# PostHog privacy rating

Product analytics platform with web analytics, session replay, feature flags, experiments and surveys. Offered as PostHog Cloud or as an unsupported self-hosted deployment.

## Summary

PostHog scores 48 out of 100 (grade D) on the website analytics criteria. It meets 4 of 11 criteria: open source, no ads or data sales, independent audit and TLS configuration. It partly meets no cookies and self-hostable. It does not meet no trackers or telemetry, transparency report, tells users about requests, security headers and no personal data. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.

- Website: https://posthog.com
- Source code: https://github.com/PostHog/posthog
- Jurisdiction: United States. Five Eyes member. Subject to the US CLOUD Act.
- Platforms: Web
- Home page trackers: none found
- Category: [Website analytics](https://privacyratings.com/web-analytics/)
- Grade: D (48/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Yes | All code is public. Most is MIT, and the ee directory in the same repository uses a source-available proprietary license. | https://github.com/PostHog/posthog/blob/master/LICENSE |
| No trackers or telemetry | No | The privacy policy describes marketing cookies and sharing account information with third-party advertising platforms such as LinkedIn. | https://posthog.com/privacy |
| No ads or data sales | Yes | Funded by usage-based subscriptions. The privacy policy states customer data is not sold. | https://posthog.com/privacy |
| Independent audit | Yes | The full SOC 2 Type 2 report from an independent service auditor is public. | https://posthog.com/security/soc2-report-2026.pdf |
| Transparency report | No | No transparency report or government request policy is published. |  |
| Tells users about requests | No | No published policy on notifying users about data requests. |  |
| TLS configuration | Yes | Grade A+ | https://www.ssllabs.com/ssltest/analyze.html?d=posthog.com&hideResults=on |
| Security headers | No | Grade C (50/100+) | https://developer.mozilla.org/en-US/observatory/analyze?host=posthog.com |
| Modern web standards | Not tested yet | Not tested yet. |  |
| No cookies | Partial | The script sets a first-party cookie and localStorage by default, and a cookieless mode can be turned on. | https://posthog.com/tutorials/cookieless-tracking |
| No personal data | No | Client IP addresses are captured by default, except for EU organizations, and can be discarded in settings. | https://posthog.com/docs/privacy/data-collection |
| Self-hostable | Partial | Self-hosting with Docker is possible but officially unsupported. | https://posthog.com/docs/self-host |

Source: https://privacyratings.com/web-analytics/posthog/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/web-analytics/posthog.md
