# Headscale privacy rating

Self-hosted, open-source implementation of the Tailscale coordination server, letting official Tailscale clients join a private network without using Tailscale's hosted service.

**Our pick.** The open-source, self-hosted replacement for Tailscale's coordination server. The official Tailscale clients connect to it unchanged, so the whole network runs on your own server with no account at Tailscale.

## Summary

Headscale scores 82 out of 100 (grade B) on the mesh VPNs and private networks criteria. It meets 5 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, keys stay on devices and self-hosted coordination server. It partly meets no connection logs by default. It does not meet independent audit.

- Website: https://headscale.net
- Source code: https://github.com/juanfont/headscale
- License: BSD-3-Clause
- Platforms: Linux
- Home page trackers: none found
- Category: [Mesh VPNs and private networks](https://privacyratings.com/mesh-vpns/)
- Grade: B (82/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Yes | BSD-3-Clause. | https://github.com/juanfont/headscale/blob/main/LICENSE |
| No trackers or telemetry | Yes | No telemetry or analytics in the source code, and the website loads no trackers. | https://github.com/juanfont/headscale |
| No ads or data sales | Yes | Free community project with no ads or data sales. | https://github.com/juanfont/headscale |
| Independent audit | No | No independent audit is published. |  |
| Keys stay on devices | Yes | Works with the official Tailscale clients, which create WireGuard keys on each device. The control server only exchanges public keys. | https://github.com/juanfont/headscale#readme |
| Self-hosted coordination server | Yes | The whole control server is open source and self-hosted. | https://github.com/juanfont/headscale/blob/main/LICENSE |
| No connection logs by default | Partial | Headscale tells clients not to upload logs by default, but official Tailscale clients still contact log.tailscale.com at startup until TS_NO_LOGS_NO_SUPPORT is set. | https://github.com/juanfont/headscale/issues/2793 |

Source: https://privacyratings.com/mesh-vpns/headscale/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/mesh-vpns/headscale.md
