Privacy Ratings

Why Privacy Ratings exists

Privacy guides help millions of people choose better apps and services, and many do excellent work. Most also share the same weaknesses:

Privacy Ratings is built to fix each of these.

From awesome lists to a maintained resource

Many of these guides began as GitHub lists. The "awesome" list format, started by Sindre Sorhus, made it easy for anyone to publish a curated list, and thousands of awesome-something lists followed, many of them forks of each other. Lists like Awesome Privacy do valuable work, and many entries here were first listed there.

The format has a weakness: most lists depend on one or two volunteers. When a maintainer moves on, the list goes quiet, gets archived, or splits into forks that each drift out of date. Readers cannot tell which copy is current, and nothing in a list is tested or scored.

Privacy Ratings is backed and run by a business, Forward Email. It does not depend on volunteers who may leave or archive the repository. The data lives in structured files instead of a single README, so scripts validate, score and test it every day. The code is open source and the content is CC BY-SA licensed, so anyone can copy, check and improve it.

What is different

Every rule is public. Each category has a short list of questions with a weight from 1 to 3. The questions, the meaning of each answer and how to verify it are all in the criteria/ folder. See the criteria.

Answers need evidence. A "yes" or "partial" must link to a source anyone can check: documentation, source code, a license file or an audit report. Anything without evidence counts as "unknown" and scores zero. An entry gets a letter grade only when enough of its answers are backed by evidence.

Scores from 0 to 100. Each entry gets a score, so you can see how services compare and where each one falls short.

Automated security tests. The Scan workflow tests hosted services on a schedule with Qualys SSL Labs, Mozilla HTTP Observatory and Internet.nl (including the Internet.nl email test for email providers). It saves the results in the repository, and each page links to them. See SCANS.md.

Jurisdiction in the open. Each rating shows where the company is based, whether that country is in the Five, Nine or Fourteen Eyes, whether GDPR applies, and whether the US CLOUD Act reaches it. The score leaves jurisdiction out, because what a provider can hand over depends mostly on what it keeps and who holds the keys. See jurisdictions and the CLOUD Act.

Contributions happen on GitHub. Suggestions and corrections are GitHub issues, changes are pull requests, and debate takes place in GitHub Discussions. There is no separate forum, chat server or account system, and Git keeps a public history of each change to each rating.

Open data. Ratings are plain Markdown and YAML files, and the build publishes the full data set as JSON. Content is licensed CC BY-SA 4.0, so anyone can reuse it.

Picks are labeled as picks. The maintainers choose one or two picks per category and explain each one. Picks appear separately and never change scores, so you can tell editorial judgment apart from measured results.

Who maintains it

Privacy Ratings is backed, funded and maintained by Forward Email, a privacy-focused email service that is also rated here. That funding keeps the project maintained for the long term. It is also a conflict of interest, and the project handles it in the open:

If a rating looks wrong, the whole process is to open an issue or a pull request with evidence.

Credits

Many entries were first listed from Awesome Privacy, released under CC0. Mail server hosting data comes from Awesome Mail Server Providers.

Edit this page on GitHub Markdown