# NetBird privacy rating

WireGuard-based mesh VPN and zero-trust access platform with open-source clients and a management server that can be self-hosted or used as NetBird's hosted service.

## Summary

NetBird scores 71 out of 100 (grade C) on the mesh VPNs and private networks criteria. It meets 5 of 7 criteria: open source, no ads or data sales, keys stay on devices, self-hosted coordination server and no connection logs by default. It does not meet no trackers or telemetry and independent audit. It is based in Germany: Fourteen Eyes member; EU member (GDPR).

- Website: https://netbird.io
- Source code: https://github.com/netbirdio/netbird
- Jurisdiction: Germany. Fourteen Eyes member. EU member (GDPR).
- Platforms: Windows, macOS, Linux, Android, iOS
- Home page trackers: none found
- Category: [Mesh VPNs and private networks](https://privacyratings.com/mesh-vpns/)
- Grade: C (71/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Yes | BSD-3-Clause for the clients and AGPL-3.0 for the management, signal and relay servers. | https://github.com/netbirdio/netbird/blob/main/LICENSE |
| No trackers or telemetry | No | The website uses Google Analytics, Microsoft Clarity, Hotjar, HubSpot and Reddit tracking. | https://netbird.io/privacy |
| No ads or data sales | Yes | Funded by paid cloud plans, with no ads in the product. | https://netbird.io/pricing |
| Independent audit | No | No independent audit is published. |  |
| Keys stay on devices | Yes | The client creates the WireGuard private key, which never leaves the device. The management service only distributes public keys, and relays cannot decrypt traffic. | https://docs.netbird.io/about-netbird/how-netbird-works |
| Self-hosted coordination server | Yes | The management, signal and relay servers are open source under AGPL-3.0 and can be self-hosted. | https://docs.netbird.io/selfhosted/selfhosted-guide |
| No connection logs by default | Yes | Traffic event logging is off by default. Client debug bundles are only uploaded when a user runs the upload command. | https://docs.netbird.io/manage/activity/traffic-events-logging |

Source: https://privacyratings.com/mesh-vpns/netbird/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/mesh-vpns/netbird.md
