# Cal.com vs Doodle: privacy compared

| Criterion | Cal.com | Doodle |
| --- | --- | --- |
| Grade | F (38/100) | F (16/100) |
| Jurisdiction | United States (Five Eyes) | Switzerland |
| Open source | No | No |
| No trackers or telemetry | No | No |
| No ads or data sales | Yes | No |
| Independent audit | Partial | No |
| Transparency report | No | No |
| Tells users about requests | No | No |
| TLS configuration | Yes | Yes |
| Security headers | Yes | Partial |
| Modern web standards | Not tested yet | Not tested yet |

**Cal.com.** Cal.com scores 38 out of 100 (grade F) on the scheduling criteria. It meets 3 of 8 criteria: no ads or data sales, TLS configuration and security headers. It partly meets independent audit. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.

**Doodle.** Doodle scores 16 out of 100 (grade F) on the scheduling criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets security headers. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report and tells users about requests. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.

Source: https://privacyratings.com/compare/scheduling/cal-com-vs-doodle/
