Umami: cookieless does not mean without visitor identification
Umami is cookieless and, according to current documentation, does not store the IP address used as a location metric. It will still be processed for session creation.
Requirements
You need access to the Umami configuration and, in the case of self-hosting, to the upstream web server or proxy configuration.
How Umami distinguishes visitors
A session is formed from a hash of, among other things, visitor IP, user agent and website ID. The current metrics documentation also describes rotating salts. This means that Umami is more data-efficient than permanent cookie tracking, but cannot be equated with a pure page view counter without recognition.
Do not use distinct IDs unnecessarily
With umami.identify() , sessions can be assigned a separate ID across visits and devices. For a minimal data-saving configuration, this function should not be used if such recognition is not really necessary.
Test
Use test visits to check whether no unnecessary distinct IDs are set and which session data is actually created.
Dismantling
If a required evaluation is missing, just reactivate the required function and re-evaluate the resulting recognition.
Here too: separate web server
Self-hosting shifts control to your own server. Web server access/error logs remain their own data source and must be checked independently of Umami.
Basics of visitor recognition
Additionally for classification Cookieless is not automatically tracking-free and Unique visitors use without recognition. What is important is not just the presence of cookies, but also whether requests are merged via sessions, hashes, local storage or other features.
Related guides
Sources and verification
This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.
Important: IP processing is not IP storage
An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.