Back to all articles

Privacy Policy Clause for PostHog (2026) - Copy-Paste Text + Store Label Mapping

By Support URL Generator Team · Published

Advertisement

PostHog sends user data to PostHog, Inc. (unless you self-host it). Event data, a distinct ID, device and page context and, by default, an IP address used for GeoIP enrichment leave the device and are stored on PostHog Cloud, which is a third-party transfer you must disclose in your privacy policy for the GDPR, the App Store and Google Play. Generate a full privacy policy with this clause built in →

Does PostHog need a privacy policy disclosure?

Yes, when you use PostHog Cloud. PostHog is a product-analytics platform that captures pageviews / screen views, autocaptured interactions and the custom events you send, attaches a distinct ID plus device, browser, OS and referrer context, and enriches events with a coarse location derived from the IP address. On PostHog Cloud, PostHog is your data processor and you are the controller; if you self-host PostHog, you are both controller and processor and no data goes to PostHog, Inc. at all — in that case you only disclose your own hosting.

PostHog states it does not need personal data to do analytics and offers strong minimization controls. A default setup does not collect an advertising identifier and does not meet Apple's definition of tracking, so it normally does not require an App Tracking Transparency prompt — but the collection still must be disclosed.

What data does PostHog collect?

Data typePurposeLinked to the user?Used for tracking?
Distinct ID (anonymous UUID until you call identify) and any user properties you setAttribute events to a device or accountYes once identified; anonymous otherwiseNo
Product-interaction / event data (pageviews, screen views, autocaptured clicks, custom events)Analytics, funnels, retentionYes / anonymousNo
Device and environment context (OS, OS version, device type, screen size, app version, browser and browser version on web, referrer, current URL / screen name)Analytics, segmentationYes / anonymousNo
IP address, used to derive GeoIP location (city, region, country) then configurable to discardGeographic reportingYes / anonymousNo
Session recordings (DOM / screen content, network timings)Debugging, UX — only if you enable session replayYesNo

The exact list depends on your configuration. Autocapture, session replay, IP capture and person profiles are all individually toggleable. On PostHog Cloud EU, IP capture is disabled by default for new projects. Anything you pass as event or person properties is data you chose to send and must disclose.

Copy-paste privacy policy clause for PostHog

Analytics. We use PostHog, a product-analytics service provided by
PostHog, Inc., to understand how our app is used. PostHog collects a
distinct identifier (anonymous until you sign in), the pageviews, screen
views and interaction events we capture, device, operating-system and
referrer context, and an IP address used to derive a coarse location that
we then discard. If enabled, PostHog also records session replays of
in-app activity with sensitive fields masked. PostHog processes this data
as our processor under its Data Processing Agreement, on servers located
in [the EU / the US], and does not sell it or use it for advertising. See
https://posthog.com/privacy for more information.

Adapt this: choose your hosting region, remove the session-replay sentence if you do not use it, and if you self-host PostHog replace the whole clause with a statement that analytics data stays on infrastructure you control. This is a template, not legal advice; you own the accuracy.

App Store "App Privacy" label answers

For a default PostHog Cloud integration, declare in App Store Connect:

  • Identifiers > Device ID — the distinct ID. Purpose "Analytics", Linked to the user (if you identify users; otherwise you may still declare it as collected), not used to track.
  • Identifiers > User ID — if you call identify with an account ID. Purpose "Analytics", Linked to the user, not used to track.
  • Usage Data > Product Interaction — purpose "Analytics", Linked to the user, not used to track.
  • Diagnostics > Performance Data — if you capture performance or error events, or use session replay network capture.
  • IP-derived city is coarse location; with no Core Location use it is generally not declared as Location.

If you enable session replay, also consider Usage Data > Other Usage Data and be explicit about masking. Nothing here is "Used to track you" in a default setup.

Google Play Data Safety answers

In the Play Console Data Safety form, a standard PostHog Cloud setup means:

  • Device or other IDs — Collected: Yes. Shared: No. Purpose: Analytics. Not processed ephemerally.
  • App activity > App interactions, plus Page views and taps in app and Other actions — Collected: Yes. Shared: No. Purpose: Analytics.
  • App info and performance > Diagnostics and Crash logs — Collected: Yes if you send those events. Shared: No.
  • Location > Approximate location — Collected: Yes unless IP capture / GeoIP is disabled (it is off by default on Cloud EU). Shared: No. Purpose: Analytics.
  • Personal info > User IDs — Collected: Yes if you identify users. Shared: No.

Data is not "processed ephemerally". Users can request deletion — PostHog provides person-level delete and a data-erasure workflow for right-to-be-forgotten requests; link your own request route.

PostHog-specific gotchas

  • Self-hosted vs Cloud changes the whole disclosure. Self-hosted PostHog is not a third-party transfer; Cloud is. Do not copy a Cloud clause into a self-hosted app or vice versa.
  • US vs EU Cloud is a real transfer decision. PostHog Cloud US stores data in the United States; only Cloud EU (Frankfurt) keeps EU data in the EU, and the two are separate accounts.
  • Anonymous events still count. The iOS and web SDKs capture events under an anonymous distinct ID before any login; that is still personal data under the GDPR in most cases and must be disclosed.
  • Autocapture can grab text and attributes. Web autocapture records element text and hrefs; use the ph-no-capture class and property denylists to keep PII out.
  • Session replay is opt-in but powerful. Once enabled it records screen content network-wide; confirm input masking and disclose it separately.
  • A signed DPA is on request. PostHog does not counter-sign a DPA automatically for every account; request one if you need it for GDPR Article 28.

Related

See the sibling clauses for Google Analytics for Firebase, Mixpanel, Amplitude and Segment. Build the full document with the privacy policy page generator, and if your app also uses Firebase read the Firebase privacy policy generator guide.

Advertisement

Need a Support URL for Your App?

Generate a compliant, professional support page in under a minute. Our easy-to-use generator creates everything you need for App Store and Google Play submissions.