# Google Password Manager privacy rating

Password manager built into Chrome, Android and the Google account that saves and syncs passwords and passkeys. Passwords are readable by Google unless on-device encryption is turned on.

## Summary

Google Password Manager scores 30 out of 100 (grade F) on the password managers criteria. It meets 3 of 11 criteria: transparency report, tells users about requests and security headers. It partly meets TLS configuration, local or self-hosted option and full export. It does not meet open source, no trackers or telemetry, no ads or data sales, independent audit and end-to-end encrypted vault. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade A+.

- Website: https://passwords.google
- Jurisdiction: United States. Five Eyes member. Subject to the US CLOUD Act.
- Platforms: Android, iOS, Web
- Home page trackers: Google Fonts (not scored), Google Tag Manager
- Category: [Password managers](https://privacyratings.com/password-managers/)
- Grade: F (30/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | No | Closed source. Chrome's password code is in Chromium, but the Android service and sync servers are not open. |  |
| No trackers or telemetry | No | Google collects activity and device data for analytics and advertising across its services. | https://policies.google.com/privacy |
| No ads or data sales | No | Google is funded mainly by advertising, and its privacy policy covers using account activity for personalized ads. | https://policies.google.com/privacy |
| Independent audit | No | No independent audit is published. |  |
| Transparency report | Yes | Google publishes government request counts and outcomes twice a year. | https://transparencyreport.google.com/user-data/overview |
| Tells users about requests | Yes | Google emails users before disclosing data to a government agency unless legally prohibited or in emergencies. | https://policies.google.com/terms/information-requests |
| TLS configuration | Partial | Grade B | https://www.ssllabs.com/ssltest/analyze.html?d=passwords.google.com&hideResults=on |
| Security headers | Yes | Grade A+ (125/100+) | https://developer.mozilla.org/en-US/observatory/analyze?host=passwords.google.com |
| Modern web standards | Not tested yet | Not tested yet. |  |
| End-to-end encrypted vault | No | By default the encryption key is stored in the Google account and Google can decrypt passwords. Optional on-device encryption keeps the key with the user. | https://support.google.com/accounts/answer/11350823?hl=en |
| Local or self-hosted option | Partial | Passwords are stored only in the Google account. Data can be exported. | https://support.google.com/chrome/answer/95606?hl=en |
| Full export | Partial | Passwords can be downloaded as a CSV file. No export is documented for passkeys. | https://support.google.com/chrome/answer/95606?hl=en |

Source: https://privacyratings.com/password-managers/google-password-manager/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/password-managers/google-password-manager.md
