GoatCounter: Correctly classify sessions, IP processing and aggregates
By default, GoatCounter stores highly aggregated statistics and not a raw IP address in the database. Nevertheless, it processes the address to detect repeat visits.
Requirements
You need access to the GoatCounter settings and should decide whether session detection is even necessary for statistical purposes.
Session recognition
GoatCounter forms a session identifier from the site ID, user agent and IP. According to current documentation, the assignment to a random UUID remains in memory for up to eight hours and is not written to disk.
Even more economical: deactivate sessions
Session detection can be deactivated in Settings → Data collection → Sessions . Then every page view is counted without having to summarize reloads for statistics.
Test
After switching off the sessions, carry out test calls and check whether the required aggregates are still sufficient.
Dismantling
If session evaluations are absolutely necessary, reactivate the session function and document the temporary recognition accordingly.
Do not activate individual page views unnecessarily
The detailed storage of individual page views is deactivated by default. For minimalist use, it should remain deactivated and only the units that are really needed should be collected.
Basics of visitor recognition
Additionally for classification purposes Cookieless is not automatically tracking-free and Unique visitors without recognition use . What is important is not just the presence of cookies, but also whether requests are merged via sessions, hashes, local storage or other features.
Related guides
Sources and verification
This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.
Important: IP processing is not IP storage
An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.