Our Methodology

Our methodology

Evidence-based privacy evaluation

Transparency is the foundation of trust. Explore our rigorous evaluation framework that transforms complex privacy concepts into clear, actionable scores you can rely on.

Our core principles

Every evaluation follows these foundational principles to ensure consistency, transparency, and actionable insights.

Evidence-based

Every score is backed by documented testing, policy analysis, and real-world usage patterns.

Consistent standards

All products in a category are evaluated using identical criteria for fair comparison.

User-centric

We prioritize factors that impact real people, not just technical specifications.

Continuously updated

Regular re-evaluations ensure scores reflect current privacy practices and threats.

Scoring framework

Our comprehensive evaluation system breaks down privacy into measurable categories, each weighted by its impact on your data security.

Total weight must equal 100%. Each category is independently scored 0-100, then weighted to produce final score.

Understanding risk levels

We translate complex scores into clear risk categories, helping you make informed decisions at a glance.

Minimal risk

Score: 80-100

Excellent privacy practices with strong user protections and minimal data exposure.

Examples:

End-to-end encrypted messaging

Privacy-first search engines

Open-source password managers

Low risk

Score: 60-79

Good privacy practices with some data collection for functionality. Generally trustworthy.

Examples:

Privacy-focused email services

Reputable VPN providers

Secure cloud storage

Moderate risk

Score: 40-59

Average privacy practices with notable data collection. Requires careful settings management.

Examples:

Mainstream social platforms

Popular productivity apps

Standard email providers

High risk

Score: 0-39

Significant privacy concerns with extensive data collection and limited user control.

Examples:

Ad-supported free services

Data broker platforms

Invasive tracking apps

Our evaluation process

Before anything else: every score is derived exclusively from the product's own published privacy policy. No third-party reviews, no press coverage, no assumptions. If a practice isn't explicitly stated in the policy, it is treated as unknown — and unknown practices are scored conservatively (i.e., they don't get credit for things they haven't committed to in writing).

The policy is read in full at the time of evaluation. Each of the five categories below is then assessed against specific criteria found (or not found) within that document.

1

Data Collection

30% weight

This is the heaviest category because what a product collects is the foundation of all privacy risk.

What is assessed

  • Types of data collectedIs it limited to what's functionally necessary, or does the policy list extensive categories (location, contacts, biometrics, browsing history, device identifiers, financial data, health data, etc.)?
  • Passive vs. active collectionDoes the product collect data only when you actively use it, or does it collect in the background (always-on microphone, continuous location tracking, idle telemetry)?
  • Third-party data ingestionDoes the policy disclose collecting data about you from other sources (data brokers, advertising networks, social graph inference)?
  • Sensitive data categoriesAre biometric, health, financial, or children's data collected? These are weighted more heavily downward.
  • Minimisation commitmentDoes the policy explicitly commit to collecting only what is necessary for the stated service function?

How the sub-score is calculated

A product starts at the top of the range and points are deducted for each additional category of data collected beyond core functional necessity, with larger deductions for sensitive categories. A product that collects only what is strictly needed to operate scores near 10; one that collects location, contacts, browsing history, device fingerprints, and infers additional data from third parties scores near 1–2.

Source data:

The privacy policy's "Information We Collect" or equivalent section. For hardware products (cars, phones, drones), the companion app policy is also reviewed since the app is typically the data transmission layer.

2

Data Usage & Retention

25% weight

Collecting data is one thing; what happens to it afterwards is another. This category assesses the full lifecycle of data after collection.

What is assessed

  • Purpose limitationIs data used only for the stated service purpose, or does the policy permit use for advertising, product improvement, model training, profiling, or sale to third parties?
  • Third-party sharingDoes the policy disclose sharing with advertisers, analytics providers, business partners, or affiliates? Are those third parties named or just described vaguely?
  • Data sale or monetisationDoes the policy explicitly state data is sold or licensed? Does it include a "we do not sell your data" commitment?
  • Retention periodsAre specific retention periods stated (e.g., "deleted within 30 days of account closure")? Or is retention described vaguely ("as long as necessary")?
  • Post-deletion behaviourDoes the policy clarify what happens to data in backups, logs, and third-party systems after a user deletes their account?
  • AI/ML training useIs user data used to train machine learning models? Is this opt-in or opt-out?

How the sub-score is calculated

Purpose limitation and third-party sharing are the two biggest sub-factors. A product that uses data only to deliver the service and shares with no third parties (or only named processors under strict contractual terms) scores high. A product that permits broad advertising use, vague "partner" sharing, and indefinite retention scores low. Explicit data sale is an automatic floor-setter — it cannot score above 3 in this category regardless of other factors.

Source data:

The "How We Use Your Information," "Sharing," "Retention," and "Third Parties" sections of the privacy policy. For products with separate terms of service, the ToS is also checked for data licensing clauses (particularly relevant for LLMs and social media).

3

Security

20% weight

This category assesses what technical and organisational measures the product commits to for protecting the data it holds.

What is assessed

  • Encryption in transitDoes the policy commit to TLS/HTTPS for all data transmission?
  • Encryption at restIs stored data encrypted? Is end-to-end encryption (E2EE) offered, where even the provider cannot read the content?
  • Zero-knowledge architectureDoes the product operate on a zero-knowledge model (they cannot access your data even if compelled)?
  • Security certificationsAre ISO 27001, SOC 2, or equivalent certifications mentioned?
  • Breach notificationDoes the policy commit to notifying users in the event of a data breach, and within what timeframe?
  • Access controlsAre internal access controls described (e.g., only specific employees can access user data, access is logged)?
  • Vulnerability disclosureIs there a bug bounty programme or responsible disclosure policy referenced?
  • Third-party auditsAre independent security audits conducted and results published?

How the sub-score is calculated

E2EE or zero-knowledge architecture is the highest-value single factor — products with this score significantly higher than those without. Absence of any stated encryption is a major deduction. Breach notification commitment is weighted because it reflects accountability. Vague statements like "we use industry-standard security measures" without specifics receive minimal credit.

Source data:

The "Security" or "How We Protect Your Information" section of the privacy policy. For open-source products, the public repository and published audit reports are also referenced. For VPNs and cloud storage, independent audit reports (where publicly available) are factored in as corroborating evidence.

4

User Control

15% weight

This category measures the degree of genuine agency users have over their own data.

What is assessed

  • Access rightsCan users request a copy of all data held about them?
  • Deletion rightsCan users request full deletion of their data, and does the policy commit to honouring this?
  • PortabilityCan users export their data in a usable format?
  • Opt-out mechanismsCan users opt out of advertising, analytics, or non-essential data collection? Are these opt-outs easy to find and use, or buried?
  • Consent modelIs data collection opt-in (user must actively consent) or opt-out (collection happens by default unless you object)?
  • Granularity of controlsCan users control individual data categories, or is it all-or-nothing?
  • Account deletionIs account deletion straightforward, or does the policy describe a lengthy process with exceptions?
  • Jurisdiction-specific rightsDoes the policy extend GDPR/CCPA rights to all users globally, or only to users in specific regions?

How the sub-score is calculated

The consent model (opt-in vs. opt-out) and the availability of genuine deletion are the two most heavily weighted sub-factors. A product that defaults to opt-in, offers granular controls, and provides easy full deletion scores near the top. A product where data collection is on by default, opt-outs are buried or ineffective, and deletion is partial or delayed scores near the bottom. Extending rights globally (not just to EU/California residents) is a positive differentiator.

Source data:

The "Your Rights," "Your Choices," "Data Subject Rights," or "Privacy Controls" sections of the privacy policy. The actual product settings interface is also considered where it can be verified — if the policy promises controls that don't exist in the product, that is noted.

5

Transparency

10% weight

This is the lightest-weighted category but acts as a credibility multiplier — a product can have good policies on paper but score poorly here if those policies are opaque, inaccessible, or unverifiable.

What is assessed

  • Policy clarityIs the privacy policy written in plain language, or is it dense legalese that obscures meaning?
  • SpecificityAre data practices described specifically (named third parties, specific retention periods, concrete examples), or are they described in vague, catch-all terms?
  • Policy accessibilityIs the policy easy to find from the product's homepage? Is it available in multiple languages where relevant?
  • Change notificationDoes the policy commit to notifying users of material changes, and how (email, in-app notice)?
  • Ownership and corporate structure disclosureIs it clear who owns the product and where it is legally incorporated? (Particularly relevant for products with opaque parent company structures.)
  • Regulatory compliance statementsAre GDPR, CCPA, or other regulatory frameworks explicitly acknowledged?
  • Audit/report publicationDoes the company publish transparency reports, warrant canaries, or law enforcement request statistics?

How the sub-score is calculated

Specificity is the dominant sub-factor — vague language is treated as a transparency failure regardless of intent. A policy that names every third-party processor, states exact retention periods, and publishes annual transparency reports scores near 10. A policy that uses phrases like "trusted partners," "reasonable period," and "as permitted by law" throughout scores near 2–3. Publication of transparency reports (particularly for products that may receive government data requests) is a strong positive signal.

Source data:

The privacy policy itself is the primary source. The company's website is checked for transparency report pages, law enforcement guidelines, and corporate structure disclosures. For products where parent company ownership is material to the privacy assessment (e.g., a product owned by a company with a poor privacy track record), that relationship is noted in the product's "Privacy Concerns" section.

How the Final Score Is Calculated

Each category is scored 1–10. The weighted total is:

CategoryScore (1–10)WeightContribution
Data Collectione.g. 730%2.10
Data Usage & Retentione.g. 625%1.50
Securitye.g. 820%1.60
User Controle.g. 515%0.75
Transparencye.g. 710%0.70
Total100%6.65 / 10
7–10 = Low Risk
4–6.9 = Medium Risk
1–3.9 = High Risk

What This Methodology Does NOT Do

  • It does not Score based on reputation, press coverage, or user reviews
  • It does not Give credit for practices that are legally required (e.g., GDPR compliance is a floor, not a differentiator)
  • It does not Penalise products for collecting data that is genuinely necessary for their core function (a GPS navigation app needs location data — the question is what else it collects and what it does with it)

Methodology updates & transparency

We continuously refine our evaluation criteria based on emerging privacy threats and user feedback. Every change is documented and timestamped.

Current methodology version

v3.2.0
Last Updated: January 5, 2026
v3.2.0MINOR
January 5, 2026
  • Enhanced AI training data usage evaluation criteria
  • Added biometric data collection assessment factors
  • Updated third-party SDK tracking methodology
  • Improved mobile app permission analysis framework
v3.1.0MINOR
November 12, 2025
  • Introduced browser fingerprinting detection methods
  • Expanded data retention policy evaluation
  • Added cross-device tracking assessment
  • Updated encryption standard requirements
v3.0.0MAJOR
August 20, 2025
  • Complete scoring framework overhaul with weighted categories
  • New risk level classification system
  • Enhanced transparency and accountability criteria
  • Standardized evaluation process across all product categories

Ready to Make Informed Privacy Decisions?

Explore our product evaluations and discover privacy-respecting alternatives that don't compromise on functionality.