All articles

Incognito mode and browser fingerprinting: what it hides and what it doesn't

Incognito mode gives you a separate browsing session on your device. It does not reroute your network or replace your browser hardware — so many signals websites read during a visit can stay the same.

Also available in 简体中文

Incognito mode and browser fingerprinting: what it hides and what it doesn't

Incognito mode is useful. It is just useful for a much narrower job than its name suggests.

Open a private window in Chrome, Firefox, Edge, or another browser and you get a fresh browsing session. Your normal cookies are separated from that session, your browsing history is not kept in the usual way, and most of the temporary site data created during the session is removed when you close it.

What does not happen is just as important.

Your IP address does not suddenly disappear. Your laptop does not become a different device. And many of the signals a website can read from your browser are still there.

So the simplest way to think about incognito mode is this:

It changes what the browser remembers locally. It does not reset everything a website can see about your connection and device.

What incognito mode actually hides

Private browsing is mainly designed to keep a session separate from your normal browser activity.

That is useful on a shared computer, when signing into a second account, or when you do not want a browsing session to remain in your regular history.

During a private session, browsers typically separate or discard things such as:

  • browsing history;
  • cookies created during that private session;
  • site data created during the session;
  • form and search history;
  • some cached data.

The exact behavior varies by browser, but the basic idea is the same: once the private session ends, much of that local session data is not kept.

That is real privacy protection.

It just happens on your device.

What incognito mode does not hide from websites

A website sits on the other side of the connection. It does not need access to your local browsing history to learn things about the current visit.

It can still receive your public IP address. It can still see normal browser information exposed during a page load. It can still know when you sign into an account.

And depending on the browser and the techniques a site uses, it may still be able to observe fingerprinting signals such as:

  • browser and operating system information;
  • screen size and display properties;
  • language settings;
  • time zone;
  • WebGL information;
  • Canvas behavior;
  • supported browser features;
  • other device and rendering characteristics.

Private mode may change some browser behavior, and privacy protections are not identical across Chrome, Firefox, Safari, Edge, and other browsers.

But opening an incognito window by itself does not turn the browser into an anonymous or completely new device.

Incognito mode does not hide your IP address

This is the easiest part to understand.

Your public IP belongs to the network connection used to reach a website.

Incognito mode changes how the browser handles local session data. It does not reroute your internet traffic.

So if you open the same website in a normal window and then in an incognito window, the site will normally see the same public IP in both.

To change the IP visible to a website, you need to change the network path itself—for example by switching networks, using a VPN, or using a proxy.

That is a different layer from private browsing.

A private session is not a new browser environment

This is where browser fingerprinting becomes relevant.

Imagine opening Chrome normally and then opening an incognito window on the same computer.

The private window starts with a separate browsing session, but it still runs on:

  • the same operating system;
  • the same display;
  • the same graphics hardware;
  • the same browser engine;
  • the same physical device.

That means many browser-side characteristics can remain very similar.

This is why deleting cookies and changing a browser fingerprint are not the same thing.

A cookie is stored data.

A browser fingerprint is built from characteristics that can be observed when the page is running.

Private browsing is good at separating stored session data. It does not automatically remove the underlying characteristics of the browser and device.

For more on that split, see Does Changing Your IP Change Your Browser Fingerprint?.

What changes and what stays visible

The difference is easier to see side by side.

Signal or dataNormal browsingIncognito / private browsing
Browsing history saved locallyUsually yesUsually not kept after the session
Existing normal-session cookiesAvailableUsually separated
Cookies created in the private sessionStored during the sessionUsually removed when the session ends
Public IP addressVisible to websitesStill visible
ISP / ASNVisibleStill visible
Browser versionVisibleUsually still visible
Screen informationVisibleUsually still visible
WebGL informationMay be visibleMay still be visible
Language and time zoneVisibleUsually still visible
Logged-in account identityVisible when signed inStill visible when signed in

The important word here is usually.

Private browsing implementations differ, and some browsers add stronger tracking protections in private mode. Firefox, for example, applies additional protections against third-party tracking in private windows. Chrome also blocks third-party cookies by default in Incognito.

Those protections matter.

But they should not be confused with making the entire browser environment disappear.

Why a website may still recognize you

There are several completely different ways a website can connect one visit to another.

Cookies are one.

Account logins are another.

Browser fingerprinting is another.

Network information can also be part of the picture.

If you open an incognito window and immediately sign into the same account, there is no mystery left: the website knows which account is using the session.

If you stay signed out, the site may have fewer stored identifiers available, but it can still see the current connection and whatever browser information is exposed during the visit.

That does not mean every website can uniquely identify every incognito session.

Browser fingerprinting is probabilistic, implementations vary, and modern browsers increasingly limit some forms of tracking.

The more useful point is simpler:

Incognito removes some identifiers. It does not remove every signal.

If you want the broader picture first, read What Is Browser Fingerprinting?.

Why incognito can still make you look like a “new user”

This is another source of confusion.

Open a private window and many websites suddenly ask you to log in again. Shopping sites may forget your cart. Recommendations may reset. A site may show a cookie banner as though you have never visited before.

That can feel like the website no longer recognizes you.

Often, what actually happened is much simpler: the normal browser cookies were not carried into the private session.

For websites that rely heavily on cookies, that is enough to make the session look new.

But “new cookie session” and “new device” are not the same thing.

The site may still see the same IP, browser family, screen characteristics, language, time zone, graphics environment, and other signals.

Incognito, VPNs, and clearing cookies solve different problems

These tools are often grouped together under “privacy,” but they work on different layers.

ActionLocal history / cookiesPublic IPBrowser environment
Open incognito modeSeparated / temporaryUsually unchangedLargely the same device
Clear cookiesRemovedUnchangedLargely unchanged
Use a VPNMostly unchangedChangesLargely unchanged
Use a proxyMostly unchangedChangesLargely unchanged
Change browserSeparate browser dataUsually unchangedMore signals change
Change deviceSeparate environmentMay changeMany signals change

There is no single privacy button that resets all three layers at once.

That is why it helps to separate three questions:

  1. What does my browser remember?
  2. What does my network reveal?
  3. What does the website see from my browser and device?

Incognito mode mostly addresses the first question.

Does incognito mode stop browser fingerprinting?

Not by itself.

Many fingerprinting techniques rely on information that is generated or exposed while the browser is running rather than on cookies saved from an earlier session.

That can include rendering behavior, graphics information, screen properties, browser capabilities, language, and other environmental signals.

A private window may alter some values or apply stronger privacy protections depending on the browser, so it is too simplistic to say that every fingerprint is always identical between normal and private mode.

But the broader point remains:

Private browsing was not designed to give your device a completely new fingerprint.

If fingerprinting is what you are checking, look at the signals themselves rather than assuming the incognito icon changed them.

Run the EnvTrace Fingerprint Uniqueness Test in both a normal window and a private window if you want to compare.

When incognito mode is actually useful

None of this means private browsing is pointless.

It is useful when you want to:

  • keep a session out of the normal browser history;
  • avoid leaving a signed-in session on a shared computer;
  • open a website without using your normal cookies;
  • sign into another account temporarily;
  • start with a cleaner local browsing session.

Those are practical uses.

The problem only starts when “private browsing” gets interpreted as “anonymous browsing.”

They are not the same promise.

Check what the website can still see

If you want to understand what incognito mode changes, do not look only at whether your history disappears after you close the window.

Look at the website side too.

Check your public IP address. Look at your browser information. Look at WebGL, language, time zone, screen information, and the other signals exposed by the environment.

That is the perspective behind EnvTrace.

The goal is not to reduce privacy to one IP address or one fingerprint hash. It is to see the browser and network together and understand which parts of the environment actually changed.

Incognito mode creates a cleaner, separate session.

It does not create a new computer.

And that one distinction explains most of what private browsing can—and cannot—hide.

Frequently asked questions

Does incognito mode hide my IP address?
No. Incognito mode mainly separates local history and cookies. It does not change your network exit. A site will usually see the same public IP in a normal window and an incognito window.
Does incognito mode change my browser fingerprint?
Usually not in a meaningful way. An incognito window still runs on the same device, browser, and graphics stack — WebGL, screen, language, and other signals often remain visible.
Why does incognito make sites feel like a first visit?
Most often because cookies from your normal window are not carried into the private session. The site loses stored cookies, but your IP and many browser signals may still match.
Is clearing cookies the same as changing a browser fingerprint?
No. Cookies are data stored in the browser. A browser fingerprint comes from environment characteristics read while the page is running. Clearing cookies does not remove those.
Do incognito, VPN, and clearing cookies solve the same problem?
No. Incognito mainly handles local records and cookies. VPNs and proxies change the public IP. Browser fingerprints come mainly from the device and browser. They are different layers.
Does incognito mode stop browser fingerprinting?
Not by itself. Many fingerprint signals are read at runtime and do not depend on cookies saved earlier. Check what your browser actually exposes rather than assuming the incognito icon changed everything.

Check what websites still see

Run the EnvTrace Fingerprint Uniqueness Test in a normal or private window and compare IP, WebGL, and other environment signals.

Test my browser fingerprint→
Keep reading

Related articles