# Session privacy rating

End-to-end encrypted messenger that uses a random Account ID instead of a phone number and sends messages through onion routing over a decentralized network of community-operated nodes. Stewarded by the Session Technology Foundation in Switzerland.

## Summary

Session scores 94 out of 100 (grade A) on the messengers criteria. It meets 7 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted by default, no phone number needed, metadata protection and decentralized. It partly meets independent audit. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law.

- Website: https://getsession.org
- Source code: https://github.com/session-foundation
- Jurisdiction: Switzerland. Not in the Five, Nine or Fourteen Eyes. GDPR-style data protection law.
- Platforms: Android, iOS, Windows, macOS, Linux
- Home page trackers: Cloudflare Web Analytics (cookieless analytics)
- Category: [Messengers](https://privacyratings.com/messengers/)
- Grade: A (94/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Yes | The apps are GPL-3.0, and the storage server run by network nodes is MIT. | https://github.com/session-foundation/session-android/blob/dev/LICENSE |
| No trackers or telemetry | Yes | Exodus finds no trackers in the Android app, and the privacy policy states Session stores no information that could be used to track users. | https://reports.exodus-privacy.eu.org/en/reports/network.loki.messenger/latest/ |
| No ads or data sales | Yes | Funded by donations to the Session Technology Foundation, with no ads. | https://getsession.org/donate |
| Independent audit | Partial | Quarkslab published a full audit report, but it is older than three years. | https://blog.quarkslab.com/resources/2021-05-04_audit-of-session-secure-messaging-application/20-08-Oxen-REP-v1.4.pdf |
| End-to-end encrypted by default | Yes | One-to-one chats and groups are end-to-end encrypted by default; large public communities are only encrypted in transit to their server. | https://getsession.org/faq |
| No phone number needed | Yes | No phone number or email is needed; accounts use a randomly generated Account ID. | https://getsession.org/faq |
| Metadata protection | Yes | Onion requests hide the sender's IP address and no single node knows both origin and destination of a message. | https://getsession.org/whitepaper |
| Decentralized | Yes | Messages are stored and relayed by a network of more than a thousand community-operated Session Nodes rather than central servers. | https://getsession.org/faq |

Source: https://privacyratings.com/messengers/session/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/messengers/session.md
