Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Umami’s cookie-free tracker does not, by itself, establish that a website needs no consent or processes no personal data. Umami’s session documentation says a session identifier is a hash generated from the visitor’s IP address, user agent, and website ID. To assess your setup, check the tracker’s actual data flow, applicable device-access rules and GDPR legal basis, then configure collection and retention to match your purpose.

What Umami collects—and what “cookie-free” does not mean

Umami says its tracking code does not use cookies. Its FAQ also lists data it collects, including page views, referrer URLs, browser, operating system, device type, and country of origin. Those product statements describe the tracker; they do not decide whether a particular deployment complies with privacy law. See Umami’s FAQ.

Umami’s Sessions documentation, available since v2.13.0, says a session is identified by a unique hash generated from the visitor’s IP address, user agent, and website ID. That means the tracker’s session mechanism uses IP information to generate an identifier. Do not describe the system as never processing an IP address based only on the fact that it does not set cookies.

A hash is not automatically anonymous. The European Data Protection Board explains in its guidance on personal data and blockchain technologies that salted or keyed hashes may still be personal data, depending on whether people can be identified or singled out by means reasonably likely to be used. That general principle is not an Umami-specific legal assessment; evaluate the identifier and surrounding data in your own deployment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does Umami require a consent banner?

There is no universal yes-or-no answer based just on Umami being cookie-free. GDPR’s legal-basis question and the separate rules governing storing information on, or accessing information from, a visitor’s device must be assessed for the actual tracker, purpose, and jurisdiction.

The EDPB identifies six GDPR legal bases and says the appropriate one depends on context; it does not designate analytics as automatically exempt. See its legal-basis guidance. In France, CNIL describes a consent exemption for audience-measurement tools only under conditions; its guidance includes truncating the last byte of an IP address among those conditions. This is conditional French regulator guidance, not a blanket ruling for all Umami deployments or all EU/EEA countries. Check the rules that apply where your visitors are located and how your specific tracker behaves.

Make your privacy notice match the implementation: explain the analytics purpose, data categories, retention, and applicable rights. Avoid claims such as “we collect no personal data” or “consent is never required” unless your legal and technical assessment supports them.

Configure the tracker to collect less

Umami documents controls for suppressing or narrowing collection. Confirm the syntax and availability against the documentation for the version you have deployed; Umami’s configuration pages include controls introduced across different versions. The tracker configuration documentation describes these options:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Respect browser Do Not Track: set data-do-not-track="true" on the tracker script to respect a visitor’s browser setting.
  • Exclude URL fragments: set data-exclude-hash="true" to prevent collection of the URL hash.
  • Cancel or modify events before sending: use the documented data-before-send callback to inspect or modify an event payload. Returning a false-y value cancels that payload. Use the callback to remove data that should not be transmitted; follow the version-specific documentation for its exact syntax.
  • Review automatic tracking: tracker initialization can automatically track page views and clicks. Disable or narrow automatic tracking if it exceeds the purpose you have documented.

Test the actual URLs and events your site sends. Routes, query strings, referrers, and custom events can inadvertently include names, email addresses, account identifiers, search terms, or other sensitive information. These tracker controls are collection controls, not a consent-management system or a substitute for a legal assessment.

Understand IP-derived sessions and the available IP controls

Umami documents SALT_ROTATION as controlling how often the anonymous session salt rotates; its documented default is month. Check the environment-variable documentation for the setting and your installed version before changing it. Salt rotation is not a deletion schedule: it does not erase historical analytics records. The documentation also says deterministic IDs derived from analytics data are not changed by the UUID setting, so do not assume that setting changes those identifiers.

The same environment-variable documentation describes IGNORE_IP as a comma-delimited list of IP addresses and CIDR ranges to exclude from data collection. Use it to exclude specified addresses, such as internal or test traffic. It is not documented as a way to anonymize every visitor’s IP or as a consent mechanism.

Do not claim the resulting session hash is anonymous solely because it is hashed or because its salt rotates. Whether it remains personal data depends on identifiability in context, including the other information available to the operator.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
J. J. Keller 2024 OSHA Safety Training Handbook, Softbound, English
  • Updated Compliance: While the new rule takes effect on 7/19/2024, training and compliance dates don’t start until 1/19/2026, giving your team ample time to prepare with this thorough guide to OSHA regulations (29 CFR 1910.1200(j)).
  • Comprehensive Safety Training Handbook: Prepares your employees for 25 of OSHA’s hottest safety topics, from Confined Space Entry to Workplace Violence, ensuring they are equipped with vital safety knowledge for a safer work environment.
  • In-Depth, Easy-to-Understand Content: Each chapter tackles key workplace hazards like Electrical Safety, Lockout/Tagout, Respiratory Protection, and more, helping to prevent injuries and illnesses while promoting safe practices.
  • Interactive Learning with Quizzes: Engaging chapter review quizzes reinforce safety concepts, making it easier for employees to retain and apply the knowledge, with downloadable answer keys for easy tracking.
  • Specifications: English, Softbound, full-color pages (272 pages) offer clear, visually appealing safety information for a diverse workforce, with home safety details included throughout.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose a retention period and enforce it

Umami’s FAQ says self-hosted analytics data is retained indefinitely unless the operator manually deletes it. The FAQ does not establish an automatic self-hosted retention interval. Choose a period that fits your documented analytics purpose and obligations, and make deletion an operational process rather than an assumption about defaults.

  • Identify where analytics records are held, including the database and any backups or logs under your control.
  • Define how long each copy is kept and how it is deleted or expires.
  • Verify deletion behavior on the Umami version you operate, including the effect on backups and other copies.

Umami Cloud’s current retention period is not stated in the cited Umami documentation. Do not infer that it matches self-hosted retention; check current service and contractual documentation for retention, processing locations, subprocessors, and transfer arrangements.

Compare self-hosted Umami with Umami Cloud

Umami describes both deployment paths in its About documentation and says self-hosting gives the operator control over infrastructure and data. That control also means the operator must manage the relevant operational safeguards.

Question Self-hosted Umami Cloud
Who controls infrastructure and data? The operator controls the self-hosted infrastructure and data, according to Umami. Specific control and processing details are not stated in the cited Umami sources.
What does Umami say about retention? Indefinite until manually deleted, according to Umami’s FAQ. Current retention period is not stated in the cited Umami sources.
What must the operator verify? Retention and deletion for the database, backups, and logs under the operator’s control. Current retention, processing locations, processor terms, subprocessors, and transfer arrangements in the current service and contractual documentation.

These documented differences do not determine which option is compliant for a particular site. Include operational workload, available evidence, and the site’s jurisdiction-specific requirements in the decision.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Review Umami’s own telemetry separately

Website visitor analytics and Umami’s application telemetry are different data flows. Umami documents anonymous application telemetry and the DISABLE_TELEMETRY=1 opt-out in its environment-variable documentation. If minimizing external calls is part of your deployment requirements, review that setting and confirm its behavior for your installed version.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.