# Zimbra Collaboration privacy rating

Self-hosted email and collaboration server from Synacor, with a web client for mail, calendar, contacts and files. An open-source edition and a commercial Network Edition with extra features are offered.

## Summary

Zimbra Collaboration scores 50 out of 100 (grade D) on the webmail criteria. It meets 4 of 9 criteria: no ads or data sales, connects directly, blocks remote content and self-hostable. It partly meets open source. It does not meet no trackers or telemetry, independent audit, OpenPGP support and works with any provider. It is based in the United States: Five Eyes member; subject to the US CLOUD Act.

- Website: https://www.zimbra.com
- Source code: https://github.com/Zimbra/zm-web-client
- Jurisdiction: United States. Five Eyes member. Subject to the US CLOUD Act.
- Platforms: Web
- Home page trackers: Google Analytics, Google Fonts (not scored), Google Tag Manager, HubSpot, TrustArc (not scored)
- Category: [Webmail](https://privacyratings.com/webmail/)
- Grade: D (50/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Partial | The open-source edition, including the web client, is public under CPAL-1.0 and GPL-2.0, but the commercial Network Edition adds closed-source features. | https://www.zimbra.com/product/licenses-and-terms-of-use/ |
| No trackers or telemetry | No | The website loads Google Analytics, HubSpot and New Relic. |  |
| No ads or data sales | Yes | Funded by commercial licenses and support. No ads. | https://www.zimbra.com/product/edition-comparison/ |
| Independent audit | No | No independent audit is published. |  |
| OpenPGP support | No | OpenPGP is not supported. S/MIME is offered in the Network Edition. |  |
| Connects directly | Yes | Self-hosted. The web client talks to the Zimbra server where it is installed, with no vendor service involved. | https://zimbra.github.io/installguides/latest/single.html |
| Blocks remote content | Yes | The zimbraPrefDisplayExternalImages preference is off by default, so external images load only on request. | https://github.com/Zimbra/zm-web-client/blob/develop/WebRoot/js/zimbraMail/mail/ZmMailApp.js |
| Works with any provider | No | The web client works only with a Zimbra server. Other IMAP and POP3 accounts can only be pulled into a Zimbra mailbox. |  |
| Self-hostable | Yes | Self-hosted software with an official installation guide. | https://zimbra.github.io/installguides/latest/single.html |

Source: https://privacyratings.com/webmail/zimbra/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/webmail/zimbra.md
