Privacy compliance
Contents
Posthog gives you privacy controls at different levels to protect user privacy and comply with regulations. This guide covers the different privacy controls we provide and guidance on how to use them.
- What you're responsible for: It's your responsibility to decide what data you collect, if it complies with regulations, and communicate with your users.
- What PostHog does for you: We provide tools and features to help you manage what's collected and store the collected data securely.
Privacy control features
You can control data collection, ingestion, and storage at different levels. Explore the guides below to learn more about the different privacy control features:
Guidance on navigating regulations
In these guides, we offer advice for using PostHog in a compliant manner under the following legal frameworks:
The General Data Protection Regulation (GDPR), which applies to all businesses collecting data on EU citizens
The Health Insurance Portability and Accountability Act (HIPAA), which applies to businesses capturing and processing health data in the US
The California Consumer Privacy Act (CCPA), which applies to qualifying for-profit businesses collecting personal information on residents of California
It is up to you to ensure you're compliant with regulations. We strongly recommend reading the relevant regulations in full and seeking independent legal advice regarding your obligations.
Frequently asked questions
This overview covers some frequently asked questions about PostHog and privacy. Have a question not covered here? Use the 'Ask a question' box at the bottom of the page.
Is it ok for my API key to be exposed and public?
It is ok for your project token (starts with phc_) to be public. It is used to initialize PostHog, capture events, evaluate feature flags, and more, but doesn't have access to your private data.
Your personal API key (starts with phx_), however, should NOT be public as it enables reading and writing potentially private data.
What is and isn't considered personal data?
It's hard to have a single legal definition of personal data because every legal privacy framework has different ideas, and even names, for it. The GDPR calls it 'personal data' but the US uses the term 'personally identifiable information' (PII) and others refer to it as 'personal information'.
According to the GDPR, personal data is any information which:
- Identifies a 'data subject' directly
- Can be used to identify a 'data subject' when combined with other information
Read our simple guide to personal data and PII for more specific examples to help you identify what personal data you are collecting.
How does the GDPR impact analytics?
There are three key GDPR principles that impact your use PostHog and analytics in general:
- You need to have a good reason to collect personal data
- You need to acquire unambiguous consent
- Data must be handled securely
Our guide to personal data provides an overview of what's considered personal data under the GDPR, but suffice it to say that its definition is broad.
Is PostHog GDPR compliant?
We have in-depth GDPR guidance documentation for advice on deploying PostHog in a GDPR-compliant way, including how to configure GDPR consent in PostHog and complying with 'right to be forgotten' requests.
We also offer PostHog Cloud EU – a managed version of PostHog with servers hosted in Frankfurt, ensuring user data never leaves EU jurisdiction.
How do I get a signed DPA?
A Data Processing Agreement (DPA) is the contract between a data controller and a data processor. If you use PostHog Cloud, PostHog may be considered your data processor. All PostHog Cloud customers can get a DPA, on any plan. This includes the free plan.
To get your signed copy:
- Open app.posthog.com/legal. It sends you to your own cloud region.
- Click "+ New" and then "Data Processing Agreement (DPA)".
- Add your company details, including legal company name, then click "Send for signature".
- PandaDoc sends an email to the address in your company details. Open that email and sign the DPA. PostHog has already countersigned it.
- The DPA is effective as soon as you sign. You receive an email with the completed document. You can also download it from PandaDoc, or find it on the legal dashboard.
The DPA is self-serve, so you do not wait for our team to approve or sign it. You can also read the full text of the DPA first. The "Get countersigned DPA" button on that page opens the same legal page in the app. The text on /dpa is a preview only. Only the copy that you generate in the app is valid.
If you need changes to the standard DPA, contact us first.
Can I use PostHog Cloud under HIPAA?
Yes. A Business Associate Agreement (BAA) may be required for HIPAA-compliant use of PostHog Cloud, but a signed BAA does not make your setup compliant on its own. It does not cover every feature, and compliance also depends on how you configure the features you use. Read our HIPAA guidance to see which features a BAA covers, and check your configuration before you send protected health information to PostHog.
You generate and download a countersigned BAA on the legal page in your PostHog organization, in the same way as the DPA. You can read the full text of the BAA first. PostHog offers a BAA to customers on the Boost, Scale, or Enterprise package. Contact us to discuss your requirements.
Is Google Analytics HIPAA compliant?
No, Google Analytics isn't HIPAA compliant, so it can't be used in any context where you're collecting or processing personal health information. PostHog can be used to collect user data under HIPAA. Read our HIPAA guidance for more information.