Every project has a compliance config, and the collector reads it on each hit. Compliance mode is always on: address truncation, personal-data stripping, and expiry deletion run for every project, and the settings only choose how strict they are.
ConsoleConfigurationPrivacy center (project pathsettings/privacy) can be edited by the owner and admins. After a save, the collector cache picks up the new rules on the next hit. Choosing a tier before you install: Privacy choices before you start.Collect tiers
The tiers are 1, 2, and 3.
| Tier | Name | What the collector does |
|---|---|---|
| 1 | Anonymous aggregate | The salt rotates daily. No persistent id is kept. Autocapture is dropped. Identity operations are dropped. Consent, opt-out, and opt-in receipts are still accepted |
| 2 | Cookie-free pseudonym | Visitors are separated with an HMAC of address and user agent. The script itself writes no cookie |
| 3 | Identified | A device id and login may be used. If the project is not in identified mode, the tier stops at 2 |
The default tier is 2. The default region rule for the EEA and the UK is tier 2 and consent required. When consent is required and the payload has no analytics-purpose bit, the tier falls to 1, and pageviews and custom events are still stored.
Client SDKs initialize in two steps. preInit only stores config. init fetches config and starts sending. With China mode on, collection waits until you grant consent. The website script lazy-loads w-id.js when consent, identity, or autocapture is needed, and holds events in memory until then.
Consent, opt-out, and region
Purposes are analytics, functional, and marketing. Behavior before consent is queue (the default) or drop.
Opt-out scope defaults to every device of that person, and can be limited to the current device. Collection stops for that scope afterward. That is not the data-subject "restrict" request. Restrict is a request with a cooling-off period, 3 days by default, and it can be cancelled during that window. Opt-out is a collect switch.
Region keys come from the country on the address (and, for the United States, whether the region is California): EEA, UK, US-CA, the rest of the US, CN, and other. Each region rule can override tier, consent required, how many address bytes to truncate, and geography (city, country, or none). A blank field inherits the project default.
Global Privacy Control (Sec-GPC: 1) and Do Not Track (DNT: 1) are honored by default. A hit drops to tier 1 and the consent bits are cleared. The website script does not load at all when the browser reports either signal, unless the tag sets data-respect-dnt="false". Both layers have to be off before a hit is sent and stored at tier 2 or 3.
China mode is added on top of region rules. It does not replace the EEA rule. When it is on, collect config requires init-after-consent, the reject cooling-off period defaults to 7 days, and the China export counter, data-subject deadline, and child-related fields apply. Child mode forces tier 1, sets no identifier, and uses a shorter retention for raw rows.
A preset can apply "pseudonymous stats without a consent requirement" or "identified collection with full consent" in one step. Locked fields stay locked until you release the preset.
Address, stripping, and retention
The address is not written on the event. The collector uses it for geography and for the visitor HMAC, then discards it. The default truncation is 2 bytes before a city lookup (the last two IPv4 octets; IPv6 drops the matching tail). Geography defaults to city, and can be country or none.
Strings that look like an email or a phone number are rewritten to a placeholder when stripping is on, which is the default. Autocapture does not capture visible element text by default. Email and phone passed at login stay out of the profile by default. Switching profile contact data to encrypted storage is what keeps a ciphertext.
Default retention inside the compliance config is 365 days for events, 90 for autocapture, 730 for profiles, and 730 for consent receipts. The project's actual days cannot exceed the analytics plan cap (180 on the free tier by default). See Plans & quotas. A scheduled job deletes expired rows. The mask a member sees on a report (none, partial, or full) is a different layer. See Account & team.
Data-subject requests
The four types are access, erasure, restrict, and portability. The subject can be a device, a login, an email, or a person. The console or a key with privacy:write can create one. An OpenDSR discovery and submit path exists for an external privacy platform.
Erasure and restrict run after the cooling-off period. An access result can be downloaded. Cancel is only available before the request runs. How retention changes reports: Retention & deletion.
FAQ
I required consent before collect. Why is realtime not empty? Pageviews and custom events remain, stored at tier 1. What goes empty is autocapture, identity, and device ids.
If a region rule sets geography to none, is the address stored? No. Geography only affects the country or city field that was inferred. The address itself is not on the event row.
Does China mode turn off the consent requirement for visitors in Europe? No. China mode adds the init gate and the China compliance fields. The EEA and UK region rules still apply.