Skip to main content
DataLeaked

Scoring methodology

How the privacy score is built, what the fingerprint heuristic means, and what browser-only testing cannot prove.

Every measurement on this site runs in your browser. Nothing is uploaded, and there is no population database — so every number here describes your current setup, not how you rank against other people.

This page documents the scoring weights, the evidence behind each result, and the hard limits of what JavaScript in a web page can observe.

How the privacy score is built

The overall score is a weighted average over four categories: Fingerprinting 30%, Network 30%, Storage 25%, Device 15%. Only categories with fresh measurements count — unavailable inputs are excluded from the average and shown as Unknown, never as perfect.

Coverage reports how much of the total weight was actually measured. A score of 80 with 50% coverage means half the picture is still missing; run the remaining analyses before treating the number as complete.

Fingerprinting
30%
Network
30%
Storage
25%
Device
15%

Unknown is honest: an input the browser would not reveal is excluded, not scored 100.

The fingerprint identifiability heuristic

The fingerprint page combines local signals — canvas and audio rendering, fonts, screen, locale, hardware hints — into a local identifiability estimate. It measures how distinctive your configuration looks, not how unique you are among all internet users.

No population comparison is possible on a static site: we collect no data, so there is no crowd to blend into or stand out from. Use the number to compare your own runs before and after a settings change.

Evidence statuses

Every result carries one of four statuses:

  • Measured

    Read directly from a browser API during this run (for example, screen resolution or permission state).

  • Heuristic

    Inferred locally from observable signals (for example, VPN presence or tracker blocking). Educated, but not certain.

  • Editorial

    Reference information written by the site authors (setup examples, tutorial advice). Not a measurement of your browser.

  • Unavailable

    The browser would not reveal this (for example, TLS cipher, system DNS resolvers, HttpOnly flags). Shown as unknown — never guessed.

What browser-only testing cannot prove

A web page cannot observe everything that matters for privacy. JavaScript cannot see:

  • TLS cipher suites and certificate details
  • System DNS resolvers and OS-level encryption
  • HttpOnly or Secure flags on cookies the page cannot read
  • The full extension list or cross-site storage
  • Any website other than the one currently open

Any tool claiming these values from pure JavaScript is guessing. This site labels them unavailable instead.

When this site contacts third parties

Most pages contact nobody. The exceptions below run only when you press the button, and each names its provider before you run it:

  • WebRTC test → STUN discovery via stun.cloudflare.com
  • Public IP lookup → api.ipify.org; the DNS privacy check adds ipapi.co (organization) and cloudflare-dns.com (DoH reachability probe)
  • Geolocation and clipboard → read only after your explicit action or permission grant

Nothing is fetched automatically on page load.

Before-and-after snapshots

The privacy score page never writes history automatically. Save an explicit snapshot before changing settings, apply one change, re-run the affected tool, and compare — so you can see which change actually moved the number.

Test your own setup

Run the guided checkup, save a snapshot, then come back after hardening.