检查清单
Does PostHog tracking fire before Accept?
Check PostHog analytics, session, and flags before Accept. A gated client does not prove pipeline capture stayed off. Not a PostHog setup guide.
In brief
PostHog can load in the browser for product analytics, session recording, and feature flags, and capture continues through a pipeline. Check cookies, storage, and requests to us.i.posthog.com, eu.i.posthog.com, or app.posthog.com on Fresh, then after Reject. Gating the browser client does not prove pipeline capture stayed quiet. ConsentProbe can store both packs. A free US-baseline scan is not an EU or California legal conclusion. This page is not a PostHog setup guide and not legal advice.
Not legal advice
This guide explains how to observe PostHog product analytics, session recording, and feature-flag client activity, plus any related pipeline sends, relative to Accept and Reject. It is not legal advice, not a PostHog project, SDK, feature-flag, or self-host setup tutorial, and not a GDPR, ePrivacy, CPRA, or other compliance certificate. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow. Observation is not counsel permission.
Last updated September 29, 2026. The before-Accept audit owns the general first load. The Reject leftovers guide owns a Reject failure. The pre-consent checklist owns the pass order. The marketing-pixels FAQ owns the wider pixel question. The party-label guide owns first-party versus third-party names. Heap is the sibling check for a browser SDK plus an export. Clarity and Hotjar, and the session-replay page, own UX-recording framing. This page stays on PostHog.
Short answer
PostHog often loads in the browser for product analytics, session recording, or feature-flag evaluation, and capture can continue through a pipeline. Check cookies, storage, and requests to us.i.posthog.com, eu.i.posthog.com, app.posthog.com, or related hosts before Accept, and again after Reject All.
Pipeline or server capture can still send when the browser client is delayed. Treat banner text that says analytics or marketing is off as a claim. Falsify it on a clean visit. If session recording or heatmaps ride with PostHog, verify those surfaces on the same labeled visits. Replay framing lives on the session-replay page and the Clarity and Hotjar page. Host names are examples. This page does not say which PostHog cookies are essential.
Downstream sends are harder to see from DevTools alone. Ask engineering for PostHog event or delivery logs labeled by consent state when the browser pack is clean and the project still shows events. First-party versus third-party labeling still applies when PostHog cookies sit on your domain. A request to eu.i.posthog.com is a browser clue. It does not turn a free US-baseline scan into an EU legal conclusion.
Browser client and pipeline capture
Analytics, session recording, and feature-flag evaluation can share PostHog hosts. Separate the browser client from pipeline capture. Write the finding as a PostHog host before Accept, or a host after Reject. Leave permission with counsel. Heap exports stay on the Heap page. Clarity and Hotjar stay on their page.
| Layer | What a browser test can see | What you may need engineering for |
|---|---|---|
| PostHog browser client (analytics, session, flags) | Cookies, storage, and Network rows to us.i.posthog.com, eu.i.posthog.com, app.posthog.com, or related hosts before Accept | Usually nothing beyond those browser rows |
| PostHog pipeline or server capture | Indirect storefront clues. DevTools rarely shows the full pipeline payload | Event or delivery logs labeled by consent state |
| CMP analytics-off or marketing-off claim | A screenshot of the banner or the category | Matching runtime on Fresh and Reject |
Fresh and Reject on the browser
These steps compare a claimed wait-for-Accept state with cookies and requests. They do not create a PostHog project, install an SDK, configure a feature flag, or deploy a self-hosted instance. The before-Accept audit and the pre-consent checklist hold the general method. Note session-recording or flag requests on the same pass when they share a PostHog host.
- Use a clean profile. Load the storefront once. Do not click Accept.
- Capture cookies, storage, and Network for PostHog-related hosts, including us.i.posthog.com, eu.i.posthog.com, and app.posthog.com. Note session-recording or flag requests if they are present.
- Screenshot the banner state. Label the pack Fresh.
- Open a new clean profile, or clear storage. Click Reject All. Navigate once more.
- Recapture cookies and Network. Label the pack Reject. Compare it with Fresh and, if you ran one, with an Accept control.
- Write one finding sentence per mismatch, such as a PostHog cookie on Fresh, or the same host after Reject.
Pipeline capture when the client looks gated
A quiet browser client leaves pipeline capture untested. Server capture, batch uploads, or warehouse syncs can still deliver events when the page delayed the client. A feature-flag evaluation on Fresh is one more Network row to label.
If Fresh and Reject look clean in DevTools and the PostHog project still shows events, ask engineering for delivery logs tagged by consent state and timestamp.
Example of a storefront clue, not a customer capture: Fresh Network shows a request to us.i.posthog.com before any banner click. After Reject and one more navigation, app.posthog.com is still there. Storage keys that include posthog are clues in Application, not a complete cookie list.
This page does not walk through project creation, SDK install, feature-flag config, or a self-host deploy. The question to falsify is whether pipeline capture happened on Fresh or after Reject. This page stays on PostHog.
When checking PostHog hosts gets slow
Checking PostHog hosts across templates by hand takes a long time. ConsentProbe runs Fresh and Reject on the storefront URL. Each finding stays tied to a request, a cookie, or a screenshot.
Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. ConsentProbe does not install or configure PostHog, does not install a CMP, and does not issue a certificate. A free US-baseline scan is not an EU or California legal conclusion.
FAQ
Does PostHog tracking fire before Accept?
It often does when the client is ungated. Verify Network and cookies on a Fresh visit, including us.i.posthog.com, eu.i.posthog.com, and app.posthog.com, before you treat the banner as proof.
Does gating the browser client stop PostHog pipeline capture?
Not by itself. Ask engineering for delivery logs labeled by consent state. A delayed client leaves pipeline capture untested.
What if Reject All still shows PostHog hosts?
Treat it as a Reject failure. The Reject leftovers guide is the network check. Keep the evidence pack.
Is this the same page as Clarity or Hotjar?
No. The Clarity and Hotjar page stays on those tools. The session-replay page owns replay versus heatmap framing. This page stays on PostHog analytics, session, and feature-flag clients.
Will this page teach PostHog SDK or feature-flag setup?
No. This page is a Fresh and Reject check, not a PostHog setup guide.
Is this legal advice?
No. These are technical observations. It is not legal advice. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.
Limits of this page
This page tells you how to check PostHog browser cookies and hosts on Fresh, how to repeat the check after Reject, and why a gated client leaves pipeline capture untested. It is not legal advice, not a PostHog setup guide, and not a certificate. Observation is not counsel permission. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.
Related guides
Open the before-Accept audit for the general first load, the Reject leftovers guide when Reject still tracks, the pre-consent checklist for the pass order, the marketing-pixels FAQ for the wider pixel question, and the party-label guide for domain names. Heap, Amplitude, and Mixpanel are the sibling checks. Session replay and Clarity or Hotjar are the UX-recording cousins.
- How to run a cookie audit before Accept
- Reject All still tracking
- Pre-consent audit checklist
- Does Reject All stop marketing pixels?
- First-party vs third-party cookies
- Does Heap tracking fire before Accept?
- Does Amplitude tracking fire before Accept?
- Does Mixpanel tracking fire before Accept?
- Session replay and heatmaps before Accept
- Microsoft Clarity and Hotjar before Accept
- Do GA4 cookies fire before Accept?
- GTM tags before Accept
- Cookie consent evidence pack
- Free US-baseline vs paid EU and California
- CMP claims vs runtime evidence
- Cookie audit hub
- ConsentProbe methodology
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
保存一次美国基线技术记录
完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。