# Vaultwarden privacy rating

Open source, lightweight server written in Rust that implements the Bitwarden client API for self-hosting. It works with the official Bitwarden apps and extensions and is not affiliated with Bitwarden.

## Summary

Vaultwarden scores 88 out of 100 (grade B) on the password managers criteria. It meets 6 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted vault, local or self-hosted option and full export. It does not meet independent audit.

- Website: https://github.com/dani-garcia/vaultwarden
- Source code: https://github.com/dani-garcia/vaultwarden
- License: AGPL-3.0
- Platforms: Linux
- Category: [Password managers](https://privacyratings.com/password-managers/)
- Grade: B (88/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Yes | AGPL-3.0. | https://github.com/dani-garcia/vaultwarden/blob/main/LICENSE.txt |
| No trackers or telemetry | Yes | No telemetry or analytics in the source code. | https://github.com/dani-garcia/vaultwarden |
| No ads or data sales | Yes | Volunteer project funded by donations, with no ads. | https://github.com/dani-garcia/vaultwarden/blob/main/.github/FUNDING.yml |
| Independent audit | No | No independent audit is published. |  |
| End-to-end encrypted vault | Yes | Vault data is encrypted by the Bitwarden clients before it reaches the server. | https://bitwarden.com/help/bitwarden-security-white-paper/ |
| Local or self-hosted option | Yes | The server is designed to be self-hosted. | https://github.com/dani-garcia/vaultwarden |
| Full export | Yes | The Bitwarden clients export to JSON (plain or encrypted), CSV, and ZIP with attachments. | https://bitwarden.com/help/export-your-data/ |

Source: https://privacyratings.com/password-managers/vaultwarden/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/password-managers/vaultwarden.md
