# LastPass privacy rating

Closed source password manager from LastPass US LP with browser extensions, desktop and mobile apps. Vaults are encrypted on the device, and a past breach exposed copies of customer vault backups that also held unencrypted website URLs.

## Summary

LastPass scores 45 out of 100 (grade D) on the password managers criteria. It meets 3 of 11 criteria: tells users about requests, TLS configuration and end-to-end encrypted vault. It partly meets no ads or data sales, transparency report, security headers, local or self-hosted option and full export. It does not meet open source, no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.

- Website: https://www.lastpass.com
- Jurisdiction: United States. Five Eyes member. Subject to the US CLOUD Act.
- Platforms: Windows, macOS, Android, iOS, Web
- Home page trackers: Google Fonts (not scored)
- Category: [Password managers](https://privacyratings.com/password-managers/)
- Grade: D (45/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | No | Closed source. |  |
| No trackers or telemetry | No | The Android app contains Google Firebase Analytics, Crashlytics, Pendo and Segment, and the website loads Google Tag Manager. | https://reports.exodus-privacy.eu.org/en/reports/com.lastpass.lpandroid/latest/ |
| No ads or data sales | Partial | Funded by subscriptions, but the privacy notice says third-party cookies for personalized advertising may count as a sale or sharing of personal data. | https://www.lastpass.com/legal-center/privacy-notice |
| Independent audit | No | No independent audit report is published. |  |
| Transparency report | Partial | Publishes law enforcement request guidelines but no request counts. | https://www.lastpass.com/legal-center/law-enforcement-request-guidelines |
| Tells users about requests | Yes | Notifies customers before disclosing data unless legally prohibited or there is a risk of harm. | https://www.lastpass.com/legal-center/law-enforcement-request-guidelines |
| TLS configuration | Yes | Grade A+ | https://www.ssllabs.com/ssltest/analyze.html?d=lastpass.com&hideResults=on |
| Security headers | Partial | Grade B (70/100+) | https://developer.mozilla.org/en-US/observatory/analyze?host=lastpass.com |
| Modern web standards | Not tested yet | Not tested yet. |  |
| End-to-end encrypted vault | Yes | Vault data is encrypted on the device with a key derived from the master password. Stolen vault backups included unencrypted website URLs. | https://www.lastpass.com/security/zero-knowledge-security |
| Local or self-hosted option | Partial | Vaults are stored only in the LastPass cloud. Data can be exported. | https://github.com/lastpass/lastpass-cli/blob/master/lpass.1.txt |
| Full export | Partial | Exports vault items to unencrypted CSV, without attachments. | https://github.com/lastpass/lastpass-cli/blob/master/lpass.1.txt |

Source: https://privacyratings.com/password-managers/lastpass/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/password-managers/lastpass.md
