# Gatsby privacy rating

React-based framework for building static websites and apps, with a GraphQL data layer and plugins for content sources.

## Summary

Gatsby scores 50 out of 100 (grade D) on the front-end and full-stack frameworks criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.

- Website: https://www.gatsbyjs.com
- Source code: https://github.com/gatsbyjs/gatsby
- License: MIT
- Jurisdiction: United States. Five Eyes member. Subject to the US CLOUD Act.
- Platforms: Linux, macOS, Windows, Web
- Home page trackers: Google Tag Manager, Segment
- Category: [Front-end and full-stack frameworks](https://privacyratings.com/web-frameworks/)
- Grade: D (50/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Yes | MIT-licensed. | https://github.com/gatsbyjs/gatsby/blob/master/LICENSE |
| No trackers or telemetry | No | The CLI sends telemetry by default until disabled, and gatsbyjs.com loads Google Tag Manager and Segment. | https://www.gatsbyjs.com/docs/telemetry/ |
| No ads or data sales | Yes | Free MIT-licensed framework maintained by Netlify, with no ads. | https://github.com/gatsbyjs/gatsby/blob/master/LICENSE |
| Independent audit | No | No independent audit is published. |  |

Source: https://privacyratings.com/web-frameworks/gatsby/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/web-frameworks/gatsby.md
