Guides
Practical instructions for reducing unnecessary storage of visitor IP addresses and other identifiers. Not every configuration is available on every hosting plan, so provider-level logging must always be checked separately.
Fundamentals & checks
-
IP processing and IP storage: the crucial difference
A website cannot be delivered without IP processing. However, this does not mean that the address has to be saved permanently. -
Anonymize IP or not save it at all?
Anonymization can be useful; if the address is not needed at all for the purpose, not saving is the more data-efficient architecture. -
Cookieless is not automatically tracking-free
Even without cookies, local storage, session storage, IP-based hashes or server-side identifiers can combine visits. -
Unique visitors without tracking: why exact counting requires recognition
Exactly unique visitors require that multiple page views can at least temporarily be assigned to the same instance. -
What does my hosting provider store about website visitors?
Website operators must consider the application, web server and hosting/security layer separately. -
Checklist: does my website store unnecessary visitor data?
A practical check from browser storage to network requests to server, provider and security logs. -
Linux: find your own test IP in log files
With your own test IP you can check which accessible server logs a single page view ends up in. -
MySQL/MariaDB: find possible IP and visitor columns
A pure schema query finds suspicious column names without reading stored visitor data. -
PHP: Check REMOTE_ADDR and passed client IP
Source code search shows places that use visitor IP or proxy headers; a hit does not prove storage. -
Check Set-Cookie header with curl
curl makes server-side cookies visible, even if JavaScript cannot read them because of HttpOnly. -
Check cookies, localStorage and sessionStorage yourself
Browser developer tools show stored identifiers that a pure HTML scanner cannot fully detect. -
Check third-party requests with browser DevTools
The network view also shows requests that JavaScript only creates after loading and that are not visible in HTML. -
WordPress: Data protection self-test with WP-CLI
WP-CLI lists active plugins and relevant options without changing the installation. -
Reverse Proxy: Check forwarding of the visitor IP at the origin
Configurations and headers show whether a proxy passes the original client IP to the origin.
Web servers, reverse proxies & CDN
-
Apache access logs without visitor IP addresses
Current Apache 2.4 configuration: Avoid access logs or use a log format without a client IP. -
nginx access logs without visitor IP addresses
Turn off access logging or use your own nginx log format without remote_addr and forwarded IP. -
Caddy: Reduce IP addresses in access logs
Minimize Caddy logs with current filter functions and take remote_ip, client_ip and forwarded headers into account. -
Traefik: Configure access logs to save data
Remove client IP, headers and query parameters from Traefik access logs. -
HAProxy: Logs without persistent client IP
Use HAProxy as an upstream security layer without unnecessarily perpetuating the visitor IP in normal request logs. -
Cloudflare: Don't share visitor IP to origin
Cloudflare processes the IP at the edge; With Remove visitor IP headers you can limit their forwarding to the origin. -
Caddy: Reconstruct original IP behind reverse proxy only if necessary
Caddy only evaluates client IP headers if trusted_proxies are configured; This allows you to consciously decide whether the Origin needs the visitor IP.
WordPress
-
WordPress: Statify as a simple, data-efficient page view counter
Statify counts page views instead of visitors and, according to the project documentation, does not store IP addresses or visitor profiles. -
WordPress: Set Koko Analytics to be as data-efficient as possible
Koko offers cookie, cookie-free and pageview-only modes. For maximum data minimization, pageview-only is the clearest option. -
WordPress: Configure Burst Statistics to save data
Burst is self-hosted but offers different detection modes. For “We don’t save!” The privacy setting must be chosen consciously. -
WordPress: Classify independent analytics in a data protection-conscious manner
Independent Analytics does not store raw IP, but creates a reusable visitor ID from IP, user agent and salt. -
WordPress: use Antispam Bee with data minimisation
Filter comment spam locally, avoid third-party providers and be aware of IP-dependent options. -
WordPress: Don't permanently save comment IP
Customize WordPress comments so that the normal comment IP is not permanently retained as metadata. -
WordPress: Avoid Gravatar third-party connections
Avatars can create a connection to Gravatar when viewing a page; Local avatars or disabled display avoid this request. -
WordPress: Contact Form 7 without unnecessary additional services
Keep Contact Form 7 itself slim and check optional reCAPTCHA, Flamingo and other integrations separately for storage. -
WordPress: Configure WP Statistics to save as much data as possible
WP Statistics works locally and without cookies; Data protection options prevent additional personal storage and data sharing. -
WordPress: MailPoet without opening and click tracking
MailPoet can reduce or disable engagement tracking for newsletters; Also check diagnostic logging and optional data transfer. -
WordPress: Classify Wordfence and IP-based security functions
Wordfence uses IP-related security data and external infrastructure; Clearly separate security purposes and normal visitor analysis. -
WordPress: Minimize Solid Security Logs and IP Detection
Solid Security logs security events and uses IP addresses for lockouts; Storage location and retention are configurable. -
WordPress: Check WP Activity Log and saved IP addresses
WP Activity Log stores, among other things, the source IP for events; for strict data economy, critically examine the scope and purpose. -
WordPress: Consciously configure login blocks and IP storage
Login limiters typically work IP-based; Attack defense does not automatically justify unlimited storage. -
WordPress: Gravity Forms without saved submitter IP
Gravity Forms can switch off the storage of the IP during form submissions and automatically delete entries after a period of time. -
WordPress: Turn off Fluent Forms IP logging and country detection
Fluent Forms provides filters to disable IP logging and country detection derived from request headers. -
WordPress: Explicitly activate SlimStat IP anonymization
In current versions, SlimStat stores full IP addresses again by default; Anonymization or hashing must be activated consciously. -
WordPress: Jetpack Stats processes visitor IP despite aggregated display
Jetpack shows aggregated statistics to website operators, but Automattic temporarily maintains stats logs with visitor IP.
WooCommerce
-
WooCommerce: turn off voluntary usage tracking
WooCommerce offers voluntary usage data reporting; it can be deactivated in the advanced settings. -
WooCommerce: Only use IP geolocation when needed
WooCommerce can geolocate customer IP locally using MaxMind data; cache mode also generates an IP-based URL hash.
Security & error diagnostics
-
CrowdSec: Attack IP as security data instead of visitor statistics
CrowdSec processes IP addresses of detected attackers specifically for security decisions and has defined retention and degradation rules for this purpose. -
Bugsnag: Do not use IP as automatic browser user ID
By default, Bugsnag uses the IP address as the user ID in the JavaScript SDK; collectUserIp can prevent this collection. -
Sentry: remove personal error data before sending
Sentry offers SDK scrubbing, server-side rules and relay; If you never want data to leave your system, it must be removed before sending. -
Rollbar: IP-based error history and diagnostic data
Rollable can group events by IP and display location information; This function must be examined critically for strict data economy.
Other CMS
-
Drupal: anonymous page views with statistics
The current Statistics module for Drupal 10.3+/11 focuses on anonymous content views instead of visitor profiles. -
Joomla: Use data protection functions and check extensions separately
Joomla's privacy functions help with information and consent, but do not replace checking logs, extensions and third-party resources. -
Joomla: User Actions Log without IP address
Joomla can log user actions without additionally including the IP address in the actions log. -
TYPO3: Configure IP anonymization and logs correctly
TYPO3 has a current ipAnonymization setting - but it does not work when creating new log entries and does not replace a log check.
Statistics & analytics
-
Matomo: configure analytics for data minimisation
Look at IP anonymization, tracker proxy and web server logs together – not just the Matomo database. -
Matomo: Remove original IP before the tracker
The Matomo Tracker Proxy can remove the visitor IP before Matomo processes it - stricter than just subsequent IP masking. -
Umami: cookieless does not mean without visitor identification
Umami does not store IP as a metric, but forms sessions from IP, user agent and website ID. Distinct IDs can additionally connect profiles. -
Plausible: Understanding IP processing and daily visitor recognition
Plausible does not store the raw IP, but processes the IP and user agent for location and a daily changing visitor ID. -
GoatCounter: Correctly classify sessions, IP processing and aggregates
GoatCounter stores aggregates by default; IP and user agent are processed in RAM for up to eight hours for session detection. -
GoAccess: Anonymize IP addresses when evaluating logs
GoAccess can mask client IP addresses when reading in; The original web server log must still be configured separately to save data. -
PostHog: Correctly classify cookieless mode
At PostHog, cookieless means no browser ID, but server-side daily recognition from IP and user agent. -
Countly: Understanding IP processing for geolocation
According to the documentation, Countly does not store raw IP, but processes it first to determine location. -
Simple Analytics: Classify analytics without visitor recognition
Simple Analytics does not document cookies, local storage identifiers, or storing or hashing IP addresses. -
Fathom Analytics: cookieless, but with short-term IP processing
Fathom does not set analytics cookies, but processes IP and user agent for daily rotating visitor signatures. -
Microsoft Clarity: Consent Mode prevents cookies, not every measurement
Clarity can work without cookies before consent, but still carries out requests and basic measurements. -
Pirsch: cookieless with daily visitor ID from IP and user agent
Pirsch does not store the IP, but processes it with user agent, date and salt to create a visitor ID that can be used for up to 24 hours. -
Piwik PRO: measure without cookies and without session hash
Piwik PRO can switch off cookies and session hash; then each event is treated as a new session and visitors are not recognized. -
Cloudflare Web Analytics: classify cookieless RUM connection
Cloudflare Web Analytics uses an external beacon and describes the measurement as without personal end-user profiles; The network request still remains. -
Plausible proxy: Visitor IP is still passed on to Analytics
A first-party proxy visually hides the analytics request but does not eliminate Plausible's IP processing.
Forms, CAPTCHA & spam protection
-
Contact form without tracking and unnecessary IP storage
Process contact forms locally, only collect necessary fields and build spam protection without unnecessary third-party connections. -
CAPTCHA and spam protection: first local, then external
Use honeypot, time check and server-side rules before external CAPTCHA services and make third-party connections visible. -
Cloudflare Turnstile: CAPTCHA replacement is still a third party
Turnstile avoids classic image CAPTCHAs, but sets up Cloudflare communication and should therefore be evaluated separately from local spam protection. -
Google reCAPTCHA: Consciously evaluate third-party connections
reCAPTCHA integrates Google into the bot check; Local spam defense is the first choice for data-saving forms. -
hCaptcha: integrate data efficiently and recognize third-party connections
hCaptcha is also an external challenge service; only load where protection is required and configure server checking separately. -
Getform: Form service collects additional visitor data
In addition to form fields, Getform also documents IP address, location, operating system, browser and device type. -
Brevo Forms: CAPTCHA means additional third-party processing
Brevo offers Google reCAPTCHA or Cloudflare turn styles for forms; Both options involve an additional external service.
Newsletters & email tracking
-
Newsletter without opening and click tracking
Send newsletters without installing invisible tracking pixels and personalized tracking links for each recipient. -
Brevo: Anonymize opening and click tracking
By default, Brevo assigns opens and clicks to recipients; Anonymous tracking separates these events from specific contacts. -
Mailchimp: Turn off open and click tracking
Mailchimp enables open and click tracking by default; both functions can be deactivated per email. -
MailerLite: Deactivate Open Tracking specifically
MailerLite allows opening measurement to be switched off; other measurements such as click or e-commerce tracking must be controlled separately. -
Buttondown: Open Tracking is opt-in
Buttondown does not necessarily activate opening tracking; When activated, a receiver-specific tracking pixel is inserted.
Hosting & providers
-
Hetzner Webhosting: Configure access logs to save data
Hetzner web hosting does not require permanent visitor IP logging; the documented standard retention of logs is seven days. -
IONOS web hosting: check anonymized logs and storage
IONOS documents anonymized web hosting logs; The hosting comparison shows a retention period of eight weeks. -
STRATO web hosting: separate anonymized customer logs and security logs
STRATO provides anonymized customer logs; Security-related processing of complete IP addresses must be considered separately. -
manitu web hosting: Activate IP anonymization yourself
At manitu, the anonymization of web server logs is a conscious setting; The replacement by 127.0.0.1 is documented in the hosting comparison. -
Mittwald Hosting: Check anonymized access logs and error logs separately
Mittwald anonymizes access log IP addresses; Error logs may contain IP addresses and have a shorter retention period.
Website builders
-
IONOS Website Builder: Classify visitor logs and web analytics
IONOS directly documents anonymized IP addresses and 21 days of storage of certain visit data for website builders. -
STRATO homepage builder: Check statistics, cookies and external content
STRATO documents its own visitor statistics, cookie control and external content as separate functions. -
Squarespace: Reduce analytics cookies and unique visitors
Squarespace Analytics uses, among other things, cookies for up to two years for unique visitors; Analytics cookies can be deactivated. -
Webflow Analyze: cookieless means local storage here
Webflow Analyze does not use cookies for visitor recognition, but uses local storage and anonymous identifiers. -
Jimdo Creator: Consciously activate or deactivate statistics
Jimdo Creator Statistics is cookieless and anonymized; the function can be completely deactivated. -
one.com Website Builder: Check consent banners and tracking integrations
one.com offers a consent banner; additional analytics and advertising integrations must be evaluated separately. -
Wix: Minimize cookies, analytics and session recordings
Wix distinguishes between essential and consent-requiring analytics cookies; Session recordings are an additional, separately activated function. -
Hostinger Website Builder: Only activate tracking integrations specifically
Google Analytics, Hotjar, Meta Pixel and other tracking services are optional integrations of the builder.
PHP & website resources
-
PHP sessions: only use when state is really needed
PHP sessions typically generate a recognizable session ID; Minimize lifespan, cookie properties and server-side data. -
External fonts and CDNs: avoid unnecessary third-party connections
Deliver fonts, JavaScript and CSS locally if there is no technical reason for external retrieval. -
Only load YouTube, maps and other embeds as needed
Do not automatically connect external media when the page is accessed; Display preview image or placeholder locally and only load embed after action. -
Disqus: Evaluate third-party comments and tracking separately
Disqus processes technical data and tracking signals for embedded comments; Publishers can disable data sharing. -
YouTube nocookie: Data protection mode does not replace a two-click solution
youtube-nocookie reduces certain storage, but still establishes a third-party connection when loading the player. -
Cloudflare Zaraz: server-side tagging is still third-party processing
Zaraz can load marketing and analytics tools differently, but does not automatically eliminate their data processing.