Password managers
Google Password Manager privacy rating
Password manager built into Chrome, Android and the Google account that saves and syncs passwords and passkeys. Passwords are readable by Google unless on-device encryption is turned on.
Summary
Google Password Manager scores 27 out of 100 (grade F) on the password managers criteria. It meets 2 of 11 criteria: transparency report and tells users about requests. It partly meets TLS configuration, security headers, local or self-hosted option and full export. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit and end-to-end encrypted vault. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade B.
Score 27 out of 100. How scoring works
Criteria
-
No
Open source Weight 3 of 3
Is all the source code needed to run the product public?
Closed source. Chrome's password code is in Chromium, but the Android service and sync servers are not open.
-
No
No trackers or telemetry Weight 3 of 3
Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
Google collects activity and device data for analytics and advertising across its services.
-
No
No ads or data sales Weight 2 of 3
Is the product funded without advertising, ad targeting or selling user data?
Google is funded mainly by advertising, and its privacy policy covers using account activity for personalized ads.
-
No
Independent audit Weight 2 of 3
Has an independent security or privacy audit been published within the last three years?
No independent audit is published.
-
Yes
Transparency report Weight 2 of 3
Does the provider regularly publish how many government and legal requests it receives and how it responds?
Google publishes government request counts and outcomes twice a year.
-
Yes
Tells users about requests Weight 1 of 3
Does the provider promise to tell users about requests for their data, unless a court forbids it?
Google emails users before disclosing data to a government agency unless legally prohibited or in emergencies.
-
No
End-to-end encrypted vault Weight 3 of 3
Is the vault encrypted on the device before it is synced, with a key the provider does not hold?
By default the encryption key is stored in the Google account and Google can decrypt passwords. Optional on-device encryption keeps the key with the user.
-
Partial
Local or self-hosted option Weight 2 of 3
Can the vault be kept locally or on your own server?
Passwords are stored only in the Google account. Data can be exported.
-
Partial
Full export Weight 1 of 3
Can every item be exported in an open format?
Passwords can be downloaded as a CSV file. No export is documented for passkeys.
Automated tests
-
Partial
TLS configuration Weight 2 of 3
Does the website pass the Qualys SSL Labs test with a grade of A or better?
Grade B
-
Partial
Security headers Weight 1 of 3
Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?
Grade B (70/100+)
-
Not tested yet
Modern web standards Weight 1 of 3
Does the website score 90% or higher on the Internet.nl website test?
Not tested yet.