# Tailscale privacy rating

Mesh VPN built on WireGuard that connects devices into a private network using a hosted coordination server for key exchange and access control, with open-source clients.

**Our pick.** A WireGuard mesh for Windows, macOS, Linux, Android and iOS, with NAT traversal and DERP relays when a direct connection fails. Keys are created on each device, so the coordination server and relays never see traffic. The clients are open source under BSD-3-Clause, ACLs and SSO come built in, and the open-source Headscale server can replace the hosted coordination server for full self-hosting.

## Summary

Tailscale scores 50 out of 100 (grade D) on the mesh VPNs and private networks criteria. It meets 1 of 7 criteria: keys stay on devices. It partly meets open source, no ads or data sales, independent audit, self-hosted coordination server and no connection logs by default. It does not meet no trackers or telemetry. It is based in Canada: Five Eyes member.

- Website: https://tailscale.com
- Source code: https://github.com/tailscale/tailscale
- License: BSD-3-Clause
- Jurisdiction: Canada. Five Eyes member.
- Platforms: Windows, macOS, Linux, Android, iOS
- Home page trackers: none found
- Category: [Mesh VPNs and private networks](https://privacyratings.com/mesh-vpns/)
- Grade: D (50/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Partial | The client daemon is BSD-3-Clause, but the Windows, macOS and iOS GUIs and the hosted coordination server are closed source. | https://tailscale.com/opensource |
| No trackers or telemetry | No | The website uses third-party analytics and advertising cookies, and client logging is on by default with an opt-out. | https://tailscale.com/privacy-policy |
| No ads or data sales | Partial | Funded by paid plans with no ads in the product, though the website shares cookie data with ad partners for Tailscale's own marketing. | https://tailscale.com/pricing |
| Independent audit | Partial | Latacora conducts regular security audits, but the reports are only available on request. | https://tailscale.com/security |
| Keys stay on devices | Yes | Each device creates its own WireGuard key pair. The private key never leaves the device, and DERP relays only forward encrypted packets. | https://tailscale.com/blog/how-tailscale-works |
| Self-hosted coordination server | Partial | Tailscale's coordination server is closed source. The clients can use the open-source, community-maintained Headscale server instead. | https://tailscale.com/opensource |
| No connection logs by default | Partial | Clients send logs to Tailscale by default, including connection open and close events. The --no-logs-no-support flag or TS_NO_LOGS_NO_SUPPORT turns this off. | https://tailscale.com/kb/1011/log-mesh-traffic |

Source: https://privacyratings.com/mesh-vpns/tailscale/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/mesh-vpns/tailscale.md
