← Back to the test

Methodology

Am I Tracked? is an open-source browser privacy demonstration. It shows what a normal web page can learn before and after you grant a permission, with each result explained in plain language.

What the test measures

The passive stage reads browser-exposed signals such as your device and operating system, browser and version, languages, timezone, screen, hardware hints, battery support, WebGL, and canvas/audio rendering. These signals are combined into explanations and confidence labels; they are not a claim that every signal uniquely identifies you.

The test may also attempt a client-side WebRTC public-IP check and a direct lookup that turns that IP into an approximate city and ISP. Hardened browsers, extensions, and network settings can block these readings, which is shown as unavailable or blocked rather than guessed.

What the exposure score means

The score is a weighted summary of the scored signals this page could read. Signals have different weights, so the percentage is not simply the share of readable fields. It is not a safety rating, a probability of being tracked, or a comparison with other visitors. Optional permission demos can change the score.

Tracker checks test whether a small set of endpoints is reachable. A reachable endpoint does not prove tracking, and a failed request can reflect a blocker, a network error, or the endpoint being unavailable.

Compare one setting at a time

  1. Run the test and wait for the initial network and tracker checks to finish.
  2. Note your browser version, extensions, and whether you are using a private window.
  3. Change one setting, such as tracking protection, then choose Check again.
  4. Compare readable signals and reachable tracker counts under the same conditions. A different fingerprint hash alone does not prove improved privacy.

Check again replaces the displayed results. It does not revoke browser permissions you already granted. Review those in your browser's site settings, and use the same permission choices when comparing runs. Browser, network, and API differences can affect results, so this is not a controlled browser benchmark.

Permissions and interaction

Precise location, camera and microphone devices, clipboard, and notifications are requested separately and only after you choose to continue. The test does not record camera or microphone content. It also demonstrates tab attention, pointer, click, scroll, and dwell signals that pages can observe without a permission prompt.

The reveal can make network requests to the WebRTC STUN service, the disclosed IP-geolocation provider, and tracker endpoints to show whether those resources are reachable from your browser. These requests are part of the demonstration and can be blocked by your browser or extensions.

Data handling

Raw test signals are computed in your browser and are not sent to an Am I Tracked backend. A localStorage value is used only for the returning-visitor demonstration, so it stays on your device. Third-party requests and anonymous analytics are described in the privacy policy.

Copy summary is optional. You can preview its text before copying: it contains readable-signal and tracker counts plus a public link to the test. It leaves out your IP address, location, fingerprint, and individual readings. Nothing is posted on your behalf.

Open source and limitations

Browser APIs differ by browser, operating system, extensions, and network. A blocked or unavailable value is a real result, not an inferred value. You can inspect the collection logic, explanations, and tests in the public repository:

View the Am I Tracked source on GitHub ↗

If a browser change makes a result or explanation inaccurate, you can report a correction in GitHub Issues ↗.