Cookieless analytics that's actually cookieless (a checklist for the skeptical)
"Cookieless analytics" has become a marketing word that means three incompatible things: no cookies but fingerprinting instead (worse), no cookies but IP-based visitor stitching (grey), or genuinely no persistent identifier at all (rare). If privacy is why you're switching, the label tells you nothing — the mechanism does. Here's how to audit it.
The trick to watch for: identifier laundering
A cookie is just a persistent identifier stored in the browser. Removing the storage while keeping the identifier — by hashing IP + user-agent + screen size into a daily "visitor hash," or by canvas/font fingerprinting — changes the compliance paperwork, not the privacy reality. Regulators have been increasingly explicit that fingerprinting requires the same consent cookies do. If a vendor's docs say "no consent banner needed" and their dashboard shows returning-visitor rates, ask precisely how both can be true at once. Someone is identifying you.
What genuinely cookieless looks like
Honest cookieless measurement accepts real limits:
- No persistent identifier: nothing stored client-side, no fingerprint derived. A session can be grouped (e.g. a random in-memory/session-scoped id that dies with the tab); a person cannot be recognized next week.
- No cross-site anything: by construction.
- Consequences you should expect: no true "returning visitors" metric, no cross-device journeys, conversion attribution limited to same-session. If a "cookieless" tool still shows those, return to the previous paragraph.
We built our own measurement on this basis — sessionStorage-scoped grouping, no cookies, no fingerprinting, Global Privacy Control honored, EU-hosted — and yes, that costs us returning-visitor stats. That's the trade, made honestly. (Details in our GDPR notes.)
The audit checklist
Ask any "cookieless" vendor these, in writing:
- What exactly is stored client-side? (localStorage and IndexedDB count. "Nothing" should mean nothing persistent.)
- Is any identifier derived from device/browser characteristics? If yes, it's fingerprinting — different word, same mechanism.
- How do you compute unique/returning visitors? The load-bearing question; vague answers here decide the audit.
- Do you honor Global Privacy Control? A one-bit test of whether privacy is architecture or copywriting.
- Where is data processed and stored? EU hosting simplifies GDPR materially.
- Is IP address stored? Transient use (geo lookup, bot verification) differs fundamentally from storage; the answer should be explicit.
A vendor that answers all six crisply is telling the truth about something. Evasion on question 3 is the tell.
The part nobody mentions: bots corrupt cookieless data more
Cookie-era analytics accidentally filtered some automation (many bots didn't persist cookies). Cookieless tools count requests or sessions — and in 2026 an enormous share of those are machines: on our own site, humans were a single-digit percentage of events in a recent 30-day window. Cookieless analytics without serious bot classification doesn't give you privacy-respecting human stats; it gives you privacy-respecting noise. Whatever tool you pick, ask what it does with the ninety-something percent of traffic that isn't a person — because after the cookie banner disappears, that's the number quietly deciding whether your dashboard means anything.
See which AI agents visit your site — free.
Start with VisitorType