{
  "slug": "posthog",
  "category": "web-analytics",
  "name": "PostHog",
  "description": "Product analytics platform with web analytics, session replay, feature flags, experiments and surveys. Offered as PostHog Cloud or as an unsupported self-hosted deployment.",
  "website": "https://posthog.com",
  "source": "https://github.com/PostHog/posthog",
  "license": null,
  "platforms": [
    "web"
  ],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 48,
  "coverage": 100,
  "summary": "PostHog scores 48 out of 100 (grade D) on the website analytics criteria. It meets 4 of 11 criteria: open source, no ads or data sales, independent audit and TLS configuration. It partly meets no cookies and self-hostable. It does not meet no trackers or telemetry, transparency report, tells users about requests, security headers and no personal data. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
  "url": "https://privacyratings.com/web-analytics/posthog/",
  "markdown": "https://privacyratings.com/web-analytics/posthog/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/PostHog/posthog/blob/master/LICENSE",
      "note": "All code is public. Most is MIT, and the ee directory in the same repository uses a source-available proprietary license."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://posthog.com/privacy",
      "note": "The privacy policy describes marketing cookies and sharing account information with third-party advertising platforms such as LinkedIn."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://posthog.com/privacy",
      "note": "Funded by usage-based subscriptions. The privacy policy states customer data is not sold."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://posthog.com/security/soc2-report-2026.pdf",
      "note": "The full SOC 2 Type 2 report from an independent service auditor is public."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No transparency report or government request policy is published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=posthog.com&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "no",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=posthog.com",
      "note": "Grade C (50/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "no_cookies": {
      "title": "No cookies",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://posthog.com/tutorials/cookieless-tracking",
      "note": "The script sets a first-party cookie and localStorage by default, and a cookieless mode can be turned on."
    },
    "no_personal_data": {
      "title": "No personal data",
      "weight": 3,
      "answer": "no",
      "evidence": "https://posthog.com/docs/privacy/data-collection",
      "note": "Client IP addresses are captured by default, except for EU organizations, and can be discarded in settings."
    },
    "self_hostable": {
      "title": "Self-hostable",
      "weight": 1,
      "answer": "partial",
      "evidence": "https://posthog.com/docs/self-host",
      "note": "Self-hosting with Docker is possible but officially unsupported."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "C",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T06:59:45.948Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}