      "markdown": "https://privacyratings.com/smart-home/amazon-alexa/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.amazon.dee.app/latest/",
          "note": "The Android app includes Amazon Analytics, Bugsnag and Google AdMob."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.amazon.com/gp/help/customer/display.html?nodeId=GLVB9XDF9M8MU7UZ",
          "note": "Amazon uses interactions with its services to show interest-based ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:01.120Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "apple-home",
      "category": "smart-home",
      "name": "Apple Home",
      "description": "Apple's smart home platform built on HomeKit and Matter, controlled with the Home app and Siri on Apple devices. Automations run on a home hub such as an Apple TV or HomePod, and Home data syncs end-to-end encrypted through iCloud.",
      "website": "https://www.apple.com/home-app/",
      "license": null,
      "platforms": [
        "ios",
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "Apple Home scores 45 out of 100 (grade D) on the smart home criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets no trackers or telemetry and independent audit. It does not meet open source. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/smart-home/apple-home/",
      "markdown": "https://privacyratings.com/smart-home/apple-home/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/device-analytics/",
          "note": "No third-party trackers in the app, and sharing device analytics with Apple is opt-in. Apple web pages load Apple's own analytics (ac-analytics, sent to metrics.apple.com) by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/en-ww/",
          "note": "Funded by device sales, with no ads in the Home app. Apple states it does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.apple.com/guide/certifications/apple-internet-services-security-apc34d2c0468b/web",
          "note": "iCloud, which stores Home data, has yearly ISO 27001 and 27018 certification audits, but only the certificates are public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:46.974Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "domoticz",
      "category": "smart-home",
      "name": "Domoticz",
      "description": "Open source home automation system written in C++ that runs locally on Linux, Windows, Raspberry Pi or Docker, with a web interface, scripting and support for many devices and protocols.",
      "website": "https://www.domoticz.com",
      "source": "https://github.com/domoticz/domoticz",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "linux",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Domoticz scores 80 out of 100 (grade B) on the smart home criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/smart-home/domoticz/",
      "markdown": "https://privacyratings.com/smart-home/domoticz/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/domoticz/domoticz/blob/development/License.txt",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/domoticz/domoticz",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.domoticz.com",
          "note": "Free software funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:47.402Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "esphome",
      "category": "smart-home",
      "name": "ESPHome",
      "description": "Open source system for building custom firmware for ESP32, ESP8266 and other microcontrollers from YAML files, turning them into local smart home devices that integrate with Home Assistant.",
      "website": "https://esphome.io",
      "source": "https://github.com/esphome/esphome",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "web"
      ],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "ESPHome scores 80 out of 100 (grade B) on the smart home criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law.",
      "url": "https://privacyratings.com/smart-home/esphome/",
      "markdown": "https://privacyratings.com/smart-home/esphome/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/esphome/esphome/blob/dev/LICENSE",
          "note": "The C++ runtime is GPL-3.0 and the Python tooling is MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/esphome/esphome",
          "note": "No third-party trackers, and the source code has no telemetry. The website's self-hosted Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.openhomefoundation.org",
          "note": "Maintained by the Open Home Foundation, funded mainly by Home Assistant Cloud subscriptions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:46.942Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gladys-assistant",
      "category": "smart-home",
      "name": "Gladys Assistant",
      "description": "Self-hosted, open source smart home software that runs locally on a Raspberry Pi, mini PC or NAS, with Zigbee, Matter and MQTT support. Optional paid remote access and backups through Gladys Plus.",
      "website": "https://gladysassistant.com",
      "source": "https://github.com/GladysAssistant/Gladys",
      "license": "Apache-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Gladys Assistant scores 50 out of 100 (grade D) on the smart home criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/smart-home/gladys-assistant/",
      "markdown": "https://privacyratings.com/smart-home/gladys-assistant/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/GladysAssistant/Gladys/blob/master/LICENSE",
          "note": "Apache-2.0. The Gladys Plus gateway is also open source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/GladysAssistant/Gladys/blob/master/server/lib/gateway/gateway.getLatestGladysVersion.js",
          "note": "Each instance sends usage statistics, including an instance ID, device count and integrations in use, with every update check, and there is no setting to turn this off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gladysassistant.com/plus/privacy/",
          "note": "Funded by Gladys Plus subscriptions. The privacy policy states data is never sold or shared for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:09.386Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "google-home",
      "category": "smart-home",
      "name": "Google Home",
      "description": "Google's smart home platform and app for setting up and controlling Nest speakers, displays, cameras and thermostats and other compatible devices, with Google Assistant or Gemini voice control.",
      "website": "https://home.google.com/welcome/",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Google Home scores 10 out of 100 (grade F) on the smart home criteria. It partly meets independent audit. It does not meet open source, no trackers or telemetry and no ads or data sales. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/smart-home/google-home/",
      "markdown": "https://privacyratings.com/smart-home/google-home/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.google.android.apps.chromecast.app/latest/",
          "note": "The Android app includes Google Firebase Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://safety.google/products/nest/",
          "note": "Part of Google's advertising business. Voice interactions with the Assistant may be used for ad personalization, though recordings and sensor data are not."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.google.com/product-documentation/answer/10231940",
          "note": "Nest devices are assessed by third-party labs such as DEKRA, but only short validation summaries are published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:46.939Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "home-assistant",
      "category": "smart-home",
      "name": "Home Assistant",
      "description": "Open source home automation platform that runs locally on a Raspberry Pi, mini PC or server and controls thousands of device brands, with companion apps for phones and computers.",
      "website": "https://www.home-assistant.io",
      "source": "https://github.com/home-assistant/core",
      "license": "Apache-2.0",
      "platforms": [
        "linux",
        "macos",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Home Assistant scores 65 out of 100 (grade C) on the smart home criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law.",
      "url": "https://privacyratings.com/smart-home/home-assistant/",
      "markdown": "https://privacyratings.com/smart-home/home-assistant/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/home-assistant/core/blob/dev/LICENSE.md",
          "note": "Apache-2.0. The companion apps are also open source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/io.homeassistant.companion.android/latest/",
          "note": "Usage analytics are opt-in and the website uses self-hosted Plausible, but the Play Store Android app sends Sentry crash reports by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.home-assistant.io/cloud/",
          "note": "Funded by optional Home Assistant Cloud subscriptions from Nabu Casa and by the Open Home Foundation, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:46.955Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "openhab",
      "category": "smart-home",
      "name": "openHAB",
      "description": "Open source, vendor-neutral home automation platform written in Java that runs locally and connects devices and services through add-ons, with rules, a web interface and mobile apps.",
      "website": "https://www.openhab.org",
      "source": "https://github.com/openhab/openhab-core",
      "license": "EPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "openHAB scores 50 out of 100 (grade D) on the smart home criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/smart-home/openhab/",
      "markdown": "https://privacyratings.com/smart-home/openhab/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/openhab/openhab-core/blob/main/LICENSE",
          "note": "EPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.openhab.org/privacy.html",
          "note": "The website uses Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.openhab.org/about/donate.html",
          "note": "Developed by volunteers and the non-profit openHAB Foundation, funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:47.661Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "smartthings",
      "category": "smart-home",
      "name": "SmartThings",
      "description": "Samsung's smart home platform and app for controlling Samsung appliances, TVs and compatible Zigbee, Z-Wave and Matter devices, with automations that run mostly in Samsung's cloud or on a SmartThings hub.",
      "website": "https://www.samsung.com/us/smartthings/",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "windows",
        "web"
      ],
      "jurisdiction": {
        "code": "KR",
        "name": "South Korea",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "SmartThings scores 10 out of 100 (grade F) on the smart home criteria. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in South Korea: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/smart-home/smartthings/",
      "markdown": "https://privacyratings.com/smart-home/smartthings/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://eula.samsungiotcloud.com/legal/us/en/pps.html",
          "note": "The privacy notice describes cookies and third-party analytics services and collection of usage data, including other apps on the device."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://eula.samsungiotcloud.com/legal/us/en/pps.html",
          "note": "Samsung may show advertisements in connection with the service, and uses SmartThings data for personalized ads only with separate consent."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:47.834Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "zigbee2mqtt",
      "category": "smart-home",
      "name": "Zigbee2MQTT",
      "description": "Open source bridge that connects Zigbee devices to an MQTT broker through a USB or network coordinator, so they can be used locally without the manufacturers' hubs or clouds.",
      "website": "https://www.zigbee2mqtt.io",
      "source": "https://github.com/Koenkk/zigbee2mqtt",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Zigbee2MQTT scores 80 out of 100 (grade B) on the smart home criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/smart-home/zigbee2mqtt/",
      "markdown": "https://privacyratings.com/smart-home/zigbee2mqtt/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Koenkk/zigbee2mqtt/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Koenkk/zigbee2mqtt",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Koenkk/zigbee2mqtt/blob/master/README.md",
          "note": "Free software funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:47.677Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "floorplanner",
      "category": "home-design",
      "name": "Floorplanner",
      "description": "Browser-based service for drawing 2D and 3D floor plans and furnishing rooms, used by homeowners, real estate agents and furniture retailers.",
      "website": "https://floorplanner.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 34,
      "coverage": 100,
      "summary": "Floorplanner scores 34 out of 100 (grade F) on the home and floor plan design criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It partly meets no trackers or telemetry. It does not meet open source, independent audit, transparency report, tells users about requests and security headers. It is based in the Netherlands: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/home-design/floorplanner/",
      "markdown": "https://privacyratings.com/home-design/floorplanner/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://floorplanner.com/privacy",
          "note": "The website uses Plausible analytics and the privacy policy mentions analytical cookies. No third-party advertising trackers were found."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://floorplanner.com/privacy",
          "note": "Funded by paid plans. The privacy policy states personal data is not sold or used for third-party commercial messages."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=floorplanner.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=floorplanner.com",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google reCAPTCHA",
            "host": "recaptcha.net",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:31:58.801Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "homebyme",
      "category": "home-design",
      "name": "HomeByMe",
      "description": "Browser-based home design service from Dassault Systèmes for drawing floor plans, furnishing rooms with products from real brands and rendering images in 3D.",
      "website": "https://home.by.me/en/",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "HomeByMe scores 25 out of 100 (grade F) on the home and floor plan design criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales and transparency report. It does not meet open source, no trackers or telemetry, independent audit, tells users about requests and security headers. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/home-design/homebyme/",
      "markdown": "https://privacyratings.com/home-design/homebyme/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://discover.3ds.com/privacy-policy",
          "note": "The website loads Heap analytics, and the Dassault Systèmes privacy policy describes analytics and advertising cookies from third parties."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://discover.3ds.com/privacy-policy",
          "note": "No ads based on user data in the planner and data is not sold, but 3DS and third parties set advertising cookies to profile interests and target content."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://discover.3ds.com/privacy-policy",
          "note": "The privacy policy states that government and legal requests are reviewed, narrowed or objected to where possible, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=home.by.me&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=home.by.me",
          "note": "Grade F (0/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:31:58.859Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "librecad",
      "category": "home-design",
      "name": "LibreCAD",
      "description": "Free, open source 2D CAD application for Windows, macOS and Linux that reads and writes DXF files and reads DWG files, used for technical drawings and floor plans.",
      "website": "https://librecad.org",
      "source": "https://github.com/LibreCAD/LibreCAD",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "LibreCAD scores 80 out of 100 (grade B) on the home and floor plan design criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/home-design/librecad/",
      "markdown": "https://privacyratings.com/home-design/librecad/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/LibreCAD/LibreCAD/blob/master/LICENSE",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/LibreCAD/LibreCAD",
          "note": "No telemetry or analytics in the source code. An update check that queries GitHub releases can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/librecad",
          "note": "Funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:34.389Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "live-home-3d",
      "category": "home-design",
      "name": "Live Home 3D",
      "description": "Home design application from BeLight Software for drawing floor plans, furnishing rooms and viewing designs in 3D, for Mac, iPhone, iPad, Windows and Android.",
      "website": "https://www.livehome3d.com",
      "license": null,
      "platforms": [
        "macos",
        "ios",
        "windows",
        "android"
      ],
      "jurisdiction": {
        "code": "UA",
        "name": "Ukraine",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Live Home 3D scores 10 out of 100 (grade F) on the home and floor plan design criteria. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in Ukraine: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/home-design/live-home-3d/",
      "markdown": "https://privacyratings.com/home-design/live-home-3d/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.livehome3d.com/privacy-policy/",
          "note": "The website uses Google Analytics, and the apps send usage statistics to the devtodev analytics service."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.livehome3d.com/privacy-policy/",
          "note": "Funded by app sales and subscriptions with no ads in the apps, but website cookies measure the effectiveness of BeLight's own advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:33.995Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "magicplan",
      "category": "home-design",
      "name": "magicplan",
      "description": "Mobile floor plan app that creates plans by scanning rooms with a phone or tablet camera or LiDAR, with estimates, reports and photos for contractors, and a cloud web app for office work.",
      "website": "https://magicplan.app",
      "license": null,
      "platforms": [
        "ios",
        "android",
        "web"
      ],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 22,
      "coverage": 100,
      "summary": "magicplan scores 22 out of 100 (grade F) on the home and floor plan design criteria. It partly meets no ads or data sales, independent audit, TLS configuration and security headers. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in Canada: Five Eyes member. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/home-design/magicplan/",
      "markdown": "https://privacyratings.com/home-design/magicplan/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.sensopia.magicplan/latest/",
          "note": "The Android app contains Google Firebase Analytics, Segment and Sentry, and the website uses Google Analytics, HubSpot and Facebook Custom Audiences."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://help.magicplan.app/privacy-web",
          "note": "Funded by subscriptions with no ads in the app, but the website uses Facebook Custom Audiences and Google Tag Manager for ad targeting of its own product."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://help.magicplan.app/data-privacy-information-security",
          "note": "magicplan cites SOC 2 and ISO/IEC 27001 controls and external audits, but reports are only available through its trust center."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=cloud.magicplan.app&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=cloud.magicplan.app",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js.hs-scripts.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:31:58.752Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "planner-5d",
      "category": "home-design",
      "name": "Planner 5D",
      "description": "Home and interior design service for drawing floor plans and furnishing rooms in 2D and 3D, available in the browser and as apps for mobile and desktop.",
      "website": "https://planner5d.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios",
        "windows",
        "macos"
      ],
      "jurisdiction": {
        "code": "LT",
        "name": "Lithuania",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 9,
      "coverage": 100,
      "summary": "Planner 5D scores 9 out of 100 (grade F) on the home and floor plan design criteria. It partly meets TLS configuration and security headers. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report and tells users about requests. It is based in Lithuania: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/home-design/planner-5d/",
      "markdown": "https://privacyratings.com/home-design/planner-5d/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.planner5d.planner5d/latest/",
          "note": "The Android app contains nine trackers, including AppsFlyer, Facebook Analytics, Google Firebase Analytics and Segment."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://planner5d.com/pages/privacy",
          "note": "The privacy policy allows advertisers to use cookies within the websites and services to optimize their advertising campaigns."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=planner5d.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=planner5d.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:31:59.025Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "roomsketcher",
      "category": "home-design",
      "name": "RoomSketcher",
      "description": "Floor plan and home design service for creating 2D and 3D floor plans and furnished 3D views, with apps for Windows, Mac and tablets and a web portal for projects.",
      "website": "https://www.roomsketcher.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "ios",
        "android",
        "web"
      ],
      "jurisdiction": {
        "code": "NO",
        "name": "Norway",
        "eyes": "Nine Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 13,
      "coverage": 100,
      "summary": "RoomSketcher scores 13 out of 100 (grade F) on the home and floor plan design criteria. It meets 1 of 8 criteria: TLS configuration. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests and security headers. It is based in Norway: Nine Eyes member; EEA member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/home-design/roomsketcher/",
      "markdown": "https://privacyratings.com/home-design/roomsketcher/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.roomsketcher.com/privacy/",
          "note": "The website loads Google Tag Manager, HubSpot and LinkedIn scripts, and the privacy policy lists Sentry and third-party advertising companies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.roomsketcher.com/privacy/",
          "note": "The privacy policy states third-party advertising companies serve ads when people visit and use RoomSketcher services, using data about visits to other websites."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.roomsketcher.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.roomsketcher.com",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "widget.trustpilot.com",
            "effect": "none"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:31:58.976Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sketchup",
      "category": "home-design",
      "name": "SketchUp",
      "description": "3D modeling software from Trimble for architecture, interior and landscape design, available as a desktop application and as SketchUp for Web in the browser.",
      "website": "https://sketchup.trimble.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "web",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 22,
      "coverage": 100,
      "summary": "SketchUp scores 22 out of 100 (grade F) on the home and floor plan design criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales and security headers. It does not meet open source, no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/home-design/sketchup/",
      "markdown": "https://privacyratings.com/home-design/sketchup/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.trimble.com/en/our-commitment/responsible-business/data-privacy-and-security/data-privacy-center/privacy-notice",
          "note": "The website loads Google Tag Manager, Trimble uses third-party tools to track visitors for targeted advertising, and SketchUp collects product usage data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.trimble.com/en/our-commitment/responsible-business/data-privacy-and-security/data-privacy-center/privacy-notice",
          "note": "Funded by subscriptions with no ads in the product, but Trimble shares data for targeted advertising of its own products."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.sketchup.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.sketchup.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          },
          {
            "name": "VWO",
            "host": "dev.visualwebsiteoptimizer.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:26:05.564Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sweet-home-3d",
      "category": "home-design",
      "name": "Sweet Home 3D",
      "description": "Free, open source interior design application for drawing 2D floor plans, placing furniture and viewing the home in 3D. Available as a desktop program, an online version and paid mobile apps.",
      "website": "https://www.sweethome3d.com",
      "source": "https://sourceforge.net/projects/sweethome3d/",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "IT",
        "name": "Italy",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Sweet Home 3D scores 50 out of 100 (grade D) on the home and floor plan design criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Italy: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/home-design/sweet-home-3d/",
      "markdown": "https://privacyratings.com/home-design/sweet-home-3d/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.sweethome3d.com/license/",
          "note": "GPL-2.0 for the free desktop version, the library editors and Sweet Home 3D JS. The paid app store versions are not covered."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.sweethome3d.com/privacy-policy/",
          "note": "The website loads Google Analytics and Firebase Analytics, and the iOS and macOS apps include Firebase Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.sweethome3d.com/privacy-policy/",
          "note": "Funded by donations and paid app store versions. The privacy policy states the website shows no advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:36.407Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "agent-dvr",
      "category": "security-cameras",
      "name": "Agent DVR",
      "description": "Video surveillance software from iSpyConnect for Windows, macOS, Linux and Docker, with motion and AI detection, free for private local use and a paid subscription for remote access.",
      "website": "https://www.ispyconnect.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "AU",
        "name": "Australia",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Agent DVR scores 0 out of 100 (grade F) on the security cameras criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in Australia: Five Eyes member; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/security-cameras/agent-dvr/",
      "markdown": "https://privacyratings.com/security-cameras/agent-dvr/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. Only plugins, install scripts and the API reference are published on GitHub."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.ispyconnect.com/privacy",
          "note": "The privacy policy says the website uses Google DART cookies and Google AdSense."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.ispyconnect.com/privacy",
          "note": "The website shows Google AdSense ads that use visitor data, although the software itself is funded by licenses."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:47.708Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "arlo",
      "category": "security-cameras",
      "name": "Arlo",
      "description": "Wireless security cameras and video doorbells with an app for live view, motion alerts and cloud recording through an Arlo Secure subscription.",
      "website": "https://www.arlo.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Arlo scores 0 out of 100 (grade F) on the security cameras criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/security-cameras/arlo/",
      "markdown": "https://privacyratings.com/security-cameras/arlo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.arlo.app/latest/",
          "note": "The Exodus report finds Amplitude, Google AdMob, Google CrashLytics, Google Firebase Analytics and Swrve in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://us.arlo.com/pages/privacy-notice",
          "note": "The privacy notice describes interest-based in-app advertising for users without a subscription and sharing data with ad networks."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "VWO",
            "host": "dev.visualwebsiteoptimizer.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:00.965Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "eufy-security",
      "category": "security-cameras",
      "name": "eufy Security",
      "description": "Anker's line of security cameras, video doorbells and home base stations that store video locally, with an app for live view and alerts. Optional end-to-end encryption is available for video.",
      "website": "https://www.eufy.com/security",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "CN",
        "name": "China",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "eufy Security scores 20 out of 100 (grade F) on the security cameras criteria. It partly meets no ads or data sales and independent audit. It does not meet open source and no trackers or telemetry. It is based in China: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/security-cameras/eufy-security/",
      "markdown": "https://privacyratings.com/security-cameras/eufy-security/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.eufy.com/policies/privacy-policy",
          "note": "The privacy policy describes third-party analytics and advertising networks that collect data through the website and apps."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.eufy.com/policies/privacy-policy",
          "note": "The privacy policy describes sharing personal data with advertising networks for targeted advertising and retargeting."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.eufy.com/privacy-commitment",
          "note": "eufy lists ISO 27001, ISO 27701, ETSI EN 303 645 and ioXt certifications, but no audit report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "VWO",
            "host": "dev.visualwebsiteoptimizer.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:01.682Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "frigate",
      "category": "security-cameras",
      "name": "Frigate",
      "description": "Open source network video recorder for IP cameras with local real-time object detection, running in Docker and integrating with Home Assistant.",
      "website": "https://frigate.video",
      "source": "https://github.com/blakeblackshear/frigate",
      "license": "MIT",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Frigate scores 50 out of 100 (grade D) on the security cameras criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/security-cameras/frigate/",
      "markdown": "https://privacyratings.com/security-cameras/frigate/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/blakeblackshear/frigate/blob/dev/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://frigate.video",
          "note": "The software has no analytics, but the frigate.video website loads Microsoft Clarity."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://frigate.video/plus/",
          "note": "Free software with no ads, funded by optional Frigate+ model subscriptions."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Microsoft Clarity",
            "host": "www.clarity.ms",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:48.002Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "google-nest-cam",
      "category": "security-cameras",
      "name": "Google Nest Cam",
      "description": "Google's indoor and outdoor security cameras and video doorbells, managed in the Google Home app, with optional cloud video history through a Google subscription.",
      "website": "https://store.google.com/category/nest_cams",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Google Nest Cam scores 10 out of 100 (grade F) on the security cameras criteria. It partly meets independent audit. It does not meet open source, no trackers or telemetry and no ads or data sales. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/security-cameras/google-nest-cam/",
      "markdown": "https://privacyratings.com/security-cameras/google-nest-cam/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.google.android.apps.chromecast.app/latest/",
          "note": "The Exodus report finds Google Firebase Analytics in the Google Home app, and the Play data safety listing declares collection of app interactions and diagnostics for analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://safety.google/products/nest/",
          "note": "Google keeps camera video, audio and sensor readings out of ad personalization, but other Google Home and Assistant interactions may be used for personalized ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.google.com/product-documentation/answer/10231940",
          "note": "Google publishes short summaries of third-party security validations for each Nest camera, not full audit reports."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:02.336Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ring",
      "category": "security-cameras",
      "name": "Ring",
      "description": "Amazon-owned video doorbells and security cameras with an app for live view, motion alerts and cloud recording through a Ring subscription. Optional end-to-end encryption is available for video.",
      "website": "https://ring.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Ring scores 10 out of 100 (grade F) on the security cameras criteria. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/security-cameras/ring/",
      "markdown": "https://privacyratings.com/security-cameras/ring/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.ringapp/latest/",
          "note": "The Exodus report finds Bugsnag and Google Firebase Analytics in the Android app, and the privacy notice describes third-party web and app analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://ring.com/privacy-notice",
          "note": "The privacy notice says activity on Ring websites and apps may be collected by ad networks for interest-based advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:48.339Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "scrypted",
      "category": "security-cameras",
      "name": "Scrypted",
      "description": "Self-hosted video integration platform that brings IP cameras into HomeKit, Google Home, Alexa and Home Assistant. The paid Scrypted NVR plugin adds recording, detection and mobile apps.",
      "website": "https://www.scrypted.app",
      "source": "https://github.com/koush/scrypted",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Scrypted scores 65 out of 100 (grade C) on the security cameras criteria. It meets 2 of 4 criteria: no trackers or telemetry and no ads or data sales. It partly meets open source. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/security-cameras/scrypted/",
      "markdown": "https://privacyratings.com/security-cameras/scrypted/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/koush/scrypted/blob/main/LICENSE.md",
          "note": "The server and most plugins are open source, but the paid Scrypted NVR plugin and its apps are closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/koush/scrypted",
          "note": "No telemetry or analytics in the open source server code, and the website loads no known trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.scrypted.app/scrypted-nvr/installation.html",
          "note": "Funded by paid Scrypted NVR subscriptions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:48.397Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "secluso",
      "category": "security-cameras",
      "name": "Secluso",
      "description": "Open source, end-to-end encrypted home security camera system for the Raspberry Pi Zero 2 W, with mobile apps for live video, alerts and recordings through a relay that cannot decrypt footage.",
      "website": "https://secluso.com",
      "source": "https://github.com/secluso/secluso",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Secluso scores 80 out of 100 (grade B) on the security cameras criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/security-cameras/secluso/",
      "markdown": "https://privacyratings.com/security-cameras/secluso/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/secluso/secluso/blob/main/LICENSE",
          "note": "GPL-3.0. The mobile app is also GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.secluso.mobile/latest/",
          "note": "The Exodus report finds no trackers in the Android app, and the website loads no known trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/secluso/secluso",
          "note": "Free open source software with no ads. Users run their own relay server or a beta relay offered by the developer."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:09.789Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "shinobi",
      "category": "security-cameras",
      "name": "Shinobi",
      "description": "Self-hosted video surveillance and recording software written in Node.js, with a web interface, motion and object detection plugins, and paid Pro licenses.",
      "website": "https://shinobi.video",
      "source": "https://gitlab.com/Shinobi-Systems/Shinobi",
      "license": null,
      "platforms": [
        "linux",
        "windows",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Shinobi scores 50 out of 100 (grade D) on the security cameras criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/security-cameras/shinobi/",
      "markdown": "https://privacyratings.com/security-cameras/shinobi/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/Shinobi-Systems/Shinobi/-/blob/master/LICENSE.md",
          "note": "All code is public under the source-available Shinobi license, which is not OSI-approved and requires a paid license for commercial use."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://shinobi.video",
          "note": "The shinobi.video website loads the third-party Tidio chat widget, and no privacy policy is published."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://licenses.shinobi.video/",
          "note": "Funded by paid licenses and support, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:48.557Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "wyze",
      "category": "security-cameras",
      "name": "Wyze",
      "description": "Low-cost smart home cameras, video doorbells and sensors with an app for live view, motion alerts and optional cloud recording through a Cam Plus subscription.",
      "website": "https://www.wyze.com",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Wyze scores 10 out of 100 (grade F) on the security cameras criteria. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/security-cameras/wyze/",
      "markdown": "https://privacyratings.com/security-cameras/wyze/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.hualai/latest/",
          "note": "The Exodus report finds Amplitude, Google CrashLytics and Google Firebase Analytics in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.wyze.com/policies/privacy-policy",
          "note": "The privacy statement describes targeted advertising through ad partners, which may count as selling or sharing data under some state laws."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Microsoft Clarity",
            "host": "www.clarity.ms",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:48.907Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "zoneminder",
      "category": "security-cameras",
      "name": "ZoneMinder",
      "description": "Open source video surveillance software for Linux that records and analyzes IP, USB and analog cameras through a web interface.",
      "website": "https://zoneminder.com",
      "source": "https://github.com/ZoneMinder/zoneminder",
      "license": "GPL-2.0",
      "platforms": [
        "linux",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "ZoneMinder scores 80 out of 100 (grade B) on the security cameras criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/security-cameras/zoneminder/",
      "markdown": "https://privacyratings.com/security-cameras/zoneminder/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ZoneMinder/zoneminder/blob/master/COPYING",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ZoneMinder/zoneminder/blob/master/scripts/ZoneMinder/lib/ZoneMinder/ConfigData.pm.in",
          "note": "Usage telemetry to the ZoneMinder team is off by default (ZM_TELEMETRY_DATA), and there are no third-party analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/ZoneMinder/zoneminder",
          "note": "Free open source software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:59:48.363Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "apple-watch",
      "category": "wearables",
      "name": "Apple Watch",
      "description": "Apple's smartwatch, paired with an iPhone, that tracks activity, workouts, heart rate, sleep and cycles and stores the data in the Health app.",
      "website": "https://www.apple.com/watch/",
      "license": null,
      "platforms": [
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "Apple Watch scores 45 out of 100 (grade D) on the wearables and health criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets no trackers or telemetry and independent audit. It does not meet open source. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/wearables/apple-watch/",
      "markdown": "https://privacyratings.com/wearables/apple-watch/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/device-analytics/",
          "note": "Device and health analytics are only shared with Apple with consent, but the Apple website sets first-party performance cookies for analytics by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/en-ww/",
          "note": "Funded by hardware sales, with no ads in the Health and Activity apps. Apple states it does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.apple.com/guide/certifications/apple-internet-services-security-apc34d2c0468b/web",
          "note": "iCloud, which syncs Health data, has yearly ISO 27001 and 27018 certification audits, but only the certificates are public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:48.405Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "asteroidos",
      "category": "wearables",
      "name": "AsteroidOS",
      "description": "Open source Linux distribution for smartwatches that replaces Wear OS on supported watches, with the AsteroidOS Sync companion app for Android.",
      "website": "https://asteroidos.org",
      "source": "https://github.com/AsteroidOS",
      "license": null,
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "AsteroidOS scores 80 out of 100 (grade B) on the wearables and health criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/wearables/asteroidos/",
      "markdown": "https://privacyratings.com/wearables/asteroidos/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/AsteroidOS/asteroid/blob/2.0/LICENSE",
          "note": "GPL-2.0 for the core, and the AsteroidOS Sync app is GPL-3.0. Some watches rely on proprietary hardware drivers from the original Android firmware."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.asteroidos.sync/latest/",
          "note": "The Exodus report finds no trackers in the AsteroidOS Sync app, and the website loads no known trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://asteroidos.org/",
          "note": "Free open source project developed by volunteers, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:49.727Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bangle-js",
      "category": "wearables",
      "name": "Bangle.js",
      "description": "Open source, hackable smartwatch from Espruino that runs JavaScript apps, with an app loader in the browser and an Android companion based on Gadgetbridge.",
      "website": "https://banglejs.com",
      "source": "https://github.com/espruino/Espruino",
      "license": null,
      "platforms": [
        "web",
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Bangle.js scores 50 out of 100 (grade D) on the wearables and health criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/wearables/bangle-js/",
      "markdown": "https://privacyratings.com/wearables/bangle-js/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/espruino/Espruino/blob/master/LICENSE",
          "note": "MPL-2.0 firmware. Apps in the BangleApps repository are MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.espruino.com/Privacy",
          "note": "The Espruino website uses Google Analytics. App analytics in the App Loader are opt-in."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://shop.espruino.com/banglejs2",
          "note": "Funded by hardware sales, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:49.173Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fitbit",
      "category": "wearables",
      "name": "Fitbit",
      "description": "Google-owned fitness trackers and smartwatches with an app that records activity, heart rate, sleep and other health data in a Fitbit or Google Account.",
      "website": "https://store.google.com/category/watches_trackers",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Fitbit scores 0 out of 100 (grade F) on the wearables and health criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/wearables/fitbit/",
      "markdown": "https://privacyratings.com/wearables/fitbit/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://support.google.com/product-documentation/answer/14815921",
          "note": "The privacy policy says partners provide analytics and advertising services using cookies and similar technologies, and the Play data safety listing declares analytics collection."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://play.google.com/store/apps/datasafety?id=com.fitbit.FitbitMobile",
          "note": "Fitbit says it never sells personal data, but the Play data safety listing declares use of app interactions, name and email for advertising or marketing."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:02.266Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gadgetbridge",
      "category": "wearables",
      "name": "Gadgetbridge",
      "description": "Open source Android app that connects smartwatches and fitness trackers to your phone without the vendor app or cloud account.",
      "website": "https://gadgetbridge.org",
      "source": "https://codeberg.org/Freeyourgadget/Gadgetbridge",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Gadgetbridge scores 80 out of 100 (grade B) on the wearables and health criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/wearables/gadgetbridge/",
      "markdown": "https://privacyratings.com/wearables/gadgetbridge/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/Freeyourgadget/Gadgetbridge/src/branch/master/LICENSE",
          "note": "AGPL-3.0 and Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/nodomain.freeyourgadget.gadgetbridge/latest/",
          "note": "The Exodus report finds no trackers in the app, and the website loads no known trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://liberapay.com/Gadgetbridge/donate",
          "note": "Free app funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:10.523Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "garmin-connect",
      "category": "wearables",
      "name": "Garmin Connect",
      "description": "Garmin's app and web service for syncing, analyzing and sharing activity, health and sleep data from Garmin watches and fitness devices.",
      "website": "https://connect.garmin.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Garmin Connect scores 20 out of 100 (grade F) on the wearables and health criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/wearables/garmin-connect/",
      "markdown": "https://privacyratings.com/wearables/garmin-connect/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.garmin.com/en-US/privacy/connect/policy/",
          "note": "The privacy policy lists Google Analytics and Firebase Crashlytics, which the Exodus report also finds in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://play.google.com/store/apps/datasafety?id=com.garmin.android.apps.connectmobile",
          "note": "Funded by device sales and subscriptions, with no ads. The Play data safety listing declares no sharing and no advertising use."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:59:48.955Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "infinitime",
      "category": "wearables",
      "name": "InfiniTime",
      "description": "Open source firmware for the PINE64 PineTime smartwatch, with notifications, step counting and heart rate over Bluetooth through companion apps such as Gadgetbridge.",
      "website": "https://infinitime.io",
      "source": "https://github.com/InfiniTimeOrg/InfiniTime",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "InfiniTime scores 80 out of 100 (grade B) on the wearables and health criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/wearables/infinitime/",
      "markdown": "https://privacyratings.com/wearables/infinitime/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/InfiniTimeOrg/InfiniTime/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/InfiniTimeOrg/InfiniTime",
          "note": "No telemetry or analytics in the source code; the firmware only talks to paired companion apps over Bluetooth, and the website loads no known trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://infinitime.io",
          "note": "Free open source firmware developed by volunteers, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:49.462Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "apple-health-cycle-tracking",
      "category": "period-trackers",
      "name": "Apple Health Cycle Tracking",
      "description": "Cycle Tracking feature in Apple's Health app on iPhone and Apple Watch for logging periods, symptoms and pregnancy, with period and fertile window predictions.",
      "website": "https://support.apple.com/en-us/120356",
      "license": null,
      "platforms": [
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 47,
      "coverage": 100,
      "summary": "Apple Health Cycle Tracking scores 47 out of 100 (grade D) on the period trackers criteria. It meets 1 of 6 criteria: no ads or data sales. It partly meets no trackers or telemetry, independent audit, data stays on device and no account needed. It does not meet open source. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/period-trackers/apple-health-cycle-tracking/",
      "markdown": "https://privacyratings.com/period-trackers/apple-health-cycle-tracking/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/device-analytics/",
          "note": "Device and health analytics are only shared with Apple with consent, but the Apple website sets first-party performance cookies for analytics by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/en-ww/",
          "note": "No ads in the Health app, which is included with Apple devices. Apple states it does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.apple.com/guide/certifications/apple-internet-services-security-apc34d2c0468b/web",
          "note": "iCloud, which syncs Health data, has yearly ISO 27001 and 27018 certification audits, but only the certificates are public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_storage": {
          "title": "Data stays on device",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://support.apple.com/en-us/102651",
          "note": "Data is stored on the device and, when iCloud is on, synced by default with end-to-end encryption that Apple cannot read, which requires two-factor authentication."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.apple.com/legal/privacy/data/en/health-app/",
          "note": "An Apple Account is optional and only needed for iCloud sync."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:49.651Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "clue",
      "category": "period-trackers",
      "name": "Clue",
      "description": "Period and cycle tracking app from Berlin-based BioWink, with predictions, symptom logging and health content, and a paid Clue Plus subscription.",
      "website": "https://helloclue.com",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 7,
      "coverage": 100,
      "summary": "Clue scores 7 out of 100 (grade F) on the period trackers criteria. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry, independent audit, data stays on device and no account needed. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/period-trackers/clue/",
      "markdown": "https://privacyratings.com/period-trackers/clue/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.clue.android/latest/",
          "note": "The Exodus report finds Adjust and Google Firebase Analytics in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://helloclue.com/privacy",
          "note": "Funded by subscriptions, and health data is never shared with advertisers, but with consent device IDs and app events are shared through Adjust with ad networks such as Meta and TikTok."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_storage": {
          "title": "Data stays on device",
          "weight": 3,
          "answer": "no",
          "evidence": "https://helloclue.com/privacy",
          "note": "Cycle data is stored on Clue's servers in the EU, encrypted at rest but not end-to-end encrypted."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 2,
          "answer": "no",
          "evidence": "https://helloclue.com/terms",
          "note": "The terms state that Clue is now only an online service and requires an account."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:49.560Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "drip",
      "category": "period-trackers",
      "name": "drip.",
      "description": "Open source menstrual cycle tracker for Android and iOS that supports the symptothermal method and keeps all data on the device.",
      "website": "https://dripapp.org",
      "source": "https://gitlab.com/bloodyhealth/drip",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 87,
      "coverage": 100,
      "summary": "drip. scores 87 out of 100 (grade B) on the period trackers criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, data stays on device and no account needed. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/period-trackers/drip/",
      "markdown": "https://privacyratings.com/period-trackers/drip/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/bloodyhealth/drip/-/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://dripapp.org/privacy-policy.html",
          "note": "The privacy policy states there is no tracking and no usage data is collected, and the Exodus report finds no trackers in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://dripapp.org/privacy-policy.html",
          "note": "Free app with no ads, developed by the nonprofit Heart of Code and funded by grants such as the Prototype Fund."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_storage": {
          "title": "Data stays on device",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://dripapp.org/privacy-policy.html",
          "note": "All data is stored only on the device."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://dripapp.org/privacy-policy.html",
          "note": "No account needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:50.088Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "euki",
      "category": "period-trackers",
      "name": "Euki",
      "description": "Open source sexual and reproductive health app from a US nonprofit, with period tracking, reminders and health information. Data stays on the device, with an optional PIN.",
      "website": "https://eukiapp.org",
      "source": "https://github.com/Euki-Inc/Euki-Android",
      "license": "GPL-3.0",
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 67,
      "coverage": 100,
      "summary": "Euki scores 67 out of 100 (grade C) on the period trackers criteria. It meets 4 of 6 criteria: open source, no ads or data sales, data stays on device and no account needed. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/period-trackers/euki/",
      "markdown": "https://privacyratings.com/period-trackers/euki/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Euki-Inc/Euki-Android/blob/main/LICENSE.md",
          "note": "GPL-3.0 for the Android and iOS apps."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://eukiapp.org",
          "note": "The Exodus report finds no trackers in the Android app, but the eukiapp.org website loads Google Ads conversion tags."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://eukiapp.org/privacy-faqs-resources",
          "note": "Free app from a donation-funded nonprofit, with no ads and no data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_storage": {
          "title": "Data stays on device",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://eukiapp.org/privacy-faqs-resources",
          "note": "All data is stored only on the device, with no servers or cloud storage."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://eukiapp.org/privacy-faqs-resources",
          "note": "No accounts and no email collected."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:50.274Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "flo",
      "category": "period-trackers",
      "name": "Flo",
      "description": "Period, ovulation and pregnancy tracking app with cycle predictions, symptom logging and health content, funded by Flo Premium subscriptions. An Anonymous Mode removes name and email from the account.",
      "website": "https://flo.health",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Flo scores 20 out of 100 (grade F) on the period trackers criteria. It partly meets no ads or data sales, independent audit and no account needed. It does not meet open source, no trackers or telemetry and data stays on device. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/period-trackers/flo/",
      "markdown": "https://privacyratings.com/period-trackers/flo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.iggymedia.periodtracker/latest/",
          "note": "The Exodus report finds AppsFlyer, Google Firebase Analytics and Sentry in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://flo.health/privacy-policy",
          "note": "Funded by subscriptions with no in-app ads or data sales, but with consent device identifiers are shared with AppsFlyer and ad partners such as Meta and Google Ads to target Flo's own ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://flo.health/privacy-portal/certification",
          "note": "Flo holds ISO 27001 and ISO 27701 certifications and cites a third-party privacy audit, but no full audit report is public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_storage": {
          "title": "Data stays on device",
          "weight": 3,
          "answer": "no",
          "evidence": "https://flo.health/privacy-portal",
          "note": "Cycle data is stored on Flo's servers, encrypted at rest but not end-to-end encrypted."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://flo.health/product-tour/anonymous-mode",
          "note": "An account is created on Flo's servers, but Anonymous Mode lets it be used without a name, email or other identifiers."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "widget.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:50.340Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mensinator",
      "category": "period-trackers",
      "name": "Mensinator",
      "description": "Open source Android period tracker with custom colour-coded symptoms, cycle and ovulation predictions, and data export, with no sign-up and no network access.",
      "website": "https://github.com/EmmaTellblom/Mensinator",
      "source": "https://github.com/EmmaTellblom/Mensinator",
      "license": "MIT",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 87,
      "coverage": 100,
      "summary": "Mensinator scores 87 out of 100 (grade B) on the period trackers criteria. It meets 5 of 6 criteria: open source, no trackers or telemetry, no ads or data sales, data stays on device and no account needed. It does not meet independent audit.",
      "url": "https://privacyratings.com/period-trackers/mensinator/",
      "markdown": "https://privacyratings.com/period-trackers/mensinator/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/EmmaTellblom/Mensinator/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.mensinator.app/latest/",
          "note": "The Exodus report finds no trackers, and the app does not request internet access."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/EmmaTellblom/Mensinator",
          "note": "Free open source app developed by volunteers, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_storage": {
          "title": "Data stays on device",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/EmmaTellblom/Mensinator",
          "note": "The README states no data is sent anywhere; data stays on the device with optional export."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/EmmaTellblom/Mensinator",
          "note": "No sign-up needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:59:49.561Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "periodical",
      "category": "period-trackers",
      "name": "Periodical",
      "description": "Open source Android period calendar that estimates fertile days with the calendar method, with notes, symptoms and local backup.",
      "website": "https://arnowelzel.de/en/projects/periodical",
      "source": "https://codeberg.org/askaaron/periodical",
      "license": null,
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 77,
      "coverage": 100,
      "summary": "Periodical scores 77 out of 100 (grade B) on the period trackers criteria. It meets 4 of 6 criteria: open source, no ads or data sales, data stays on device and no account needed. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/period-trackers/periodical/",
      "markdown": "https://privacyratings.com/period-trackers/periodical/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/askaaron/periodical/src/branch/main/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/de.arnowelzel.android.periodical/latest/",
          "note": "The Exodus report finds no trackers and the app has no internet permission, but the project website uses self-hosted Matomo analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://arnowelzel.de/en/projects/periodical",
          "note": "Free software with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_storage": {
          "title": "Data stays on device",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://arnowelzel.de/en/projects/periodical",
          "note": "Data is stored only on the device, with optional backups to local storage."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://arnowelzel.de/en/projects/periodical",
          "note": "No account needed."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:51.198Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "stardust",
      "category": "period-trackers",
      "name": "Stardust",
      "description": "Period tracking app with cycle predictions, symptom logging and moon-phase features, funded by subscriptions. Health data is stored against a random account ID, separate from contact details.",
      "website": "https://stardust.app",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 7,
      "coverage": 100,
      "summary": "Stardust scores 7 out of 100 (grade F) on the period trackers criteria. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry, independent audit, data stays on device and no account needed. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/period-trackers/stardust/",
      "markdown": "https://privacyratings.com/period-trackers/stardust/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.stardust.app/latest/",
          "note": "The Exodus report finds AppsFlyer, Google CrashLytics, Mixpanel, OneSignal and other trackers, and the website loads Google Tag Manager and New Relic."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://stardust.app/privacy-policy",
          "note": "Funded by subscriptions with no data sales, but with consent device data is shared with AppsFlyer and Firebase to target Stardust's own ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "local_storage": {
          "title": "Data stays on device",
          "weight": 3,
          "answer": "no",
          "evidence": "https://stardust.app/your-data",
          "note": "Health data is stored on Stardust's servers, encrypted and linked to a random account ID, but not end-to-end encrypted."
        },
        "no_account_needed": {
          "title": "No account needed",
          "weight": 2,
          "answer": "no",
          "evidence": "https://stardust.app/terms-of-use",
          "note": "An account is required."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "New Relic",
            "host": "js-agent.newrelic.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:50.517Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fitotrack",
      "category": "fitness-trackers",
      "name": "FitoTrack",
      "description": "Open source Android app for recording and viewing workouts such as running, cycling and hiking, with maps, charts and statistics stored on the device.",
      "website": "https://codeberg.org/jannis/FitoTrack",
      "source": "https://codeberg.org/jannis/FitoTrack",
      "license": null,
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "FitoTrack scores 80 out of 100 (grade B) on the fitness trackers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/fitness-trackers/fitotrack/",
      "markdown": "https://privacyratings.com/fitness-trackers/fitotrack/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/jannis/FitoTrack/src/branch/master/LICENSE.txt",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/de.tadris.fitness/latest/",
          "note": "The Exodus report finds no trackers, and the README states the app has no tracking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://codeberg.org/jannis/FitoTrack",
          "note": "Free open source app with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:59:49.728Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fittrackee",
      "category": "fitness-trackers",
      "name": "FitTrackee",
      "description": "Self-hosted open source web application for tracking outdoor workouts from GPS files or manual entries, with maps and statistics.",
      "website": "https://docs.fittrackee.org",
      "source": "https://codeberg.org/FitTrackee/FitTrackee",
      "license": null,
      "platforms": [
        "web",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "FitTrackee scores 80 out of 100 (grade B) on the fitness trackers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/fitness-trackers/fittrackee/",
      "markdown": "https://privacyratings.com/fitness-trackers/fittrackee/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/FitTrackee/FitTrackee/src/branch/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/FitTrackee/FitTrackee",
          "note": "No telemetry or analytics in the source code, and the documentation website loads no known trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://codeberg.org/FitTrackee/FitTrackee",
          "note": "Free open source software you host yourself, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:50.756Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "google-fit",
      "category": "fitness-trackers",
      "name": "Google Fit",
      "description": "Google's activity tracking app for Android, iOS and Wear OS that records steps, workouts and Heart Points in a Google Account. Google has deprecated the Google Fit APIs in favor of Health Connect and closed them to new developers.",
      "website": "https://www.google.com/fit/",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Google Fit scores 20 out of 100 (grade F) on the fitness trackers criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/fitness-trackers/google-fit/",
      "markdown": "https://privacyratings.com/fitness-trackers/google-fit/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://play.google.com/store/apps/datasafety?id=com.google.android.apps.fitness",
          "note": "Exodus finds no third-party trackers, but the Play data safety listing declares required collection of crash logs, app interactions and device IDs for analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://play.google.com/store/apps/datasafety?id=com.google.android.apps.fitness",
          "note": "Free app with no ads. The Play data safety listing declares no sharing with third parties and no data use for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:50.430Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "opentracks",
      "category": "fitness-trackers",
      "name": "OpenTracks",
      "description": "Open source Android sport tracker that records runs, rides and hikes with GPS and Bluetooth sensors, with no analytics and no cloud account.",
      "website": "https://opentracksapp.com",
      "source": "https://codeberg.org/OpenTracksApp/OpenTracks",
      "license": null,
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "OpenTracks scores 80 out of 100 (grade B) on the fitness trackers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/fitness-trackers/opentracks/",
      "markdown": "https://privacyratings.com/fitness-trackers/opentracks/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/OpenTracksApp/OpenTracks/src/branch/main/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/de.dennisguse.opentracks/latest/",
          "note": "The Exodus report finds no trackers, and the website states the app contains no in-app analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://liberapay.com/OpenTracks/",
          "note": "Free app funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:51.048Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "strava",
      "category": "fitness-trackers",
      "name": "Strava",
      "description": "Social fitness app and service for recording runs, rides and other workouts with GPS, sharing them with followers and comparing efforts on segments, with a paid subscription tier.",
      "website": "https://www.strava.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Strava scores 0 out of 100 (grade F) on the fitness trackers criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/fitness-trackers/strava/",
      "markdown": "https://privacyratings.com/fitness-trackers/strava/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.strava/latest/",
          "note": "The Exodus report finds Branch, Facebook Analytics, Google Firebase Analytics, Sentry and other trackers in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.strava.com/legal/privacy",
          "note": "The privacy policy describes sponsored content and sharing personal information with third-party advertising networks for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cookiebot",
            "host": "consent.cookiebot.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:51.011Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "wger",
      "category": "fitness-trackers",
      "name": "wger",
      "description": "Open source workout and nutrition manager for planning routines, logging workouts, weight and meals, available as a self-hosted server, a free public instance at wger.de and mobile apps.",
      "website": "https://wger.de",
      "source": "https://github.com/wger-project/wger",
      "license": "AGPL-3.0",
      "platforms": [
        "web",
        "android",
        "ios",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "wger scores 80 out of 100 (grade B) on the fitness trackers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/fitness-trackers/wger/",
      "markdown": "https://privacyratings.com/fitness-trackers/wger/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/wger-project/wger/blob/master/LICENSE.txt",
          "note": "AGPL-3.0 for the server and the mobile app."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/de.wger.flutter/latest/",
          "note": "The Exodus report finds no trackers in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://liberapay.com/wger/",
          "note": "Free open source project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:51.310Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "accuweather",
      "category": "weather",
      "name": "AccuWeather",
      "description": "Weather forecast website and app from AccuWeather, with hourly and daily forecasts, radar and severe weather alerts.",
      "website": "https://www.accuweather.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "AccuWeather scores 0 out of 100 (grade F) on the weather apps criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/weather/accuweather/",
      "markdown": "https://privacyratings.com/weather/accuweather/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.accuweather.android/latest/",
          "note": "The Exodus report finds Google AdMob, Google Crashlytics, Google Firebase Analytics and Urban Airship in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.accuweather.com/en/privacy",
          "note": "Funded by advertising. The privacy policy says data collected through cookies for targeted advertising may be considered a sale or sharing under California law."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:59:50.915Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "breezy-weather",
      "category": "weather",
      "name": "Breezy Weather",
      "description": "Open-source Android weather app with forecasts, nowcasting, air quality, pollen and alerts from more than 50 selectable weather sources.",
      "website": "https://github.com/breezy-weather/breezy-weather",
      "source": "https://github.com/breezy-weather/breezy-weather",
      "license": "LGPL-3.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Breezy Weather scores 80 out of 100 (grade B) on the weather apps criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/weather/breezy-weather/",
      "markdown": "https://privacyratings.com/weather/breezy-weather/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/breezy-weather/breezy-weather/blob/main/LICENSE",
          "note": "LGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.breezyweather/latest/",
          "note": "The Exodus report finds no trackers, and the privacy policy states the app collects no personal data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/breezy-weather/breezy-weather/blob/main/PRIVACY.md",
          "note": "Free software with no ads. The privacy policy states no personal data is collected."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:59:50.756Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bura",
      "category": "weather",
      "name": "Bura",
      "description": "Open-source Android weather app that shows forecasts from Open-Meteo with graphs, works offline and does not access the device location.",
      "website": "https://github.com/davidtakac/bura",
      "source": "https://github.com/davidtakac/bura",
      "license": "GPL-3.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Bura scores 80 out of 100 (grade B) on the weather apps criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/weather/bura/",
      "markdown": "https://privacyratings.com/weather/bura/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/davidtakac/bura/blob/dev/LICENSE.txt",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.davidtakac.bura/latest/",
          "note": "The Exodus report finds no trackers in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/davidtakac/bura",
          "note": "Free hobby project with no ads. The developer does not accept donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:59:50.757Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "meteoblue",
      "category": "weather",
      "name": "meteoblue",
      "description": "Swiss weather service with forecasts, meteograms, multi-model comparisons and weather maps on its website and apps.",
      "website": "https://www.meteoblue.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "meteoblue scores 0 out of 100 (grade F) on the weather apps criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law.",
      "url": "https://privacyratings.com/weather/meteoblue/",
      "markdown": "https://privacyratings.com/weather/meteoblue/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://content.meteoblue.com/en/about-us/legal/privacy",
          "note": "The privacy policy lists Google Analytics, Crashlytics and Microsoft Clarity, and the Exodus report finds Google AdMob, Crashlytics and Firebase Analytics in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://content.meteoblue.com/en/about-us/legal/ad-providers",
          "note": "The free website and apps show ads through Google Ad Manager and many third-party ad providers. An ad-free subscription is offered."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google DoubleClick",
            "host": "securepubads.g.doubleclick.net",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:04.320Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "the-weather-channel",
      "category": "weather",
      "name": "The Weather Channel",
      "description": "Weather forecast website and app from The Weather Company, with radar, severe weather alerts and news.",
      "website": "https://weather.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "The Weather Channel scores 0 out of 100 (grade F) on the weather apps criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/weather/the-weather-channel/",
      "markdown": "https://privacyratings.com/weather/the-weather-channel/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.weather.Weather/latest/",
          "note": "The Exodus report finds 16 trackers in the Android app, including Google AdMob, AppsFlyer, Amplitude, Facebook Ads and Taboola."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://trust.weather.com/en-US/privacy/privacy-policy",
          "note": "Funded by advertising. The privacy policy describes targeted advertising cookies and trackers used by advertising partners."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google DoubleClick",
            "host": "securepubads.g.doubleclick.net",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:51.087Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bitcoin",
      "category": "cryptocurrencies",
      "name": "Bitcoin",
      "description": "Decentralized cryptocurrency and payment network. Every transaction, address and amount is recorded on a public blockchain, so payments are pseudonymous rather than private.",
      "website": "https://bitcoin.org",
      "source": "https://github.com/bitcoin/bitcoin",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 100,
      "coverage": 100,
      "summary": "Bitcoin scores 100 out of 100 (grade A) on the private cryptocurrencies criteria. It meets 4 of 4 criteria: open source, no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/cryptocurrencies/bitcoin/",
      "markdown": "https://privacyratings.com/cryptocurrencies/bitcoin/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bitcoin/bitcoin/blob/master/COPYING",
          "note": "The reference implementation, Bitcoin Core, is MIT licensed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://bitcoin.org/en/privacy",
          "note": "The bitcoin.org privacy policy describes only server logs with shortened IP addresses and a consent cookie, and Bitcoin Core contains no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://bitcoincore.org/en/about/",
          "note": "Open protocol and software maintained by an open source developer community, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ostif.org/wp-content/uploads/2025/11/25-05-2133-REP-bitcoincore-security-assessment-V1.3.pdf",
          "note": "Quarkslab published a full security audit of Bitcoin Core, arranged by OSTIF."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:02:01.749Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bittensor",
      "category": "cryptocurrencies",
      "name": "Bittensor",
      "description": "Decentralized network where subnets compete to produce machine learning and other digital work, rewarded in its TAO token. All transactions and balances are recorded on a public blockchain.",
      "website": "https://www.bittensor.com",
      "source": "https://github.com/opentensor/subtensor",
      "license": "Apache-2.0",
      "platforms": [
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Bittensor scores 80 out of 100 (grade B) on the private cryptocurrencies criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/cryptocurrencies/bittensor/",
      "markdown": "https://privacyratings.com/cryptocurrencies/bittensor/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/opentensor/subtensor/blob/main/LICENSE",
          "note": "The Subtensor blockchain node is Apache-2.0, and the Python SDK and btcli are MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/opentensor/btcli",
          "note": "No third-party trackers, and the SDK and btcli have no telemetry. Vercel Web Analytics on bittensor.com are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.bittensor.com/whitepaper",
          "note": "Open protocol where participants are paid through TAO emissions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:47.601Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ethereum",
      "category": "cryptocurrencies",
      "name": "Ethereum",
      "description": "Decentralized blockchain platform for smart contracts and applications, with Ether as its native currency. All transactions and contract activity are recorded on a public blockchain.",
      "website": "https://ethereum.org",
      "source": "https://github.com/ethereum/go-ethereum",
      "license": "LGPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 75,
      "coverage": 100,
      "summary": "Ethereum scores 75 out of 100 (grade B) on the private cryptocurrencies criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/cryptocurrencies/ethereum/",
      "markdown": "https://privacyratings.com/cryptocurrencies/ethereum/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ethereum/go-ethereum/blob/master/COPYING",
          "note": "The go-ethereum client is LGPL-3.0 and GPL-3.0, and the other major clients and the protocol specifications are also open source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://ethereum.org/privacy-policy/",
          "note": "The ethereum.org website uses Matomo analytics and Sentry error reporting. Client software such as go-ethereum sends no telemetry by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ethereum.foundation/ef",
          "note": "Protocol development is funded by the non-profit Ethereum Foundation and other community organizations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://github.com/ethereum/go-ethereum/tree/master/docs/audits",
          "note": "Audits of the go-ethereum client and its peer discovery protocol are published, but they are older than three years."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:59:51.689Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "monero",
      "category": "cryptocurrencies",
      "name": "Monero",
      "description": "Cryptocurrency that hides the sender, receiver and amount of every transaction by default, using ring signatures, stealth addresses and RingCT.",
      "website": "https://www.getmonero.org",
      "source": "https://github.com/monero-project/monero",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 100,
      "coverage": 100,
      "summary": "Monero scores 100 out of 100 (grade A) on the private cryptocurrencies criteria. It meets 4 of 4 criteria: open source, no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/cryptocurrencies/monero/",
      "markdown": "https://privacyratings.com/cryptocurrencies/monero/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/monero-project/monero/blob/master/LICENSE",
          "note": "BSD-3-Clause and MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.getmonero.org/legal/",
          "note": "The website privacy policy describes only standard server logs, and the wallet and node software contain no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ccs.getmonero.org",
          "note": "Community project funded by donations through the Community Crowdfunding System, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/trailofbits/publications/blob/master/reviews/2026-07-magicgrants-monerofcmp++crypto-securityreview.pdf",
          "note": "Trail of Bits published a full review of cryptography changes to the Monero codebase for the FCMP++ upgrade. Other protocol components have older audits."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:09.850Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "zcash",
      "category": "cryptocurrencies",
      "name": "Zcash",
      "description": "Cryptocurrency that uses zero-knowledge proofs to offer shielded transactions, which hide the sender, receiver and amount. Transparent transactions are also supported, so privacy depends on using shielded addresses.",
      "website": "https://z.cash",
      "source": "https://github.com/ZcashFoundation/zebra",
      "license": "Apache-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 70,
      "coverage": 100,
      "summary": "Zcash scores 70 out of 100 (grade C) on the private cryptocurrencies criteria. It meets 3 of 4 criteria: open source, no ads or data sales and independent audit. It does not meet no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/cryptocurrencies/zcash/",
      "markdown": "https://privacyratings.com/cryptocurrencies/zcash/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ZcashFoundation/zebra/blob/main/LICENSE-APACHE",
          "note": "MIT and Apache-2.0. Zebra is the main node implementation after zcashd reached end of life."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://z.cash/privacy-policy/",
          "note": "The z.cash cookie settings list Google Analytics and Google Tag Manager as essential cookies that cannot be switched off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://z.cash/privacy-policy/",
          "note": "The privacy policy states personal data is not sold or used for targeted advertising. Development is funded by a protocol development fund and donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://leastauthority.com/wp-content/uploads/2025/11/ZCG-Zebra-NU6.1-Network-Upgrade-Final-Audit-Report.pdf",
          "note": "Least Authority published a full audit of the Zebra node's NU6.1 network upgrade changes."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:09.932Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bitbox02",
      "category": "crypto-wallets",
      "name": "BitBox02",
      "description": "Swiss hardware wallet for Bitcoin and other cryptocurrencies with open source firmware and companion app, a secure chip, multisig support and microSD card backups.",
      "website": "https://bitbox.swiss",
      "source": "https://github.com/BitBoxSwiss/bitbox02-firmware",
      "license": "Apache-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 60,
      "coverage": 100,
      "summary": "BitBox02 scores 60 out of 100 (grade C) on the crypto wallets criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets independent audit. It does not meet no trackers or telemetry. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law.",
      "url": "https://privacyratings.com/crypto-wallets/bitbox02/",
      "markdown": "https://privacyratings.com/crypto-wallets/bitbox02/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/BitBoxSwiss/bitbox02-firmware/blob/master/LICENSE",
          "note": "Apache-2.0 for the firmware. The BitBoxApp is also Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://bitbox.swiss/policies/privacy-policy/",
          "note": "The privacy policy says the website uses Google Analytics. The BitBoxApp has no third-party trackers or analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://bitbox.swiss/policies/privacy-policy/",
          "note": "Funded by hardware sales. The privacy policy states user information is never sold, rented or leased."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://bitbox.swiss/bitbox02/security-features/",
          "note": "The vendor states Census Labs audited the firmware, but the report is not published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Trustpilot",
            "host": "widget.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:10.065Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bitcoin-core",
      "category": "crypto-wallets",
      "name": "Bitcoin Core",
      "description": "Reference implementation of Bitcoin: a full node that downloads and validates the entire blockchain, with a built-in wallet, a graphical interface and an RPC interface.",
      "website": "https://bitcoincore.org",
      "source": "https://github.com/bitcoin/bitcoin",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 90,
      "coverage": 100,
      "summary": "Bitcoin Core scores 90 out of 100 (grade A) on the crypto wallets criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It partly meets independent audit.",
      "url": "https://privacyratings.com/crypto-wallets/bitcoin-core/",
      "markdown": "https://privacyratings.com/crypto-wallets/bitcoin-core/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bitcoin/bitcoin/blob/master/COPYING",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bitcoin/bitcoin",
          "note": "No telemetry or analytics in the source code, and the website loads no known trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/bitcoin/bitcoin/blob/master/COPYING",
          "note": "Free MIT-licensed software developed by contributors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://ostif.org/wp-content/uploads/2025/11/25-05-2133-REP-bitcoincore-security-assessment-V1.3.pdf",
          "note": "Quarkslab published a full audit through OSTIF, but it covers the peer-to-peer and validation code and not the wallet."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:48.029Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bitkey",
      "category": "crypto-wallets",
      "name": "Bitkey",
      "description": "Bitcoin wallet from Block made of a phone app, a hardware key and a Block-run server key in a 2-of-3 multisig setup, with recovery without a seed phrase.",
      "website": "https://bitkey.world",
      "source": "https://github.com/proto-at-block/bitkey",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Bitkey scores 40 out of 100 (grade D) on the crypto wallets criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/crypto-wallets/bitkey/",
      "markdown": "https://privacyratings.com/crypto-wallets/bitkey/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/proto-at-block/bitkey/blob/main/LICENSE",
          "note": "MIT for the app, firmware and server code, published as a copy of the internal repository."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/world.bitkey.app/latest/",
          "note": "Exodus finds Bugsnag in the Android app, and the website loads Google Tag Manager and Amplitude."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://bitkey.world/legal/privacy-notice",
          "note": "Funded by hardware sales with no ads in the app and no sale of personal information, but website data is shared with advertising platforms to market Bitkey."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:48.659Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "blockstream-app",
      "category": "crypto-wallets",
      "name": "Blockstream App",
      "description": "Bitcoin and Liquid wallet from Blockstream, formerly Blockstream Green, with single-signature and two-factor multisig accounts, hardware wallet support and the option to connect to a personal Electrum server.",
      "website": "https://blockstream.com/app/",
      "source": "https://github.com/Blockstream/green_android",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Blockstream App scores 35 out of 100 (grade F) on the crypto wallets criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/crypto-wallets/blockstream-app/",
      "markdown": "https://privacyratings.com/crypto-wallets/blockstream-app/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/Blockstream/green_android/blob/master/LICENSE",
          "note": "The Android, iOS and desktop apps are GPL-3.0, but the server that co-signs two-factor multisig accounts is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.greenaddress.greenbits_android_wallet/latest/",
          "note": "Exodus finds Countly analytics in the Android app, and the blockstream.com website loads Google Analytics and Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://blockstream.com/privacy/",
          "note": "Free app with no ads. The privacy policy states collected personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Reddit Pixel",
            "host": "www.redditstatic.com",
            "effect": "no"
          },
          {
            "name": "X (Twitter) Pixel",
            "host": "static.ads-twitter.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:47.991Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "blockstream-jade",
      "category": "crypto-wallets",
      "name": "Blockstream Jade",
      "description": "Open-source Bitcoin and Liquid hardware wallet from Blockstream, with a camera for air-gapped QR signing and a virtual secure element that splits PIN protection between the device and a remote oracle server.",
      "website": "https://blockstream.com/jade/",
      "source": "https://github.com/Blockstream/Jade",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Blockstream Jade scores 50 out of 100 (grade D) on the crypto wallets criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/crypto-wallets/blockstream-jade/",
      "markdown": "https://privacyratings.com/crypto-wallets/blockstream-jade/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Blockstream/Jade/blob/master/COPYING",
          "note": "GPL-3.0 for the firmware as a whole, with some components under MIT. The PIN oracle server code is also public."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The blockstream.com website loads Google Tag Manager and Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://blockstream.com/privacy",
          "note": "Funded by hardware sales with no ads. The privacy policy states collected personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Reddit Pixel",
            "host": "www.redditstatic.com",
            "effect": "no"
          },
          {
            "name": "X (Twitter) Pixel",
            "host": "static.ads-twitter.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:51.841Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bluewallet",
      "category": "crypto-wallets",
      "name": "BlueWallet",
      "description": "Self-custodial Bitcoin wallet for Android, iOS and macOS with watch-only wallets, multisig vaults, coin control, hardware wallet support and the option to connect to a personal Electrum server.",
      "website": "https://bluewallet.io",
      "source": "https://github.com/BlueWallet/BlueWallet",
      "license": "MIT",
      "platforms": [
        "android",
        "ios",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "BlueWallet scores 50 out of 100 (grade D) on the crypto wallets criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/crypto-wallets/bluewallet/",
      "markdown": "https://privacyratings.com/crypto-wallets/bluewallet/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/BlueWallet/BlueWallet/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/io.bluewallet.bluewallet/latest/",
          "note": "Exodus finds Bugsnag in the Android app, which sends crash reports with a device ID by default and can be turned off in the privacy settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://bluewallet.io/privacy/",
          "note": "Free app with no ads, and the privacy policy says it collects as little user information as possible."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:48.067Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cake-wallet",
      "category": "crypto-wallets",
      "name": "Cake Wallet",
      "description": "Open-source, self-custodial mobile and desktop wallet for Monero, Bitcoin, Litecoin, Ethereum and other cryptocurrencies, with built-in exchange and purchase integrations.",
      "website": "https://cakewallet.com",
      "source": "https://github.com/cake-tech/cake_wallet",
      "license": "MIT",
      "platforms": [
        "android",
        "ios",
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Cake Wallet scores 80 out of 100 (grade B) on the crypto wallets criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/crypto-wallets/cake-wallet/",
      "markdown": "https://privacyratings.com/crypto-wallets/cake-wallet/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cake-tech/cake_wallet/blob/dev/LICENSE.md",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://cakewallet.com/privacy/",
          "note": "No third-party trackers, and the app collects no usage data. The website's Fathom analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cakewallet.com/privacy/",
          "note": "No ads. Funded through integrated exchange and purchase services, and the privacy policy states usage data is not collected."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Fathom",
            "host": "cdn.usefathom.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:59:51.831Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "coinbase-wallet",
      "category": "crypto-wallets",
      "name": "Coinbase Wallet",
      "description": "Self-custodial crypto wallet app from Coinbase for holding and trading tokens and using onchain apps, with optional smart contract accounts and messaging. Formerly branded as Base App.",
      "website": "https://wallet.coinbase.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "BM",
        "name": "Bermuda",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Coinbase Wallet scores 0 out of 100 (grade F) on the crypto wallets criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in Bermuda: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/crypto-wallets/coinbase-wallet/",
      "markdown": "https://privacyratings.com/crypto-wallets/coinbase-wallet/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.toshi/latest/",
          "note": "The Exodus report finds 7 trackers in the Android app, including Amplitude, AppsFlyer, Branch and Google Firebase Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://wallet.coinbase.com/privacy-policy",
          "note": "The privacy policy describes ads shown in the app and ad attribution data shared with third-party advertising partners."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Impact",
            "host": "app.impact.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:01.600Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "coldcard",
      "category": "crypto-wallets",
      "name": "COLDCARD",
      "description": "Bitcoin-only hardware wallet from Coinkite designed for air-gapped signing using a microSD card or NFC, with secure elements, PIN protection and multisig support.",
      "website": "https://coldcard.com",
      "source": "https://github.com/Coldcard/firmware",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CA",
        "name": "Canada",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "COLDCARD scores 50 out of 100 (grade D) on the crypto wallets criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Canada: Five Eyes member.",
      "url": "https://privacyratings.com/crypto-wallets/coldcard/",
      "markdown": "https://privacyratings.com/crypto-wallets/coldcard/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Coldcard/firmware/blob/master/COPYING-CC",
          "note": "All firmware code is public under the MIT license with the Commons Clause, a source-available combination that is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The coldcard.com website loads Google Analytics through Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://coinkite.com/privacy",
          "note": "Funded by hardware sales. The privacy policy states personal information is not sold or rented to third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": "https://coldcard.com/security/status",
          "note": "No independent audit is published. The security status page lists only scoped reviews and states no complete independent audit of the firmware is established."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:53.149Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cryptosteel",
      "category": "crypto-wallets",
      "name": "Cryptosteel",
      "description": "Stainless steel backup for a wallet recovery phrase, assembled from individual letter tiles in a sealed case to withstand fire, water and impact. Works offline with no electronics.",
      "website": "https://cryptosteel.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Cryptosteel scores 0 out of 100 (grade F) on the crypto wallets criteria. It does not meet no trackers or telemetry and no ads or data sales. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/crypto-wallets/cryptosteel/",
      "markdown": "https://privacyratings.com/crypto-wallets/cryptosteel/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "n/a",
          "evidence": null,
          "note": "Hardware seed backup with no software."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://cryptosteel.com/privacy/",
          "note": "Funded by product sales, but the privacy policy lists Google AdWords conversion tracking and Microsoft Advertising for advertising purposes."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Passive steel backup with no software or electronics to audit."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:10.052Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "electrum",
      "category": "crypto-wallets",
      "name": "Electrum",
      "description": "Lightweight Bitcoin wallet for desktop and Android that verifies transactions through SPV servers, with support for hardware wallets, multisig, watch-only wallets and Lightning.",
      "website": "https://electrum.org",
      "source": "https://github.com/spesmilo/electrum",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Electrum scores 80 out of 100 (grade B) on the crypto wallets criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/crypto-wallets/electrum/",
      "markdown": "https://privacyratings.com/crypto-wallets/electrum/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/spesmilo/electrum/blob/master/LICENCE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.electrum.electrum/latest/",
          "note": "The Exodus report finds no trackers in the Android app, and crash report uploads are opt-in."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://electrum.org/#privacy",
          "note": "Free software provided at no cost, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:10.430Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "envoy",
      "category": "crypto-wallets",
      "name": "Envoy",
      "description": "Companion mobile app for the Foundation Passport hardware wallet, used to set up the device, manage accounts and send transactions over QR codes, with encrypted cloud backups.",
      "website": "https://foundation.xyz/envoy/",
      "source": "https://github.com/Foundation-Devices/envoy",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Envoy scores 40 out of 100 (grade D) on the crypto wallets criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/crypto-wallets/envoy/",
      "markdown": "https://privacyratings.com/crypto-wallets/envoy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Foundation-Devices/envoy/blob/main/LICENSES/GPL-3.0-or-later.txt",
          "note": "GPL-3.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://foundation.xyz/policies/privacy-policy",
          "note": "Exodus finds no trackers in the Android app, but the foundation.xyz website uses Google Analytics, Meta Pixel, X advertising tools and Intercom."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://foundation.xyz/policies/privacy-policy",
          "note": "Funded by hardware sales with no ads in the app, but the website shares data with Google, Meta and X to measure advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit of Envoy is published. The published audits cover Passport hardware and firmware."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:48.204Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "feather-wallet",
      "category": "crypto-wallets",
      "name": "Feather Wallet",
      "description": "Open-source desktop Monero wallet for Linux, Tails, Windows and macOS, with Tor support, hardware wallet support and coin control.",
      "website": "https://featherwallet.org",
      "source": "https://github.com/feather-wallet/feather",
      "license": "BSD-3-Clause",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Feather Wallet scores 80 out of 100 (grade B) on the crypto wallets criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/crypto-wallets/feather-wallet/",
      "markdown": "https://privacyratings.com/crypto-wallets/feather-wallet/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/feather-wallet/feather/blob/master/LICENSE",
          "note": "BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/feather-wallet/feather",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://featherwallet.org/donate",
          "note": "Free software funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:52.622Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "keystone",
      "category": "crypto-wallets",
      "name": "Keystone",
      "description": "Air-gapped hardware wallet that signs transactions by QR code and works with third-party software wallets. The Keystone 3 Pro firmware and hardware schematics are published.",
      "website": "https://keyst.one",
      "source": "https://github.com/KeystoneHQ/keystone3-firmware",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "HK",
        "name": "Hong Kong",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Keystone scores 35 out of 100 (grade F) on the crypto wallets criteria. It partly meets open source, no ads or data sales and independent audit. It does not meet no trackers or telemetry. It is based in Hong Kong: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/crypto-wallets/keystone/",
      "markdown": "https://privacyratings.com/crypto-wallets/keystone/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://keyst.one/open-source",
          "note": "The Keystone 3 firmware is MIT licensed, but some third-party chip vendor libraries are not open."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://keyst.one/privacy-policy",
          "note": "The privacy policy names Google Analytics and advertising pixels, and the website loads Google Tag Manager, Mixpanel and the Facebook pixel."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://keyst.one/privacy-policy",
          "note": "Funded by hardware sales, but the privacy policy says site use, purchases and ad interactions are shared with advertising partners. It states personal data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://keyst.one/open-source",
          "note": "Keystone names SlowMist and Keylabs as reviewers of the Keystone 3 Pro firmware and hardware, but the full reports are not linked."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Meta Pixel",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Reddit Pixel",
            "host": "www.redditstatic.com",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "www.trustpilot.com",
            "effect": "none"
          },
          {
            "name": "X (Twitter) Pixel",
            "host": "static.ads-twitter.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:53.058Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ledger",
      "category": "crypto-wallets",
      "name": "Ledger",
      "description": "Hardware wallets that keep private keys in a secure element chip, managed through the Ledger Wallet app. The optional paid Ledger Recover service can back up an encrypted, split copy of the recovery phrase with third-party companies.",
      "website": "https://www.ledger.com",
      "source": "https://github.com/LedgerHQ/ledger-live",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Ledger scores 25 out of 100 (grade F) on the crypto wallets criteria. It partly meets open source and independent audit. It does not meet no trackers or telemetry and no ads or data sales. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/crypto-wallets/ledger/",
      "markdown": "https://privacyratings.com/crypto-wallets/ledger/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.ledger.com/academy/topics/ledgersolutions/is-ledger-open-source",
          "note": "The Ledger Wallet app, SDK and device apps are open source (Ledger Wallet under MIT), but the low-level secure element operating system code is closed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.ledger.live/latest/",
          "note": "The Exodus report finds Google AdMob and Google Firebase Analytics in the Android app, and the website uses Contentsquare, Hotjar and advertising cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://shop.ledger.com/pages/cookie-policy",
          "note": "Funded by hardware sales, but the cookie policy lists targeting cookies from Facebook, Google, LinkedIn, Twitter and Snapchat that build interest profiles for ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ledger.com/academy/topics/ledgersolutions/is-ledger-open-source",
          "note": "Ledger states a third-party security laboratory audits the operating system before each release, but the reports are not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          },
          {
            "name": "Optimizely",
            "host": "cdn.optimizely.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:02.299Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "muun",
      "category": "crypto-wallets",
      "name": "Muun",
      "description": "Self-custodial Bitcoin and Lightning wallet for Android and iOS that uses a 2-of-2 multisig setup with Muun's server and submarine swaps for Lightning payments.",
      "website": "https://muun.com",
      "source": "https://github.com/muun/apollo",
      "license": "MIT",
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "KY",
        "name": "Cayman Islands",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Muun scores 35 out of 100 (grade F) on the crypto wallets criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source. It does not meet no trackers or telemetry and independent audit. It is based in the Cayman Islands: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/crypto-wallets/muun/",
      "markdown": "https://privacyratings.com/crypto-wallets/muun/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/muun/apollo/blob/master/LICENSE",
          "note": "The Android and iOS apps are MIT, but the co-signing server is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/io.muun.apollo/latest/",
          "note": "Exodus finds Crashlytics, Firebase Analytics and OpenTelemetry in the Android app, and the website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://muun.com/privacy_policy.html",
          "note": "Free app with no ads. The privacy policy says service providers may not use personal information for other purposes."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:48.181Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nunchuk",
      "category": "crypto-wallets",
      "name": "Nunchuk",
      "description": "Bitcoin wallet built around multisig, with collaborative shared wallets, support for many hardware signers, and paid plans that add assisted key recovery and inheritance.",
      "website": "https://nunchuk.io",
      "source": "https://github.com/nunchuk-io/nunchuk-android",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Nunchuk scores 25 out of 100 (grade F) on the crypto wallets criteria. It partly meets open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/crypto-wallets/nunchuk/",
      "markdown": "https://privacyratings.com/crypto-wallets/nunchuk/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/nunchuk-io/nunchuk-android/blob/master/LICENSE",
          "note": "The Android and desktop apps are GPL-3.0, but the iOS app and the server for shared wallets and paid plans are not public."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/io.nunchuk.android/latest/",
          "note": "Exodus finds Branch and Google Crashlytics in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://nunchuk.io/privacy",
          "note": "Funded by subscriptions with no ads and no sale of personal information, but the privacy policy allows sharing aggregated demographic data with advertisers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:48.551Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "phoenix",
      "category": "crypto-wallets",
      "name": "Phoenix",
      "description": "Self-custodial Bitcoin Lightning wallet for Android and iOS from ACINQ, which manages channels and liquidity automatically through the ACINQ node.",
      "website": "https://phoenix.acinq.co",
      "source": "https://github.com/ACINQ/phoenix",
      "license": "Apache-2.0",
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Phoenix scores 80 out of 100 (grade B) on the crypto wallets criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/crypto-wallets/phoenix/",
      "markdown": "https://privacyratings.com/crypto-wallets/phoenix/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ACINQ/phoenix/blob/master/LICENSE",
          "note": "Apache-2.0. The ACINQ node runs the open-source eclair Lightning implementation."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/fr.acinq.phoenix.mainnet/latest/",
          "note": "The Exodus report finds no trackers in the Android app, and the website loads no third-party analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://phoenix.acinq.co/content/faq-1-general.md",
          "note": "Funded by fees on Lightning liquidity, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:52.319Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sparrow-wallet",
      "category": "crypto-wallets",
      "name": "Sparrow Wallet",
      "description": "Desktop Bitcoin wallet with detailed transaction and UTXO control, hardware wallet and multisig support, and the option to connect to a personal Bitcoin Core or Electrum server over Tor.",
      "website": "https://sparrowwallet.com",
      "source": "https://github.com/sparrowwallet/sparrow",
      "license": "Apache-2.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Sparrow Wallet scores 80 out of 100 (grade B) on the crypto wallets criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/crypto-wallets/sparrow-wallet/",
      "markdown": "https://privacyratings.com/crypto-wallets/sparrow-wallet/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sparrowwallet/sparrow/blob/master/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/sparrowwallet/sparrow",
          "note": "No telemetry or analytics in the source code, and the website loads no known trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://sparrowwallet.com/donate/",
          "note": "Free software funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:10.795Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "specter-desktop",
      "category": "crypto-wallets",
      "name": "Specter Desktop",
      "description": "Desktop app and web interface for managing Bitcoin multisig and single-key wallets with hardware signers, using a personal Bitcoin Core node or an Electrum server.",
      "website": "https://specter.solutions/desktop/",
      "source": "https://github.com/cryptoadvance/specter-desktop",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Specter Desktop scores 80 out of 100 (grade B) on the crypto wallets criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law.",
      "url": "https://privacyratings.com/crypto-wallets/specter-desktop/",
      "markdown": "https://privacyratings.com/crypto-wallets/specter-desktop/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cryptoadvance/specter-desktop/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cryptoadvance/specter-desktop",
          "note": "No telemetry or analytics in the source code, and the website loads no known trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://specter.solutions/donate/",
          "note": "Free software maintained by the non-profit Specter Association and funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:48.475Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "trezor",
      "category": "crypto-wallets",
      "name": "Trezor",
      "description": "Hardware wallet with open source firmware, used with the Trezor Suite desktop and mobile app to keep keys offline and sign transactions for Bitcoin and many other coins.",
      "website": "https://trezor.io",
      "source": "https://github.com/trezor/trezor-firmware",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CZ",
        "name": "Czechia",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Trezor scores 30 out of 100 (grade F) on the crypto wallets criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit. It is based in Czechia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/crypto-wallets/trezor/",
      "markdown": "https://privacyratings.com/crypto-wallets/trezor/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/trezor/trezor-suite/blob/develop/LICENSE.md",
          "note": "All code is public. The firmware is GPL-3.0 and the Trezor Suite app uses the source-available Trezor Reference Source License, which is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Meta Pixel (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://data.trezor.io/legal/privacy-policy.html",
          "note": "Funded by hardware sales, but the privacy policy says website cookies are used to personalize ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Meta Pixel",
            "host": "www.facebook.com",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "www.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:10.688Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "wasabi-wallet",
      "category": "crypto-wallets",
      "name": "Wasabi Wallet",
      "description": "Open source desktop Bitcoin wallet that routes traffic through Tor and supports WabiSabi coinjoins. The original zkSNACKs coordinator has shut down, so coinjoin requires configuring a third-party or self-hosted coordinator.",
      "website": "https://www.wasabiwallet.io",
      "source": "https://github.com/WalletWasabi/WalletWasabi",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Wasabi Wallet scores 80 out of 100 (grade B) on the crypto wallets criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/crypto-wallets/wasabi-wallet/",
      "markdown": "https://privacyratings.com/crypto-wallets/wasabi-wallet/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/WalletWasabi/WalletWasabi/blob/master/LICENSE.md",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/WalletWasabi/WalletWasabi",
          "note": "No telemetry or analytics in the source code. Network traffic goes through Tor by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.wasabiwallet.io/using-wasabi/CoinJoin.html",
          "note": "Free open source software with no ads. The client skips coinjoin rounds that charge a coordination fee."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:11.262Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "zeus",
      "category": "crypto-wallets",
      "name": "ZEUS",
      "description": "Self-custodial Bitcoin and Lightning wallet for Android and iOS that runs an embedded Lightning node or connects to a personal LND, Core Lightning or other remote node.",
      "website": "https://zeusln.com",
      "source": "https://github.com/ZeusLN/zeus",
      "license": null,
      "platforms": [
        "android",
        "ios"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "ZEUS scores 80 out of 100 (grade B) on the crypto wallets criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/crypto-wallets/zeus/",
      "markdown": "https://privacyratings.com/crypto-wallets/zeus/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ZeusLN/zeus/blob/master/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://zeusln.com/privacy-policy",
          "note": "The privacy policy states the app uses no tracking technology and lets no third parties track users. The Exodus report finds no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://zeusln.com/privacy-policy",
          "note": "No ads, and the privacy policy states no personal information is collected or shared when using the app."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:48.316Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "binance",
      "category": "crypto-exchanges",
      "name": "Binance",
      "description": "Centralized cryptocurrency exchange offering spot, futures and other trading products, with custodial accounts that require identity verification.",
      "website": "https://www.binance.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web",
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Binance scores 0 out of 100 (grade F) on the crypto exchanges criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/crypto-exchanges/binance/",
      "markdown": "https://privacyratings.com/crypto-exchanges/binance/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.binance.dev/latest/",
          "note": "The Exodus report finds 7 trackers in the Android app, including AppsFlyer, Google Firebase Analytics, Pangle and Sensors Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.binance.dev/latest/",
          "note": "Funded by trading fees, but the Android app includes the Pangle ad network and AppsFlyer ad attribution SDKs."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:52.459Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bisq",
      "category": "crypto-exchanges",
      "name": "Bisq",
      "description": "Open source, peer-to-peer desktop app for trading bitcoin for national currencies and other assets over Tor, using multisig escrow and no central server or registration.",
      "website": "https://bisq.network",
      "source": "https://github.com/bisq-network/bisq",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Bisq scores 80 out of 100 (grade B) on the crypto exchanges criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/crypto-exchanges/bisq/",
      "markdown": "https://privacyratings.com/crypto-exchanges/bisq/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bisq-network/bisq/blob/master/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://bisq.network/",
          "note": "Data is stored locally and never sent to a central server, and the software contains no telemetry. The website uses no advertising trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://bisq.network/dao/",
          "note": "Funded by trading fees distributed to contributors through the Bisq DAO, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:11.466Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "coinbase",
      "category": "crypto-exchanges",
      "name": "Coinbase",
      "description": "Centralized cryptocurrency exchange and custodial platform for buying, selling, storing and staking crypto. Accounts require identity verification.",
      "website": "https://www.coinbase.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Coinbase scores 0 out of 100 (grade F) on the crypto exchanges criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/crypto-exchanges/coinbase/",
      "markdown": "https://privacyratings.com/crypto-exchanges/coinbase/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.coinbase.android/latest/",
          "note": "The Exodus report finds 7 trackers in the Android app, including Amplitude, AppsFlyer, Facebook SDKs and Google Firebase Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.coinbase.com/legal/privacy",
          "note": "Funded by trading fees, but the privacy policy says conversion data including IP addresses is shared with advertisers such as Meta and AppLovin to target ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:52.449Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "haveno",
      "category": "crypto-exchanges",
      "name": "Haveno",
      "description": "Open-source, peer-to-peer exchange software for trading Monero with fiat and other cryptocurrencies over Tor, using non-custodial multisig escrow. Trading happens on third-party networks that run Haveno.",
      "website": "https://haveno.exchange",
      "source": "https://github.com/haveno-dex/haveno",
      "license": "AGPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Haveno scores 80 out of 100 (grade B) on the crypto exchanges criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/crypto-exchanges/haveno/",
      "markdown": "https://privacyratings.com/crypto-exchanges/haveno/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/haveno-dex/haveno/blob/master/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/haveno-dex/haveno",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/haveno-dex/haveno",
          "note": "Community project funded by donations and development bounties, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:53.252Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "hodl-hodl",
      "category": "crypto-exchanges",
      "name": "Hodl Hodl",
      "description": "Non-custodial peer-to-peer Bitcoin trading platform where trades are secured by multisig escrow contracts and payments are made directly between users.",
      "website": "https://hodlhodl.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "MH",
        "name": "Marshall Islands",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Hodl Hodl scores 20 out of 100 (grade F) on the crypto exchanges criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the Marshall Islands: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/crypto-exchanges/hodl-hodl/",
      "markdown": "https://privacyratings.com/crypto-exchanges/hodl-hodl/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://accounts.hodlhodl.com/privacy-policy",
          "note": "The privacy policy lists Google Analytics and Sentry, and the website loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://hodlhodl.com/faq",
          "note": "Funded by trading fees, with no ads. The privacy policy states personal data is never sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:53.557Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kraken",
      "category": "crypto-exchanges",
      "name": "Kraken",
      "description": "Centralized cryptocurrency exchange from Payward for buying, selling and trading crypto, with custodial accounts that require identity verification.",
      "website": "https://www.kraken.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Kraken scores 10 out of 100 (grade F) on the crypto exchanges criteria. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/crypto-exchanges/kraken/",
      "markdown": "https://privacyratings.com/crypto-exchanges/kraken/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.kraken.invest.app/latest/",
          "note": "The Exodus report finds AppsFlyer, FullStory, Google Firebase Analytics and Sentry in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.kraken.com/legal/privacy",
          "note": "Funded by trading fees. The privacy policy says data is not sold for money, but identifiers are shared with advertising partners and ad networks."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:53.285Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "peach-bitcoin",
      "category": "crypto-exchanges",
      "name": "Peach Bitcoin",
      "description": "Swiss peer-to-peer Bitcoin exchange app where buyers and sellers trade directly, with bitcoin held in multisig escrow during each trade.",
      "website": "https://peachbitcoin.com",
      "source": "https://github.com/Peach2Peach/peach-app",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Peach Bitcoin scores 35 out of 100 (grade F) on the crypto exchanges criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source. It does not meet no trackers or telemetry and independent audit. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law.",
      "url": "https://privacyratings.com/crypto-exchanges/peach-bitcoin/",
      "markdown": "https://privacyratings.com/crypto-exchanges/peach-bitcoin/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/Peach2Peach/peach-app/blob/main/LICENSE.md",
          "note": "The app source is public under the MIT license with the Commons Clause, which is not OSI-approved. The server is closed."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://peachbitcoin.com/privacy-policy/",
          "note": "The website uses Google Analytics. The Android app includes Google Crashlytics, with crash data sharing described as opt-in."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://peachbitcoin.com/terms-and-conditions/",
          "note": "Funded by a fee on each trade, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Trustpilot",
            "host": "widget.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:53.404Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "robosats",
      "category": "crypto-exchanges",
      "name": "RoboSats",
      "description": "Peer-to-peer exchange for trading bitcoin against national currencies over Tor, using Lightning hold invoices as escrow and a new robot identity for each trade with no registration.",
      "website": "https://learn.robosats.org",
      "source": "https://github.com/RoboSats/robosats",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "RoboSats scores 80 out of 100 (grade B) on the crypto exchanges criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/crypto-exchanges/robosats/",
      "markdown": "https://privacyratings.com/crypto-exchanges/robosats/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/RoboSats/robosats/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://learn.robosats.org/docs/private/",
          "note": "No registration is needed and all access goes over Tor. No telemetry or analytics in the source code, and the website loads no known trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://learn.robosats.org/docs/fees/",
          "note": "Funded by a small platform fee on each trade, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:11.718Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ironvest",
      "category": "virtual-cards",
      "name": "IronVest",
      "description": "Privacy service formerly called Abine Blur that provides masked virtual payment cards, masked email addresses and masked phone numbers, along with password management.",
      "website": "https://ironvest.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 47,
      "coverage": 100,
      "summary": "IronVest scores 47 out of 100 (grade D) on the virtual cards criteria. It meets 3 of 8 criteria: no ads or data sales, tells users about requests and TLS configuration. It partly meets independent audit, transparency report and security headers. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/virtual-cards/ironvest/",
      "markdown": "https://privacyratings.com/virtual-cards/ironvest/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.abine.dnt/latest/",
          "note": "The Exodus report finds AppsFlyer, Google Crashlytics, Google Firebase Analytics and Segment in the Android app. The website loads Google Analytics after consent."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ironvest.com/legal/privacy",
          "note": "Funded by subscriptions. The privacy policy states personal data is never sold or shared for cross-context behavioral advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://ironvest.com/legal/security",
          "note": "States it holds SOC 2 Type II, but the report is not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://ironvest.com/legal/privacy",
          "note": "The privacy policy says information is provided only under valid court orders, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://ironvest.com/legal/privacy",
          "note": "The privacy policy promises to notify users of law enforcement requests when legally permitted."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=ironvest.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=ironvest.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:54.780Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mysudo",
      "category": "virtual-cards",
      "name": "MySudo",
      "description": "App for creating separate personas called Sudos, each with its own phone number, email address, virtual payment cards and encrypted messaging. Virtual cards require identity verification.",
      "website": "https://mysudo.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 34,
      "coverage": 100,
      "summary": "MySudo scores 34 out of 100 (grade F) on the virtual cards criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It partly meets transparency report and tells users about requests. It does not meet open source, no trackers or telemetry, independent audit and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/virtual-cards/mysudo/",
      "markdown": "https://privacyratings.com/virtual-cards/mysudo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. The MySudo apps and servers are proprietary."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.anonyome.mysudo/latest/",
          "note": "The Exodus report finds Amazon Mobile Analytics and Google Crashlytics in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://anonyome.com/privacy-policy/",
          "note": "Funded by subscriptions. The privacy policy states personal information is never sold, traded or exchanged."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://anonyome.com/government-requests/",
          "note": "Publishes guidelines for government requests, but no request counts."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://anonyome.com/government-requests/",
          "note": "The guidelines reserve the right to notify users before disclosing data, but do not promise notice."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mysudo.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mysudo.com",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:03:55.349Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "privacy-com",
      "category": "virtual-cards",
      "name": "Privacy.com",
      "description": "US service by Lithic that issues virtual Visa and Mastercard cards locked to single merchants or spending limits, hiding the real card number from merchants. Sign-up requires name, date of birth and a government ID number.",
      "website": "https://www.privacy.com",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 19,
      "coverage": 100,
      "summary": "Privacy.com scores 19 out of 100 (grade F) on the virtual cards criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets independent audit. It does not meet open source, no trackers or telemetry, no ads or data sales, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/virtual-cards/privacy-com/",
      "markdown": "https://privacyratings.com/virtual-cards/privacy-com/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads PostHog and Reddit Pixel (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.privacy.com/privacy-policy",
          "note": "The privacy policy says it does not sell user information, but marketing cookies are used to show Privacy.com ads on other sites after a visit."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.privacy.com/security",
          "note": "States it holds SOC 1 and SOC 2 Type 2 reports and ISO 27001 compliance, but the reports are not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=privacy.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=privacy.com",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "PostHog",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Reddit Pixel",
            "host": "www.redditstatic.com",
            "effect": "no"
          },
          {
            "name": "Zendesk",
            "host": "static.zdassets.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:03:55.398Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "revolut",
      "category": "virtual-cards",
      "name": "Revolut",
      "description": "Financial app offering accounts, payment cards, transfers and investing, including disposable and merchant-specific virtual cards. Accounts require identity verification.",
      "website": "https://www.revolut.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 13,
      "coverage": 100,
      "summary": "Revolut scores 13 out of 100 (grade F) on the virtual cards criteria. It meets 1 of 8 criteria: TLS configuration. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests and security headers. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade B-.",
      "url": "https://privacyratings.com/virtual-cards/revolut/",
      "markdown": "https://privacyratings.com/virtual-cards/revolut/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.revolut.revolut/latest/",
          "note": "The Exodus report finds AppsFlyer, Google Crashlytics and Google Firebase Analytics in the Android app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.revolut.com/legal/privacy/",
          "note": "The privacy notice says data is never sold, but names, email addresses and app events may be shared with social media platforms for targeted ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.revolut.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.revolut.com",
          "note": "Grade B- (65/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "B-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:59:53.588Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "actual",
      "category": "budgeting",
      "name": "Actual",
      "description": "Local-first personal finance app based on envelope budgeting, with optional self-hosted sync between devices and optional end-to-end encryption.",
      "website": "https://actualbudget.org",
      "source": "https://github.com/actualbudget/actual",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Actual scores 80 out of 100 (grade B) on the budgeting criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/budgeting/actual/",
      "markdown": "https://privacyratings.com/budgeting/actual/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/actualbudget/actual/blob/master/LICENSE.txt",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://actualbudget.org/docs/privacy-policy/",
          "note": "The privacy policy states that no data is collected automatically and no tracking is used."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/actual",
          "note": "Community project funded by donations through Open Collective, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:11.003Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "beecount",
      "category": "budgeting",
      "name": "BeeCount",
      "description": "Offline-first expense tracker for Android and iOS, with optional sync through a self-hosted BeeCount Cloud server, iCloud, Supabase, WebDAV or S3.",
      "website": "https://count.beejz.com",
      "source": "https://github.com/TNT-Likely/BeeCount",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "BeeCount scores 80 out of 100 (grade B) on the budgeting criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/budgeting/beecount/",
      "markdown": "https://privacyratings.com/budgeting/beecount/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TNT-Likely/BeeCount/blob/main/LICENSE_EN",
          "note": "All code is public under a custom source-available non-commercial license that is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://count.beejz.com/en/privacy/",
          "note": "The privacy policy states the app has no analytics, crash reporting, advertising SDKs or third-party tracking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://count.beejz.com/en/donate/",
          "note": "Free app funded by donations, with no ads, and the privacy policy states data is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:11.398Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ezbookkeeping",
      "category": "budgeting",
      "name": "ezBookkeeping",
      "description": "Self-hosted personal finance app for recording transactions and analyzing spending, with data kept on the user's own server. Supports two-factor authentication and OIDC login.",
      "website": "https://ezbookkeeping.mayswind.net",
      "source": "https://github.com/mayswind/ezbookkeeping",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "ezBookkeeping scores 50 out of 100 (grade D) on the budgeting criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/budgeting/ezbookkeeping/",
      "markdown": "https://privacyratings.com/budgeting/ezbookkeeping/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mayswind/ezbookkeeping/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics and Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/mayswind/ezbookkeeping",
          "note": "Free self-hosted software under the MIT license, with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:11.498Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "firefly-iii",
      "category": "budgeting",
      "name": "Firefly III",
      "description": "Self-hosted personal finance manager with double-entry bookkeeping, budgets, categories, tags, a rule engine, reports and a REST API.",
      "website": "https://www.firefly-iii.org",
      "source": "https://github.com/firefly-iii/firefly-iii",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Firefly III scores 65 out of 100 (grade C) on the budgeting criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/budgeting/firefly-iii/",
      "markdown": "https://privacyratings.com/budgeting/firefly-iii/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/firefly-iii/firefly-iii/blob/main/COPYING",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://docs.firefly-iii.org/references/firefly-iii/changelog/",
          "note": "The app no longer has telemetry, but the project website runs self-hosted Matomo analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.firefly-iii.org/explanation/support/",
          "note": "Funded by donations and sponsorships, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:11.783Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gnucash",
      "category": "budgeting",
      "name": "GnuCash",
      "description": "Cross-platform double-entry accounting application for personal and small business finance, with accounts, budgets, scheduled transactions, investments and reports.",
      "website": "https://www.gnucash.org",
      "source": "https://github.com/Gnucash/gnucash",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "GnuCash scores 80 out of 100 (grade B) on the budgeting criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/budgeting/gnucash/",
      "markdown": "https://privacyratings.com/budgeting/gnucash/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Gnucash/gnucash/blob/stable/LICENSE",
          "note": "GPL-2.0 and LGPL-2.1."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Gnucash/gnucash",
          "note": "No telemetry or analytics in the source code, and the website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.gnucash.org/donate.phtml",
          "note": "Volunteer project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:11.982Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "homebank",
      "category": "budgeting",
      "name": "HomeBank",
      "description": "Open-source personal finance program for Windows and Linux for tracking accounts, budgets and spending, with charts, reports and bank file import.",
      "website": "https://www.gethomebank.org",
      "source": "https://code.launchpad.net/homebank",
      "license": null,
      "platforms": [
        "windows",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "HomeBank scores 30 out of 100 (grade F) on the budgeting criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/budgeting/homebank/",
      "markdown": "https://privacyratings.com/budgeting/homebank/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://git.launchpad.net/~mdoyen/homebank/+git/homebank/tree/COPYING?h=5.10.x",
          "note": "GPL-2.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The gethomebank.org website loads Google Analytics through Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.gethomebank.org/en/index.php",
          "note": "The website states the project is mainly supported by advertising on the site. The program itself shows no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:03.923Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kmymoney",
      "category": "budgeting",
      "name": "KMyMoney",
      "description": "Open-source double-entry personal finance manager from KDE for Linux, Windows and macOS, with budgets, investments, scheduled transactions and bank statement import.",
      "website": "https://kmymoney.org",
      "source": "https://invent.kde.org/office/kmymoney",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "KMyMoney scores 80 out of 100 (grade B) on the budgeting criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/budgeting/kmymoney/",
      "markdown": "https://privacyratings.com/budgeting/kmymoney/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://invent.kde.org/office/kmymoney/-/tree/master/LICENSES",
          "note": "GPL-2.0-or-later, with some files under other GPL-compatible licenses."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kde.org/privacypolicy-apps/",
          "note": "The KDE applications privacy policy says any telemetry is opt-in and off by default, and the kmymoney.org website loads no analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kde.org/donate/",
          "note": "Free software from the KDE community, funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:53.994Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "monarch",
      "category": "budgeting",
      "name": "Monarch",
      "description": "Subscription personal finance app that syncs bank and investment accounts to track spending, budgets, net worth and goals, with shared access for households.",
      "website": "https://www.monarch.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Monarch scores 20 out of 100 (grade F) on the budgeting criteria. It partly meets no ads or data sales and independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/budgeting/monarch/",
      "markdown": "https://privacyratings.com/budgeting/monarch/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.monarchmoney.mobile/latest/",
          "note": "The Exodus report finds 10 trackers in the Android app, including Amplitude, Facebook Analytics, FullStory, Segment and Singular."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.monarch.com/privacy",
          "note": "Funded by subscriptions and says financial data is never sold, but the privacy policy says advertising partners receive device, IP and web analytics data for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.monarch.com/security",
          "note": "States independent auditors verified its SOC 2 compliance, but the report is not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:54.124Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "money-manager-ex",
      "category": "budgeting",
      "name": "Money Manager Ex",
      "description": "Open-source personal finance app for Windows, macOS, Linux and Android for tracking accounts, budgets, investments and scheduled transactions, with data stored in a local database.",
      "website": "https://moneymanagerex.org",
      "source": "https://github.com/moneymanagerex/moneymanagerex",
      "license": "GPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 40,
      "coverage": 100,
      "summary": "Money Manager Ex scores 40 out of 100 (grade D) on the budgeting criteria. It meets 1 of 4 criteria: open source. It partly meets no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/budgeting/money-manager-ex/",
      "markdown": "https://privacyratings.com/budgeting/money-manager-ex/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/moneymanagerex/moneymanagerex/blob/master/LICENSE",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.money.manager.ex/latest/",
          "note": "The Exodus report finds Amplitude in the Android app, and the website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://moneymanagerex.org/",
          "note": "The desktop program is funded by donations with no ads, but the website shows Google AdSense ads, with ad personalization only after cookie consent."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:54.045Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "plain-text-accounting",
      "category": "budgeting",
      "name": "Plain Text Accounting",
      "description": "An approach to bookkeeping that keeps records in plain text files and processes them with command-line tools such as Ledger, hledger and Beancount.",
      "website": "https://plaintextaccounting.org",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 100,
      "coverage": 100,
      "summary": "Plain Text Accounting scores 100 out of 100 (grade A) on the budgeting criteria. It meets 3 of 3 criteria: open source, no trackers or telemetry and no ads or data sales.",
      "url": "https://privacyratings.com/budgeting/plain-text-accounting/",
      "markdown": "https://privacyratings.com/budgeting/plain-text-accounting/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ledger/ledger/blob/master/LICENSE.md",
          "note": "An ecosystem of tools rather than one product. The main tools are open source: Ledger (BSD-3-Clause), hledger (GPL-3.0) and Beancount (GPL-2.0)."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/hledgerorg/hledger",
          "note": "The main tools are offline command-line programs with no telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://hledger.org/sponsor.html",
          "note": "The main tools are volunteer projects funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "A bookkeeping method and a set of independent tools, not a single product that could be audited."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:11.892Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "quicken",
      "category": "budgeting",
      "name": "Quicken",
      "description": "Personal finance software from Quicken Inc., including the Quicken Classic desktop app and the Quicken Simplifi web and mobile app, for budgeting, bill tracking and investment tracking.",
      "website": "https://www.quicken.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Quicken scores 0 out of 100 (grade F) on the budgeting criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/budgeting/quicken/",
      "markdown": "https://privacyratings.com/budgeting/quicken/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.quicken.qm2014/latest/",
          "note": "The Exodus report finds 7 trackers in the Android app, including AppsFlyer, Google AdMob, Google Firebase Analytics, Mixpanel and Pendo."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.quicken.com/privacy-us/us/",
          "note": "Funded by subscriptions, but the privacy statement allows third-party advertising companies to collect information on its website through cookies."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:53.962Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "rotki",
      "category": "budgeting",
      "name": "rotki",
      "description": "Self-hosted, open source portfolio tracking and accounting tool for crypto assets and other investments, with data stored locally. Runs on Linux, macOS, Windows and Docker.",
      "website": "https://rotki.com",
      "source": "https://github.com/rotki/rotki",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "rotki scores 65 out of 100 (grade C) on the budgeting criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/budgeting/rotki/",
      "markdown": "https://privacyratings.com/budgeting/rotki/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rotki/rotki/blob/develop/LICENSE.md",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://docs.rotki.com/usage-guides/settings/general.html",
          "note": "Anonymous usage analytics are sent to rotki by default and can be turned off in the settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://rotki.com/products",
          "note": "Funded by premium subscriptions and sponsorships, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:12.298Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "skrooge",
      "category": "budgeting",
      "name": "Skrooge",
      "description": "Open-source personal finance manager from KDE for tracking accounts, budgets, investments and scheduled operations, with reports and import from many file formats.",
      "website": "https://skrooge.org",
      "source": "https://invent.kde.org/office/skrooge",
      "license": null,
      "platforms": [
        "windows",
        "linux"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Skrooge scores 80 out of 100 (grade B) on the budgeting criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/budgeting/skrooge/",
      "markdown": "https://privacyratings.com/budgeting/skrooge/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://invent.kde.org/office/skrooge/-/blob/master/LICENSES/GPL-3.0-or-later.txt",
          "note": "GPL-3.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kde.org/privacypolicy/",
          "note": "No third-party trackers, and the app has no telemetry by default. KDE websites use self-hosted Matomo with cookies disabled and IP addresses anonymized."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kde.org/donate/",
          "note": "Free software from the KDE community, funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:54.548Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ynab",
      "category": "budgeting",
      "name": "YNAB",
      "description": "Subscription budgeting app based on zero-based budgeting, where every unit of income is assigned a job, with optional bank account syncing.",
      "website": "https://www.ynab.com",
      "license": null,
      "platforms": [
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "YNAB scores 0 out of 100 (grade F) on the budgeting criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/budgeting/ynab/",
      "markdown": "https://privacyratings.com/budgeting/ynab/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.youneedabudget.evergreen.app/latest/",
          "note": "The Exodus report finds Amplitude, Bugsnag and Google Firebase Analytics in the Android app, and the privacy policy names Google Analytics and session recording tools."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.ynab.com/privacy-policy",
          "note": "Funded by subscriptions and says user data is not sold, but the privacy policy describes ad-network cookies, pixels and hashed email addresses shared with platforms for ad targeting."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Amplitude",
            "host": "cdn.amplitude.com",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:54.530Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "akkoma",
      "category": "social-networks",
      "name": "Akkoma",
      "description": "Federated, self-hostable microblogging server built on ActivityPub, forked from Pleroma, with emoji reactions, Markdown posts and low resource use.",
      "website": "https://akkoma.social",
      "source": "https://akkoma.dev/AkkomaGang/akkoma",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Akkoma scores 80 out of 100 (grade B) on the social networks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/social-networks/akkoma/",
      "markdown": "https://privacyratings.com/social-networks/akkoma/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://akkoma.dev/AkkomaGang/akkoma/src/branch/develop/COPYING",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://akkoma.dev/AkkomaGang/akkoma",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://akkoma.social",
          "note": "Funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:54.894Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bluesky",
      "category": "social-networks",
      "name": "Bluesky",
      "description": "Microblogging social network built on the open AT Protocol, run by Bluesky Social PBC, with custom feeds, composable moderation and account portability.",
      "website": "https://bsky.app",
      "source": "https://github.com/bluesky-social/social-app",
      "license": "MIT",
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Bluesky scores 50 out of 100 (grade D) on the social networks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/social-networks/bluesky/",
      "markdown": "https://privacyratings.com/social-networks/bluesky/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bluesky-social/social-app/blob/main/LICENSE",
          "note": "The app is MIT licensed and the AT Protocol server software is dual MIT and Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/xyz.blueskyweb.app/latest/",
          "note": "The Android app includes Sentry, the privacy policy allows third-party analytics providers, and the bsky.social site loads Google Tag Manager."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://bsky.social/about/support/privacy-policy",
          "note": "No ads, and the privacy policy states personal data is not sold or shared for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:54.813Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "diaspora",
      "category": "social-networks",
      "name": "diaspora*",
      "description": "Decentralized social network made of independently run servers called pods, with aspects to control who sees each post.",
      "website": "https://diasporafoundation.org",
      "source": "https://github.com/diaspora/diaspora",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "diaspora* scores 80 out of 100 (grade B) on the social networks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/social-networks/diaspora/",
      "markdown": "https://privacyratings.com/social-networks/diaspora/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/diaspora/diaspora/blob/develop/COPYRIGHT",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/diaspora/diaspora",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://diasporafoundation.org",
          "note": "Community-developed free software, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:18.043Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "discourse",
      "category": "social-networks",
      "name": "Discourse",
      "description": "Open source, self-hostable discussion platform that works as a forum, mailing list or long-form chat room. A hosted version is sold by its developer.",
      "website": "https://www.discourse.org",
      "source": "https://github.com/discourse/discourse",
      "license": "GPL-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Discourse scores 30 out of 100 (grade F) on the social networks criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/social-networks/discourse/",
      "markdown": "https://privacyratings.com/social-networks/discourse/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/discourse/discourse/blob/main/LICENSE.txt",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Tag Manager and HubSpot (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.discourse.org/privacy",
          "note": "Funded by hosting plans, but the privacy policy allows sharing personal information with data brokers and using it for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "HubSpot",
            "host": "js-eu1.hsforms.net",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:12.307Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "facebook",
      "category": "social-networks",
      "name": "Facebook",
      "description": "Social network from Meta for sharing posts, photos and videos with friends, groups and pages, with Marketplace and Messenger chat.",
      "website": "https://www.facebook.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Facebook scores 0 out of 100 (grade F) on the social networks criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/social-networks/facebook/",
      "markdown": "https://privacyratings.com/social-networks/facebook/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.facebook.katana/latest/",
          "note": "The Android app includes Facebook Analytics, Facebook Ads, Google Analytics and Mapbox, and activity tracking for ads cannot be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.facebook.com/about/ads",
          "note": "Funded by targeted advertising based on user activity."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:59:55.291Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "friendica",
      "category": "social-networks",
      "name": "Friendica",
      "description": "Federated, self-hostable social network that connects over ActivityPub, diaspora* and other protocols, with per-post access lists and RSS import.",
      "website": "https://friendi.ca",
      "source": "https://github.com/friendica/friendica",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Friendica scores 80 out of 100 (grade B) on the social networks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/social-networks/friendica/",
      "markdown": "https://privacyratings.com/social-networks/friendica/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/friendica/friendica/blob/develop/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/friendica/friendica",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://friendi.ca/resources/contribute/",
          "note": "Developed by volunteers, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:24.549Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gotosocial",
      "category": "social-networks",
      "name": "GoToSocial",
      "description": "Lightweight, self-hostable ActivityPub server written in Go, used with Mastodon-compatible client apps.",
      "website": "https://gotosocial.org",
      "source": "https://codeberg.org/superseriousbusiness/gotosocial",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "GoToSocial scores 80 out of 100 (grade B) on the social networks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/social-networks/gotosocial/",
      "markdown": "https://privacyratings.com/social-networks/gotosocial/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/superseriousbusiness/gotosocial/src/branch/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gotosocial.org",
          "note": "The project states users are not tracked, and the software has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/gotosocial",
          "note": "Funded by donations and grants, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:55.737Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "instagram",
      "category": "social-networks",
      "name": "Instagram",
      "description": "Photo and video sharing social network from Meta, with Stories, Reels short videos and direct messages.",
      "website": "https://www.instagram.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Instagram scores 0 out of 100 (grade F) on the social networks criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/social-networks/instagram/",
      "markdown": "https://privacyratings.com/social-networks/instagram/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.instagram.android/latest/",
          "note": "The Android app includes Google Analytics and Facebook SDKs, and activity tracking for ads cannot be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://privacycenter.instagram.com/policy/",
          "note": "Funded by targeted advertising based on user activity."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:55.615Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "lemmy",
      "category": "social-networks",
      "name": "Lemmy",
      "description": "Federated link aggregator and discussion platform built on ActivityPub, organized into communities hosted on independent servers.",
      "website": "https://join-lemmy.org",
      "source": "https://github.com/LemmyNet/lemmy",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Lemmy scores 80 out of 100 (grade B) on the social networks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/social-networks/lemmy/",
      "markdown": "https://privacyratings.com/social-networks/lemmy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/LemmyNet/lemmy/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://join-lemmy.org/donate",
          "note": "The project states Lemmy has no advertising or tracking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://join-lemmy.org/donate",
          "note": "Funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:12.851Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "linkedin",
      "category": "social-networks",
      "name": "LinkedIn",
      "description": "Professional social network owned by Microsoft for profiles, job listings, recruiting, messaging and business content.",
      "website": "https://www.linkedin.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios",
        "windows"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "LinkedIn scores 0 out of 100 (grade F) on the social networks criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/social-networks/linkedin/",
      "markdown": "https://privacyratings.com/social-networks/linkedin/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.linkedin.android/latest/",
          "note": "The Android app includes Facebook Analytics, App Center Analytics and Qualtrics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.linkedin.com/legal/privacy-policy",
          "note": "Funded partly by targeted advertising, which uses data from on and off LinkedIn."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:55.315Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mastodon",
      "category": "social-networks",
      "name": "Mastodon",
      "description": "Open source, decentralized microblogging platform built on ActivityPub, run as a network of independent servers with chronological timelines.",
      "website": "https://joinmastodon.org",
      "source": "https://github.com/mastodon/mastodon",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Mastodon scores 80 out of 100 (grade B) on the social networks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/social-networks/mastodon/",
      "markdown": "https://privacyratings.com/social-networks/mastodon/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mastodon/mastodon/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://joinmastodon.org",
          "note": "No third-party trackers, and the software has no telemetry. The joinmastodon.org website's Simple Analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://joinmastodon.org/sponsors",
          "note": "Funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Simple Analytics",
            "host": "scripts.simpleanalyticscdn.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:12.524Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mbin",
      "category": "social-networks",
      "name": "Mbin",
      "description": "Federated, self-hostable link aggregator, discussion and microblogging platform built on ActivityPub, forked from /kbin.",
      "website": "https://joinmbin.org",
      "source": "https://github.com/MbinOrg/mbin",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Mbin scores 80 out of 100 (grade B) on the social networks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/social-networks/mbin/",
      "markdown": "https://privacyratings.com/social-networks/mbin/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/MbinOrg/mbin/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/MbinOrg/mbin",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/MbinOrg/mbin",
          "note": "Volunteer-developed community project, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:55.908Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "misskey",
      "category": "social-networks",
      "name": "Misskey",
      "description": "Federated, self-hostable microblogging platform built on ActivityPub, with emoji reactions, customizable web interface, drive storage and channels.",
      "website": "https://misskey-hub.net",
      "source": "https://github.com/misskey-dev/misskey",
      "license": "AGPL-3.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Misskey scores 80 out of 100 (grade B) on the social networks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/social-networks/misskey/",
      "markdown": "https://privacyratings.com/social-networks/misskey/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/misskey-dev/misskey/blob/develop/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/misskey-dev/misskey",
          "note": "No telemetry or analytics by default. Server admins can optionally enable Google Analytics or Sentry for their own server."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://misskey-hub.net/en/docs/donate/",
          "note": "The project is funded by donations. Server admins can choose to show their own ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:59:55.445Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "nostr",
      "category": "social-networks",
      "name": "nostr",
      "description": "Nostr (Notes and Other Stuff Transmitted by Relays) is an open protocol for publishing signed messages through independent relays, with identity based on public keys. Many independent clients and relays implement it.",
      "website": "https://github.com/nostr-protocol/nostr",
      "source": "https://github.com/nostr-protocol/nips",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "A",
      "score": 100,
      "coverage": 100,
      "summary": "nostr scores 100 out of 100 (grade A) on the social networks criteria. It meets 1 of 1 criteria: open source.",
      "url": "https://privacyratings.com/social-networks/nostr/",
      "markdown": "https://privacyratings.com/social-networks/nostr/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/nostr-protocol/nips",
          "note": "Open protocol whose specifications (NIPs) are public domain. Reference clients and relays are separate projects."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "n/a",
          "evidence": null,
          "note": "A protocol specification, not an app or service. Tracking depends on the client and relay each user chooses."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "A protocol specification with no funding model of its own. Ads depend on the client and relay each user chooses."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "A protocol specification implemented by many independent clients and relays, not a single product that could be audited."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:12.299Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "piefed",
      "category": "social-networks",
      "name": "PieFed",
      "description": "Federated, self-hostable link aggregator and forum built on ActivityPub, compatible with Lemmy communities.",
      "website": "https://join.piefed.social",
      "source": "https://codeberg.org/rimu/pyfedi",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "PieFed scores 80 out of 100 (grade B) on the social networks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/social-networks/piefed/",
      "markdown": "https://privacyratings.com/social-networks/piefed/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/rimu/pyfedi/src/branch/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://join.piefed.social",
          "note": "The project states PieFed has no tracking. Error reporting to Sentry is only used when a server admin configures it."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://join.piefed.social",
          "note": "The project states PieFed has no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:59:55.809Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "pixelfed",
      "category": "social-networks",
      "name": "Pixelfed",
      "description": "Federated, self-hostable photo sharing platform built on ActivityPub, with chronological feeds, albums, stories and no ads.",
      "website": "https://pixelfed.org",
      "source": "https://github.com/pixelfed/pixelfed",
      "license": "AGPL-3.0",
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Pixelfed scores 80 out of 100 (grade B) on the social networks criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/social-networks/pixelfed/",
      "markdown": "https://privacyratings.com/social-networks/pixelfed/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pixelfed/pixelfed/blob/dev/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.pixelfed/latest/",
          "note": "The Android app has no trackers, and the server software has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/pixelfed",
          "note": "Funded by donations and grants, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T06:59:56.002Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "reddit",
      "category": "social-networks",
      "name": "Reddit",
      "description": "Discussion site organized into topic communities called subreddits, where posts and comments are ranked by user votes.",
      "website": "https://www.reddit.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Reddit scores 0 out of 100 (grade F) on the social networks criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/social-networks/reddit/",
      "markdown": "https://privacyratings.com/social-networks/reddit/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.reddit.frontpage/latest/",
          "note": "The Android app includes AppsFlyer, Crashlytics and Firebase Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.business.reddit.com/",
          "note": "Funded by advertising, including ads targeted on user activity."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:59:55.874Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "threads",
      "category": "social-networks",
      "name": "Threads",
      "description": "Text-based microblogging app from Meta, linked to Instagram accounts, with optional sharing to the fediverse over ActivityPub.",
      "website": "https://www.threads.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Threads scores 0 out of 100 (grade F) on the social networks criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/social-networks/threads/",
      "markdown": "https://privacyratings.com/social-networks/threads/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.instagram.barcelona/latest/",
          "note": "The Android app includes Google Analytics and Facebook SDKs, and activity tracking for ads cannot be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://privacycenter.instagram.com/policy/",
          "note": "Funded by targeted advertising under the Meta Privacy Policy."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:56.129Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "tiktok",
      "category": "social-networks",
      "name": "TikTok",
      "description": "Short-form video platform owned by ByteDance, with an algorithmic For You feed, live streams, messaging and shopping features.",
      "website": "https://www.tiktok.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "SG",
        "name": "Singapore",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "TikTok scores 0 out of 100 (grade F) on the social networks criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in Singapore: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/social-networks/tiktok/",
      "markdown": "https://privacyratings.com/social-networks/tiktok/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.zhiliaoapp.musically/latest/",
          "note": "The Android app includes AppsFlyer, Facebook Analytics, Firebase Analytics and Pangle."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.tiktok.com/legal/page/row/privacy-policy/en",
          "note": "Funded by targeted advertising based on user activity."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:57.503Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "x",
      "category": "social-networks",
      "name": "X",
      "description": "Microblogging social network, formerly Twitter, for short public posts, replies, reposts and direct messages.",
      "website": "https://x.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "X scores 0 out of 100 (grade F) on the social networks criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/social-networks/x/",
      "markdown": "https://privacyratings.com/social-networks/x/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. Only parts of the recommendation algorithm have been published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.twitter.android/latest/",
          "note": "The Android app includes Google AdMob, Crashlytics and Firebase Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://x.com/en/privacy",
          "note": "Funded largely by targeted advertising based on user activity and data from ad partners."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:56.222Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "dailymotion",
      "category": "video-platforms",
      "name": "Dailymotion",
      "description": "Ad-supported video sharing platform based in France, with a vertical video feed and an embeddable video player.",
      "website": "https://www.dailymotion.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Dailymotion scores 0 out of 100 (grade F) on the video platforms criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/video-platforms/dailymotion/",
      "markdown": "https://privacyratings.com/video-platforms/dailymotion/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.dailymotion.dailymotion/latest/",
          "note": "The Android app includes Adjust, Amplitude, AppsFlyer, ComScore, Google AdMob and Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://legal.dailymotion.com/en/privacy-policy/",
          "note": "Funded by advertising, including targeted ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:56.462Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "odysee",
      "category": "video-platforms",
      "name": "Odysee",
      "description": "Video sharing platform built on the LBRY protocol, with creator tips and memberships paid in credits or money.",
      "website": "https://odysee.com",
      "source": "https://github.com/OdyseeTeam/odysee-frontend",
      "license": "MIT",
      "platforms": [
        "web",
        "android"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 15,
      "coverage": 100,
      "summary": "Odysee scores 15 out of 100 (grade F) on the video platforms criteria. It partly meets open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/video-platforms/odysee/",
      "markdown": "https://privacyratings.com/video-platforms/odysee/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/OdyseeTeam/odysee-frontend/blob/master/LICENSE",
          "note": "The web app is MIT licensed, but not all server components of the hosted service are published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://odysee.com/$/privacypolicy",
          "note": "The privacy policy states the site uses Google Analytics and Google AdSense."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://odysee.com/$/privacypolicy",
          "note": "Shows Google AdSense ads, with an ad-free paid plan."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:56.336Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "owncast",
      "category": "video-platforms",
      "name": "Owncast",
      "description": "Self-hosted live streaming server with built-in chat, compatible with standard broadcasting software and the fediverse.",
      "website": "https://owncast.online",
      "source": "https://github.com/owncast/owncast",
      "license": "MIT",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Owncast scores 80 out of 100 (grade B) on the video platforms criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/video-platforms/owncast/",
      "markdown": "https://privacyratings.com/video-platforms/owncast/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/owncast/owncast/blob/develop/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://owncast.online",
          "note": "The project states Owncast has no tracking, and the software has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/owncast",
          "note": "Funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:56.451Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "peertube",
      "category": "video-platforms",
      "name": "PeerTube",
      "description": "Federated, self-hostable video platform built on ActivityPub, with peer-to-peer streaming to reduce server load. Videos from any PeerTube server can be watched from any other.",
      "website": "https://joinpeertube.org",
      "source": "https://github.com/Chocobozzz/PeerTube",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "PeerTube scores 65 out of 100 (grade C) on the video platforms criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/video-platforms/peertube/",
      "markdown": "https://privacyratings.com/video-platforms/peertube/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Chocobozzz/PeerTube/blob/develop/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://framasoft.org/en/legals/",
          "note": "The PeerTube software has no telemetry, but the joinpeertube.org website uses Framasoft's self-hosted Matomo analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://framasoft.org/en/association/",
          "note": "Developed by the non-profit Framasoft, funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:13.421Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "twitch",
      "category": "video-platforms",
      "name": "Twitch",
      "description": "Live streaming platform owned by Amazon, focused on gaming, with chat, subscriptions and video on demand.",
      "website": "https://www.twitch.tv",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Twitch scores 0 out of 100 (grade F) on the video platforms criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/video-platforms/twitch/",
      "markdown": "https://privacyratings.com/video-platforms/twitch/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/tv.twitch.android.app/latest/",
          "note": "The Android app includes Branch, ComScore, Crashlytics and Sentry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://legal.twitch.com/legal/privacy-notice/",
          "note": "Funded partly by advertising, including targeted ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:56.790Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vimeo",
      "category": "video-platforms",
      "name": "Vimeo",
      "description": "Video hosting platform for creators and businesses, with ad-free playback, privacy controls, live streaming and video tools sold by subscription.",
      "website": "https://vimeo.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Vimeo scores 10 out of 100 (grade F) on the video platforms criteria. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/video-platforms/vimeo/",
      "markdown": "https://privacyratings.com/video-platforms/vimeo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.vimeo.android.videoapp/latest/",
          "note": "The Android app includes AppsFlyer, Firebase Analytics, Pendo and Swrve."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://vimeo.com/legal/privacy/us-state-notice",
          "note": "Funded by subscriptions with no ads on videos, but the privacy notice discloses sale or sharing of data with third parties for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:56.666Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "youtube",
      "category": "video-platforms",
      "name": "YouTube",
      "description": "Video sharing platform owned by Google for uploading, watching and live streaming videos, with an optional paid Premium plan.",
      "website": "https://www.youtube.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "YouTube scores 0 out of 100 (grade F) on the video platforms criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/video-platforms/youtube/",
      "markdown": "https://privacyratings.com/video-platforms/youtube/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.google.android.youtube/latest/",
          "note": "The Android app includes Firebase Analytics, and watch and search history is used for recommendations and ads unless turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Funded mainly by targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:56.771Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "amazon-music",
      "category": "music-streaming",
      "name": "Amazon Music",
      "description": "Music and podcast streaming service from Amazon, with an ad-supported free tier, a catalog included with Prime and the paid Amazon Music Unlimited plan.",
      "website": "https://music.amazon.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 28,
      "coverage": 100,
      "summary": "Amazon Music scores 28 out of 100 (grade F) on the music streaming criteria. It meets 2 of 8 criteria: transparency report and tells users about requests. It partly meets TLS configuration and security headers. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/music-streaming/amazon-music/",
      "markdown": "https://privacyratings.com/music-streaming/amazon-music/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.amazon.mp3/latest/",
          "note": "The Android app includes Amazon Advertisement, Branch, Bugsnag, Pangle and Snowplow."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.amazon.com/gp/help/customer/display.html?nodeId=GX7NJQ4ZB8MHFRNJ",
          "note": "The free tier is funded by ads, and Amazon uses personal data for interest-based advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.amazon.com/gp/help/customer/display.html?nodeId=GYSDRGWQ2C2CRYEF",
          "note": "Amazon publishes information request reports for its consumer services every six months."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.amazon.com/gp/help/customer/display.html?nodeId=GYSDRGWQ2C2CRYEF",
          "note": "Amazon notifies customers before disclosing content information, unless prohibited or there is clear indication of illegal conduct."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=music.amazon.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=music.amazon.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:56.997Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "apple-music",
      "category": "music-streaming",
      "name": "Apple Music",
      "description": "Subscription music streaming service from Apple, with lossless and spatial audio, radio stations, lyrics and a classical music app.",
      "website": "https://www.apple.com/apple-music/",
      "license": null,
      "platforms": [
        "macos",
        "ios",
        "windows",
        "android",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 41,
      "coverage": 100,
      "summary": "Apple Music scores 41 out of 100 (grade D) on the music streaming criteria. It meets 3 of 8 criteria: no ads or data sales, transparency report and tells users about requests. It partly meets TLS configuration and security headers. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A- and Mozilla HTTP Observatory grade A-.",
      "url": "https://privacyratings.com/music-streaming/apple-music/",
      "markdown": "https://privacyratings.com/music-streaming/apple-music/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.apple.android.music/latest/",
          "note": "The Android app includes Crashlytics and Firebase Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/apple-music/",
          "note": "Funded by subscriptions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/transparency/",
          "note": "Apple publishes government request counts by country every six months."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/law-enforcement-guidelines-us.pdf",
          "note": "Apple notifies customers when their account information is sought, unless notice is prohibited."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=music.apple.com&hideResults=on",
          "note": "Grade A-"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=music.apple.com",
          "note": "Grade A- (85/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A-",
        "observatory": "A-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:57.047Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bandcamp",
      "category": "music-streaming",
      "name": "Bandcamp",
      "description": "Online music store and community where fans buy and stream music and merchandise directly from artists and labels.",
      "website": "https://bandcamp.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 28,
      "coverage": 100,
      "summary": "Bandcamp scores 28 out of 100 (grade F) on the music streaming criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It partly meets security headers. It does not meet open source, no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/music-streaming/bandcamp/",
      "markdown": "https://privacyratings.com/music-streaming/bandcamp/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://bandcamp.com/privacy",
          "note": "The privacy policy states the site uses Google Analytics, and the Android app includes Crashlytics and Firebase Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://bandcamp.com/privacy",
          "note": "Funded by a share of sales, with no ads, and the privacy policy states personal data is not rented or sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=bandcamp.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=bandcamp.com",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:57.058Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "deezer",
      "category": "music-streaming",
      "name": "Deezer",
      "description": "Music, podcast and radio streaming service based in France, with an ad-supported free tier and paid plans.",
      "website": "https://www.deezer.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 13,
      "coverage": 100,
      "summary": "Deezer scores 13 out of 100 (grade F) on the music streaming criteria. It meets 1 of 8 criteria: TLS configuration. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests and security headers. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/music-streaming/deezer/",
      "markdown": "https://privacyratings.com/music-streaming/deezer/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/deezer.android.app/latest/",
          "note": "The Android app includes Adjust, Google AdMob, Google Analytics, Firebase Analytics and Segment."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.deezer.com/legal/personal-datas",
          "note": "The free tier shows targeted ads, and personal data is used to build ad profiles."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.deezer.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.deezer.com",
          "note": "Grade F (10/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:22:31.332Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "funkwhale",
      "category": "music-streaming",
      "name": "Funkwhale",
      "description": "Federated, self-hostable platform for streaming and sharing music and podcasts, built on ActivityPub and compatible with Subsonic apps.",
      "website": "https://www.funkwhale.audio",
      "source": "https://dev.funkwhale.audio/funkwhale/funkwhale",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Funkwhale scores 80 out of 100 (grade B) on the music streaming criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/music-streaming/funkwhale/",
      "markdown": "https://privacyratings.com/music-streaming/funkwhale/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://dev.funkwhale.audio/funkwhale/funkwhale/-/blob/develop/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.funkwhale.audio/",
          "note": "The project states Funkwhale has no third-party analytics and no tracking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.funkwhale.audio/",
          "note": "Maintained by the non-profit Funkwhale Collective, funded by donations and grants, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:58.242Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "qobuz",
      "category": "music-streaming",
      "name": "Qobuz",
      "description": "Subscription music streaming and download store based in France, focused on hi-res audio, with album notes and editorial content.",
      "website": "https://www.qobuz.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 14,
      "coverage": 100,
      "summary": "Qobuz scores 14 out of 100 (grade F) on the music streaming criteria. It meets 1 of 7 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/music-streaming/qobuz/",
      "markdown": "https://privacyratings.com/music-streaming/qobuz/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.qobuz.music/latest/",
          "note": "The Android app includes Crashlytics, Firebase Analytics and Facebook Login, and the website loads New Relic and Google tags."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.qobuz.com/us-en/discover/legals/privacy",
          "note": "Funded by subscriptions and purchases, with no ads, and the privacy policy states data is used only by the company and its service providers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=play.qobuz.com",
          "note": "Grade D (35/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:23:20.375Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "soundcloud",
      "category": "music-streaming",
      "name": "SoundCloud",
      "description": "Audio sharing and music streaming platform where artists upload tracks, with an ad-supported free tier and paid Go plans.",
      "website": "https://soundcloud.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 13,
      "coverage": 100,
      "summary": "SoundCloud scores 13 out of 100 (grade F) on the music streaming criteria. It meets 1 of 8 criteria: TLS configuration. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests and security headers. It is based in Germany: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/music-streaming/soundcloud/",
      "markdown": "https://privacyratings.com/music-streaming/soundcloud/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.soundcloud.android/latest/",
          "note": "The Android app includes AppsFlyer, ComScore, Facebook Ads, Google AdMob, Firebase Analytics and Segment."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://soundcloud.com/pages/privacy",
          "note": "Funded partly by ads, and personal data is used for personalized advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=soundcloud.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=soundcloud.com",
          "note": "Grade C (55/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Comscore",
            "host": "sb.scorecardresearch.com",
            "effect": "no"
          },
          {
            "name": "Google Analytics",
            "host": "ssl.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "OneTrust",
            "host": "cdn.cookielaw.org",
            "effect": "none"
          },
          {
            "name": "Quantcast",
            "host": "secure.quantserve.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:57.462Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "spotify",
      "category": "music-streaming",
      "name": "Spotify",
      "description": "Music, podcast and audiobook streaming service with an ad-supported free tier and paid Premium plans.",
      "website": "https://open.spotify.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "SE",
        "name": "Sweden",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 16,
      "coverage": 100,
      "summary": "Spotify scores 16 out of 100 (grade F) on the music streaming criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets security headers. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report and tells users about requests. It is based in Sweden: Fourteen Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/music-streaming/spotify/",
      "markdown": "https://privacyratings.com/music-streaming/spotify/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.spotify.music/latest/",
          "note": "The Android app includes Branch, ComScore, Crashlytics and Firebase Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.spotify.com/us/legal/privacy-policy/",
          "note": "The free tier is funded by ads, and the privacy policy describes using personal data to tailor advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=open.spotify.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=open.spotify.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:20:55.964Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "tidal",
      "category": "music-streaming",
      "name": "Tidal",
      "description": "Subscription music streaming service with lossless and hi-res audio, music videos and editorial playlists, owned by Block.",
      "website": "https://tidal.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "NO",
        "name": "Norway",
        "eyes": "Nine Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 19,
      "coverage": 100,
      "summary": "Tidal scores 19 out of 100 (grade F) on the music streaming criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in Norway: Nine Eyes member; EEA member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/music-streaming/tidal/",
      "markdown": "https://privacyratings.com/music-streaming/tidal/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.aspiro.tidal/latest/",
          "note": "The Android app includes Crashlytics, and the privacy notice describes third-party analytics providers and ad partners."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://tidal.com/privacy",
          "note": "Funded by subscriptions with no ads in the app, but the privacy notice describes sharing data with ad partners for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=tidal.com&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=tidal.com",
          "note": "Grade C (50/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:59:57.349Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "youtube-music",
      "category": "music-streaming",
      "name": "YouTube Music",
      "description": "Music streaming service from Google, drawing on YouTube's catalog of songs, videos and live performances, with an ad-supported free tier and a paid Premium plan.",
      "website": "https://music.youtube.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "YouTube Music scores 25 out of 100 (grade F) on the music streaming criteria. It meets 2 of 7 criteria: transparency report and tells users about requests. It partly meets security headers. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/music-streaming/youtube-music/",
      "markdown": "https://privacyratings.com/music-streaming/youtube-music/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.google.android.apps.youtube.music/latest/",
          "note": "The Android app includes Firebase Analytics, and listening history is used for recommendations and ads unless turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "The free tier is funded by targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://transparencyreport.google.com/user-data/overview",
          "note": "Google publishes government request counts and outcomes every six months."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://policies.google.com/terms/information-requests",
          "note": "Google emails users before disclosing their data to government agencies, unless legally prohibited or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "pending",
          "evidence": null,
          "note": "Could not test: Timed out"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=music.youtube.com",
          "note": "Grade B (75/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:19:54.133Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bear-blog",
      "category": "blogging",
      "name": "Bear Blog",
      "description": "Minimal hosted blogging platform with small, fast pages, no third-party trackers and built-in first-party analytics.",
      "website": "https://bearblog.dev",
      "source": "https://github.com/HermanMartinus/bearblog",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 59,
      "coverage": 100,
      "summary": "Bear Blog scores 59 out of 100 (grade D) on the blogging criteria. It meets 3 of 8 criteria: open source, no trackers or telemetry and no ads or data sales. It partly meets TLS configuration and security headers. It does not meet independent audit, transparency report and tells users about requests. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/blogging/bear-blog/",
      "markdown": "https://privacyratings.com/blogging/bear-blog/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/HermanMartinus/bearblog/blob/master/LICENSE.md",
          "note": "All code is public, including the code that runs bearblog.dev, under a custom source-available license that forbids running a competing hosted service and is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://docs.bearblog.dev/analytics/",
          "note": "Built-in analytics are first-party with no third-party trackers, and Google Analytics is not supported."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://docs.bearblog.dev/privacy-policy/",
          "note": "No ads, and the privacy policy states collected information is never shared with or sold to other organizations for commercial purposes."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=bearblog.dev&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=bearblog.dev",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:03:55.485Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "blogger",
      "category": "blogging",
      "name": "Blogger",
      "description": "Free hosted blogging service from Google, with blogs on blogspot.com or a custom domain, tied to a Google account.",
      "website": "https://www.blogger.com",
      "license": null,
      "platforms": [
        "web",
        "android"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Blogger scores 25 out of 100 (grade F) on the blogging criteria. It meets 2 of 8 criteria: transparency report and tells users about requests. It partly meets TLS configuration. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade F.",
      "url": "https://privacyratings.com/blogging/blogger/",
      "markdown": "https://privacyratings.com/blogging/blogger/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.google.android.apps.blogger/latest/",
          "note": "The Android app contains Google Firebase Analytics, and Google uses Blogger activity for its own analytics and advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Google is funded by advertising and its privacy policy covers using data to show personalized ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://transparencyreport.google.com/user-data/overview",
          "note": "Google publishes twice-yearly counts of government requests for user data and how often data is disclosed."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://policies.google.com/terms/information-requests",
          "note": "Google emails the user before disclosing data to a government agency unless legally prohibited or in emergencies."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.blogger.com&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.blogger.com",
          "note": "Grade F (0/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "F",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:20:56.048Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ghost",
      "category": "blogging",
      "name": "Ghost",
      "description": "Open source publishing platform for blogs and newsletters with paid memberships, run by the non-profit Ghost Foundation. Available as hosted Ghost(Pro) or self-hosted.",
      "website": "https://ghost.org",
      "source": "https://github.com/TryGhost/Ghost",
      "license": "MIT",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "SG",
        "name": "Singapore",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 47,
      "coverage": 100,
      "summary": "Ghost scores 47 out of 100 (grade D) on the blogging criteria. It meets 3 of 8 criteria: open source, no ads or data sales and TLS configuration. It partly meets security headers. It does not meet no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in Singapore: Not in the Five, Nine or Fourteen Eyes. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
      "url": "https://privacyratings.com/blogging/ghost/",
      "markdown": "https://privacyratings.com/blogging/ghost/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/TryGhost/Ghost/blob/main/LICENSE",
          "note": "MIT. Ghost(Pro) runs the same open source software, which can also be self-hosted."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://ghost.org/privacy/",
          "note": "The ghost.org website loads Ahrefs and Dub analytics and the FirstPromoter affiliate tracking script."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ghost.org/about/",
          "note": "Non-profit funded by Ghost(Pro) subscriptions, and the privacy policy states it does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=account.ghost.org&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=account.ghost.org",
          "note": "Grade B (70/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:57.819Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mataroa",
      "category": "blogging",
      "name": "Mataroa",
      "description": "Minimal hosted blogging platform with Markdown posts, RSS and email subscriptions, and full export. Operated by a UK company, with public revenue and cost figures.",
      "website": "https://mataroa.blog",
      "source": "https://github.com/mataroablog/mataroa",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "GB",
        "name": "United Kingdom",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": true,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 63,
      "coverage": 100,
      "summary": "Mataroa scores 63 out of 100 (grade C) on the blogging criteria. It meets 4 of 8 criteria: open source, no trackers or telemetry, no ads or data sales and TLS configuration. It does not meet independent audit, transparency report, tells users about requests and security headers. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C.",
      "url": "https://privacyratings.com/blogging/mataroa/",
      "markdown": "https://privacyratings.com/blogging/mataroa/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mataroablog/mataroa/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://mataroa.blog/about/methodology/",
          "note": "The methodology page commits to no tracking and no cookies for analytics, advertising or third-party services."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://mataroa.blog/about/methodology/",
          "note": "Funded by premium subscriptions. The methodology page commits to no ads and never selling user data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=mataroa.blog&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=mataroa.blog",
          "note": "Grade C (55/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "C",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:03:55.542Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "medium",
      "category": "blogging",
      "name": "Medium",
      "description": "Hosted publishing platform for articles and blogs, with a paid membership that unlocks member-only stories and pays writers.",
      "website": "https://medium.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 41,
      "coverage": 100,
      "summary": "Medium scores 41 out of 100 (grade D) on the blogging criteria. It meets 3 of 8 criteria: no ads or data sales, tells users about requests and TLS configuration. It partly meets transparency report and security headers. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
      "url": "https://privacyratings.com/blogging/medium/",
      "markdown": "https://privacyratings.com/blogging/medium/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.medium.reader/latest/",
          "note": "The Android app contains Google Analytics, Google Crashlytics and Facebook Login, and the privacy policy names third-party analytics providers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://medium.com/membership",
          "note": "Member-supported with no ads, and the privacy policy states Medium does not sell personal information."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://policy.medium.com/medium-privacy-policy-f03bf92035c9",
          "note": "The privacy policy describes how legal requests are handled, but no request counts are published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://policy.medium.com/medium-privacy-policy-f03bf92035c9",
          "note": "The privacy policy promises notice before disclosing data in response to legal process unless prohibited or it would endanger others."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=medium.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "partial",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=medium.com",
          "note": "Grade B+ (80/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B+",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:57.715Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "micro-blog",
      "category": "blogging",
      "name": "Micro.blog",
      "description": "Paid blog hosting service and social network for short and long posts, with custom domains and cross-posting to Mastodon, Bluesky and other networks over ActivityPub.",
      "website": "https://micro.blog",
      "license": null,
      "platforms": [
        "web",
        "macos",
        "ios",
        "android"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 34,
      "coverage": 100,
      "summary": "Micro.blog scores 34 out of 100 (grade F) on the blogging criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It partly meets open source. It does not meet no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/blogging/micro-blog/",
      "markdown": "https://privacyratings.com/blogging/micro-blog/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/microdotblog/microblog-mac/blob/master/LICENSE",
          "note": "The macOS and iOS apps are MIT-licensed, but the Micro.blog service is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/blog.micro.android/latest/",
          "note": "The Android app contains Google Firebase Analytics. The website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://help.micro.blog/t/privacy-policy/114",
          "note": "Funded by subscriptions with no ads, and the privacy policy states data is never sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=micro.blog&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=micro.blog",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:57.784Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "movim",
      "category": "blogging",
      "name": "Movim",
      "description": "Self-hostable web client for XMPP that combines chat, group chat, video calls, personal blogs and communities, with public instances available.",
      "website": "https://movim.eu",
      "source": "https://github.com/movim/movim",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 63,
      "coverage": 100,
      "summary": "Movim scores 63 out of 100 (grade C) on the blogging criteria. It meets 4 of 8 criteria: open source, no trackers or telemetry, no ads or data sales and TLS configuration. It does not meet independent audit, transparency report, tells users about requests and security headers. It is based in France: Nine Eyes member; EU member (GDPR). Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/blogging/movim/",
      "markdown": "https://privacyratings.com/blogging/movim/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/movim/movim/blob/master/COPYING.txt",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/movim/movim",
          "note": "No telemetry or analytics in the source code, and the project website loads no third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://movim.eu",
          "note": "Funded by donations, sponsors and grants, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=movim.eu&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=movim.eu",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:03:55.989Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "pico",
      "category": "blogging",
      "name": "Pico",
      "description": "Hosted services managed over SSH, including a blogging platform (Prose), static site hosting (Pages), pipes and tunnels. Accounts use SSH public keys instead of passwords or email.",
      "website": "https://pico.sh",
      "source": "https://github.com/picosh/pico",
      "license": "MIT",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 63,
      "coverage": 100,
      "summary": "Pico scores 63 out of 100 (grade C) on the blogging criteria. It meets 4 of 8 criteria: open source, no trackers or telemetry, no ads or data sales and TLS configuration. It does not meet independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
      "url": "https://privacyratings.com/blogging/pico/",
      "markdown": "https://privacyratings.com/blogging/pico/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/picosh/pico/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://pico.sh/privacy",
          "note": "No browser-based tracking or cookies. Usage statistics are collected by first-party software and anonymized."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://pico.sh/plus",
          "note": "Funded by paid pico+ memberships. The privacy policy states user data is never shared with third parties."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy is published."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=pico.sh&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=pico.sh",
          "note": "Grade D (30/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:03:56.035Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "telegraph",
      "category": "blogging",
      "name": "Telegraph",
      "description": "Minimal publishing tool from Telegram for posting formatted articles with images, without an account. Pages are public to anyone with the link.",
      "website": "https://telegra.ph",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "VG",
        "name": "British Virgin Islands",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 28,
      "coverage": 100,
      "summary": "Telegraph scores 28 out of 100 (grade F) on the blogging criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no trackers or telemetry and no ads or data sales. It does not meet open source, independent audit, transparency report, tells users about requests and security headers. It is based in the British Virgin Islands: Not in the Five, Nine or Fourteen Eyes. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B-.",
      "url": "https://privacyratings.com/blogging/telegraph/",
      "markdown": "https://privacyratings.com/blogging/telegraph/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://telegra.ph/",
          "note": "No third-party trackers are loaded, but every page loads a Telegram sync script from t.me, and no privacy policy covers Telegraph."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://telegram.org/privacy",
          "note": "Telegraph pages show no ads, but the service is run by Telegram, which is partly funded by contextual ads in its messenger."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No transparency report or government request policy covers Telegraph."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=telegra.ph&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=telegra.ph",
          "note": "Grade B- (65/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "B-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:03:56.235Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "wordpress-com",
      "category": "blogging",
      "name": "WordPress.com",
      "description": "Hosted website and blogging platform run by Automattic, built on the open source WordPress software, with web, Android and iOS apps.",
      "website": "https://wordpress.com",
      "source": "https://github.com/Automattic/wp-calypso",
      "license": "GPL-2.0",
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 41,
      "coverage": 100,
      "summary": "WordPress.com scores 41 out of 100 (grade D) on the blogging criteria. It meets 3 of 8 criteria: transparency report, tells users about requests and TLS configuration. It partly meets open source. It does not meet no trackers or telemetry, no ads or data sales, independent audit and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/blogging/wordpress-com/",
      "markdown": "https://privacyratings.com/blogging/wordpress-com/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://raw.githubusercontent.com/Automattic/wp-calypso/trunk/LICENSE.md",
          "note": "The Calypso web interface and mobile apps are GPL-2.0, but the WordPress.com hosting platform is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://automattic.com/privacy/",
          "note": "The website loads Google Analytics, Hotjar and the Facebook pixel, and the privacy policy describes sharing data with advertising and analytics vendors."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://wordpress.com/support/no-ads/",
          "note": "Free sites show ads from advertising partners, and public site content is shared with third parties, including for AI training, unless the owner opts out."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://transparency.automattic.com/transparency-report/wordpress-com-transparency-report-jan-jun-2026/",
          "note": "Automattic publishes twice-yearly reports with counts of information requests and disclosures."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "yes",
          "evidence": "https://transparency.automattic.com/transparency-report/wordpress-com-transparency-report-jan-jun-2026/",
          "note": "Policy is to notify users and give them a copy of legal requests unless prohibited by law or court order."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=wordpress.com&hideResults=on",
          "note": "Grade A+"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=wordpress.com",
          "note": "Grade D- (25/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A+",
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "ssl.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Meta Pixel",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Reddit Pixel",
            "host": "www.redditstatic.com",
            "effect": "no"
          },
          {
            "name": "WordPress.com Stats",
            "host": "stats.wp.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T06:59:57.860Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "write-as",
      "category": "blogging",
      "name": "Write.as",
      "description": "Minimalist hosted blogging service from Musing Studio, focused on distraction-free writing and anonymous publishing, with federation over ActivityPub.",
      "website": "https://write.as",
      "source": "https://github.com/writefreely/writefreely",
      "license": "AGPL-3.0",
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Write.as scores 50 out of 100 (grade D) on the blogging criteria. It meets 2 of 8 criteria: no ads or data sales and TLS configuration. It partly meets open source, no trackers or telemetry and transparency report. It does not meet independent audit, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/blogging/write-as/",
      "markdown": "https://privacyratings.com/blogging/write-as/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/writefreely/writefreely/blob/develop/LICENSE",
          "note": "Write.as runs on WriteFreely, which is AGPL-3.0, but the code for Write.as Pro features beyond WriteFreely is not published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://write.as/privacy",
          "note": "Uses self-hosted Matomo analytics with cookies, which respects Do Not Track and can be opted out of. The Android app has no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://write.as/pricing",
          "note": "Funded by paid plans with no ads, and the privacy policy states data is never shared for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://write.as/privacy",
          "note": "The privacy policy states requests are reviewed and require a warrant, and a quarterly warrant canary is published, but no request counts."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=write.as&hideResults=on",
          "note": "Grade A"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=write.as",
          "note": "Grade D- (25/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "A",
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:57.851Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "write-freely",
      "category": "blogging",
      "name": "Write Freely",
      "description": "Minimal, federated blogging platform built on ActivityPub, self-hosted or offered as managed hosting by its developer, Musing Studio.",
      "website": "https://writefreely.org",
      "source": "https://github.com/writefreely/writefreely",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 53,
      "coverage": 100,
      "summary": "Write Freely scores 53 out of 100 (grade D) on the blogging criteria. It meets 2 of 8 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry, transparency report and TLS configuration. It does not meet independent audit, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade D-.",
      "url": "https://privacyratings.com/blogging/write-freely/",
      "markdown": "https://privacyratings.com/blogging/write-freely/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/writefreely/writefreely/blob/develop/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://write.as/privacy",
          "note": "The software has no telemetry, but the developer's websites use self-hosted Matomo analytics, which respects Do Not Track and offers an opt-out."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://writefreely.org/fund",
          "note": "Funded by paid hosting, app sales and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://write.as/canary.txt",
          "note": "The developer publishes a quarterly warrant canary and a policy of reviewing every legal request, but no request counts."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "no",
          "evidence": null,
          "note": "No published policy on notifying users about data requests."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=writefreely.org&hideResults=on",
          "note": "Grade B"
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "no",
          "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=writefreely.org",
          "note": "Grade D- (25/100+)"
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "pending",
          "evidence": null,
          "note": "Not tested yet."
        }
      },
      "tests": {
        "ssllabs": "B",
        "observatory": "D-",
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:03:56.655Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "feeder",
      "category": "news-readers",
      "name": "Feeder",
      "description": "Open source RSS, Atom and JSON Feed reader for Android that runs locally without an account, with optional sync between devices.",
      "website": "https://github.com/spacecowboy/Feeder",
      "source": "https://github.com/spacecowboy/Feeder",
      "license": "GPL-3.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Feeder scores 80 out of 100 (grade B) on the news readers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/news-readers/feeder/",
      "markdown": "https://privacyratings.com/news-readers/feeder/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/spacecowboy/Feeder/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.nononsenseapps.feeder.play/latest/",
          "note": "Exodus finds 0 trackers in the app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/spacecowboy/Feeder",
          "note": "Free app funded by donations through Ko-fi, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:59:57.819Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "feedly",
      "category": "news-readers",
      "name": "Feedly",
      "description": "Hosted news reader for following RSS feeds, newsletters and other sources in one place, with web, Android and iOS apps and optional paid features.",
      "website": "https://feedly.com/news-reader",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Feedly scores 20 out of 100 (grade F) on the news readers criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/news-readers/feedly/",
      "markdown": "https://privacyratings.com/news-readers/feedly/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://feedly.com/legal/privacy",
          "note": "The website loads Google Tag Manager, Mixpanel and HubSpot, and the privacy policy lists marketing analytics providers. The Android app has no trackers per Exodus."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://feedly.com/legal/privacy",
          "note": "Funded by paid plans with no ads in the reader, and the privacy policy states personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:58.112Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fluent-reader",
      "category": "news-readers",
      "name": "Fluent Reader",
      "description": "Open source desktop feed reader for Windows, macOS and Linux built with Electron, which reads feeds locally or syncs with Fever and Google Reader API services, Inoreader and Feedbin.",
      "website": "https://hyliu.me/fluent-reader/",
      "source": "https://github.com/yang991178/fluent-reader",
      "license": "BSD-3-Clause",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Fluent Reader scores 80 out of 100 (grade B) on the news readers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/news-readers/fluent-reader/",
      "markdown": "https://privacyratings.com/news-readers/fluent-reader/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/yang991178/fluent-reader/blob/master/LICENSE",
          "note": "BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/yang991178/fluent-reader",
          "note": "No telemetry or analytics in the source code, and the project website loads no scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/yang991178/fluent-reader",
          "note": "Free app funded by donations through GitHub Sponsors and PayPal, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:58.197Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "freshrss",
      "category": "news-readers",
      "name": "FreshRSS",
      "description": "Self-hosted feed reader and aggregator written in PHP, with multi-user support, extensions, WebSub and APIs compatible with Google Reader and Fever mobile clients.",
      "website": "https://freshrss.org",
      "source": "https://github.com/FreshRSS/FreshRSS",
      "license": "AGPL-3.0",
      "platforms": [
        "web",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "FreshRSS scores 80 out of 100 (grade B) on the news readers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/news-readers/freshrss/",
      "markdown": "https://privacyratings.com/news-readers/freshrss/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/FreshRSS/FreshRSS/blob/edge/LICENSE.txt",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/FreshRSS/FreshRSS",
          "note": "No telemetry or analytics in the source code, and the project website loads no third-party scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://liberapay.com/FreshRSS/",
          "note": "Volunteer project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:58.769Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "inoreader",
      "category": "news-readers",
      "name": "Inoreader",
      "description": "Hosted news reader for RSS feeds, newsletters and social feeds, with rules, filters and search, available on the web, Android and iOS.",
      "website": "https://www.inoreader.com",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "BG",
        "name": "Bulgaria",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Inoreader scores 0 out of 100 (grade F) on the news readers criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in Bulgaria: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/news-readers/inoreader/",
      "markdown": "https://privacyratings.com/news-readers/inoreader/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.innologica.inoreader/latest/",
          "note": "The Android app contains Google Firebase Analytics, and the privacy policy describes website analytics used to measure advertising."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.inoreader.com/pricing",
          "note": "The free plan shows ads, removed only on the paid plan, and the privacy policy covers using data for ad targeting, including Facebook ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google reCAPTCHA",
            "host": "www.google.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:58.963Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "miniflux",
      "category": "news-readers",
      "name": "Miniflux",
      "description": "Minimalist self-hosted feed reader for RSS, Atom and JSON Feed, written in Go with PostgreSQL. Removes tracking pixels and parameters. Also offered as a paid hosted service.",
      "website": "https://miniflux.app",
      "source": "https://github.com/miniflux/v2",
      "license": "Apache-2.0",
      "platforms": [
        "web",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Miniflux scores 80 out of 100 (grade B) on the news readers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/news-readers/miniflux/",
      "markdown": "https://privacyratings.com/news-readers/miniflux/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/miniflux/v2/blob/main/LICENSE",
          "note": "Apache-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://miniflux.app/hosting.html",
          "note": "States there is no telemetry and no analytics software, and usage is not tracked."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://miniflux.app/hosting.html",
          "note": "Funded by paid hosting and donations, with no advertising, and data is not shared or sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:58.630Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "netnewswire",
      "category": "news-readers",
      "name": "NetNewsWire",
      "description": "Free, open source RSS and Atom feed reader for Mac, iPhone and iPad, with sync through iCloud or services such as Feedbin, Feedly and FreshRSS.",
      "website": "https://netnewswire.com",
      "source": "https://github.com/Ranchero-Software/NetNewsWire",
      "license": "MIT",
      "platforms": [
        "macos",
        "ios"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "NetNewsWire scores 80 out of 100 (grade B) on the news readers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/news-readers/netnewswire/",
      "markdown": "https://privacyratings.com/news-readers/netnewswire/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Ranchero-Software/NetNewsWire/blob/main/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://netnewswire.com/privacypolicy.html",
          "note": "Crash logs are sent only when users opt in, and the website uses only its own server logs."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/Ranchero-Software/NetNewsWire/blob/main/Technotes/HowToSupportNetNewsWire.markdown",
          "note": "Free volunteer project with no ads, paid tiers or donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:58.742Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "newsblur",
      "category": "news-readers",
      "name": "NewsBlur",
      "description": "Hosted feed reader with web, Android and iOS apps that learns which stories a reader likes, with shared stories and paid premium tiers. The server code is open source and can be self-hosted.",
      "website": "https://newsblur.com",
      "source": "https://github.com/samuelclay/NewsBlur",
      "license": "MIT",
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "NewsBlur scores 80 out of 100 (grade B) on the news readers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/news-readers/newsblur/",
      "markdown": "https://privacyratings.com/news-readers/newsblur/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/samuelclay/NewsBlur/blob/main/LICENSE.md",
          "note": "MIT, covering the server and apps."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://newsblur.com/privacy",
          "note": "No third-party trackers, and Exodus finds none in the Android app. The website's Plausible analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://newsblur.com/about",
          "note": "Funded by premium subscriptions with no ads, and the privacy policy states user information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Plausible",
            "host": "plausible.io",
            "effect": "partial"
          },
          {
            "name": "Trustpilot",
            "host": "www.trustpilot.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:59.942Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "newsboat",
      "category": "news-readers",
      "name": "Newsboat",
      "description": "Terminal-based RSS and Atom feed reader for Linux, macOS and BSD, a maintained fork of Newsbeuter, with support for podcasts and sync services such as Miniflux and FreshRSS.",
      "website": "https://newsboat.org",
      "source": "https://github.com/newsboat/newsboat",
      "license": "MIT",
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Newsboat scores 80 out of 100 (grade B) on the news readers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/news-readers/newsboat/",
      "markdown": "https://privacyratings.com/news-readers/newsboat/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/newsboat/newsboat/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/newsboat/newsboat",
          "note": "No telemetry or analytics in the source code, and the project website loads no scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/newsboat/newsboat",
          "note": "Free volunteer project with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:59.954Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "read-you",
      "category": "news-readers",
      "name": "Read You",
      "description": "Open source Material You feed reader for Android that works locally or syncs with FreshRSS and services using the Fever or Google Reader API.",
      "website": "https://github.com/ReadYouApp/ReadYou",
      "source": "https://github.com/ReadYouApp/ReadYou",
      "license": "GPL-3.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Read You scores 80 out of 100 (grade B) on the news readers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/news-readers/read-you/",
      "markdown": "https://privacyratings.com/news-readers/read-you/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ReadYouApp/ReadYou/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/me.ash.reader/latest/",
          "note": "Exodus finds 0 trackers in the app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/ReadYouApp/ReadYou",
          "note": "Free volunteer project funded by sponsorships, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:59:58.770Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "tiny-rss",
      "category": "news-readers",
      "name": "Tiny Tiny RSS",
      "description": "Self-hosted, web-based feed reader and aggregator for RSS and Atom, with plugins, filters and an API for mobile clients. Maintained as a community fork after the original project was retired.",
      "website": "https://tt-rss.org",
      "source": "https://github.com/tt-rss/tt-rss",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Tiny Tiny RSS scores 80 out of 100 (grade B) on the news readers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/news-readers/tiny-rss/",
      "markdown": "https://privacyratings.com/news-readers/tiny-rss/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/tt-rss/tt-rss/blob/main/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/tt-rss/tt-rss",
          "note": "No telemetry or analytics in the source code, and the project website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/tt-rss/tt-rss",
          "note": "Volunteer-maintained free software with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:12.531Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "antennapod",
      "category": "media-players",
      "name": "AntennaPod",
      "description": "Open source podcast manager and player for Android, with subscriptions by RSS feed and optional sync through gpodder.net or Nextcloud. No iOS or desktop app.",
      "website": "https://antennapod.org",
      "source": "https://github.com/AntennaPod/AntennaPod",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "AntennaPod scores 80 out of 100 (grade B) on the media and podcast players criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/media-players/antennapod/",
      "markdown": "https://privacyratings.com/media-players/antennapod/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/AntennaPod/AntennaPod/blob/develop/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://antennapod.org/privacy/",
          "note": "The privacy policy states the app has no advertising, third-party tracking or analytics code, and the website uses no third-party tracking."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/antennapod",
          "note": "Volunteer project funded by donations through Open Collective. The privacy policy states the app has no advertising libraries."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:13.059Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "audacious",
      "category": "media-players",
      "name": "Audacious",
      "description": "Open source audio player for Linux, BSD, macOS and Windows with Qt and GTK interfaces, Winamp Classic skin support and plugins for effects, lyrics and visualizations.",
      "website": "https://audacious-media-player.org",
      "source": "https://github.com/audacious-media-player/audacious",
      "license": null,
      "platforms": [
        "linux",
        "windows",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Audacious scores 80 out of 100 (grade B) on the media and podcast players criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/media-players/audacious/",
      "markdown": "https://privacyratings.com/media-players/audacious/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/audacious-media-player/audacious/blob/master/COPYING",
          "note": "BSD-2-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/audacious-media-player/audacious",
          "note": "No telemetry or analytics in the source code, and the project website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/audacious-media-player/audacious",
          "note": "Volunteer-maintained free software with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:59.994Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "auxio",
      "category": "media-players",
      "name": "Auxio",
      "description": "Open source local music player for Android with a Material Design interface, built on ExoPlayer, with gapless playback, ReplayGain and advanced tag support.",
      "website": "https://github.com/OxygenCobalt/Auxio",
      "source": "https://github.com/OxygenCobalt/Auxio",
      "license": "GPL-3.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Auxio scores 80 out of 100 (grade B) on the media and podcast players criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/media-players/auxio/",
      "markdown": "https://privacyratings.com/media-players/auxio/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/OxygenCobalt/Auxio/blob/dev/LICENSE",
          "note": "GPL-3.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.oxycblt.auxio/latest/",
          "note": "Exodus finds 0 trackers in the app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/OxygenCobalt/Auxio",
          "note": "Free app funded by GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:59:58.963Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "celluloid",
      "category": "media-players",
      "name": "Celluloid",
      "description": "Open source GTK front end for the mpv video player on Linux, with a GNOME-style interface, playlists and mpv configuration and script support.",
      "website": "https://celluloid-player.github.io",
      "source": "https://github.com/celluloid-player/celluloid",
      "license": "GPL-3.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Celluloid scores 80 out of 100 (grade B) on the media and podcast players criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/media-players/celluloid/",
      "markdown": "https://privacyratings.com/media-players/celluloid/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/celluloid-player/celluloid/blob/master/COPYING",
          "note": "GPL-3.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/celluloid-player/celluloid",
          "note": "No telemetry or analytics in the source code, and the project website loads no scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/celluloid-player/celluloid",
          "note": "Volunteer-maintained free software with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T06:59:59.767Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gpodder",
      "category": "media-players",
      "name": "gPodder",
      "description": "Open source desktop podcast client for Linux, Windows and macOS that downloads and manages episodes from RSS feeds and YouTube channels, with optional sync through gpodder.net.",
      "website": "https://gpodder.github.io",
      "source": "https://github.com/gpodder/gpodder",
      "license": "GPL-3.0",
      "platforms": [
        "linux",
        "windows",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "gPodder scores 50 out of 100 (grade D) on the media and podcast players criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/media-players/gpodder/",
      "markdown": "https://privacyratings.com/media-players/gpodder/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gpodder/gpodder/blob/master/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://gpodder.github.io",
          "note": "The app has no telemetry, but the gpodder.github.io website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/gpodder/gpodder",
          "note": "Volunteer-maintained free software with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T06:59:59.908Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "iina",
      "category": "media-players",
      "name": "IINA",
      "description": "Open source video player for macOS built on mpv, with a native interface, picture-in-picture, online subtitle search and plugin support.",
      "website": "https://iina.io",
      "source": "https://github.com/iina/iina",
      "license": "GPL-3.0",
      "platforms": [
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "IINA scores 80 out of 100 (grade B) on the media and podcast players criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/media-players/iina/",
      "markdown": "https://privacyratings.com/media-players/iina/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/iina/iina/blob/develop/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/iina/iina",
          "note": "No telemetry or analytics in the source code, and the project website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/iina/iina",
          "note": "Volunteer-maintained free software with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:00.326Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kasts",
      "category": "media-players",
      "name": "Kasts",
      "description": "Open source podcast app from KDE for Linux, Windows and Android, built with Kirigami for desktop and mobile, with episode downloads, streaming and optional sync through gpodder.net or Nextcloud.",
      "website": "https://apps.kde.org/kasts/",
      "source": "https://invent.kde.org/multimedia/kasts",
      "license": null,
      "platforms": [
        "linux",
        "windows",
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Kasts scores 80 out of 100 (grade B) on the media and podcast players criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/media-players/kasts/",
      "markdown": "https://privacyratings.com/media-players/kasts/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/KDE/kasts/tree/master/LICENSES",
          "note": "GPL-2.0-or-later and GPL-3.0-or-later, with some files under other OSI-approved licenses."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kde.org/privacypolicy/",
          "note": "No third-party trackers, and the app has no telemetry. KDE websites use self-hosted Matomo with cookies disabled and IP addresses anonymized."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kde.org/donate/",
          "note": "Developed by the KDE community, funded by donations to the non-profit KDE e.V., with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:00.488Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kodi",
      "category": "media-players",
      "name": "Kodi",
      "description": "Open source media center for playing and organizing local and network video, music and photos, with a TV-friendly interface and add-ons. Developed by the non-profit Kodi Foundation.",
      "website": "https://kodi.tv",
      "source": "https://github.com/xbmc/xbmc",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Kodi scores 80 out of 100 (grade B) on the media and podcast players criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/media-players/kodi/",
      "markdown": "https://privacyratings.com/media-players/kodi/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/xbmc/xbmc/blob/master/LICENSE.md",
          "note": "GPL-2.0-or-later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kodi.tv/about/privacy-policy",
          "note": "No third-party trackers, and Exodus finds none in the Android app. The website's GoatCounter analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kodi.tv/donate",
          "note": "Developed by a non-profit foundation funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:00.139Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mpc-hc",
      "category": "media-players",
      "name": "MPC-HC",
      "description": "Lightweight open source media player for Windows, a community-maintained continuation of Media Player Classic Home Cinema with built-in LAV Filters codecs.",
      "website": "https://github.com/clsid2/mpc-hc",
      "source": "https://github.com/clsid2/mpc-hc",
      "license": "GPL-3.0",
      "platforms": [
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "MPC-HC scores 80 out of 100 (grade B) on the media and podcast players criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/media-players/mpc-hc/",
      "markdown": "https://privacyratings.com/media-players/mpc-hc/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/clsid2/mpc-hc/blob/develop/COPYING.txt",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/clsid2/mpc-hc",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/clsid2/mpc-hc",
          "note": "Volunteer-maintained free software with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T06:59:59.994Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "mpv",
      "category": "media-players",
      "name": "mpv",
      "description": "Free, open source command-line media player for Windows, macOS and Linux based on FFmpeg, with a minimal on-screen controller, scripting in Lua and JavaScript, and libmpv for embedding in other apps.",
      "website": "https://mpv.io",
      "source": "https://github.com/mpv-player/mpv",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "mpv scores 80 out of 100 (grade B) on the media and podcast players criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/media-players/mpv/",
      "markdown": "https://privacyratings.com/media-players/mpv/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mpv-player/mpv/blob/master/Copyright",
          "note": "GPL-2.0-or-later, or LGPL-2.1-or-later when built without GPL-only files."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mpv-player/mpv",
          "note": "No telemetry or analytics in the source code, and the project website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/mpv-player/mpv",
          "note": "Volunteer-maintained free software with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:00:00.281Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "pocket-casts",
      "category": "media-players",
      "name": "Pocket Casts",
      "description": "Podcast player from Automattic for Android, iOS, the web and desktop, with syncing across devices, discovery and a paid Plus tier. The mobile apps are open source.",
      "website": "https://pocketcasts.com",
      "source": "https://github.com/Automattic/pocket-casts-android",
      "license": "MPL-2.0",
      "platforms": [
        "android",
        "ios",
        "web",
        "windows",
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 25,
      "coverage": 100,
      "summary": "Pocket Casts scores 25 out of 100 (grade F) on the media and podcast players criteria. It partly meets open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/media-players/pocket-casts/",
      "markdown": "https://privacyratings.com/media-players/pocket-casts/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/Automattic/pocket-casts-android/blob/main/LICENSE.md",
          "note": "The Android and iOS apps are MPL-2.0, but the sync server and web player are closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/au.com.shiftyjelly.pocketcasts/latest/",
          "note": "The Android app contains Google Firebase Analytics and Sentry. In-app analytics can be turned off in settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.pocketcasts.com/article/privacy-policy/",
          "note": "The free app shows banner ads that Plus removes, and the privacy policy states personal data is not sold or shared for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:00.648Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "podcast-addict",
      "category": "media-players",
      "name": "Podcast Addict",
      "description": "Podcast, audiobook and radio app for Android with RSS feed subscriptions, downloads and playback controls, free with ads and an in-app purchase to remove them.",
      "website": "https://podcastaddict.com",
      "license": null,
      "platforms": [
        "android"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Podcast Addict scores 0 out of 100 (grade F) on the media and podcast players criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/media-players/podcast-addict/",
      "markdown": "https://privacyratings.com/media-players/podcast-addict/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.bambuna.podcastaddict/latest/",
          "note": "Exodus finds trackers including Google Firebase Analytics, Crashlytics, AdMob, AppLovin and InMobi."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://podcastaddict.com/privacy",
          "note": "Funded by ads from networks including AdMob, AppLovin, Fyber and InMobi, which collect cookie and usage data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:00.404Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "rhythmbox",
      "category": "media-players",
      "name": "Rhythmbox",
      "description": "Open source music player and library manager for the GNOME desktop on Linux, with internet radio, podcasts, audio CD playback and plugins such as Last.fm and ListenBrainz scrobbling.",
      "website": "https://gnome.pages.gitlab.gnome.org/rhythmbox/",
      "source": "https://gitlab.gnome.org/GNOME/rhythmbox",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Rhythmbox scores 80 out of 100 (grade B) on the media and podcast players criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/media-players/rhythmbox/",
      "markdown": "https://privacyratings.com/media-players/rhythmbox/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/GNOME/rhythmbox/blob/master/COPYING",
          "note": "GPL-2.0-or-later with an exception for GStreamer plugins."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/GNOME/rhythmbox",
          "note": "No telemetry or analytics in the source code, and the project website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://donate.gnome.org/en/",
          "note": "Part of the GNOME project, supported by the non-profit GNOME Foundation through donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:00.326Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "strawberry",
      "category": "media-players",
      "name": "Strawberry",
      "description": "Open source music player and collection organizer for audiophiles, forked from Clementine, with tag editing, lyrics, scrobbling and streaming from Subsonic, Tidal and Qobuz. Windows and macOS builds are for sponsors.",
      "website": "https://www.strawberrymusicplayer.org",
      "source": "https://github.com/strawberrymusicplayer/strawberry",
      "license": "GPL-3.0",
      "platforms": [
        "linux",
        "windows",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Strawberry scores 80 out of 100 (grade B) on the media and podcast players criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/media-players/strawberry/",
      "markdown": "https://privacyratings.com/media-players/strawberry/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/strawberrymusicplayer/strawberry/blob/master/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/strawberrymusicplayer/strawberry",
          "note": "No telemetry or analytics in the source code, and the project website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.strawberrymusicplayer.org",
          "note": "Funded by sponsorships through Patreon, GitHub, Ko-fi and PayPal, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:01.406Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vlc-media-player",
      "category": "media-players",
      "name": "VLC Media Player",
      "description": "Cross-platform media player from the non-profit VideoLAN project that plays most audio and video formats, discs and network streams without extra codecs.",
      "website": "https://www.videolan.org/vlc",
      "source": "https://github.com/videolan/vlc",
      "license": "GPL-2.0",
      "platforms": [],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "VLC Media Player scores 50 out of 100 (grade D) on the media and podcast players criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/media-players/vlc-media-player/",
      "markdown": "https://privacyratings.com/media-players/vlc-media-player/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/videolan/vlc/blob/master/COPYING",
          "note": "GPL-2.0 and LGPL-2.1."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.videolan.org/privacy.html",
          "note": "VLC collects no telemetry, but the videolan.org website uses Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.videolan.org/contribute.html",
          "note": "Developed by the non-profit VideoLAN, funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:02:03.440Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "audiobookshelf",
      "category": "media-servers",
      "name": "Audiobookshelf",
      "description": "Self-hosted audiobook and podcast server with a web player and mobile apps, supporting multiple users, progress sync across devices, podcast downloads and offline listening.",
      "website": "https://audiobookshelf.org",
      "source": "https://github.com/advplyr/audiobookshelf",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Audiobookshelf scores 80 out of 100 (grade B) on the media servers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/media-servers/audiobookshelf/",
      "markdown": "https://privacyratings.com/media-servers/audiobookshelf/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/advplyr/audiobookshelf/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://audiobookshelf.org/privacy-policy/",
          "note": "The privacy policy states no personal data is collected, the Android app has no trackers per Exodus Privacy, and the website loads no analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://audiobookshelf.org/privacy-policy/",
          "note": "Free volunteer project with no ads or paid tiers, and no personal data collected."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:01.147Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "emby",
      "category": "media-servers",
      "name": "Emby",
      "description": "Media server that organizes personal movies, TV, music and photos and streams them to Emby apps on phones, TVs and browsers. Core features are free and some, such as offline sync and DVR, need a paid Emby Premiere subscription.",
      "website": "https://emby.media",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "Emby scores 35 out of 100 (grade F) on the media servers criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets no trackers or telemetry. It does not meet open source and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/media-servers/emby/",
      "markdown": "https://privacyratings.com/media-servers/emby/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. Only older versions of the server were open source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://emby.media/privacy.html",
          "note": "The website and Android app load no third-party trackers, but the privacy policy allows cookies, web beacons and third-party scripts, and the server connects to Emby for Emby Connect and Premiere checks."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://emby.media/premiere.html",
          "note": "Funded by Emby Premiere subscriptions, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:01.058Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "jellyfin",
      "category": "media-servers",
      "name": "Jellyfin",
      "description": "Self-hosted media server for movies, TV, music, books and live TV, with client apps for web, mobile and TV devices. All features are free, with no account on a central server.",
      "website": "https://jellyfin.org",
      "source": "https://github.com/jellyfin/jellyfin",
      "license": "GPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Jellyfin scores 80 out of 100 (grade B) on the media servers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/media-servers/jellyfin/",
      "markdown": "https://privacyratings.com/media-servers/jellyfin/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jellyfin/jellyfin/blob/master/LICENSE",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/org.jellyfin.mobile/latest/",
          "note": "The Android app has no trackers, the server has no telemetry, and the website loads no analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://jellyfin.org/docs/general/faq/",
          "note": "Volunteer project with no premium features or ads. Donations through Open Collective pay for infrastructure."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:01.080Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kavita",
      "category": "media-servers",
      "name": "Kavita",
      "description": "Self-hosted reading server for manga, comics and books, with web readers for comics, EPUB and PDF, OPDS support and multiple users. An optional paid Kavita+ subscription adds metadata and scrobbling features.",
      "website": "https://www.kavitareader.com",
      "source": "https://github.com/Kareadita/Kavita",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Kavita scores 50 out of 100 (grade D) on the media servers criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/media-servers/kavita/",
      "markdown": "https://privacyratings.com/media-servers/kavita/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Kareadita/Kavita/blob/develop/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://wiki.kavitareader.com/troubleshooting/faq/",
          "note": "The website loads Google Tag Manager (automated test). The server also sends anonymous usage statistics by default, which can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://wiki.kavitareader.com/kavita+/",
          "note": "Funded by the optional Kavita+ subscription and Open Collective donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:01.233Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "komga",
      "category": "media-servers",
      "name": "Komga",
      "description": "Self-hosted media server for comics, manga, magazines and eBooks, with a web reader, OPDS and Kobo sync support, multiple users and a REST API used by third-party reader apps.",
      "website": "https://komga.org",
      "source": "https://github.com/gotson/komga",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Komga scores 80 out of 100 (grade B) on the media servers criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/media-servers/komga/",
      "markdown": "https://privacyratings.com/media-servers/komga/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/gotson/komga/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://komga.org/",
          "note": "No third-party trackers, and the server has no telemetry. The website's Cloudflare Web Analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/komga",
          "note": "Funded by donations through Open Collective and GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:00:01.633Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "navidrome",
      "category": "media-servers",
      "name": "Navidrome",
      "description": "Self-hosted music server and streamer with a web player, compatible with Subsonic and OpenSubsonic client apps, supporting multiple users, smart playlists and scrobbling.",
      "website": "https://www.navidrome.org",
      "source": "https://github.com/navidrome/navidrome",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Navidrome scores 50 out of 100 (grade D) on the media servers criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/media-servers/navidrome/",
      "markdown": "https://privacyratings.com/media-servers/navidrome/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/navidrome/navidrome/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.navidrome.org/docs/usage/admin/insights/",
          "note": "The website loads Google Analytics and Google Tag Manager (automated test). The server also sends anonymous usage statistics to the project by default, which can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://opencollective.com/navidrome",
          "note": "Funded by donations through Open Collective and other platforms, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:01.906Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "plex",
      "category": "media-servers",
      "name": "Plex",
      "description": "Proprietary media server and client apps for streaming a personal video, music and photo library to other devices. It requires a Plex account and also offers free ad-supported movies, TV and live channels.",
      "website": "https://www.plex.tv/your-media/",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "CH",
        "name": "Switzerland",
        "eyes": null,
        "eu": false,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Plex scores 0 out of 100 (grade F) on the media servers criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law.",
      "url": "https://privacyratings.com/media-servers/plex/",
      "markdown": "https://privacyratings.com/media-servers/plex/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.plex.tv/about/privacy-legal/",
          "note": "The privacy policy lists analytics providers, advertising IDs and optional playback data sent by default, and the Android app contains FullStory and Sentry per Exodus Privacy."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.plex.tv/about/privacy-legal/",
          "note": "The free streaming service shows ads, and the privacy policy describes selling and sharing personal data for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "Sentry",
            "host": "js.sentry-cdn.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:01.886Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "amazon-photos",
      "category": "photo-management",
      "name": "Amazon Photos",
      "description": "Amazon's photo and video backup and sharing service, with automatic phone upload, image search and a shared Family Vault. Storage comes with an Amazon Prime membership or a paid storage plan.",
      "website": "https://www.amazon.com/photos",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Amazon Photos scores 0 out of 100 (grade F) on the photo management criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/photo-management/amazon-photos/",
      "markdown": "https://privacyratings.com/photo-management/amazon-photos/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.amazon.clouddrive.photos/latest/",
          "note": "The Android app includes the Branch and MoEngage trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.amazon.com/gp/help/customer/display.html?nodeId=GX7NJQ4ZB8MHFRNJ",
          "note": "No ads in the app, but Amazon's privacy notice, which covers Amazon Photos, uses personal information for interest-based advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:02:03.647Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "aves",
      "category": "photo-management",
      "name": "Aves",
      "description": "Gallery and metadata explorer for Android that handles images, videos and formats such as multi-page TIFF, SVG, motion photos and panoramas, with albums, tags, maps and search.",
      "website": "https://github.com/deckerst/aves",
      "source": "https://github.com/deckerst/aves",
      "license": "BSD-3-Clause",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Aves scores 80 out of 100 (grade B) on the photo management criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/photo-management/aves/",
      "markdown": "https://privacyratings.com/photo-management/aves/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/deckerst/aves/blob/develop/LICENSE",
          "note": "BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://reports.exodus-privacy.eu.org/en/reports/deckers.thibault.aves.libre/latest/",
          "note": "The F-Droid build has no trackers. The Google Play build includes Firebase Crashlytics, which stays off unless error reporting is turned on."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/deckerst/aves",
          "note": "Free app funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:01.407Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "digikam",
      "category": "photo-management",
      "name": "digiKam",
      "description": "Desktop photo management app from the KDE community for importing, organizing, tagging, searching and editing large photo libraries, including RAW files, face recognition and metadata editing.",
      "website": "https://www.digikam.org",
      "source": "https://invent.kde.org/graphics/digikam",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "digiKam scores 80 out of 100 (grade B) on the photo management criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/photo-management/digikam/",
      "markdown": "https://privacyratings.com/photo-management/digikam/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://invent.kde.org/graphics/digikam/-/blob/master/LICENSES/GPL-2.0-or-later.txt",
          "note": "GPL-2.0 or later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://invent.kde.org/graphics/digikam",
          "note": "No telemetry or analytics in the source code, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.digikam.org/donate/",
          "note": "Volunteer KDE project funded by donations and sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:02.547Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ente-photos",
      "category": "photo-management",
      "name": "Ente Photos",
      "description": "End-to-end encrypted photo and video backup and sharing, with apps for mobile, desktop and web. The server is open source and can be self-hosted.",
      "website": "https://ente.com",
      "source": "https://github.com/ente-io/ente",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 70,
      "coverage": 100,
      "summary": "Ente Photos scores 70 out of 100 (grade C) on the photo management criteria. It meets 3 of 4 criteria: open source, no ads or data sales and independent audit. It does not meet no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/photo-management/ente-photos/",
      "markdown": "https://privacyratings.com/photo-management/ente-photos/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ente-io/ente/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads PostHog (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ente.com/privacy/",
          "note": "Funded by paid storage plans. The privacy policy states personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ente.com/reports/Cure53-Audit-Report-Oct-2025.pdf",
          "note": "Full Cure53 report on the platform, cryptography and infrastructure, sponsored by CERN."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "PostHog",
            "host": "inline code",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:12.774Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fossify-gallery",
      "category": "photo-management",
      "name": "Fossify Gallery",
      "description": "Offline photo and video gallery for Android with albums, a basic photo editor, EXIF metadata removal and hidden folders. It does not request internet access.",
      "website": "https://www.fossify.org/apps/gallery/",
      "source": "https://github.com/FossifyOrg/Gallery",
      "license": "GPL-3.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Fossify Gallery scores 80 out of 100 (grade B) on the photo management criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/photo-management/fossify-gallery/",
      "markdown": "https://privacyratings.com/photo-management/fossify-gallery/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/FossifyOrg/Gallery/blob/main/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.fossify.org/policy/gallery.html",
          "note": "The app has no internet permission and no trackers, and the website loads no analytics or third-party scripts."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.fossify.org/donate/",
          "note": "Funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:02.274Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "google-photos",
      "category": "photo-management",
      "name": "Google Photos",
      "description": "Google's photo and video backup and sharing service, with automatic phone upload, face grouping, search and editing tools.",
      "website": "https://www.google.com/photos/about/",
      "license": null,
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Google Photos scores 20 out of 100 (grade F) on the photo management criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/photo-management/google-photos/",
      "markdown": "https://privacyratings.com/photo-management/google-photos/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://policies.google.com/privacy",
          "note": "Google collects activity, device and usage data across its services, the Android app includes Google Firebase Analytics per Exodus Privacy, and the website loads Google Analytics (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://safety.google/products/photos/",
          "note": "No ads in Google Photos, and Google states photos and videos are not sold or used for advertising. Extra storage is sold as a subscription."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:02.378Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "icloud-photos",
      "category": "photo-management",
      "name": "iCloud Photos",
      "description": "Apple's photo and video library sync built into the Photos app on Apple devices, with iCloud for Windows and web access. Photos are end-to-end encrypted only with the optional Advanced Data Protection setting, which is off by default.",
      "website": "https://support.apple.com/en-us/108782",
      "license": null,
      "platforms": [
        "macos",
        "ios",
        "windows",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 60,
      "coverage": 100,
      "summary": "iCloud Photos scores 60 out of 100 (grade C) on the photo management criteria. It meets 2 of 4 criteria: no trackers or telemetry and no ads or data sales. It partly meets independent audit. It does not meet open source. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/photo-management/icloud-photos/",
      "markdown": "https://privacyratings.com/photo-management/icloud-photos/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/data/en/device-analytics/",
          "note": "Device and iCloud analytics are only shared with Apple if the user agrees, and no third-party trackers are included."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.apple.com/legal/privacy/en-ww/",
          "note": "Funded by iCloud+ subscriptions and device sales, with no ads in iCloud Photos. Apple states it does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://support.apple.com/guide/certifications/apple-internet-services-security-apc34d2c0468b/web",
          "note": "Apple's internet services, including iCloud, have yearly ISO 27001 and 27018 certification audits, but only the certificates are public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:02.390Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "immich",
      "category": "photo-management",
      "name": "Immich",
      "description": "Self-hosted photo and video backup and management server, with automatic mobile upload, timeline view, albums, search and facial recognition.",
      "website": "https://immich.app",
      "source": "https://github.com/immich-app/immich",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Immich scores 65 out of 100 (grade C) on the photo management criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit.",
      "url": "https://privacyratings.com/photo-management/immich/",
      "markdown": "https://privacyratings.com/photo-management/immich/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/immich-app/immich/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://immich.app/privacy-policy",
          "note": "No third-party trackers in the apps, but the version check and map tile services send request metadata to Immich by default and can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://buy.immich.app/",
          "note": "Developed by a full-time team at FUTO and funded by optional product key purchases, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:12.979Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "librephotos",
      "category": "photo-management",
      "name": "LibrePhotos",
      "description": "Self-hosted photo and video management server with a web interface, timeline view, multiple users, face recognition, object and scene detection, semantic search and automatically generated event albums.",
      "website": "https://github.com/LibrePhotos/librephotos",
      "source": "https://github.com/LibrePhotos/librephotos",
      "license": "MIT",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "LibrePhotos scores 80 out of 100 (grade B) on the photo management criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/photo-management/librephotos/",
      "markdown": "https://privacyratings.com/photo-management/librephotos/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/LibrePhotos/librephotos/blob/dev/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/LibrePhotos/librephotos",
          "note": "No telemetry or analytics in the source code. Reverse geocoding uses an external map service that can be configured."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/LibrePhotos/librephotos#readme",
          "note": "Volunteer project funded by donations through GitHub Sponsors and PayPal, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:02.274Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "lychee",
      "category": "photo-management",
      "name": "Lychee",
      "description": "Self-hosted photo management and sharing app with a web interface for uploading, organizing and sharing albums. An optional paid Supporter Edition adds extra features such as watermarking and statistics.",
      "website": "https://lycheeorg.dev",
      "source": "https://github.com/LycheeOrg/Lychee",
      "license": "MIT",
      "platforms": [
        "web"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Lychee scores 80 out of 100 (grade B) on the photo management criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/photo-management/lychee/",
      "markdown": "https://privacyratings.com/photo-management/lychee/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/LycheeOrg/Lychee/blob/master/LICENSE",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://lycheeorg.dev/privacy-policy/",
          "note": "The privacy policy states the website uses no cookies or tracking, and the software has no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://lycheeorg.dev/get-supporter-edition/",
          "note": "Funded by the optional Supporter Edition and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:03.732Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "photoprism",
      "category": "photo-management",
      "name": "PhotoPrism",
      "description": "Self-hosted photo management app with a web interface that indexes a photo library and adds automatic tagging, face recognition, maps and search. A free Community Edition is available, with paid memberships adding extra features.",
      "website": "https://www.photoprism.app",
      "source": "https://github.com/photoprism/photoprism",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "web"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "PhotoPrism scores 50 out of 100 (grade D) on the photo management criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source and no trackers or telemetry. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/photo-management/photoprism/",
      "markdown": "https://privacyratings.com/photo-management/photoprism/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/photoprism/photoprism/blob/develop/LICENSE",
          "note": "The Community Edition is AGPL-3.0, but features in the paid editions are unpublished and under a separate commercial license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.photoprism.app/privacy/",
          "note": "No third-party trackers, but the website and backend services record requests with self-hosted Plausible Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.photoprism.app/editions/",
          "note": "Funded by paid memberships, with no ads. The privacy policy states data is never sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:02.916Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "piwigo",
      "category": "photo-management",
      "name": "Piwigo",
      "description": "Photo gallery software for publishing and managing large photo collections on the web, with albums, tags, user permissions, plugins and mobile apps. It can be self-hosted or used as a paid hosted service from its developers.",
      "website": "https://piwigo.org",
      "source": "https://github.com/Piwigo/Piwigo",
      "license": "GPL-2.0",
      "platforms": [
        "web",
        "android",
        "ios"
      ],
      "jurisdiction": {
        "code": "FR",
        "name": "France",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Piwigo scores 65 out of 100 (grade C) on the photo management criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in France: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/photo-management/piwigo/",
      "markdown": "https://privacyratings.com/photo-management/piwigo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Piwigo/Piwigo/blob/master/LICENSE.txt",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/Piwigo/Piwigo/blob/master/include/config_default.inc.php",
          "note": "No third-party trackers on the website or in the software, but self-hosted installs send anonymous technical data and statistics to piwigo.org weekly by default, which can be turned off in the configuration."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://doc.piwigo.org/legal/privacy/",
          "note": "Funded by subscriptions to the hosted service, with no ads. The privacy policy states personal information is not rented or sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:03.376Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "biglybt",
      "category": "torrent-clients",
      "name": "BiglyBT",
      "description": "Java-based BitTorrent client descended from Vuze, with swarm merging, a built-in media player, I2P and Tor support through plugins, and an Android app.",
      "website": "https://www.biglybt.com",
      "source": "https://github.com/BiglySoftware/BiglyBT",
      "license": "GPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "BiglyBT scores 50 out of 100 (grade D) on the torrent clients criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/torrent-clients/biglybt/",
      "markdown": "https://privacyratings.com/torrent-clients/biglybt/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/BiglySoftware/BiglyBT/blob/master/LICENSE",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.biglybt.com/privacy.php",
          "note": "The website uses Google Analytics and Google Tag Manager (automated test). The client contacts BiglyBT servers for update checks."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.biglybt.com/donation/donate.php",
          "note": "Funded by donations, with no ads in the client and no third-party offers in the installer."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "www.google-analytics.com",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:03.133Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "deluge",
      "category": "torrent-clients",
      "name": "Deluge",
      "description": "BitTorrent client built on libtorrent with a client-server design, so a daemon can run on a headless machine and be controlled from GTK, web or console interfaces. Most features come as plugins.",
      "website": "https://deluge-torrent.org",
      "source": "https://github.com/deluge-torrent/deluge",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Deluge scores 80 out of 100 (grade B) on the torrent clients criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/torrent-clients/deluge/",
      "markdown": "https://privacyratings.com/torrent-clients/deluge/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/deluge-torrent/deluge/blob/develop/LICENSE",
          "note": "GPL-3.0 with an OpenSSL linking exception."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/deluge-torrent/deluge/blob/develop/deluge/core/preferencesmanager.py",
          "note": "No analytics in the apps or website. The option to send anonymous usage statistics is off by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://deluge-torrent.org/about/",
          "note": "Volunteer-developed free software with no ads or paid tiers."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:03.272Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "fragments",
      "category": "torrent-clients",
      "name": "Fragments",
      "description": "BitTorrent client for the GNOME desktop, built on Transmission, with a torrent queue, magnet link detection from the clipboard and remote control of other Fragments or Transmission sessions.",
      "website": "https://apps.gnome.org/Fragments/",
      "source": "https://gitlab.gnome.org/World/Fragments",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Fragments scores 80 out of 100 (grade B) on the torrent clients criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/torrent-clients/fragments/",
      "markdown": "https://privacyratings.com/torrent-clients/fragments/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/World/Fragments/-/blob/main/COPYING.md",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.gnome.org/World/Fragments",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://apps.gnome.org/Fragments/",
          "note": "Volunteer project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:03.583Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "libretorrent",
      "category": "torrent-clients",
      "name": "LibreTorrent",
      "description": "BitTorrent client for Android with sequential downloading, streaming, RSS auto-downloading, scheduling, WebTorrent support and Android TV support.",
      "website": "https://github.com/proninyaroslav/libretorrent",
      "source": "https://github.com/proninyaroslav/libretorrent",
      "license": "GPL-3.0",
      "platforms": [
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "LibreTorrent scores 80 out of 100 (grade B) on the torrent clients criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/torrent-clients/libretorrent/",
      "markdown": "https://privacyratings.com/torrent-clients/libretorrent/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/proninyaroslav/libretorrent/blob/master/LICENSE.md",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/proninyaroslav/libretorrent/blob/master/app/src/main/java/org/proninyaroslav/libretorrent/MainApplication.java",
          "note": "No analytics. Crash reports use ACRA and are only sent by email after the user confirms a dialog."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/proninyaroslav/libretorrent#-donations",
          "note": "Funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:03.273Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "qbittorrent",
      "category": "torrent-clients",
      "name": "qBittorrent",
      "description": "Cross-platform BitTorrent client with a built-in search engine, RSS feed downloading and an optional web interface for remote control.",
      "website": "https://www.qbittorrent.org",
      "source": "https://github.com/qbittorrent/qBittorrent",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "qBittorrent scores 80 out of 100 (grade B) on the torrent clients criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/torrent-clients/qbittorrent/",
      "markdown": "https://privacyratings.com/torrent-clients/qbittorrent/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/qbittorrent/qBittorrent/blob/master/COPYING",
          "note": "GPL-2.0 or later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/qbittorrent/qBittorrent",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.qbittorrent.org/donate",
          "note": "Volunteer project funded by donations, with no ads or bundled software."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:13.141Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "rtorrent",
      "category": "torrent-clients",
      "name": "rTorrent",
      "description": "Text-based BitTorrent client for the terminal, built on libtorrent, with an ncurses interface, scripting through its configuration file and an XML-RPC interface used by web front ends.",
      "website": "https://github.com/rakshasa/rtorrent",
      "source": "https://github.com/rakshasa/rtorrent",
      "license": "GPL-2.0",
      "platforms": [
        "linux",
        "macos"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "rTorrent scores 80 out of 100 (grade B) on the torrent clients criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/torrent-clients/rtorrent/",
      "markdown": "https://privacyratings.com/torrent-clients/rtorrent/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rakshasa/rtorrent/blob/master/COPYING",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/rakshasa/rtorrent",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/rakshasa/rtorrent#donate-to-rtorrent-development",
          "note": "Funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:03.273Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "transmission",
      "category": "torrent-clients",
      "name": "Transmission",
      "description": "Lightweight BitTorrent client with native apps for macOS, Windows and Linux, plus a daemon with a web interface for headless servers and NAS devices.",
      "website": "https://transmissionbt.com",
      "source": "https://github.com/transmission/transmission",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Transmission scores 80 out of 100 (grade B) on the torrent clients criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/torrent-clients/transmission/",
      "markdown": "https://privacyratings.com/torrent-clients/transmission/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/transmission/transmission/blob/main/COPYING",
          "note": "GPL-2.0 or GPL-3.0, with some files under more permissive licenses."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://transmissionbt.com/",
          "note": "No third-party trackers, and the apps have no telemetry. The website's Cloudflare Web Analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://transmissionbt.com/donate",
          "note": "Volunteer project funded by donations, with no ads or bundled software."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:00:03.416Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "utorrent",
      "category": "torrent-clients",
      "name": "µTorrent",
      "description": "Proprietary BitTorrent client from BitTorrent, offered as a desktop client (Classic), a browser-based client (Web) and an Android app. The free versions show ads and paid plans remove them.",
      "website": "https://www.utorrent.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "µTorrent scores 0 out of 100 (grade F) on the torrent clients criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/torrent-clients/utorrent/",
      "markdown": "https://privacyratings.com/torrent-clients/utorrent/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.bittorrent.com/legal/privacy-policy/",
          "note": "The website loads Google Analytics and Google Tag Manager (automated test), and the privacy policy describes advertising cookies and third-party SDKs. The Android app contains 28 trackers per Exodus Privacy."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.utorrent.com/desktop/compare/",
          "note": "The free versions are ad-supported, and the privacy policy describes interest-based advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:04.027Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "bottles",
      "category": "games",
      "name": "Bottles",
      "description": "Linux app for running Windows software and games through Wine, with isolated environments called bottles, preset configurations for gaming or software, dependency installers and runner management.",
      "website": "https://usebottles.com",
      "source": "https://github.com/bottlesdevs/Bottles",
      "license": "GPL-3.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Bottles scores 80 out of 100 (grade B) on the games criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/games/bottles/",
      "markdown": "https://privacyratings.com/games/bottles/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/bottlesdevs/Bottles/blob/main/COPYING.md",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://usebottles.com/",
          "note": "No third-party trackers, and the app has no telemetry. The website's Cloudflare Web Analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/bottlesdevs/Bottles#sponsors",
          "note": "Funded by donations through Liberapay and GitHub Sponsors and by infrastructure sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:03.606Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "epic-games-launcher",
      "category": "games",
      "name": "Epic Games Launcher",
      "description": "Epic Games' desktop client for the Epic Games Store, used to buy, install and update PC games, including Fortnite and Unreal Engine, with friends, achievements and cloud saves.",
      "website": "https://store.epicgames.com",
      "license": null,
      "platforms": [
        "windows",
        "macos"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Epic Games Launcher scores 20 out of 100 (grade F) on the games criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/games/epic-games-launcher/",
      "markdown": "https://privacyratings.com/games/epic-games-launcher/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://legal.epicgames.com/epicgames/privacy-policy",
          "note": "The privacy policy describes automatic data collection for analytics, crash reporting and advertising measurement, including by third parties providing features of the service."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://legal.epicgames.com/epicgames/privacy-policy",
          "note": "Funded by game sales and store commissions. The privacy policy states Epic does not sell personal data or process it for targeted advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:03.887Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gog-galaxy",
      "category": "games",
      "name": "GOG Galaxy",
      "description": "GOG's optional desktop client for installing and updating DRM-free games bought on GOG.com, with cloud saves, achievements and integrations that combine game libraries from other platforms.",
      "website": "https://www.gog.com/galaxy",
      "license": null,
      "platforms": [
        "windows",
        "macos"
      ],
      "jurisdiction": {
        "code": "PL",
        "name": "Poland",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "GOG Galaxy scores 0 out of 100 (grade F) on the games criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in Poland: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/games/gog-galaxy/",
      "markdown": "https://privacyratings.com/games/gog-galaxy/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source. Only the platform integrations API is published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://support.gog.com/hc/en-us/articles/212632109-Privacy-Policy",
          "note": "The website loads Google Tag Manager (automated test), and the privacy policy lists third-party analytics and error tracking providers. GOG GALAXY collects activity and play time data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://support.gog.com/hc/en-us/articles/212632109-Privacy-Policy",
          "note": "Funded by game sales, but the privacy policy lists advertising and advertising measurement partners among the third parties that receive user data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:04.243Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "heroic-games-launcher",
      "category": "games",
      "name": "Heroic Games Launcher",
      "description": "Open source game launcher for Epic Games Store, GOG and Amazon Games on Linux, Windows and macOS. It replaces the official clients but still signs in to the user's store accounts.",
      "website": "https://heroicgameslauncher.com",
      "source": "https://github.com/Heroic-Games-Launcher/HeroicGamesLauncher",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Heroic Games Launcher scores 80 out of 100 (grade B) on the games criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/games/heroic-games-launcher/",
      "markdown": "https://privacyratings.com/games/heroic-games-launcher/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Heroic-Games-Launcher/HeroicGamesLauncher/blob/main/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Heroic-Games-Launcher/HeroicGamesLauncher",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://heroicgameslauncher.com/donate",
          "note": "Funded by donations through Patreon, Ko-fi and store referral links, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:13.122Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "itch-io",
      "category": "games",
      "name": "itch.io",
      "description": "Desktop app for itch.io, an online marketplace for independent games, used to browse, download, install, update and launch games bought or claimed on the site.",
      "website": "https://itch.io/app",
      "source": "https://github.com/itchio/itch",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 35,
      "coverage": 100,
      "summary": "itch.io scores 35 out of 100 (grade F) on the games criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets open source. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/games/itch-io/",
      "markdown": "https://privacyratings.com/games/itch-io/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://github.com/itchio/itch/blob/master/LICENSE",
          "note": "The desktop app is MIT-licensed, but the itch.io service it depends on is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://itch.io/docs/legal/privacy-policy",
          "note": "The website loads Google Analytics and Google Tag Manager (automated test), and the privacy policy names Google Analytics as a third party that collects data."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://itch.io/docs/creators/faq",
          "note": "Funded by a share of game sales chosen by each creator. The FAQ states ads are never placed on creator pages."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:04.335Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "lutris",
      "category": "games",
      "name": "Lutris",
      "description": "Open source game manager for Linux that installs and launches games from GOG, Steam, Epic and other stores, emulators and Windows games through Wine, using community install scripts from lutris.net.",
      "website": "https://lutris.net",
      "source": "https://github.com/lutris/lutris",
      "license": "GPL-3.0",
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Lutris scores 80 out of 100 (grade B) on the games criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/games/lutris/",
      "markdown": "https://privacyratings.com/games/lutris/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/lutris/lutris/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://lutris.net/",
          "note": "No third-party trackers, and the client has no telemetry. The website's Cloudflare Web Analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://lutris.net/donate",
          "note": "Not-for-profit project funded by donations and grants, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:04.194Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "playnite",
      "category": "games",
      "name": "Playnite",
      "description": "Open source game library manager for Windows that imports games from Steam, Epic, GOG, emulators and other launchers into one interface, with metadata downloads, a fullscreen mode and extensions.",
      "website": "https://playnite.link",
      "source": "https://github.com/JosefNemec/Playnite",
      "license": "MIT",
      "platforms": [
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Playnite scores 80 out of 100 (grade B) on the games criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/games/playnite/",
      "markdown": "https://privacyratings.com/games/playnite/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/JosefNemec/Playnite/blob/master/LICENSE.md",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/JosefNemec/Playnite#privacy-statement",
          "note": "The privacy statement says Playnite stores no user information and keeps library data on the device. No analytics on the website or in the app."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/JosefNemec/Playnite#readme",
          "note": "Funded by donations through Patreon and Ko-fi, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:04.767Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "steam",
      "category": "games",
      "name": "Steam",
      "description": "Valve's game store and launcher for buying, installing and updating PC games, with friends, chat, cloud saves, workshop mods and a mobile app for account security and trading.",
      "website": "https://store.steampowered.com",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "android",
        "ios",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Steam scores 20 out of 100 (grade F) on the games criteria. It meets 1 of 4 criteria: no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/games/steam/",
      "markdown": "https://privacyratings.com/games/steam/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://store.steampowered.com/privacy_agreement/",
          "note": "The client sends playtime, device and crash data to Valve as part of the service, and the website offers optional third-party analytics cookies. The Android app has no trackers per Exodus Privacy."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://store.steampowered.com/privacy_agreement/",
          "note": "Funded by game sales, with no third-party ads. The privacy policy states Valve does not sell personal data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:04.611Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cloudconvert",
      "category": "file-converters",
      "name": "CloudConvert",
      "description": "An online file conversion service and API that converts audio, video, documents, ebooks, archives, images and spreadsheets on its servers, with files deleted after processing.",
      "website": "https://cloudconvert.com",
      "license": null,
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 45,
      "coverage": 100,
      "summary": "CloudConvert scores 45 out of 100 (grade D) on the file converters criteria. It meets 1 of 4 criteria: no ads or data sales. It partly meets no trackers or telemetry and independent audit. It does not meet open source. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/file-converters/cloudconvert/",
      "markdown": "https://privacyratings.com/file-converters/cloudconvert/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://cloudconvert.com/privacy",
          "note": "Only technically necessary cookies and no third-party analytics, but first-party telemetry tied to IP address and user ID is collected by default."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://cloudconvert.com/pricing",
          "note": "Funded by paid plans and API credits, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://cloudconvert.com/security",
          "note": "Only the ISO 27001 certificate is public, not the audit report."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:04.420Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "convertx",
      "category": "file-converters",
      "name": "ConvertX",
      "description": "A self-hosted web app for converting files between over a thousand formats, using converters such as FFmpeg, LibreOffice, Pandoc and ImageMagick, with password-protected accounts.",
      "website": "https://github.com/C4illin/ConvertX",
      "source": "https://github.com/C4illin/ConvertX",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "ConvertX scores 80 out of 100 (grade B) on the file converters criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-converters/convertx/",
      "markdown": "https://privacyratings.com/file-converters/convertx/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/C4illin/ConvertX/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/C4illin/ConvertX",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/C4illin/ConvertX/blob/main/.github/FUNDING.yml",
          "note": "Funded through GitHub Sponsors, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:04.335Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ffmpeg",
      "category": "file-converters",
      "name": "FFmpeg",
      "description": "Cross-platform command-line tools and libraries to record, convert and stream audio and video, supporting a wide range of codecs and formats.",
      "website": "https://ffmpeg.org",
      "source": "https://code.ffmpeg.org/FFmpeg/FFmpeg",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "FFmpeg scores 80 out of 100 (grade B) on the file converters criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-converters/ffmpeg/",
      "markdown": "https://privacyratings.com/file-converters/ffmpeg/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://code.ffmpeg.org/FFmpeg/FFmpeg/src/branch/master/LICENSE.md",
          "note": "LGPL-2.1 or later, with optional GPL-2.0 or later components."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://code.ffmpeg.org/FFmpeg/FFmpeg",
          "note": "No telemetry or analytics in the source code, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://ffmpeg.org/donations.html",
          "note": "Volunteer project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:14.908Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "file-converter",
      "category": "file-converters",
      "name": "File Converter",
      "description": "A Windows tool that converts and compresses audio, video, image and document files from the File Explorer context menu, using customizable presets.",
      "website": "https://file-converter.io",
      "source": "https://github.com/Tichau/FileConverter",
      "license": "GPL-3.0",
      "platforms": [
        "windows"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "File Converter scores 80 out of 100 (grade B) on the file converters criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-converters/file-converter/",
      "markdown": "https://privacyratings.com/file-converters/file-converter/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Tichau/FileConverter/blob/master/LICENSE.md",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://file-converter.io/",
          "note": "No third-party trackers, and the app collects no data. The website's counter.dev analytics are cookieless and aggregate-only."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://file-converter.io/",
          "note": "Free, funded by donations, with no ads or data collection."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:04.961Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "handbrake",
      "category": "file-converters",
      "name": "HandBrake",
      "description": "A video transcoder that converts video from nearly any format to modern codecs such as H.264, H.265 and AV1, with presets for common devices.",
      "website": "https://handbrake.fr",
      "source": "https://github.com/HandBrake/HandBrake",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "HandBrake scores 80 out of 100 (grade B) on the file converters criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-converters/handbrake/",
      "markdown": "https://privacyratings.com/file-converters/handbrake/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/HandBrake/HandBrake/blob/master/LICENSE",
          "note": "Mostly GPL-2.0, with some GPL-2.0-or-later and LGPL-2.1 files."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://handbrake.fr/privacy.php",
          "note": "No usage or error data is collected. The only network feature is an update check that can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://handbrake.fr/privacy.php",
          "note": "Volunteer project with no company or sponsors, and no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:05.004Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "imagemagick",
      "category": "file-converters",
      "name": "ImageMagick",
      "description": "A command-line suite and set of libraries for creating, editing, converting and composing raster and vector images in over 200 formats.",
      "website": "https://imagemagick.org",
      "source": "https://github.com/ImageMagick/ImageMagick",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "ImageMagick scores 30 out of 100 (grade F) on the file converters criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/file-converters/imagemagick/",
      "markdown": "https://privacyratings.com/file-converters/imagemagick/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://imagemagick.org/license/",
          "note": "All code is public under the ImageMagick License, an Apache-2.0-derived source-available license that is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The website loads Google AdSense."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://imagemagick.org/support/",
          "note": "The website shows Google AdSense ads, alongside sponsorships and donations."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:05.007Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "pandoc",
      "category": "file-converters",
      "name": "Pandoc",
      "description": "A command-line tool and Haskell library that converts documents between markup formats such as Markdown, HTML, LaTeX, DOCX, EPUB and PDF.",
      "website": "https://pandoc.org",
      "source": "https://github.com/jgm/pandoc",
      "license": "GPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Pandoc scores 80 out of 100 (grade B) on the file converters criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-converters/pandoc/",
      "markdown": "https://privacyratings.com/file-converters/pandoc/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jgm/pandoc/blob/main/COPYRIGHT",
          "note": "GPL-2.0 or later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jgm/pandoc",
          "note": "No telemetry or analytics in the source code, and the website loads no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/jgm/pandoc",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:00:05.455Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "switcheroo",
      "category": "file-converters",
      "name": "Switcheroo",
      "description": "A GNOME app for converting and manipulating images, such as changing format, resizing and compressing, built on ImageMagick.",
      "website": "https://apps.gnome.org/Converter/",
      "source": "https://gitlab.com/adhami3310/Switcheroo",
      "license": null,
      "platforms": [
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Switcheroo scores 80 out of 100 (grade B) on the file converters criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-converters/switcheroo/",
      "markdown": "https://privacyratings.com/file-converters/switcheroo/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/adhami3310/Switcheroo/-/blob/main/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/adhami3310/Switcheroo",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://gitlab.com/adhami3310/Switcheroo",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:05.236Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vert",
      "category": "file-converters",
      "name": "VERT",
      "description": "Web-based file converter for images, audio and documents that runs locally in the browser using WebAssembly. Video conversions are processed on the VERT server, and the app can be self-hosted.",
      "website": "https://vert.sh",
      "source": "https://github.com/VERT-sh/VERT",
      "license": "AGPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "VERT scores 80 out of 100 (grade B) on the file converters criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/file-converters/vert/",
      "markdown": "https://privacyratings.com/file-converters/vert/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/VERT-sh/VERT/blob/main/LICENSE",
          "note": "AGPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://vert.sh/privacy/",
          "note": "No third-party trackers or cookies. Self-hosted Plausible analytics are cookieless and aggregate-only, and can be turned off in settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://vert.sh/about/",
          "note": "Funded by donations, with no ads. The privacy policy states no data about users is collected or stored."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:13.481Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "adobe-illustrator",
      "category": "creative-tools",
      "name": "Adobe Illustrator",
      "description": "A vector graphics editor from Adobe for illustrations, logos, typography and print or web layouts, part of Adobe Creative Cloud.",
      "website": "https://www.adobe.com/products/illustrator.html",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "ios"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Adobe Illustrator scores 10 out of 100 (grade F) on the creative tools criteria. It partly meets independent audit. It does not meet open source, no trackers or telemetry and no ads or data sales. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/creative-tools/adobe-illustrator/",
      "markdown": "https://privacyratings.com/creative-tools/adobe-illustrator/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.adobe.com/privacy/policy.html",
          "note": "The privacy policy discloses website and app activity to advertising partners and social media platforms. Content analysis of cloud files for product improvement and desktop app usage data are on by default for personal accounts and can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.adobe.com/privacy/policy.html",
          "note": "Sold by subscription, but the privacy policy shares personal information with advertising partners and with third parties for their own marketing."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.adobe.com/trust/compliance/compliance-list.html",
          "note": "Adobe lists SOC 2 and ISO 27001 audits, but SOC 2 reports are only shared under NDA; only SOC 3 summary reports are public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:35.005Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "adobe-lightroom",
      "category": "creative-tools",
      "name": "Adobe Lightroom",
      "description": "A photo organizing and editing app from Adobe for raw processing, adjustments and cloud-synced photo libraries, part of Adobe Creative Cloud.",
      "website": "https://www.adobe.com/products/photoshop-lightroom.html",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "ios",
        "android",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Adobe Lightroom scores 10 out of 100 (grade F) on the creative tools criteria. It partly meets independent audit. It does not meet open source, no trackers or telemetry and no ads or data sales. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/creative-tools/adobe-lightroom/",
      "markdown": "https://privacyratings.com/creative-tools/adobe-lightroom/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.adobe.com/privacy/policy.html",
          "note": "The privacy policy discloses website and app activity to advertising partners and social media platforms. Content analysis of cloud files for product improvement and desktop app usage data are on by default for personal accounts and can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.adobe.com/privacy/policy.html",
          "note": "Sold by subscription, but the privacy policy shares personal information with advertising partners and with third parties for their own marketing."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.adobe.com/trust/compliance/compliance-list.html",
          "note": "Adobe lists SOC 2 and ISO 27001 audits, but SOC 2 reports are only shared under NDA; only SOC 3 summary reports are public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:35.007Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "adobe-photoshop",
      "category": "creative-tools",
      "name": "Adobe Photoshop",
      "description": "A raster image editor from Adobe for photo editing, compositing and digital painting, with generative AI features, part of Adobe Creative Cloud.",
      "website": "https://www.adobe.com/products/photoshop.html",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "ios",
        "android",
        "web"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Adobe Photoshop scores 10 out of 100 (grade F) on the creative tools criteria. It partly meets independent audit. It does not meet open source, no trackers or telemetry and no ads or data sales. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/creative-tools/adobe-photoshop/",
      "markdown": "https://privacyratings.com/creative-tools/adobe-photoshop/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.adobe.com/privacy/policy.html",
          "note": "The privacy policy discloses website and app activity to advertising partners and social media platforms. Content analysis of cloud files for product improvement and desktop app usage data are on by default for personal accounts and can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.adobe.com/privacy/policy.html",
          "note": "Sold by subscription, but the privacy policy shares personal information with advertising partners and with third parties for their own marketing."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.adobe.com/trust/compliance/compliance-list.html",
          "note": "Adobe lists SOC 2 and ISO 27001 audits, but SOC 2 reports are only shared under NDA; only SOC 3 summary reports are public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:35.238Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "adobe-premiere",
      "category": "creative-tools",
      "name": "Adobe Premiere",
      "description": "A non-linear video editor from Adobe, formerly called Premiere Pro, for editing, color grading and audio mixing, part of Adobe Creative Cloud.",
      "website": "https://www.adobe.com/products/premiere.html",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "ios",
        "android"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Adobe Premiere scores 10 out of 100 (grade F) on the creative tools criteria. It partly meets independent audit. It does not meet open source, no trackers or telemetry and no ads or data sales. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/creative-tools/adobe-premiere/",
      "markdown": "https://privacyratings.com/creative-tools/adobe-premiere/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.adobe.com/privacy/policy.html",
          "note": "The privacy policy discloses website and app activity to advertising partners and social media platforms. Content analysis of cloud files for product improvement and desktop app usage data are on by default for personal accounts and can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.adobe.com/privacy/policy.html",
          "note": "Sold by subscription, but the privacy policy shares personal information with advertising partners and with third parties for their own marketing."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.adobe.com/trust/compliance/compliance-list.html",
          "note": "Adobe lists SOC 2 and ISO 27001 audits, but SOC 2 reports are only shared under NDA; only SOC 3 summary reports are public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:35.456Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "ardour",
      "category": "creative-tools",
      "name": "Ardour",
      "description": "A digital audio workstation for recording, editing and mixing multi-track audio and MIDI on Windows, macOS and Linux.",
      "website": "https://ardour.org",
      "source": "https://github.com/Ardour/ardour",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Ardour scores 65 out of 100 (grade C) on the creative tools criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/creative-tools/ardour/",
      "markdown": "https://privacyratings.com/creative-tools/ardour/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Ardour/ardour/blob/master/COPYING",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://ardour.org/privacy.html",
          "note": "Official builds contact ardour.org at startup to check for announcements, sending a hashed IP address, the operating system name and country. No third-party trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://community.ardour.org/download",
          "note": "Funded by payments and subscriptions for ready-to-run builds, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:18.748Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "aseprite",
      "category": "creative-tools",
      "name": "Aseprite",
      "description": "An animated sprite editor and pixel art tool for Windows, macOS and Linux.",
      "website": "https://www.aseprite.org",
      "source": "https://github.com/aseprite/aseprite",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "AR",
        "name": "Argentina",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Aseprite scores 50 out of 100 (grade D) on the creative tools criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Argentina: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/creative-tools/aseprite/",
      "markdown": "https://privacyratings.com/creative-tools/aseprite/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/aseprite/aseprite/blob/main/EULA.txt",
          "note": "All code is public under a source-available EULA that limits redistribution and is not OSI-approved."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/aseprite/aseprite/blob/main/src/app/check_update.cpp",
          "note": "Official builds send a persistent ID and launch and exit counts to the vendor's update server, with no setting to turn this off. Crash reports are only sent with consent."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.aseprite.org/privacy/",
          "note": "Paid software with no ads. The privacy policy states that user data is not sold or given to other companies."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:13.602Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "audacity",
      "category": "creative-tools",
      "name": "Audacity",
      "description": "A multi-track audio editor and recorder for Windows, macOS and Linux.",
      "website": "https://www.audacityteam.org",
      "source": "https://github.com/audacity/audacity",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "CY",
        "name": "Cyprus",
        "eyes": null,
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "C",
      "score": 65,
      "coverage": 100,
      "summary": "Audacity scores 65 out of 100 (grade C) on the creative tools criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It partly meets no trackers or telemetry. It does not meet independent audit. It is based in Cyprus: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR).",
      "url": "https://privacyratings.com/creative-tools/audacity/",
      "markdown": "https://privacyratings.com/creative-tools/audacity/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/audacity/audacity/blob/master/LICENSE.txt",
          "note": "GPL-3.0 and GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "partial",
          "evidence": "https://www.audacityteam.org/legal/privacy-notice/",
          "note": "The update check is on by default and can be turned off. Error reports and usage analytics are opt-in, and the website uses Matomo analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.audacityteam.org/legal/privacy-notice/",
          "note": "Free app with no ads. The privacy notice describes no advertising or sale of user data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:14.319Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "blender",
      "category": "creative-tools",
      "name": "Blender",
      "description": "A 3D creation suite for modeling, sculpting, texturing, rigging, animation, rendering, compositing, motion tracking and video editing, extendable with add-ons.",
      "website": "https://www.blender.org",
      "source": "https://github.com/blender/blender",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Blender scores 80 out of 100 (grade B) on the creative tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the Netherlands: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/creative-tools/blender/",
      "markdown": "https://privacyratings.com/creative-tools/blender/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/blender/blender/blob/main/COPYING",
          "note": "GPL-2.0 or later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.blender.org/privacy-policy/",
          "note": "The website states that no third party tracks visitors, and the software needs no account or internet access."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://fund.blender.org/",
          "note": "Funded by the Blender Development Fund and donations. The website carries no third-party ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:14.481Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "canva",
      "category": "creative-tools",
      "name": "Canva",
      "description": "An online design platform for creating graphics, presentations, documents, videos and websites from templates, with AI features and team collaboration.",
      "website": "https://www.canva.com",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "ios",
        "android"
      ],
      "jurisdiction": {
        "code": "AU",
        "name": "Australia",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "Canva scores 10 out of 100 (grade F) on the creative tools criteria. It partly meets independent audit. It does not meet open source, no trackers or telemetry and no ads or data sales. It is based in Australia: Five Eyes member; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/creative-tools/canva/",
      "markdown": "https://privacyratings.com/creative-tools/canva/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.canva.com/policies/privacy-policy/",
          "note": "Uses third-party analytics tools and ad networks such as Facebook, Google, LiveRamp and Taboola. User content and activity may be used to train AI unless turned off in privacy settings."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.canva.com/policies/privacy-policy/",
          "note": "The privacy policy describes personalized ads with partners such as Facebook, Google, LiveRamp and Taboola, on the service and other sites."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.canva.com/security/",
          "note": "Lists ISO 27001, SOC 2 Type II and SOC 3 audits, but the full reports are not public."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:00:18.893Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "cinelerra-gg-infinity",
      "category": "creative-tools",
      "name": "Cinelerra GG Infinity",
      "description": "A non-linear video editor and compositor for Linux, with multi-track editing, effects, transitions and titling.",
      "website": "https://www.cinelerra-gg.org",
      "source": "https://github.com/cinelerra-gg/cinelerra-gg",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Cinelerra GG Infinity scores 80 out of 100 (grade B) on the creative tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/creative-tools/cinelerra-gg-infinity/",
      "markdown": "https://privacyratings.com/creative-tools/cinelerra-gg-infinity/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/cinelerra-gg/cinelerra-gg/blob/master/cinelerra-5.1/COPYING",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.cinelerra-gg.org/en/privacy",
          "note": "The website uses no advertising networks or behavioural tracking, and the software contains no telemetry."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.cinelerra-gg.org/en/privacy",
          "note": "Non-commercial community project with no advertising networks."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:02:04.909Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "darktable",
      "category": "creative-tools",
      "name": "DarkTable",
      "description": "A photography workflow application and non-destructive raw developer for managing and editing digital negatives.",
      "website": "https://www.darktable.org",
      "source": "https://github.com/darktable-org/darktable",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "DarkTable scores 80 out of 100 (grade B) on the creative tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/creative-tools/darktable/",
      "markdown": "https://privacyratings.com/creative-tools/darktable/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/darktable-org/darktable/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/darktable-org/darktable",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.darktable.org/about/",
          "note": "Free and open source project developed by volunteers, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:14.563Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "davinci-resolve",
      "category": "creative-tools",
      "name": "DaVinci Resolve",
      "description": "A video editing, color grading, visual effects and audio post-production application from Blackmagic Design.",
      "website": "https://www.blackmagicdesign.com/products/davinciresolve",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux",
        "ios"
      ],
      "jurisdiction": {
        "code": "AU",
        "name": "Australia",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "agreement"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 10,
      "coverage": 100,
      "summary": "DaVinci Resolve scores 10 out of 100 (grade F) on the creative tools criteria. It partly meets no ads or data sales. It does not meet open source, no trackers or telemetry and independent audit. It is based in Australia: Five Eyes member; CLOUD Act data access agreement with the US.",
      "url": "https://privacyratings.com/creative-tools/davinci-resolve/",
      "markdown": "https://privacyratings.com/creative-tools/davinci-resolve/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.blackmagicdesign.com/privacy",
          "note": "The website loads Google Analytics and uses remarketing cookies to advertise on third-party websites."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.blackmagicdesign.com/privacy",
          "note": "Funded by hardware and software sales with no ads in the app, and personal information is not sold, but the website uses remarketing to advertise on third-party sites."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:19.151Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "figma",
      "category": "creative-tools",
      "name": "Figma",
      "description": "A browser-based collaborative interface design and prototyping tool, with a desktop app, whiteboarding, developer handoff and AI features.",
      "website": "https://www.figma.com",
      "license": null,
      "platforms": [
        "web",
        "windows",
        "macos",
        "ios",
        "android"
      ],
      "jurisdiction": {
        "code": "US",
        "name": "United States",
        "eyes": "Five Eyes",
        "eu": false,
        "gdpr": false,
        "cloud_act": "provider"
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 20,
      "coverage": 100,
      "summary": "Figma scores 20 out of 100 (grade F) on the creative tools criteria. It partly meets no ads or data sales and independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.",
      "url": "https://privacyratings.com/creative-tools/figma/",
      "markdown": "https://privacyratings.com/creative-tools/figma/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.figma.com/legal/privacy/",
          "note": "Uses Google Analytics and third-party advertising trackers. Content training for AI is on by default for Starter and Professional teams and can be turned off."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.figma.com/legal/privacy/",
          "note": "Sold by subscription, but the privacy policy says its retargeting pixels and third-party cookies may count as a sale or sharing of personal information for advertising."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "partial",
          "evidence": "https://www.figma.com/security/",
          "note": "Lists SOC 2 Type 2, SOC 3 and ISO 27001 audits, with reports provided through its Trust Center rather than published in full."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:20.234Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "flowblade",
      "category": "creative-tools",
      "name": "FlowBlade",
      "description": "A multi-track non-linear video editor for Linux, based on the MLT framework.",
      "website": "https://jliljebl.github.io/flowblade",
      "source": "https://github.com/jliljebl/flowblade",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "FlowBlade scores 80 out of 100 (grade B) on the creative tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/creative-tools/flowblade/",
      "markdown": "https://privacyratings.com/creative-tools/flowblade/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jliljebl/flowblade/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/jliljebl/flowblade",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/jliljebl/flowblade",
          "note": "Free and open source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:14.572Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "freecad",
      "category": "creative-tools",
      "name": "FreeCAD",
      "description": "A parametric 3D CAD modeler for product design, mechanical engineering and architecture, with a Python scripting interface.",
      "website": "https://www.freecad.org",
      "source": "https://github.com/FreeCAD/FreeCAD",
      "license": "LGPL-2.1",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "BE",
        "name": "Belgium",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "FreeCAD scores 80 out of 100 (grade B) on the creative tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Belgium: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/creative-tools/freecad/",
      "markdown": "https://privacyratings.com/creative-tools/freecad/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/FreeCAD/FreeCAD/blob/main/LICENSE",
          "note": "LGPL-2.0 or later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://www.freecad.org/privacy.php?lang=en",
          "note": "The software does not collect or send personal data, and the website contains no trackers."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.freecad.org/privacy.php?lang=en",
          "note": "Funded by donations through the FreeCAD Project Association, with no ads in the software or website."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:21.215Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "gimp",
      "category": "creative-tools",
      "name": "Gimp",
      "description": "A free, open source, cross-platform raster image editor for photo retouching, image composition and image authoring, with support for many file formats.",
      "website": "https://www.gimp.org",
      "source": "https://github.com/GNOME/gimp",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Gimp scores 80 out of 100 (grade B) on the creative tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/creative-tools/gimp/",
      "markdown": "https://privacyratings.com/creative-tools/gimp/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/GNOME/gimp/blob/master/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/GNOME/gimp",
          "note": "No telemetry or analytics in the source code. The update check can be turned off and only downloads a version list from gimp.org."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.gimp.org/donating/",
          "note": "Funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:14.848Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "glaxnimate",
      "category": "creative-tools",
      "name": "Glaxnimate",
      "description": "A vector animation program by KDE for creating 2D animations, with support for Lottie, animated SVG, GIF and video export.",
      "website": "https://glaxnimate.org",
      "source": "https://github.com/KDE/glaxnimate",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Glaxnimate scores 80 out of 100 (grade B) on the creative tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/creative-tools/glaxnimate/",
      "markdown": "https://privacyratings.com/creative-tools/glaxnimate/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/KDE/glaxnimate/blob/master/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/KDE/glaxnimate",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://glaxnimate.org/contributing/",
          "note": "Volunteer KDE project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:22.111Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "inkscape",
      "category": "creative-tools",
      "name": "InkScape",
      "description": "A free, open source vector graphics editor for illustrations, icons, logos, diagrams, maps and web graphics, using SVG as its native format.",
      "website": "https://inkscape.org",
      "source": "https://gitlab.com/inkscape/inkscape",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "InkScape scores 80 out of 100 (grade B) on the creative tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/creative-tools/inkscape/",
      "markdown": "https://privacyratings.com/creative-tools/inkscape/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://gitlab.com/inkscape/inkscape/-/blob/master/COPYING",
          "note": "GPL-2.0 or later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://inkscape.org/about/privacy/",
          "note": "The privacy policy states that the software does not collect or transmit any information."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://inkscape.org/about/privacy/",
          "note": "Free and open source project with no ads. The privacy policy describes no advertising or sale of user data."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:15.194Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "kdenlive",
      "category": "creative-tools",
      "name": "Kdenlive",
      "description": "A non-linear video editor from KDE, based on the MLT framework, Qt and FFmpeg.",
      "website": "https://kdenlive.org",
      "source": "https://invent.kde.org/multimedia/kdenlive",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "DE",
        "name": "Germany",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Kdenlive scores 80 out of 100 (grade B) on the creative tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/creative-tools/kdenlive/",
      "markdown": "https://privacyratings.com/creative-tools/kdenlive/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://invent.kde.org/multimedia/kdenlive/-/blob/master/COPYING",
          "note": "GPL-2.0 or later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://kde.org/privacypolicy-apps/",
          "note": "KDE applications only include telemetry as an opt-in feature. The website uses KDE's self-hosted, cookieless Matomo."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://kde.org/donate/",
          "note": "Funded by donations to KDE e.V., with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:15.596Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "krita",
      "category": "creative-tools",
      "name": "Krita",
      "description": "A free and open source digital painting application for Windows, macOS and Linux, developed by the Krita Foundation and KDE.",
      "website": "https://krita.org/en",
      "source": "https://github.com/KDE/krita",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": {
        "code": "NL",
        "name": "Netherlands",
        "eyes": "Nine Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Krita scores 80 out of 100 (grade B) on the creative tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit. It is based in the Netherlands: Nine Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/creative-tools/krita/",
      "markdown": "https://privacyratings.com/creative-tools/krita/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/KDE/krita/blob/master/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://krita.org/en/privacy-statement/",
          "note": "The app collects no user data, and network features such as the news feed are optional. The website uses KDE's self-hosted, cookieless Matomo."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://fund.krita.org/",
          "note": "Funded by the Krita Development Fund, donations and sales, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:16.081Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "libresprite",
      "category": "creative-tools",
      "name": "LibreSprite",
      "description": "An animated sprite editor and pixel art tool, forked from the last GPL-licensed version of Aseprite.",
      "website": "https://libresprite.github.io",
      "source": "https://github.com/LibreSprite/LibreSprite",
      "license": "GPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "LibreSprite scores 80 out of 100 (grade B) on the creative tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/creative-tools/libresprite/",
      "markdown": "https://privacyratings.com/creative-tools/libresprite/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/LibreSprite/LibreSprite/blob/master/LICENSE.txt",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/LibreSprite/LibreSprite",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/LibreSprite/LibreSprite",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:22.257Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "lmms",
      "category": "creative-tools",
      "name": "LMMS",
      "description": "A digital audio workstation for making music, with a pattern and song editor, piano roll, built-in synthesizers and support for VST and LADSPA plugins.",
      "website": "https://lmms.io",
      "source": "https://github.com/LMMS/lmms",
      "license": "GPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "LMMS scores 80 out of 100 (grade B) on the creative tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/creative-tools/lmms/",
      "markdown": "https://privacyratings.com/creative-tools/lmms/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/LMMS/lmms/blob/master/LICENSE.txt",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/LMMS/lmms",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://lmms.io/get-involved",
          "note": "Volunteer project funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:22.859Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "natron",
      "category": "creative-tools",
      "name": "Natron",
      "description": "A node-based video compositing application for visual effects and motion graphics.",
      "website": "https://natrongithub.github.io",
      "source": "https://github.com/NatronGitHub/Natron",
      "license": "GPL-2.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Natron scores 80 out of 100 (grade B) on the creative tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/creative-tools/natron/",
      "markdown": "https://privacyratings.com/creative-tools/natron/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/NatronGitHub/Natron/blob/RB-2.6/LICENSE.txt",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/NatronGitHub/Natron",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/NatronGitHub/Natron",
          "note": "Free and open source community project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:15.393Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "obs-studio",
      "category": "creative-tools",
      "name": "OBS Studio",
      "description": "Free and open source software for video recording and live streaming on Windows, macOS and Linux.",
      "website": "https://obsproject.com",
      "source": "https://github.com/obsproject/obs-studio",
      "license": "GPL-2.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "OBS Studio scores 50 out of 100 (grade D) on the creative tools criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/creative-tools/obs-studio/",
      "markdown": "https://privacyratings.com/creative-tools/obs-studio/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/obsproject/obs-studio/blob/master/COPYING",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics and Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://obsproject.com/contribute",
          "note": "Funded by sponsors and donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.gstatic.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:15.915Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "openshot",
      "category": "creative-tools",
      "name": "OpenShot",
      "description": "A free, open source, cross-platform video editor for trimming, effects, titles and animation.",
      "website": "https://www.openshot.org",
      "source": "https://github.com/OpenShot/openshot-qt",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "OpenShot scores 50 out of 100 (grade D) on the creative tools criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/creative-tools/openshot/",
      "markdown": "https://privacyratings.com/creative-tools/openshot/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/OpenShot/openshot-qt/blob/develop/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics, Google DoubleClick and Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.openshot.org/donate/",
          "note": "Funded by donations, with no ads in the app."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google DoubleClick",
            "host": "securepubads.g.doubleclick.net",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:16.290Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "opentoonz",
      "category": "creative-tools",
      "name": "OpenToonz",
      "description": "A 2D animation program based on Toonz, used for traditional and digital animation, with scanning, ink and paint, and effects tools.",
      "website": "https://opentoonz.github.io",
      "source": "https://github.com/opentoonz/opentoonz",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": {
        "code": "JP",
        "name": "Japan",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "OpenToonz scores 50 out of 100 (grade D) on the creative tools criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Japan: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/creative-tools/opentoonz/",
      "markdown": "https://privacyratings.com/creative-tools/opentoonz/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/opentoonz/opentoonz/blob/master/LICENSE.txt",
          "note": "BSD-3-Clause."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The app has no telemetry, but the website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/opentoonz/opentoonz",
          "note": "Free project developed by DWANGO and volunteers, with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:23.004Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "paint-net",
      "category": "creative-tools",
      "name": "Paint.NET",
      "description": "A freeware image and photo editor for Windows with layers, unlimited undo, effects and plugin support.",
      "website": "https://paint.net",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Paint.NET scores 0 out of 100 (grade F) on the creative tools criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/creative-tools/paint-net/",
      "markdown": "https://privacyratings.com/creative-tools/paint-net/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": "https://paint.net/license.html",
          "note": "Freeware with a proprietary license. The source is not published."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://paint.net/privacy.html",
          "note": "The website uses Google AdSense. The app sends anonymous update checks and install statistics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://paint.net/privacy.html",
          "note": "The website is funded in part by Google AdSense ads. The app itself shows no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:16.263Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "pencil2d",
      "category": "creative-tools",
      "name": "Pencil2D",
      "description": "A 2D hand-drawn animation program for sketching, inking and painting frame-by-frame animation with bitmap and vector layers.",
      "website": "https://www.pencil2d.org",
      "source": "https://github.com/pencil2d/pencil",
      "license": "GPL-2.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Pencil2D scores 50 out of 100 (grade D) on the creative tools criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/creative-tools/pencil2d/",
      "markdown": "https://privacyratings.com/creative-tools/pencil2d/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/pencil2d/pencil/blob/master/LICENSE.TXT",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The app has no telemetry, but the website loads Google Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.pencil2d.org/contribute/",
          "note": "Not-for-profit volunteer project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          },
          {
            "name": "YouTube embed",
            "host": "www.youtube.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:00:23.244Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "penpot",
      "category": "creative-tools",
      "name": "Penpot",
      "description": "An open source design and prototyping platform for teams, based on open web standards such as SVG, CSS and HTML, available as a hosted service or self-hosted.",
      "website": "https://penpot.app",
      "source": "https://github.com/penpot/penpot",
      "license": "MPL-2.0",
      "platforms": [
        "web"
      ],
      "jurisdiction": {
        "code": "ES",
        "name": "Spain",
        "eyes": "Fourteen Eyes",
        "eu": true,
        "gdpr": true,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Penpot scores 50 out of 100 (grade D) on the creative tools criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Spain: Fourteen Eyes member; EU member (GDPR).",
      "url": "https://privacyratings.com/creative-tools/penpot/",
      "markdown": "https://privacyratings.com/creative-tools/penpot/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/penpot/penpot/blob/develop/LICENSE",
          "note": "MPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://penpot.app/cookie",
          "note": "The website and hosted app use Google Analytics and PostHog analytics cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://penpot.app/pricing",
          "note": "Funded by paid plans and self-hosting support, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:24.411Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "photopea",
      "category": "creative-tools",
      "name": "PhotoPea",
      "description": "A browser-based image editor for raster and vector graphics that opens PSD, XCF, Sketch and many other formats, processing files locally.",
      "website": "https://www.photopea.com",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "PhotoPea scores 0 out of 100 (grade F) on the creative tools criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/creative-tools/photopea/",
      "markdown": "https://privacyratings.com/creative-tools/photopea/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source web app. The linked GitHub repository only holds documentation and issues."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.photopea.com/ads.txt",
          "note": "Ads are served through third-party ad networks including Google and other programmatic exchanges."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://www.photopea.com/tuts/ads-in-photopea-do-not-work-what-to-do/",
          "note": "Ads are the main source of income."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:01:16.251Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "pinta",
      "category": "creative-tools",
      "name": "Pinta",
      "description": "A simple open source drawing and image editing program with layers, adjustments, effects and unlimited undo, for Windows, macOS and Linux.",
      "website": "https://www.pinta-project.com/",
      "source": "https://github.com/PintaProject/Pinta",
      "license": "MIT",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Pinta scores 80 out of 100 (grade B) on the creative tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/creative-tools/pinta/",
      "markdown": "https://privacyratings.com/creative-tools/pinta/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/PintaProject/Pinta/blob/master/license-mit.txt",
          "note": "MIT."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/PintaProject/Pinta",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/PintaProject/Pinta",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:24.563Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "pixlrx",
      "category": "creative-tools",
      "name": "Pixlr Express",
      "description": "A browser-based image editor with templates and AI tools, with a free tier and paid plans.",
      "website": "https://pixlr.com/express/",
      "license": null,
      "platforms": [],
      "jurisdiction": {
        "code": "SG",
        "name": "Singapore",
        "eyes": null,
        "eu": false,
        "gdpr": false,
        "cloud_act": null
      },
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 0,
      "coverage": 100,
      "summary": "Pixlr Express scores 0 out of 100 (grade F) on the creative tools criteria. It does not meet open source, no trackers or telemetry, no ads or data sales and independent audit. It is based in Singapore: Not in the Five, Nine or Fourteen Eyes.",
      "url": "https://privacyratings.com/creative-tools/pixlrx/",
      "markdown": "https://privacyratings.com/creative-tools/pixlrx/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "Closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://pixlr.com/privacy-policy/",
          "note": "The privacy policy describes tracking cookies and third-party advertising partners."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": "https://pixlr.com/privacy-policy/",
          "note": "The free tier is ad-supported through third-party advertising partners."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          }
        ],
        "tested_at": "2026-10-01T07:01:16.508Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "rawtherapee",
      "category": "creative-tools",
      "name": "RawTherapee",
      "description": "A cross-platform raw photo processor for non-destructive editing of raw digital photos.",
      "website": "https://rawtherapee.com",
      "source": "https://github.com/Beep6581/RawTherapee",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "RawTherapee scores 80 out of 100 (grade B) on the creative tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/creative-tools/rawtherapee/",
      "markdown": "https://privacyratings.com/creative-tools/rawtherapee/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Beep6581/RawTherapee/blob/dev/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/Beep6581/RawTherapee",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://rawtherapee.com/about/",
          "note": "Free and open source project developed by volunteers, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:17.466Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "scribus",
      "category": "creative-tools",
      "name": "Scribus",
      "description": "A desktop publishing application for page layout, with CMYK color, spot colors, ICC color management and PDF/X export for print.",
      "website": "https://www.scribus.net",
      "source": "https://github.com/scribusproject/scribus",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Scribus scores 80 out of 100 (grade B) on the creative tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/creative-tools/scribus/",
      "markdown": "https://privacyratings.com/creative-tools/scribus/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/scribusproject/scribus/blob/master/COPYING",
          "note": "GPL-2.0 or later."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/scribusproject/scribus",
          "note": "No telemetry or analytics in the source code. The update check only runs when requested."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/scribusproject/scribus",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:30.456Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "sharex",
      "category": "creative-tools",
      "name": "ShareX",
      "description": "Open-source screen-capture tool for Windows. Takes screenshots and short screen recordings, with annotation, OCR, a colour picker, and configurable save/upload destinations.",
      "website": "https://getsharex.com",
      "source": "https://github.com/ShareX/ShareX",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "ShareX scores 50 out of 100 (grade D) on the creative tools criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/creative-tools/sharex/",
      "markdown": "https://privacyratings.com/creative-tools/sharex/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ShareX/ShareX/blob/develop/LICENSE.txt",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google Analytics and Google Tag Manager (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://getsharex.com/donate",
          "note": "Funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Analytics",
            "host": "inline code",
            "effect": "no"
          },
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "Google Tag Manager",
            "host": "www.googletagmanager.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:16.993Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "shotcut",
      "category": "creative-tools",
      "name": "Shotcut",
      "description": "A free, open source, cross-platform video editor based on FFmpeg and MLT, with support for many formats and resolutions.",
      "website": "https://shotcut.org",
      "source": "https://github.com/mltframework/shotcut",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "F",
      "score": 30,
      "coverage": 100,
      "summary": "Shotcut scores 30 out of 100 (grade F) on the creative tools criteria. It meets 1 of 4 criteria: open source. It does not meet no trackers or telemetry, no ads or data sales and independent audit.",
      "url": "https://privacyratings.com/creative-tools/shotcut/",
      "markdown": "https://privacyratings.com/creative-tools/shotcut/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/mltframework/shotcut/blob/master/COPYING",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": null,
          "note": "The home page loads Google AdSense (automated test)."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "The website is funded by Google AdSense ads. The app itself shows no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google AdSense",
            "host": "pagead2.googlesyndication.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:01:17.418Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "synfig-studio",
      "category": "creative-tools",
      "name": "Synfig Studio",
      "description": "A 2D vector animation program that uses bones and interpolated keyframes to create animation without drawing every frame.",
      "website": "https://www.synfig.org",
      "source": "https://github.com/synfig/synfig",
      "license": "GPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Synfig Studio scores 50 out of 100 (grade D) on the creative tools criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/creative-tools/synfig-studio/",
      "markdown": "https://privacyratings.com/creative-tools/synfig-studio/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/synfig/synfig/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://www.synfig.org/privacy-policy/",
          "note": "The website uses WordPress Stats analytics from Automattic, with cookies."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.synfig.org/donate/",
          "note": "Funded by donations, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Google Fonts",
            "host": "fonts.googleapis.com",
            "effect": "none"
          },
          {
            "name": "WordPress.com Stats",
            "host": "stats.wp.com",
            "effect": "no"
          }
        ],
        "tested_at": "2026-10-01T07:00:26.886Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "tenacity",
      "category": "creative-tools",
      "name": "Tenacity",
      "description": "A multi-track audio editor and recorder forked from Audacity, developed by volunteers, with no telemetry.",
      "website": "https://tenacityaudio.org",
      "source": "https://codeberg.org/tenacityteam/tenacity",
      "license": null,
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Tenacity scores 80 out of 100 (grade B) on the creative tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/creative-tools/tenacity/",
      "markdown": "https://privacyratings.com/creative-tools/tenacity/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/tenacityteam/tenacity/src/branch/main/LICENSE.txt",
          "note": "GPL-2.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://codeberg.org/tenacityteam/tenacity",
          "note": "No telemetry or analytics in the source code. Update checks only run in alpha builds."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://tenacityaudio.org",
          "note": "Free volunteer project with no ads or data sales."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:00:27.449Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "upscayl",
      "category": "creative-tools",
      "name": "Upscayl",
      "description": "A desktop app that upscales and enhances low-resolution images locally using AI models, from the makers of the Upscayl Cloud service.",
      "website": "https://upscayl.org",
      "source": "https://github.com/upscayl/upscayl",
      "license": "AGPL-3.0",
      "platforms": [
        "windows",
        "macos",
        "linux"
      ],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "D",
      "score": 50,
      "coverage": 100,
      "summary": "Upscayl scores 50 out of 100 (grade D) on the creative tools criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit.",
      "url": "https://privacyratings.com/creative-tools/upscayl/",
      "markdown": "https://privacyratings.com/creative-tools/upscayl/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/upscayl/upscayl/blob/main/LICENSE",
          "note": "AGPL-3.0 for the desktop app. The optional Upscayl Cloud service is closed source."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "no",
          "evidence": "https://github.com/upscayl/upscayl/blob/main/renderer/components/posthog-provider-wrapper.tsx",
          "note": "The desktop app sends usage events with system information to PostHog, and the launch event is sent even when usage sharing is turned off. The website uses Cloudflare Web Analytics."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://upscayl.org/privacy",
          "note": "Funded by paid cloud plans, with no ads. The privacy policy states personal information is not sold."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [
          {
            "name": "Cloudflare Web Analytics",
            "host": "static.cloudflareinsights.com",
            "effect": "partial"
          }
        ],
        "tested_at": "2026-10-01T07:00:27.750Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "vidcutter",
      "category": "creative-tools",
      "name": "VidCutter",
      "description": "A cross-platform tool written in Python for cutting and joining video files.",
      "website": "https://github.com/ozmartian/vidcutter",
      "source": "https://github.com/ozmartian/vidcutter",
      "license": "GPL-3.0",
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "VidCutter scores 80 out of 100 (grade B) on the creative tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/creative-tools/vidcutter/",
      "markdown": "https://privacyratings.com/creative-tools/vidcutter/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ozmartian/vidcutter/blob/master/LICENSE",
          "note": "GPL-3.0."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/ozmartian/vidcutter",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://github.com/ozmartian/vidcutter",
          "note": "Free and open source project with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": null,
        "tested_at": "2026-10-01T07:01:17.418Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    },
    {
      "slug": "wings3d",
      "category": "creative-tools",
      "name": "Wings3D",
      "description": "An open source subdivision 3D modeler with an AutoUV facility for unfolding a model's surface for painting and texturing.",
      "website": "https://www.wings3d.com",
      "source": "https://github.com/dgud/wings",
      "license": null,
      "platforms": [],
      "jurisdiction": null,
      "pick": false,
      "pick_reason": null,
      "disclosure": null,
      "grade": "B",
      "score": 80,
      "coverage": 100,
      "summary": "Wings3D scores 80 out of 100 (grade B) on the creative tools criteria. It meets 3 of 4 criteria: open source, no trackers or telemetry and no ads or data sales. It does not meet independent audit.",
      "url": "https://privacyratings.com/creative-tools/wings3d/",
      "markdown": "https://privacyratings.com/creative-tools/wings3d/index.md",
      "answers": {
        "open_source": {
          "title": "Open source",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dgud/wings/blob/master/license.terms",
          "note": "BSD-style license."
        },
        "no_trackers": {
          "title": "No trackers or telemetry",
          "weight": 3,
          "answer": "yes",
          "evidence": "https://github.com/dgud/wings",
          "note": "No telemetry or analytics in the source code."
        },
        "no_ads": {
          "title": "No ads or data sales",
          "weight": 2,
          "answer": "yes",
          "evidence": "https://www.wings3d.com/",
          "note": "Open source and free for personal and commercial use, with no ads."
        },
        "independent_audit": {
          "title": "Independent audit",
          "weight": 2,
          "answer": "no",
          "evidence": null,
          "note": "No independent audit is published."
        },
        "transparency_report": {
          "title": "Transparency report",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "user_notice": {
          "title": "Tells users about requests",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "tls": {
          "title": "TLS configuration",
          "weight": 2,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "security_headers": {
          "title": "Security headers",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        },
        "web_standards": {
          "title": "Modern web standards",
          "weight": 1,
          "answer": "n/a",
          "evidence": null,
          "note": "Only applies to hosted services with a website to test."
        }
      },
      "tests": {
        "ssllabs": null,
        "observatory": null,
        "internetnl_web": null,
        "internetnl_mail": null,
        "trackers": [],
        "tested_at": "2026-10-01T07:01:19.568Z"
      },
      "last_modified": "2026-10-01T07:44:20Z"
    }
  ]
}