# LessPass privacy rating

Stateless password manager that derives each site's password from the site name, login and a master password, so no vault is stored or synced. The hosted profile server is closed to new users, who can self-host one.

## Summary

LessPass scores 71 out of 100 (grade C) on the password managers criteria. It meets 6 of 10 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, end-to-end encrypted vault and local or self-hosted option. It does not meet independent audit, transparency report, tells users about requests and security headers. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.

- Website: https://lesspass.com
- Source code: https://github.com/lesspass/lesspass
- License: GPL-3.0
- Home page trackers: none found
- Category: [Password managers](https://privacyratings.com/password-managers/)
- Grade: C (71/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Yes | GPL-3.0. | https://github.com/lesspass/lesspass/blob/main/LICENSE |
| No trackers or telemetry | Yes | Exodus finds no trackers in the Android app, and the website loads no third-party scripts. | https://reports.exodus-privacy.eu.org/en/reports/com.lesspass.android/latest/ |
| No ads or data sales | Yes | Funded by donations through Open Collective, with no ads. | https://opencollective.com/lesspass |
| Independent audit | No | No independent audit is published. |  |
| Transparency report | No | No transparency report or government request policy is published. |  |
| Tells users about requests | No | No published policy on notifying users about data requests. |  |
| TLS configuration | Yes | Grade A | https://www.ssllabs.com/ssltest/analyze.html?d=lesspass.com&hideResults=on |
| Security headers | No | Grade D (30/100+) | https://developer.mozilla.org/en-US/observatory/analyze?host=lesspass.com |
| Modern web standards | Not tested yet | Not tested yet. |  |
| End-to-end encrypted vault | Yes | No vault exists: passwords are generated on the device and never stored or synced. | https://github.com/lesspass/lesspass#readme |
| Local or self-hosted option | Yes | Works without a server, and the optional profile server can be self-hosted. | https://github.com/lesspass/lesspass#readme |

Source: https://privacyratings.com/password-managers/lesspass/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/password-managers/lesspass.md
