Cookieless is not automatically tracking-free
Cookies are just a way to recognize browsers or visitors. localStorage persists regularly across browser sessions; sessionStorage applies to the respective page session. Analytics can also create identifiers from request characteristics on the server side. Therefore, always check the actual recognition, not just the cookie information.
Check
Check cookies, web storage, network requests and server-side identifiers together; Simply stating “cookieless” is not enough.
Principle
“We don’t save!” does not evaluate whether an IP address becomes visible during technical communication, but rather whether this results in unnecessary persistent storage, recognition or sharing.
Related guides
Sources and verification
This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.
Important: IP processing is not IP storage
An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.