# Pass privacy rating

Command-line password manager that stores each password as a GPG-encrypted file in a folder, with optional git for history and syncing. Many third-party clients and extensions exist.

## Summary

Pass scores 69 out of 100 (grade C) on the password managers criteria. It meets 5 of 7 criteria: open source, no ads or data sales, end-to-end encrypted vault, local or self-hosted option and full export. It does not meet no trackers or telemetry and independent audit. Automated tests: Mozilla HTTP Observatory grade B.

- Website: https://www.passwordstore.org
- Source code: https://git.zx2c4.com/password-store
- Home page trackers: none found
- Category: [Password managers](https://privacyratings.com/password-managers/)
- Grade: C (69/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Yes | GPL-2.0. | https://git.zx2c4.com/password-store/tree/COPYING |
| No trackers or telemetry | No | The pass tool has no telemetry, but the website loads Google Analytics and the Twitter widgets script. | https://www.passwordstore.org/ |
| No ads or data sales | Yes | Free software with no ads, accounts or paid tiers. | https://www.passwordstore.org/ |
| Independent audit | No | No independent audit is published. |  |
| End-to-end encrypted vault | Yes | Local-only: each password is a separate GPG-encrypted file, with no sync service. | https://www.passwordstore.org/ |
| Local or self-hosted option | Yes | Passwords are stored in a local folder that can be synced with any git server. | https://www.passwordstore.org/ |
| Full export | Yes | Passwords are ordinary GPG files in a folder that standard tools can read. | https://www.passwordstore.org/ |

Source: https://privacyratings.com/password-managers/pass/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/password-managers/pass.md
