# Ruby web frameworks privacy ratings

Web and API frameworks for Ruby.

| Name | Grade | Jurisdiction | Description |
| --- | --- | --- | --- |
| [Ruby on Rails](https://privacyratings.com/ruby-frameworks/ruby-on-rails/) | A (100/100) | Unknown | Full-stack Ruby web framework following the model-view-controller pattern, with the Active Record ORM, conventions over configuration and built-in support for mail, background jobs and WebSockets. |
| [Grape](https://privacyratings.com/ruby-frameworks/grape/) | B (80/100) | Unknown | Ruby framework for building REST-like APIs, with a DSL for versioning, parameter validation and response formatting, running on Rack or alongside Rails. |
| [Hanami](https://privacyratings.com/ruby-frameworks/hanami/) | B (80/100) | Unknown | Ruby web framework for structured, modular applications, with slices, actions, views and a repository-based database layer. |
| [Hotwire](https://privacyratings.com/ruby-frameworks/hotwire/) | B (80/100) | United States (Five Eyes) | Approach from 37signals for building web applications by sending HTML instead of JSON over the wire, made up of the Turbo, Stimulus and Hotwire Native libraries. |
| [Padrino](https://privacyratings.com/ruby-frameworks/padrino/) | B (80/100) | Unknown | Ruby web framework built on Sinatra that adds generators, helpers, mailers, an admin interface and support for mounting several apps. |
| [Roda](https://privacyratings.com/ruby-frameworks/roda/) | B (80/100) | Unknown | Ruby web toolkit built around a routing tree, with a small core and features added through plugins. |
| [Sinatra](https://privacyratings.com/ruby-frameworks/sinatra/) | B (80/100) | Unknown | Minimal Ruby library for building web applications and APIs with a DSL that maps HTTP routes to blocks of code. |

## Criteria

- **Open source** (weight 3): Is all the source code needed to run the product public?
- **No trackers or telemetry** (weight 3): Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
- **No ads or data sales** (weight 2): Is the product funded without advertising, ad targeting or selling user data?
- **Independent audit** (weight 2): Has an independent security or privacy audit been published within the last three years?

Source: https://privacyratings.com/ruby-frameworks/
