Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

Browser Privacy Check (What Sites See)

The fingerprint any site can take of your browser — measured in this tab, never sent.

Security No upload Works offline Free, no sign-up

See what any website can read from your browser

The check runs the same measurements fingerprinting scripts use — canvas, WebGL, audio, fonts, screen, hardware and more — in this tab only. Nothing is stored or sent, and nothing asks for permission, which is the point.

Next steps

About the Browser Privacy Check (What Sites See)

Every website can read a surprising amount about your browser without asking: the user agent, your languages and time zone, the size and colour depth of your screen, the number of processor threads, your accessibility settings, and — by drawing invisibly to a canvas, rendering WebGL and processing sound — values that differ from one device to the next. Combined, they form a fingerprint that can recognise your browser across sites and visits, and unlike a cookie, as the W3C’s guidance on fingerprinting puts it, it cannot be cleared or reset.

This check runs those measurements in your tab and shows each value, what it reveals and how identifying it tends to be. It tells you which protections your browser applies — whether canvas and audio readings come back exact or altered, whether your graphics card is named, whether the Global Privacy Control signal is on — and computes the ID a script could derive. Then it gives advice that follows the W3C’s guidance and EFF’s Cover Your Tracks project. Nothing is stored, and nothing is sent anywhere.

How to use it

  1. Press Check my browser. The measurements take about a second.
  2. Look at Protections first: green means your browser hides or alters that value, amber means a page gets it as it is.
  3. Read How to share less for steps that fit what was found.
  4. Go through the three lists — sent with every request, readable by scripts, rendering fingerprints — to see each value and why it matters.
  5. Change a setting or try another browser and press Check again: the fingerprint ID shows whether you now look different.

Common uses

  • Seeing how much a site can learn about you before you install a privacy extension or change browser.
  • Checking that Global Privacy Control is really switched on after enabling it.
  • Comparing browsers, private windows and protection settings by their fingerprint ID.
  • Showing students, colleagues or family how fingerprinting works, with their own browser.

Passive and active fingerprinting

The W3C note Mitigating Browser Fingerprinting in Web Specifications separates two kinds. Passive fingerprinting uses what your browser sends with every request — the user agent, accepted languages, client hints, your IP address — and cannot be seen from the page. Active fingerprinting runs code in the page to read more: screen and hardware details, fonts, and rendering results. Active fingerprinting can at least be detected and limited by the browser, which is what fingerprinting protections do.

How the rendering fingerprints are made

  • Canvas: the page draws text in two fonts, an emoji and blended shapes, reads the pixels back and hashes them. Graphics hardware, drivers, fonts and anti-aliasing all change the result slightly.
  • WebGL: the graphics card’s name and limits, read through the WebGL API (the unmasked name where the browser provides it).
  • Audio: a tone passed through a compressor is rendered off-screen and its samples summed; the result varies between audio stacks.
  • Fonts: the width of a test string is measured in each of about a hundred common fonts against generic fallbacks; a different width means the font is installed.

To see whether your browser defends itself, the check also draws exact solid colours and a constant audio signal: an unprotected browser returns exactly what was drawn, a protected one alters the readings or blocks them.

Global Privacy Control and Do Not Track

Global Privacy Control sends the header Sec-GPC: 1 and sets navigator.globalPrivacyControl to ask sites not to sell or share your personal information. Several US states, California among them, recognise it as a legal opt-out. According to the GPC project, Brave and DuckDuckGo send it by default and Firefox offers it in its settings; extensions such as Privacy Badger add it elsewhere. Do Not Track (DNT: 1) is its predecessor: it never became a binding standard, and few sites act on it.

What actually reduces your fingerprint

EFF’s Cover Your Tracks describes two strategies that work: blend in, as Tor Browser does by making its users look alike, or randomise, as Brave does by changing values per site and per session. Tracker blockers such as Privacy Badger stop some fingerprinting scripts, and blocking JavaScript stops most of them at the cost of broken sites. Faking a single value (a different user agent, say) usually backfires: it makes your combination rarer, not hidden.

Limitations

  • The fingerprint ID is computed here from the values shown; real trackers use their own measurements and server-side data such as your IP address, so their IDs differ from this one.
  • It cannot say how rare your fingerprint is: that needs a database of other visitors’ fingerprints, which this page does not collect.
  • Browsers that change readings per site or per session give the same values twice in a row on the same site. The exact-colour and constant-signal tests detect such alterations; comparing IDs between sites or after a restart is the other way.
  • Your IP address is not shown, because reading it needs a server; the What Is My IP tool shows it.

Privacy

Everything is measured in this tab when you press the button and kept only in the page’s memory. No value, hash or ID is stored, uploaded or shared, and nothing is measured before you ask.

Frequently asked questions

Is this test itself tracking me?

No. It runs the measurements a tracking script would, but only after you press the button, only in your tab, and it keeps nothing: there are no cookies, no storage and no network requests with the results. Reload the page and they are gone.

Why does the ID stay the same in a private window?

A private window starts without cookies and history, but it runs on the same device, fonts and graphics card, so most values are unchanged. EFF notes that Chrome’s Incognito mode does not protect against fingerprinting; Firefox’s private windows block known fingerprinting scripts.

My browser shows “altered” readings. Is that bad?

It is good: your browser adds small changes to canvas or audio readings, or blocks them, so they cannot be used to recognise you reliably. You will not notice the changes on normal pages.

Should I switch on Do Not Track?

It does little: few sites honour it and it is one more detail that sets you apart. Global Privacy Control is the signal that laws in several US states recognise as an opt-out of the sale or sharing of your data.

Can a site really identify me with this?

It can recognise your browser — that the same device came back, or visited another site using the same script — without knowing your name. Combined with a login, a payment or an e-mail address on any one of those sites, that link becomes personal.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.