# Bundlers and build tools privacy ratings

JavaScript bundlers and build tools.

| Name | Grade | Jurisdiction | Description |
| --- | --- | --- | --- |
| [esbuild](https://privacyratings.com/build-tools/esbuild/) | B (80/100) | Unknown | JavaScript and TypeScript bundler and minifier written in Go, with a command-line tool and APIs for JavaScript and Go. |
| [Rolldown](https://privacyratings.com/build-tools/rolldown/) | B (80/100) | Unknown | JavaScript and TypeScript bundler written in Rust with a Rollup-compatible API, developed as the bundler for Vite. |
| [Rollup](https://privacyratings.com/build-tools/rollup/) | B (80/100) | Unknown | Module bundler for JavaScript that compiles ES modules into bundles for libraries and applications, with tree shaking and a plugin API. |
| [Vite](https://privacyratings.com/build-tools/vite/) | B (80/100) | Unknown | Frontend build tool with a fast development server using native ES modules and hot module replacement, and a production bundler for web applications. |
| [Bun](https://privacyratings.com/build-tools/bun/) | C (65/100) | United States (Five Eyes) | JavaScript runtime, package manager, test runner and bundler in a single executable, built on JavaScriptCore and written in Zig. |
| [Parcel](https://privacyratings.com/build-tools/parcel/) | D (50/100) | Unknown | Zero-configuration bundler for web applications that builds JavaScript, CSS, HTML and other assets, with a Rust-based compiler and built-in development server. |
| [Rspack](https://privacyratings.com/build-tools/rspack/) | D (50/100) | Unknown | JavaScript bundler written in Rust that is compatible with the webpack configuration and plugin API, developed by the ByteDance web infrastructure team. |
| [webpack](https://privacyratings.com/build-tools/webpack/) | D (50/100) | Unknown | Module bundler for JavaScript applications that builds a dependency graph and packages code and assets into bundles, extensible through loaders and plugins. |
| [Turbopack](https://privacyratings.com/build-tools/turbopack/) | D (40/100) | United States (Five Eyes) | Incremental bundler written in Rust and built into Next.js, used by the Next.js development server and production builds. |

## Criteria

- **Open source** (weight 3): Is all the source code needed to run the product public?
- **No trackers or telemetry** (weight 3): Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
- **No ads or data sales** (weight 2): Is the product funded without advertising, ad targeting or selling user data?
- **Independent audit** (weight 2): Has an independent security or privacy audit been published within the last three years?

Source: https://privacyratings.com/build-tools/
