Skip to content

trackingOptions are ignored #1308

Description

@SebastianFranze

We tried to disable tracking of IP addresses by providing the trackingOptions object when calling amplitude.init of the SDK. IP addresses are still stored in Amplitude. Is there some other configuration overriding it?

Expected Behavior

I would expect no information about IP, location, operating system, or browser stored in Amplitude events.

Current Behavior

My information is stored. The IP address is not even anonymised/truncated.

Steps to Reproduce

  1. Provide a trackingOptions object when calling amplitude.init as shown here: https://amplitude.com/docs/sdks/analytics/browser/browser-sdk-2#optional-tracking
  2. track event by calling amplitude.track
  3. Check data stored in Amplitude dashboard

Environment

  • JS SDK Version: amplitude-ts/2.24.1
  • Installation Method: NPM
  • Browser and Version: Chrome 140

Activity

  1. Mercy811 commented on Sep 30, 2025

    @Mercy811
    Contributor

    Hi @SebastianFranze, trackingOptions govern what the SDK sends going forward. Once you disable ipAddress, subsequent events from that browser won’t include IP and thus won’t get location derived. Historical events (and any properties already recorded on them) are not modified retroactively. Please contact support team if you want to work on historical data. https://community.amplitude.com/data-instrumentation-57/disable-ip-address-tracking-via-tracking-object-414

  2. SebastianFranze commented on Sep 30, 2025

    @SebastianFranze
    Author

    Hello @Mercy811,

    Thank you for your response. I understand how the trackingOptions should work, but it seems like it doesn't work for me. I initialised Amplitude with the following object:

    amplitude.init('OUR_API_KEY', undefined, {
      trackingOptions: {
        ipAddress: false,
        language: false,
        platform: false,
      },
    });

    My tracked events in Amplitude (new ones, not historical data) still contain personal data like my IP address, city, etc.. That's why I'm a bit confused.

    Maybe it's worth mentioning that we are on the EU servers, but I don't think there should be a difference.

  3. Mercy811 commented on Sep 30, 2025

    @Mercy811
    Contributor

    Hi @SebastianFranze, could you share the example user? EU should behave the same.

  4. SebastianFranze commented on Oct 1, 2025

    @SebastianFranze
    Author

    Hi @Mercy811,

    Can you explain to me how I should share the user with you? Via a screenshot of the tracked event in Amplitude? 🤔

    Here is an example request from our application: (I stripped the event_properties and our api_key)

    POST https://api.eu.amplitude.com/2/httpapi
    
    {
      "api_key": "xxxxxxxxx",
      "events": [
        {
          "device_id": "d028c6ae-25d8-4db6-bd9c-a18391c116d6",
          "session_id": 1759311573701,
          "time": 1759311573705,
          "insert_id": "2e48eb93-bcf3-4b81-892a-f3e62a09a75c",
          "event_type": "Link Visited",
          "event_properties": {
          },
          "event_id": 138,
          "library": "amplitude-ts/2.24.1",
          "user_agent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"
        }
      ],
      "options": {},
    }

    From this and the headers (there are no interesting ones), I can't see the information that the IP shouldn't be tracked. This leads to the raw event here: (again stripped my private stuff)

    {
      "_time": 1759311574070,
      "$insert_id": "25c9ea88-efde-4a28-a23f-e2e9cbd7449a",
      "$schema": 13,
      "amplitude_attribution_ids": null,
      "amplitude_id": 89296992890,
      "app": 100030750,
      "city": "Dresden",
      "client_event_time": "2025-10-01 09:39:34.070000",
      "client_upload_time": "2025-10-01 09:39:34.871000",
      "country": "Germany",
      "data": {
        "group_first_event": {},
        "group_ids": {},
        "path": "/2/httpapi"
      },
      "device_carrier": null,
      "device_family": "Linux",
      "device_id": "d028c6ae-25d8-4db6-bd9c-a18391c116d6",
      "device_type": "Linux",
      "display_name": "Page Viewed",
      "dma": null,
      "event_id": 141,
      "event_properties": {
      },
      "event_time": "2025-10-01 09:39:34.070000",
      "event_type": "Page Viewed",
      "group_properties": {},
      "groups": {},
      "ip_address": "xxx.xxx.xxx.xxx",
      "language": "English",
      "library": "amplitude-ts/2.24.1",
      "location_lat": null,
      "location_lng": null,
      "os": "Chrome 140",
      "os_name": "Chrome",
      "os_version": "140",
      "partner_id": null,
      "paying": null,
      "plan": {},
      "platform": null,
      "processed_time": "2025-10-01 09:39:35.043000",
      "region": "Saxony",
      "sample_rate": null,
      "server_received_time": "2025-10-01 09:39:34.871000",
      "server_upload_time": "2025-10-01 09:39:34.877000",
      "session_id": 1759311573701,
      "source_id": null,
      "start_version": null,
      "timeline_hidden": false,
      "user_id": null,
      "user_properties": {},
      "uuid": "0a11db8a-213f-4cf9-a7bc-0390bc4a9dca",
      "version_name": null
    }

    Edit: I disabled batch reporting and the result is the same. The request sent without batch processing ignores the trackingOptions:

    POST https://api.eu.amplitude.com/batch
    
    {
      "api_key": "xxxxxxxx",
      "events": [
        {
          "device_id": "d028c6ae-25d8-4db6-bd9c-a18391c116d6",
          "session_id": 1759323224195,
          "time": 1759323224306,
          "insert_id": "5cc3c0a4-098a-4ec0-afd5-73980b2604a7",
          "event_type": "Page Viewed",
          "event_properties": {
          },
          "event_id": 142,
          "library": "amplitude-ts/2.24.1",
          "user_agent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"
        }
      ],
      "options": {},
      "client_upload_time": "2025-10-01T12:53:45.308Z"
    }
  5. SebastianFranze commented on Oct 8, 2025

    @SebastianFranze
    Author

    @Mercy811 Any idea?

  6. epartipilo commented on Oct 17, 2025

    @epartipilo

    Hi @SebastianFranze, what is this undefined in between the key and the settings?

    amplitude.init('OUR_API_KEY', undefined, {

    Thanks

  7. SebastianFranze commented on Oct 27, 2025

    @SebastianFranze
    Author

    Hello @epartipilo. We call the init method with undefined as the user ID (because the user is set later). I think we can omit it and pass the options as a second parameter directly, but this doesn't matter.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions