Back to Blog

What Is Supercookie Tracking and How Is It Different From Regular Cookies

PB

Patrick Bushe

April 14, 2026 · 5 min read

A supercookie is any tracking ID stored somewhere other than the normal cookie jar, so that clearing your cookies doesn't remove it. The name covers several different tricks. Some live in your browser, and one kind lived in your mobile carrier's network.

How supercookies differ from regular cookies

  • Regular cookies are small files a site stores in your browser. You can see them, delete them and block them, and laws like the GDPR require consent for tracking ones.
  • Supercookies hide an ID in browser features meant for other jobs, or outside the browser entirely. They survive clearing cookies, and some survived Incognito in older browsers.

The main kinds

  • Cache-based IDs. A site can hide an ID in a file your browser caches, or in the ETag label the browser sends back to check whether a cached file has changed.
  • HSTS supercookies. HSTS is a security feature that remembers which sites must use HTTPS. By making a browser remember a pattern across many subdomains, a tracker can encode an ID in those yes/no records.
  • Favicon and other caches. Researchers have shown similar tricks using cached site icons and other stored data.
  • Flash cookies. Flash Player had its own storage that browsers didn't clear. Flash is gone, so this one is history.
  • Evercookies. A technique that stores the same ID in many places at once and restores any copy you delete.
  • Carrier headers. Some mobile carriers added a unique ID to their customers' web traffic. Verizon's version was the best known; it settled with the US Federal Communications Commission in 2016 and agreed to ask customers for consent.

How browsers fight back

Modern browsers now keep caches and similar storage separate for each website you visit (often called partitioning). An ID stored while you're on one site can't be read on another, which breaks most browser-based supercookies. Chrome, Firefox, Safari and Brave all do this. Browsers have also limited how HSTS records can be set, to stop that trick.

What you can do

  • Keep your browser updated, since most fixes come in updates.
  • Clear all site data, not just cookies. In Chrome, Delete browsing data with "Cookies and other site data" and "Cached images and files" both ticked.
  • Use HTTPS sites. A carrier can't add headers to encrypted traffic, which is the main reason header IDs faded away. A VPN also hides traffic from your carrier.
  • Block trackers. A content blocker stops many tracking scripts from loading at all.

Supercookies are one part of cookieless tracking. Fingerprinting is the bigger one today. See how sites track you without cookies.

More Tools by Patrick Bushe

Free Chrome extensions to boost your productivity and privacy