Our methodology
Evidence-based privacy evaluation
Transparency is the foundation of trust. Explore our rigorous evaluation framework that transforms complex privacy concepts into clear, actionable scores you can rely on.
Our core principles
Every evaluation follows these foundational principles to ensure consistency, transparency, and actionable insights.
Evidence-based
Every score is backed by documented testing, policy analysis, and real-world usage patterns.
Consistent standards
All products in a category are evaluated using identical criteria for fair comparison.
User-centric
We prioritize factors that impact real people, not just technical specifications.
Continuously updated
Regular re-evaluations ensure scores reflect current privacy practices and threats.
Scoring framework
Our comprehensive evaluation system breaks down privacy into measurable categories, each weighted by its impact on your data security.
Total weight must equal 100%. Each category is independently scored 0-100, then weighted to produce final score.
Understanding risk levels
We translate complex scores into clear risk categories, helping you make informed decisions at a glance.
Minimal risk
Score: 80-100
Excellent privacy practices with strong user protections and minimal data exposure.
Examples:
•End-to-end encrypted messaging
•Privacy-first search engines
•Open-source password managers
Low risk
Score: 60-79
Good privacy practices with some data collection for functionality. Generally trustworthy.
Examples:
•Privacy-focused email services
•Reputable VPN providers
•Secure cloud storage
Moderate risk
Score: 40-59
Average privacy practices with notable data collection. Requires careful settings management.
Examples:
•Mainstream social platforms
•Popular productivity apps
•Standard email providers
High risk
Score: 0-39
Significant privacy concerns with extensive data collection and limited user control.
Examples:
•Ad-supported free services
•Data broker platforms
•Invasive tracking apps
Our evaluation process
Before anything else: every score is derived exclusively from the product's own published privacy policy. No third-party reviews, no press coverage, no assumptions. If a practice isn't explicitly stated in the policy, it is treated as unknown — and unknown practices are scored conservatively (i.e., they don't get credit for things they haven't committed to in writing).
The policy is read in full at the time of evaluation. Each of the five categories below is then assessed against specific criteria found (or not found) within that document.
Data Collection
30% weightThis is the heaviest category because what a product collects is the foundation of all privacy risk.
What is assessed
- Types of data collected — Is it limited to what's functionally necessary, or does the policy list extensive categories (location, contacts, biometrics, browsing history, device identifiers, financial data, health data, etc.)?
- Passive vs. active collection — Does the product collect data only when you actively use it, or does it collect in the background (always-on microphone, continuous location tracking, idle telemetry)?
- Third-party data ingestion — Does the policy disclose collecting data about you from other sources (data brokers, advertising networks, social graph inference)?
- Sensitive data categories — Are biometric, health, financial, or children's data collected? These are weighted more heavily downward.
- Minimisation commitment — Does the policy explicitly commit to collecting only what is necessary for the stated service function?
How the sub-score is calculated
A product starts at the top of the range and points are deducted for each additional category of data collected beyond core functional necessity, with larger deductions for sensitive categories. A product that collects only what is strictly needed to operate scores near 10; one that collects location, contacts, browsing history, device fingerprints, and infers additional data from third parties scores near 1–2.
The privacy policy's "Information We Collect" or equivalent section. For hardware products (cars, phones, drones), the companion app policy is also reviewed since the app is typically the data transmission layer.
Data Usage & Retention
25% weightCollecting data is one thing; what happens to it afterwards is another. This category assesses the full lifecycle of data after collection.
What is assessed
- Purpose limitation — Is data used only for the stated service purpose, or does the policy permit use for advertising, product improvement, model training, profiling, or sale to third parties?
- Third-party sharing — Does the policy disclose sharing with advertisers, analytics providers, business partners, or affiliates? Are those third parties named or just described vaguely?
- Data sale or monetisation — Does the policy explicitly state data is sold or licensed? Does it include a "we do not sell your data" commitment?
- Retention periods — Are specific retention periods stated (e.g., "deleted within 30 days of account closure")? Or is retention described vaguely ("as long as necessary")?
- Post-deletion behaviour — Does the policy clarify what happens to data in backups, logs, and third-party systems after a user deletes their account?
- AI/ML training use — Is user data used to train machine learning models? Is this opt-in or opt-out?
How the sub-score is calculated
Purpose limitation and third-party sharing are the two biggest sub-factors. A product that uses data only to deliver the service and shares with no third parties (or only named processors under strict contractual terms) scores high. A product that permits broad advertising use, vague "partner" sharing, and indefinite retention scores low. Explicit data sale is an automatic floor-setter — it cannot score above 3 in this category regardless of other factors.
The "How We Use Your Information," "Sharing," "Retention," and "Third Parties" sections of the privacy policy. For products with separate terms of service, the ToS is also checked for data licensing clauses (particularly relevant for LLMs and social media).
Security
20% weightThis category assesses what technical and organisational measures the product commits to for protecting the data it holds.
What is assessed
- Encryption in transit — Does the policy commit to TLS/HTTPS for all data transmission?
- Encryption at rest — Is stored data encrypted? Is end-to-end encryption (E2EE) offered, where even the provider cannot read the content?
- Zero-knowledge architecture — Does the product operate on a zero-knowledge model (they cannot access your data even if compelled)?
- Security certifications — Are ISO 27001, SOC 2, or equivalent certifications mentioned?
- Breach notification — Does the policy commit to notifying users in the event of a data breach, and within what timeframe?
- Access controls — Are internal access controls described (e.g., only specific employees can access user data, access is logged)?
- Vulnerability disclosure — Is there a bug bounty programme or responsible disclosure policy referenced?
- Third-party audits — Are independent security audits conducted and results published?
How the sub-score is calculated
E2EE or zero-knowledge architecture is the highest-value single factor — products with this score significantly higher than those without. Absence of any stated encryption is a major deduction. Breach notification commitment is weighted because it reflects accountability. Vague statements like "we use industry-standard security measures" without specifics receive minimal credit.
The "Security" or "How We Protect Your Information" section of the privacy policy. For open-source products, the public repository and published audit reports are also referenced. For VPNs and cloud storage, independent audit reports (where publicly available) are factored in as corroborating evidence.
User Control
15% weightThis category measures the degree of genuine agency users have over their own data.
What is assessed
- Access rights — Can users request a copy of all data held about them?
- Deletion rights — Can users request full deletion of their data, and does the policy commit to honouring this?
- Portability — Can users export their data in a usable format?
- Opt-out mechanisms — Can users opt out of advertising, analytics, or non-essential data collection? Are these opt-outs easy to find and use, or buried?
- Consent model — Is data collection opt-in (user must actively consent) or opt-out (collection happens by default unless you object)?
- Granularity of controls — Can users control individual data categories, or is it all-or-nothing?
- Account deletion — Is account deletion straightforward, or does the policy describe a lengthy process with exceptions?
- Jurisdiction-specific rights — Does the policy extend GDPR/CCPA rights to all users globally, or only to users in specific regions?
How the sub-score is calculated
The consent model (opt-in vs. opt-out) and the availability of genuine deletion are the two most heavily weighted sub-factors. A product that defaults to opt-in, offers granular controls, and provides easy full deletion scores near the top. A product where data collection is on by default, opt-outs are buried or ineffective, and deletion is partial or delayed scores near the bottom. Extending rights globally (not just to EU/California residents) is a positive differentiator.
The "Your Rights," "Your Choices," "Data Subject Rights," or "Privacy Controls" sections of the privacy policy. The actual product settings interface is also considered where it can be verified — if the policy promises controls that don't exist in the product, that is noted.
Transparency
10% weightThis is the lightest-weighted category but acts as a credibility multiplier — a product can have good policies on paper but score poorly here if those policies are opaque, inaccessible, or unverifiable.
What is assessed
- Policy clarity — Is the privacy policy written in plain language, or is it dense legalese that obscures meaning?
- Specificity — Are data practices described specifically (named third parties, specific retention periods, concrete examples), or are they described in vague, catch-all terms?
- Policy accessibility — Is the policy easy to find from the product's homepage? Is it available in multiple languages where relevant?
- Change notification — Does the policy commit to notifying users of material changes, and how (email, in-app notice)?
- Ownership and corporate structure disclosure — Is it clear who owns the product and where it is legally incorporated? (Particularly relevant for products with opaque parent company structures.)
- Regulatory compliance statements — Are GDPR, CCPA, or other regulatory frameworks explicitly acknowledged?
- Audit/report publication — Does the company publish transparency reports, warrant canaries, or law enforcement request statistics?
How the sub-score is calculated
Specificity is the dominant sub-factor — vague language is treated as a transparency failure regardless of intent. A policy that names every third-party processor, states exact retention periods, and publishes annual transparency reports scores near 10. A policy that uses phrases like "trusted partners," "reasonable period," and "as permitted by law" throughout scores near 2–3. Publication of transparency reports (particularly for products that may receive government data requests) is a strong positive signal.
The privacy policy itself is the primary source. The company's website is checked for transparency report pages, law enforcement guidelines, and corporate structure disclosures. For products where parent company ownership is material to the privacy assessment (e.g., a product owned by a company with a poor privacy track record), that relationship is noted in the product's "Privacy Concerns" section.
How the Final Score Is Calculated
Each category is scored 1–10. The weighted total is:
| Category | Score (1–10) | Weight | Contribution |
|---|---|---|---|
| Data Collection | e.g. 7 | 30% | 2.10 |
| Data Usage & Retention | e.g. 6 | 25% | 1.50 |
| Security | e.g. 8 | 20% | 1.60 |
| User Control | e.g. 5 | 15% | 0.75 |
| Transparency | e.g. 7 | 10% | 0.70 |
| Total | 100% | 6.65 / 10 |
What This Methodology Does NOT Do
- ✕It does not Score based on reputation, press coverage, or user reviews
- ✕It does not Give credit for practices that are legally required (e.g., GDPR compliance is a floor, not a differentiator)
- ✕It does not Penalise products for collecting data that is genuinely necessary for their core function (a GPS navigation app needs location data — the question is what else it collects and what it does with it)
Methodology updates & transparency
We continuously refine our evaluation criteria based on emerging privacy threats and user feedback. Every change is documented and timestamped.
Current methodology version
v3.2.0- Enhanced AI training data usage evaluation criteria
- Added biometric data collection assessment factors
- Updated third-party SDK tracking methodology
- Improved mobile app permission analysis framework
- Introduced browser fingerprinting detection methods
- Expanded data retention policy evaluation
- Added cross-device tracking assessment
- Updated encryption standard requirements
- Complete scoring framework overhaul with weighted categories
- New risk level classification system
- Enhanced transparency and accountability criteria
- Standardized evaluation process across all product categories
Ready to Make Informed Privacy Decisions?
Explore our product evaluations and discover privacy-respecting alternatives that don't compromise on functionality.