Loghound can store a visitor’s address in three ways: in full, truncated, or hashed with a salt that changes every day. You choose in Settings › Privacy under How IP addresses are stored. A new installation stores the full address.
| Full (default) | Truncated | Hashed | |
|---|---|---|---|
| Bot detection quality | best | good | reduced |
| Geography, network, reverse DNS | yes | yes | no |
| Following a person across days | possible | partly | no |
| Abuse reporting | yes | approximately | no |
| Personal data under GDPR? | yes | pseudonymised | pseudonymised, strongly |
- Full address: stored as received, best detection. It is the default because you already have the raw address in your own access logs, indefinitely. Loghound storing it changes your exposure far less than people assume.
- Truncated (/24 and /48): the last part of the address is zeroed, so it names a network rather than a device. Widely accepted as pseudonymisation. Clustering still works, but a fleet whose exits share a range can merge below the proxy fleet threshold, and unrelated people can merge into one address. Expect noisier verdicts.
- Hashed with a daily-rotating salt: nobody can be followed across days, and visits within one day still work. Location, network and reverse DNS are lost entirely, because there is no address left to look up. The salt is the whole protection: without it the address space is small enough to guess in seconds, so treat it like a password.
It never rewrites history. Requests from private network addresses are never recorded at all, in any mode.
An unattended install can set the mode with LOGHOUND_IP_MODE: Unattended installs. What it means for data subject requests: GDPR.
Privacy & retention
- What leaves the machine
- How addresses are stored
- GDPR
- Text for your visitors
- Retention & disk