#1744·pocket-id

Bug Report: Analytics MUST be opt-in, not opt-out,

Author: alvar-freudeCreated Sep 11, 2026Updated Sep 16, 2026

Reproduction steps

According to the documentation, every Pocket ID installation transmits data to a central Pocket ID server by default; see https://pocket-id.org/docs/configuration/analytics.

This is not permitted in the European Union.

  1. According to the EU ePrivacy Directive, retrieving information from the terminal equipment (the server) is only permitted if it is based on the user’s request or if the user has given informed consent. This is clearly not the case. (The “user” in this case is the administrator or their supervisor.)

  2. A random ID constitutes personal data. Therefore, the scope of the GDPR applies, and a legal basis for processing this personal data is required. In this case, this can only be consent. Without consent, it is not allowed.

What should be done?

Option A: Completely remove the analytics feature. Option B: Implement a process to determine whether the administrator WANTS this data transfer, and whether his employer permits it; provide him with detailed information about all the data; and request informed consent.

Note: The fact that other software has similar tracking features — or even more — does NOT make this lawful in this specific case.

GDPR fines can reach up to €20 million or 4% of a company’s global annual turnover, whichever is higher, for serious violations.

Expected behavior

No data is ever transferred from the Pocket ID server to any other destination unless it is absolutely necessary for the service to function.

Actual Behavior

According to the documentation, personal data is transferred: https://pocket-id.org/docs/configuration/analytics

Pocket ID Version

Current, v2.14.0

Database

doesn't matter

OS and Environment

doesn't matter

Log Output

No response