# SimpleLogin privacy rating

Open-source email alias service run by Proton. Creates aliases that forward to real mailboxes and lets replies go out from the alias. Can also be self-hosted.

## Summary

SimpleLogin scores 58 out of 100 (grade D) on the email forwarding and aliases criteria. It meets 6 of 16 criteria: open source, no ads or data sales, tells users about requests, TLS configuration, custom domains and mail transport security. It partly meets no trackers or telemetry, independent audit, transparency report, security headers, end-to-end encryption and no stored mail. It does not meet open protocols, sign up without personal data, Sender Rewriting Scheme and ARC sealing. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.

- Website: https://simplelogin.io
- Source code: https://github.com/simple-login/app
- License: AGPL-3.0
- Jurisdiction: Switzerland. Not in the Five, Nine or Fourteen Eyes. GDPR-style data protection law.
- Home page trackers: none found
- Category: [Email forwarding and aliases](https://privacyratings.com/email-forwarding/)
- Grade: D (58/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Yes | AGPL-3.0. | https://github.com/simple-login/app/blob/master/LICENSE |
| No trackers or telemetry | Partial | No advertising trackers. The privacy policy lists cookieless Plausible analytics on the website and crash reporting in the apps. The Android app has no trackers in Exodus. | https://simplelogin.io/privacy/ |
| No ads or data sales | Yes | Funded by the Premium plan. No ads, and the privacy policy states data is never sold. | https://simplelogin.io/pricing/ |
| Independent audit | Partial | Securitum audited the web app, browser extensions and mobile apps. The full report is public but older than three years. | https://simplelogin.io/audit2022/web.pdf |
| Transparency report | Partial | The privacy policy describes how legal requests are handled, but no request counts are published for SimpleLogin. | https://simplelogin.io/privacy/ |
| Tells users about requests | Yes | Users are informed of legal requests unless legally prevented. | https://simplelogin.io/privacy/ |
| TLS configuration | Yes | Grade A+ | https://www.ssllabs.com/ssltest/analyze.html?d=simplelogin.io&hideResults=on |
| Security headers | Partial | Grade B+ (80/100+) | https://developer.mozilla.org/en-US/observatory/analyze?host=simplelogin.io |
| Modern web standards | Not tested yet | Not tested yet. |  |
| End-to-end encryption | Partial | Forwarded mail can be encrypted with the user's PGP key on the Premium plan. Not on by default. | https://simplelogin.io/pricing/ |
| No stored mail | Partial | Mail is deleted once delivered. Undeliverable mail is kept for 7 days so the user can review it. | https://simplelogin.io/privacy/ |
| Open protocols | No | No IMAP or SMTP access. Mail is forwarded to an existing mailbox and replies go through reverse aliases. |  |
| Custom domains | Yes | Unlimited custom domains on the Premium plan. | https://simplelogin.io/pricing/ |
| Sign up without personal data | No | An existing email address is required to create an account and receive forwarded mail. | https://simplelogin.io/privacy/ |
| Email security standards | Not tested yet | Not tested yet. |  |
| Mail transport security | Yes | Passes: SPF, DMARC reject, MTA-STS enforce, TLS-RPT, DNSSEC, DANE all. |  |
| Sender Rewriting Scheme | No | No published documentation on SRS. Forwarded mail is sent with a VERP return address on SimpleLogin's domain. |  |
| ARC sealing | No | No published documentation on ARC signing or validation. |  |

Source: https://privacyratings.com/email-forwarding/simplelogin/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/email-forwarding/simplelogin.md
