Browser Fingerprint Test

See exactly what data points your browser leaks — and get a uniqueness score showing how easily you can be tracked across the web without cookies. Fingerprinting is a separate threat from an IP leak — a VPN can hide your address but does nothing to change the hardware and software signals measured here.

Your Fingerprint ID
Click Run Test…
Uniqueness score -- /100
Run the test to see your score

Scored using our published methodology (14-signal entropy calculation). View methodology

14
Signals checked
--
Scan time
--
High exposure
--
Entropy

100% client-side  ·  No data stored  ·  Free forever

Signal breakdown Run the test to see results
Canvas fingerprint
GPU renderer hash
-- --
WebGL renderer
Graphics card identity
-- --
Fonts detected
Installed system fonts
-- --
Audio context
Sound processing hash
-- --
Screen resolution
Display dimensions
-- --
CPU threads
Hardware concurrency
-- --
Platform
OS architecture
-- --
Browser language
Locale setting
-- --
Color depth
Display bit depth
-- --
Device pixel ratio
Screen scaling factor
-- --
Timezone
Local time offset
-- --
Browser plugins
Extension count
-- --
Device memory
RAM (rounded by browser)
-- --
Touch support
Pointer input type
-- --

What your fingerprint reveals

You can be tracked without cookies

Advertisers combine these signals into a unique ID that persists even after you clear cookies, switch browsers, or use incognito mode.

Your device identity is exposed

Canvas and WebGL hashes are tied to your specific GPU — nearly impossible to fake without a privacy browser or dedicated extension.

Ad networks use this right now

Google, Meta, and thousands of ad-tech companies use browser fingerprinting to serve targeted ads — with no cookie banner or consent notice required.

How browser fingerprinting works

1

You visit a site

The site's JavaScript runs silently in the background — no popup, no permission needed from you.
2

Browser leaks signals

Your GPU, fonts, screen size, and dozens of other settings are read through standard browser APIs.
3

A unique hash is built

All signals are combined into a single fingerprint hash that is stable across sessions and devices.
4

You are identified

The hash matches a profile in a tracking database, linking your visit history and behaviour over time.

Fingerprinting edge cases most guides skip

Cross-browser linking on one device

Switching from Chrome to Firefox to "reset" your identity doesn't work as well as people assume. Canvas and WebGL hashes differ slightly between rendering engines, but hardware-level signals — CPU core count, GPU model, installed system fonts, screen resolution — are usually identical across every browser on the same machine. Cross-browser fingerprinting research has demonstrated well over 90% accuracy linking separate browsers back to one device using exactly this overlap.

"Do Not Track" can backfire

Enabling Do Not Track feels protective, but because so few browsers still send it and even fewer users enable it, doing so puts you in a small, distinguishable group — the header becomes a fingerprinting signal in its own right. The EFF's Panopticlick research documented this directly: a rarely-used privacy setting can increase your entropy instead of reducing it.

Mobile devices are harder to fingerprint — but not immune

iPhones and most Android flagships ship with far less hardware and font diversity than desktops, which naturally shrinks the entropy available from canvas and font-enumeration signals. Sites compensate by leaning harder on battery API timing, sensor availability (accelerometer/gyroscope), and precise screen/viewport ratios, which the desktop-oriented signals in this test don't fully capture — mobile fingerprinting typically needs a broader signal set to reach the same identification accuracy as desktop.

A changing hash doesn't always mean you're protected

Brave and some hardened Firefox configurations intentionally randomize canvas and audio output per-session as a countermeasure — a new hash on every visit is the anti-fingerprinting feature working correctly. But a changing hash can also simply mean you updated your browser, resized the window, or changed a font — none of which is protection. The score and per-signal exposure breakdown above are a better indicator than the raw hash alone.

How to reduce your fingerprint

Use Brave browser

Brave randomizes canvas, WebGL, and audio fingerprints on every site visit, making your fingerprint useless for tracking.
Best protection

Install uBlock Origin

Blocks the tracker scripts that collect fingerprint data before they even run. Works in both Firefox and Chrome.
Strong protection

Firefox + strict mode

Enable "Strict" Enhanced Tracking Protection in Firefox settings. It blocks most fingerprinting scripts by default.
Strong protection

Use Tor browser

All Tor users share the same fingerprint by design — maximum anonymity, but browsing speed is noticeably reduced.
Maximum anonymity

Frequently asked questions

“Does clearing my cookies reset my fingerprint?”
No. Cookies and fingerprinting are unrelated mechanisms. A cookie is a piece of data the site stores in your browser; a fingerprint is derived live, on each visit, from your hardware and software configuration — GPU, installed fonts, screen size, and similar signals. Clearing cookies removes stored identifiers but does not change your GPU model, your installed fonts, or your screen resolution, so the same fingerprint hash is reconstructed the next time you load the page.
“Does Incognito or Private Browsing mode protect against fingerprinting?”
Only partially. Private browsing modes prevent cookies and history from persisting after you close the window, but the underlying signals used for fingerprinting — canvas rendering, WebGL renderer string, hardware concurrency, installed fonts — are identical in a private window and a normal window. A site can still compute the same fingerprint hash in both modes; what changes is only whether a cookie-based identifier survives the session.
“Will a VPN lower my fingerprint score?”
A VPN changes your IP address and can reduce IP-based geolocation, but it has no effect on the 14 signals this tool measures. A VPN does not alter your GPU, fonts, screen resolution, or audio stack, so your uniqueness score is expected to be the same with or without a VPN connected. If you want to reduce IP-based tracking specifically, pair this test with our WebRTC and DNS leak checks, which are the tests a VPN is actually meant to affect.
“Does enabling "Do Not Track" reduce my fingerprint?”
Somewhat counterintuitively, no — it can make you more identifiable. The DNT header is honored by very few sites and disabled by default in most browsers, so a request with DNT enabled is itself a distinguishing signal, since only a small minority of visitors send it. Research from the EFF's Cover Your Tracks project (formerly Panopticlick) documented this effect directly: turning on a rarely-used privacy signal can increase entropy rather than reduce it, because it narrows you into a smaller group of users.
“Why does Brave show a different canvas hash every time I test?”
Brave intentionally randomizes canvas, WebGL, and AudioContext output on a per-site, per-session basis as a countermeasure — the values are close enough to a real render that most sites can't detect the noise, but different enough between visits that they can't be used as a stable identifier. This is why your Brave fingerprint hash will change on re-test even though your actual hardware hasn't. A stable hash across repeated tests in a "hardened" browser is actually a sign the anti-fingerprinting feature isn't active or has been disabled.
“Can Chrome and Firefox on the same computer be linked to the same person?”
Yes, this is a known cross-browser fingerprinting technique. Even though canvas and WebGL hashes differ slightly between browser engines, hardware-level signals — CPU core count, installed system fonts, screen resolution, GPU model exposed via WebGL renderer string, and timezone — are often identical across browsers on the same machine. Research groups have demonstrated cross-browser correlation with well over 90% accuracy using exactly this kind of hardware-signal overlap, independent of any cookie or login. Run our canvas fingerprint test in each browser to compare the individual hashes yourself.
“Does GDPR or a cookie consent banner cover fingerprinting?”
In the EU, ePrivacy rules generally treat fingerprinting for tracking purposes the same as cookies — it requires consent under most regulator guidance, including from France's CNIL and the UK ICO, because the outcome is the same: identifying a device across visits without the user's clear opt-in. In practice, most cookie consent banners only mention cookies and say nothing about fingerprinting, which means a huge share of sites collecting these signals are doing so without the consent their own banner implies they're asking for.
“My score is high — does that mean I'm being actively tracked right now?”
A high score means your combination of signals is statistically rare enough to reliably re-identify you if a site chooses to fingerprint you — it doesn't confirm any specific site is doing so at this moment. Think of it as measuring exposure, not an active attack: a high score tells you how easy tracking would be if attempted, which is exactly the information you need to decide whether to act on the protection steps below.

Community

Get the next leak test before it's news

Tool releases and research notes, sent when there's something worth reading. Nothing else.

At least 10 characters.