# Dashlane privacy rating

Password manager from Dashlane with browser extensions and mobile apps, end-to-end encrypted sync, passkey support and dark web monitoring. The mobile app source code is published under a non-commercial license.

## Summary

Dashlane scores 45 out of 100 (grade D) on the password managers criteria. It meets 3 of 11 criteria: TLS configuration, end-to-end encrypted vault and full export. It partly meets open source, no ads or data sales, security headers and local or self-hosted option. It does not meet no trackers or telemetry, independent audit, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.

- Website: https://www.dashlane.com
- Source code: https://github.com/Dashlane/android-apps
- Jurisdiction: United States. Five Eyes member. Subject to the US CLOUD Act.
- Platforms: Android, iOS, Web
- Home page trackers: VWO
- Category: [Password managers](https://privacyratings.com/password-managers/)
- Grade: D (45/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Partial | The Android and Apple app sources are published under CC BY-NC 4.0, which is not OSI-approved. The server is closed. | https://github.com/Dashlane/android-apps/blob/main/LICENSE.md |
| No trackers or telemetry | No | The Android app contains Adjust and Sentry, and the privacy policy says the website uses Google Analytics. | https://reports.exodus-privacy.eu.org/en/reports/com.dashlane/latest/ |
| No ads or data sales | Partial | Funded by subscriptions, but the privacy policy says Dashlane and third-party advertising partners use personal data for interest-based advertising. | https://www.dashlane.com/privacy |
| Independent audit | No | No independent audit is published. |  |
| Transparency report | No | No transparency report or government request policy is published. |  |
| Tells users about requests | No | No published policy on notifying users about data requests. |  |
| TLS configuration | Yes | Grade A+ | https://www.ssllabs.com/ssltest/analyze.html?d=app.dashlane.com&hideResults=on |
| Security headers | Partial | Grade B+ (80/100+) | https://developer.mozilla.org/en-US/observatory/analyze?host=app.dashlane.com |
| Modern web standards | Not tested yet | Not tested yet. |  |
| End-to-end encrypted vault | Yes | Zero-knowledge design: vault data is encrypted on the device and Dashlane cannot read it. | https://www.dashlane.com/security |
| Local or self-hosted option | Partial | Vaults are stored only in the Dashlane cloud. Data can be exported. | https://support.dashlane.com/hc/en-us/articles/202625092-Export-your-data-from-Dashlane |
| Full export | Yes | Exports to CSV, an encrypted DASH file, or through the Credential Exchange protocol. | https://support.dashlane.com/hc/en-us/articles/202625092-Export-your-data-from-Dashlane |

Source: https://privacyratings.com/password-managers/dashlane/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/password-managers/dashlane.md
