When I signed up for a meditation app during a bad month, I clicked "I agree" without reading a word. Most people do. Turns out there's a volunteer project that already read it for me — for that app, and thousands of others — and graded it A through E, the same way a restaurant gets a health inspection.

What "agreeing" actually means

A 2008 study calculated that reading every privacy policy the average person encounters in a year would take about 244 hours — a figure later popularized as "76 work days" by The Atlantic. Nobody does this. Companies know nobody does this. That's the whole design: a "clickwrap" agreement (the box you check) creates a real record you agreed to something specific, and courts enforce it; a "browsewrap" agreement (just using the site counts as agreeing) is weaker in court but used constantly anyway, and it's been upheld often enough that "if you keep using this, you agree" functions as real consent. Not a loophole in the law. The law working exactly as designed, on a "yes" nobody meaningfully gave.

The grades — and what mine looked like

Terms of Service; Didn't Read (ToS;DR) is a volunteer project that's been reading these agreements since 2012 and grading them A (best) to E (worst), with a free browser extension that shows you the grade before you agree to anything. I checked what's actually on my phone.

Grade E — "very serious concerns." Instagram: reads your private messages, uses your identity in ads shown to other people, keeps your content after you delete it. PayPal: changes its policy retroactively and keeps tracking you even after you opt out of tracking. Credit Karma, Flickr, Rotten Tomatoes, CouchSurfing, and Discovery (Food Network, HGTV, TLC) all carry the same grade.

Grade D — "very uneven." Headspace — yes, the meditation app: even changes to its terms are inferred from you just continuing to use it, not something you're actually asked to agree to, and your data may be sold if the company is acquired or goes bankrupt. The BBC, Skillshare, Urban Dictionary, and MyAnimeList are all here too.

Grade C — "okay, but issues need your attention." Apple has 16 flagged issues on its own page — more than any other service that didn't land in D or E territory. USPS, Ecosia, Bandcamp, and Canonical (Ubuntu) all land here too — genuinely mixed, not disqualifying.

Grade B — "fair, could be improved." Waze, the privacy-focused search engine Qwant, FastMail, Nextcloud. Qwant's entire bad list is three items. This is what "pretty good" actually looks like in writing.

Grade A — the best rating — was the most telling thing I found. The services that earn it are almost all small, privacy-focused tools most people have never heard of. Not one thing I actually use every day cleared that bar.

The catch: grading it doesn't stop it

A grade tells you what you're agreeing to. It doesn't make the company stop. Instagram doesn't read your messages less because it's rated E. This is a transparency tool, not an enforcement one — the same limit every label has, from nutrition facts to a car's crash-test rating. Useful precisely because it's honest about what it isn't.

Do it yourself (about 2 minutes)

  1. Install the free ToS;DR browser extension — it shows a letter grade on sites as you visit them.
  2. Before your next "I agree," check the grade instead of the document.
  3. If something you rely on grades D or E, that's not a reason to panic — it's a reason to know, and to check whether a real opt-out exists (many do; California's DROP tool is the strongest one currently running).
  4. Report a bad or missing grade yourself — it's volunteer-run, and it's only as good as who shows up to read.

You can't read every agreement you click through. You can glance at a letter grade in the time it takes to tap "I agree" anyway.

The Receipts

Spotted an error? editor@thebluf.news