Site Rankings

Privacy scores from our latest analysis of each site. Updated as new analyses land.

1,590Sites analyzed
318Sites queued
Updated: Sep 15, 2026Last Added: gains.com

Best 5

#1
10
proton.me
Proton publishes a gold-standard privacy policy. Strong commitments: no selling of data, no targeted advertising, no profiling, no logs (per product), end-to-end encryption by default for Mail, Drive, Calendar, VPN, Pass, Wallet, Meet, Lumo. Encrypted content cannot be decrypted by Proton itself. Only minimal billing info retained (name + last 4 of credit card). Swiss-law-governed with published transparency reports about data requests. As a privacy-first company, Proton's policy is the closest the analyzed sample gets to architectural privacy.
Also covers: protonmail.com
#2
10
brave.com
Brave (privacy-focused web browser + search engine) — extraordinary privacy posture by design. Brave does NOT collect or retain user browsing history. Explicit no-buy/no-sell/no-share of personal data about consumers. Brave Ads on New Tab Page is opt-out; Brave Search ads can be blocked via 'Aggressively block trackers and ads' in Brave Shields. Anonymous-data contribution is opt-in. Full GDPR/CCPA rights catalog. The score reflects the genuinely no-tracking-by-design browser architecture, no-sale/no-share/no-buy posture, and opt-in-only anonymous data contribution — among the strongest browser privacy postures.
#3
9
pressbooks.pub
Pressbooks (Book Oven Inc., Quebec) runs a consent-based, minimal-collection privacy policy that explicitly does not sell or rent personal data. It complies with GDPR, PIPEDA, CCPA and Quebec Law 25, grants a broad set of user rights, uses SCCs for cross-border transfers, and avoids automated decision-making. The only sharing is with named processors for analytics, email, support, hosting and payments, plus one opt-out-able LinkedIn ad network.
#4
9
iawriter.com
iA (Information Architects, a Swiss company) collects only account, device, payment and transaction data needed to run its apps and services. It does not sell data or share it with third parties for their own marketing, limits service providers to processing on its behalf, and commits to the shortest practical retention. Users get a full set of GDPR-style rights including access, deletion, portability and consent withdrawal.
#5
9
ndr.de
NDR is a German public broadcaster whose privacy practices are unusually data-minimal: no advertising, no advertiser tracking, and no user profiling. Analytics run only in anonymized form with a clear opt-out, and data is not sold or shared with third parties except contracted processors under GDPR or where legally required. Retention is short and clearly stated, and the full slate of GDPR rights is provided.

Worst 5

#1
1
ecured.cu
EcuRed, the Cuban state-run collaborative encyclopedia, displays a footer link reading "Normativa de privacidad" that leads to a page which has never been written. Checked on 16 August 2026, that URL returns HTTP 404 with the MediaWiki empty-article message: "Actualmente no hay texto en esta pagina ... no tienes permiso para crear esta pagina." The neighbouring "Exoneraciones" disclaimer link is blank in exactly the same way. This is worse than a site that stays silent, because the link asserts a policy exists and a reader has to click through to discover there is nothing behind it. Meanwhile the site is not passive about data: loading the homepage contacted Google Analytics and the Cuban national collector stats.cubava.cu and set five cookies across two analytics stacks, Google Analytics and Matomo. And it is not read-only, either. It runs registered contributor accounts, a collaborator portal, moderation policies and public page histories over 282,081 pages, so it solicits registration and records per-user editing activity, all without a single published word about what is collected, who receives it, how long it is kept, or how to have it removed. Score 1 reflects that nothing whatsoever is committed to in writing.
#2
1
cnrtl.fr
The CNRTL lexical portal, created in 2005 by the CNRS and run by the UMR ATILF within the ORTOLANG project, publishes no privacy policy at all. Checked on 16 August 2026, the rendered homepage contains zero occurrences of "privacy", "confidentialite", "donnees", "cookie" or "RGPD", and the single legal link on the page, "Infos legales", leads to a publication masthead that covers only the postal address, the publication director, a CNRS liability disclaimer, copyright, and hyperlinking rules. The site returns HTTP 200 with homepage content for every unknown path, so the ten privacy and legal paths probed were compared by content rather than status code; all ten served byte-identical homepage text, meaning none exists. The one genuinely mitigating fact is that observed behavior is unusually clean for a site this size: the homepage issued zero third-party requests and set zero cookies, with no analytics, tag manager, or ad tech anywhere. But that is a measurement taken on one day, not a promise, and it is undermined by who is publishing. This is a French public research institution squarely inside the GDPR and the Loi Informatique et Libertes, and it names no data controller, no DPO, and no contact route for an access or deletion request, while saying nothing about the server logs or the search queries users type into a dictionary. Score 1 is the floor and reflects the absence of any published commitment, not evidence of misuse.
#3
1
uml.edu.ni
Universidad Martin Lutero publishes no privacy policy at all. Checked on 16 August 2026, the rendered homepage contains zero occurrences of either "privacy" or "privacidad", none of its 186 links points to a privacy notice, aviso legal, or cookie policy, and /privacidad, /politica-de-privacidad, /aviso-legal, /privacy-policy, /legal/privacy and /terms all return 404. Spanish paths were probed alongside English ones, so this is not a case of looking in the wrong language. This is not a thin or outdated policy, it is the absence of one, and a Contacto page resolves fine, so the site plainly has somewhere to put one. The stakes are higher than for a brochure site: this is a university with 12 campuses running permanently open admissions, a scholarships programme, and a virtual learning environment, with degree programmes including clinical psychology, nursing and pharmacy. Prospective and enrolled students hand over identity documents, academic history, and financial-need information, and are told nothing about what is collected, who receives it, how long it is kept, or how to obtain or delete their records. No data protection statement, legal notice, or privacy contact appears anywhere, and the site references no data protection law. Score 1 is the floor: with nothing published, there is not a single commitment a student could hold the university to.
#4
1
lexiconlearning.com
Lexicon Learning publishes no privacy policy at all. Checked on 16 August 2026, the rendered homepage contains zero occurrences of the words "privacy" or "cookie", none of its 32 links points to a privacy notice, terms of service, or any legal page, and /privacy, /privacy-policy, /legal/privacy and /terms all return 404. This is not a thin or outdated policy, it is the absence of one, and the site has an About page and a Contact page, so it plainly has somewhere to put one. That gap matters here because this is not a brochure site: Lexicon Learning registers user accounts, sells paid subscriptions, issues completion certificates, and by its own marketing runs AI personalisation that monitors learner progress with "detailed analytics and personalized learning insights". It also ships apps on both the Apple App Store and Google Play, each of which requires a privacy policy URL for a listed app, which makes the absence harder to read as an oversight. Learners hand over an identity, payment details, and a continuous record of study behaviour, and are told nothing about what is collected, who receives it, whether it is sold, how long it is kept, or how to have it deleted. Score 1 is the floor: with nothing published, there is not a single commitment a user could hold the operator to.
#5
1
rileagroup.com
The Rilea Group publishes no privacy policy at all. Its full WordPress sitemap was enumerated - 34 pages across English and Spanish - and there is no privacy, cookie, legal, or terms page anywhere on the site; eleven common privacy paths all return 404, and no page links to one. The site is not passive: the homepage runs a Contact Form 7 lead form and the company actively solicits inquiries from prospective condo buyers and investors for projects like The Rider in Wynwood. So contact details are collected with no statement of what is gathered, why, how long it is kept, who it goes to, or how to ask for a copy or a deletion. Nothing here is legally forbidden in the way a bad policy can be - the site simply says nothing either way, which leaves you with no rights you can point to and no promise anyone can be held to. The one small mercy is that no third-party analytics or advertising tags were detected in the pages served, so there is no evidence the lead data is being piped into ad tech.