Skip to content
SilktideHelp

Enhanced privacy

Some third-party services offer optional privacy settings that reduce how much data they collect about your visitors. Silktide detects services on your pages that are running without these settings enabled.

Silktide currently detects two cases:

  • Google Analytics without IP anonymization - analytics requests that send the visitor's full IP address.
  • YouTube videos without privacy-enhanced mode - embedded videos that let YouTube set tracking before the visitor presses play.

Why this matters

These settings exist because the default behavior collects more visitor data than most websites need, and often more than privacy laws such as the comfortably allow without consent. An IP address can identify a person, and tracking cookies follow visitors across the web.

Enabling the enhanced options costs you nothing in functionality: your analytics still work and your videos still play, but your visitors give up less of their privacy for them.

How to fix it

For Google Analytics, turn on IP anonymization. Using the older analytics.js script, that means passing the anonymizeIp setting:

// Before: sends the visitor's full IP address
ga('send', 'pageview');

// After: the IP address is truncated before being stored
ga('set', 'anonymizeIp', true);
ga('send', 'pageview');

For YouTube, embed videos using the privacy-enhanced domain www.youtube-nocookie.com:

<!-- Before: YouTube can set tracking cookies immediately -->
<iframe src="https://www.youtube.com/embed/VIDEO_ID"></iframe>

<!-- After: no tracking cookies until the visitor plays the video -->
<iframe src="https://www.youtube-nocookie.com/embed/VIDEO_ID"></iframe>

If your embeds are produced by a plugin or module, look for a "privacy mode" or "no-cookie" option in its settings. If a finding is a deliberate choice, you can ignore it so it isn't raised again.

How Silktide tests this

  1. Load each page in a real browser, running scripts just as a visitor's browser would.
  2. Watch the requests the page makes to Google Analytics. If an analytics request is sent without the IP anonymization parameter, report it (once per page).
  3. Watch for embedded YouTube players loaded from www.youtube.com, which do not use privacy-enhanced mode, and report each one. Embeds from www.youtube-nocookie.com pass.

Troubleshooting

I use Google Analytics 4

This detection targets the older Universal Analytics (analytics.js) behavior. Google Analytics 4 anonymizes IP addresses by default and has no equivalent setting to enable, so if you have fully migrated to GA4 there is nothing to turn on; findings usually mean an old tag is still firing somewhere.

My video embeds come from a page builder

Many page builders and video plugins default to the standard YouTube domain. Check the embed or plugin settings for a privacy option before editing by hand.

Learn more

Last updated

Was this page helpful?