FAQ
Questions, answered
What the scores mean, where the data comes from, and how access and billing work. Anything missing? Write to [email protected].
The data
What is an App Store privacy label?
Apple requires every developer to declare what data their app collects and how it is used. The declaration is shown on the app's App Store page, sorted into groups: data used to track you, data linked to you, data not linked to you, and data not collected. privacybench reads those declarations and turns each one into a score.
Are the labels verified?
No. Labels are self-declarations. Apple does not audit them, and neither do we. A low score can mean an app collects little, or that its developer declared little. A high score means an app declares a lot of collection, not that it was caught doing anything.
How is the score calculated?
Every distinct data type an app declares counts once per group, multiplied by the group's weight: tracking ×10, linked ×4, not linked ×1.5. The sum is scaled against the most a label could ever declare (every one of Apple's 16 data types in every group) to give a number from 0 to 100. Higher means more declared collection. The full formula, weights and reasoning are on the methodology page.
Why is tracking weighted so heavily?
Data used to follow a person across other companies' apps and websites is the most consequential declaration a developer can make. The weights are ordinal judgements, not measurements, which is why they are published rather than buried in code.
How often is the data updated?
Weekly. Each run stores a new snapshot for every app, so a label that changes shows up as a change on the changes page instead of silently overwriting the old one.
Which storefront are the labels read from?
One: the US App Store, so scores stay comparable. Labels can differ between storefronts, and we can compare a chosen app across countries separately; that comparison never changes its score.
Why is an app missing, or shown as "no data"?
Either it is not in the corpus yet, or its label could not be read. An unreadable label is never scored as zero: the app is tracked but left out of the ranking, because "we could not read it" is not evidence that it collects nothing. You can add an app yourself with Check your app.
Do you cover Android?
Partly. Google Play's Data Safety section uses a different vocabulary from Apple's, so those declarations are stored and available to staff and to API plans that include them, but they are not folded into the iOS score.
Access and accounts
Do I need an account?
To view the ranking and app pages, yes: privacybench is in preview and the data is open to signed-in accounts. This page, the pricing page, the terms and the privacy policy are public. Sign in with Google or with an email and password.
What do you do with my Google account?
We ask Google for your basic profile (name and email) so we can create your account. We never see your Google password and cannot access anything else in your Google account. Details are in the privacy policy.
Can I delete my account?
Yes. Email [email protected] from the address on the account and we will delete it, its sessions and its API keys.
Plans and billing
What do the paid plans add?
The website stays free. Paid plans add programmatic access: a rankings API, a developer lookup API, and on higher tiers a weekly change feed and exports. The pricing page lists exactly what each plan includes.
Who handles payment?
Lemon Squeezy is our merchant of record: it takes payment, calculates and remits sales tax and VAT, and issues invoices. Card details go to Lemon Squeezy, never to us.
How do I cancel?
From your account page, open Manage billing and cancel there. You keep paid access until the end of the period you already paid for, then the account returns to the free plan.
Do you offer refunds?
Yes, within 14 days of your first payment on a plan, if the service did not do what the plan describes. Write to [email protected]. See the terms for details.
Is there a rate limit?
Yes, per API key per day. Pro is 1,000 requests a day, Business 20,000. Higher volumes are available on an Enterprise contract.
About privacybench
Are you affiliated with Apple or Google?
No. privacybench is an independent project. Apple, App Store and Google Play are trademarks of their respective owners. Data is retrieved from public endpoints.
A developer disagrees with their score. What happens?
The score is derived only from what the developer declared. If a label is updated, the next weekly run picks it up and the score follows. If you believe a label was read incorrectly, write to us with the app's link and we will re-check it.