# Cal.com vs Rallly: privacy compared

| Criterion | Cal.com | Rallly |
| --- | --- | --- |
| Grade | F (38/100) | D (44/100) |
| Jurisdiction | United States (Five Eyes) | United Kingdom (Five Eyes) |
| Open source | No | Yes |
| No trackers or telemetry | No | No |
| No ads or data sales | Yes | Yes |
| Independent audit | Partial | No |
| Transparency report | No | No |
| Tells users about requests | No | No |
| TLS configuration | Yes | Yes |
| Security headers | Yes | No |
| Modern web standards | Not tested yet | Not tested yet |

**Cal.com.** Cal.com scores 38 out of 100 (grade F) on the scheduling criteria. It meets 3 of 8 criteria: no ads or data sales, TLS configuration and security headers. It partly meets independent audit. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.

**Rallly.** Rallly scores 44 out of 100 (grade D) on the scheduling criteria. It meets 3 of 8 criteria: open source, no ads or data sales and TLS configuration. It does not meet no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C-.

Source: https://privacyratings.com/compare/scheduling/cal-com-vs-rallly/
