← All guides

Plausible: Understanding IP processing and daily visitor recognition

Plausible does not use normal tracking cookies or persistent visitor IDs. For unique visitors, the IP address and user agent are still processed on the server side.

Requirements

Clarify in advance whether Plausible is hosted or self-operated and which events or custom properties are really needed.

What happens to the IP

According to current Plausible documentation, the IP and user agent are used for an identifier that changes daily; the salt is rotated every 24 hours. According to the provider, the raw IP is not stored in the database or logs on disk. In addition, the IP is used to determine location.

Do not include your own data

Custom properties may not contain any personal or pseudonymous user IDs. Names, email addresses, IP addresses or your own permanent IDs would undermine the basic data-saving approach.

Test

Send test events and check that no personal or permanent IDs are transferred as properties.

Dismantling

Remove unnecessary custom properties and events. If an evaluation is reactivated, check your data fields again for identifiers.

Distinguish between hosted and self-hosted

With the hosted service, an additional processor level is added. With self-hosting, web server, proxy and hoster logs must be checked separately.

Basics of visitor recognition

Additionally for classification Cookieless is not automatically tracking-free and Unique visitors without recognition use . What is important is not just the presence of cookies, but also whether requests are merged via sessions, hashes, local storage or other features.

Related guides

Sources and verification

This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.

Important: IP processing is not IP storage

An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.

↑