Checklist: does my website store unnecessary visitor data?
Check in this order: 1. Cookies, localStorage and sessionStorage in the browser. 2. Network requests to third parties. 3. Forms, comments and application tables. 4. Web server access and error logs. 5. Reverse Proxy/CDN and passed IP headers. 6. WAF, Fail2ban and other security logs. 7. Hoster/Provider Retention. 8. Statistics systems for permanent visitor identification. 9. After making changes, test again with a fresh browser session.
Completion
Recheck with a fresh browser session after each change, treating browser, network, application, server and provider as separate layers.
Principle
“We don’t save!” does not evaluate whether an IP address becomes visible during technical communication, but rather whether this results in unnecessary persistent storage, recognition or sharing.
Related guides
Sources and verification
This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.
Important: IP processing is not IP storage
An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.