Site Rankings
Privacy scores from our latest analysis of each site. Updated as new analyses land.
1,502Sites analyzed
329Sites queued
Updated: Jul 2, 2026Last Added: render.com
Best 5
#1
10
proton.me
Proton publishes a gold-standard privacy policy. Strong commitments: no selling of data, no targeted advertising, no profiling, no logs (per product), end-to-end encryption by default for Mail, Drive, Calendar, VPN, Pass, Wallet, Meet, Lumo. Encrypted content cannot be decrypted by Proton itself. Only minimal billing info retained (name + last 4 of credit card). Swiss-law-governed with published transparency reports about data requests. As a privacy-first company, Proton's policy is the closest the analyzed sample gets to architectural privacy.
Also covers: protonmail.com
#2
10
brave.com
Brave (privacy-focused web browser + search engine) — extraordinary privacy posture by design. Brave does NOT collect or retain user browsing history. Explicit no-buy/no-sell/no-share of personal data about consumers. Brave Ads on New Tab Page is opt-out; Brave Search ads can be blocked via 'Aggressively block trackers and ads' in Brave Shields. Anonymous-data contribution is opt-in. Full GDPR/CCPA rights catalog. The score reflects the genuinely no-tracking-by-design browser architecture, no-sale/no-share/no-buy posture, and opt-in-only anonymous data contribution — among the strongest browser privacy postures.
#3
9
pressbooks.pub
Pressbooks (Book Oven Inc., Quebec) runs a consent-based, minimal-collection privacy policy that explicitly does not sell or rent personal data. It complies with GDPR, PIPEDA, CCPA and Quebec Law 25, grants a broad set of user rights, uses SCCs for cross-border transfers, and avoids automated decision-making. The only sharing is with named processors for analytics, email, support, hosting and payments, plus one opt-out-able LinkedIn ad network.
#4
9
iawriter.com
iA (Information Architects, a Swiss company) collects only account, device, payment and transaction data needed to run its apps and services. It does not sell data or share it with third parties for their own marketing, limits service providers to processing on its behalf, and commits to the shortest practical retention. Users get a full set of GDPR-style rights including access, deletion, portability and consent withdrawal.
#5
9
ndr.de
NDR is a German public broadcaster whose privacy practices are unusually data-minimal: no advertising, no advertiser tracking, and no user profiling. Analytics run only in anonymized form with a clear opt-out, and data is not sold or shared with third parties except contracted processors under GDPR or where legally required. Retention is short and clearly stated, and the full slate of GDPR rights is provided.
Worst 5
#1
1
robinhood.com
An extremely one-sided crypto customer agreement. RHC disclaims liability for nearly everything (Downtime, System Failures, forks, price moves, unauthorized account use, irreversible wallet transfers sent to the wrong address, and forfeited 'dust' balances), limiting its own exposure to actual losses from gross negligence or willful misconduct proven in a final non-appealable judgment, while excluding all indirect, consequential, and punitive damages. The customer shoulders broad indemnification (including a California Civil Code 1542 waiver), a 24-hour fraud-notice window, 2-day/10-day objection deadlines, and mandatory binding arbitration with a class-action and public-injunctive-relief waiver (rejectable only within 60 days). RHC may suspend, freeze, restrict, liquidate, or close accounts and offset balances across affiliated accounts at its sole discretion, amend the agreement at any time without notice, and assign the account and the information it has collected without consent. It defers all actual privacy practices to a separate Robinhood Privacy Policy.
#2
2
niche.com
Niche.com collects extensive personal and sensitive data (including academic, employment, location and user-submitted content) and explicitly sells it to advertisers such as realtors, loan providers and schools, confirming in its CCPA disclosure that it sold data in the past 12 months. Opt-out of sale exists but is not the default, and users cannot opt out of sharing with processors, business partners, or enterprise partners who reuse data for their own marketing and R&D. Providing a phone number is treated as express consent to telemarketing and autodialed calls regardless of Do-Not-Call status, and the site does not honor Do Not Track signals.
#3
2
everydayhealth.com
Everyday Health (a Ziff Davis company, covering sites such as Everyday Health and Castle Connolly and apps like Calorie Counter and Diabetes In Check) pairs a comprehensive rights framework and Data Privacy Framework certification with some of the most aggressive data practices for a health platform. It explicitly states it may sell your sensitive personal data (Texas notice), sells and transfers Online Data to advertisers, runs lead-generation that shares your name and email with third-party advertisers, makes contact details available on a 'rental or sale' basis, and sources data from data brokers - all while processing health, diet and fitness data for targeted advertising. Broad opt-outs, a 180-day cap on behavioral-ad data, and free DPF dispute resolution soften it slightly, but selling sensitive health data, ignoring Do-Not-Track, and a binding arbitration clause with a class-action waiver make this a serious red flag.
#4
2
rocketreach.co
RocketReach is a contact-lookup data broker that scrapes publicly available information and acquires data from other data brokers, then makes identified personal contact data (name, email, phone, work history, location, social profiles) available to its customers and business partners. It self-registers as a Texas data broker and offers CCPA 'Do Not Sell or Share' opt-outs, confirming its model involves selling/sharing personal data. While it provides GDPR/CCPA rights, honors GPC, and is transparent, the underlying business is building and monetizing dossiers on people who never signed up, which is inherently privacy-hostile.
#5
2
babycenter.com
BabyCenter (operated by Everyday Health, a Ziff Davis company) pairs a comprehensive rights framework and DPF certification with some of the most aggressive data practices for a health platform. It explicitly states it may sell your sensitive personal data (Texas notice), sells and transfers Online Data and identifiable information to advertisers, runs lead-generation that shares your name and email with third-party advertisers, and sources data from data brokers - all while using health data like pregnancy status and due date for targeted advertising. Comprehensive opt-outs, a 180-day OBA retention limit, and free dispute resolution soften it slightly, but selling sensitive health data on a pregnancy-tracking service is a serious red flag.