Skip to main content

Browser Privacy Statistics — What 9,084 Real Tests Show

Original measurements from real browser privacy tests: WebRTC leak rates, DNS leak rates, VPN usage and IPv6 adoption, with sample sizes.

Last updated: August 12, 2026

Most privacy statistics you find online are survey results — people reporting what they believe about their setup. These are measurements. Every figure below comes from a privacy test that actually ran in a real browser on this site, and every one is published with the number of sessions behind it.

What we measured

Between 2026-06-07 and 2026-08-12 we recorded 9,084 test results from human sessions. Automated traffic is excluded before counting.

Measurement Result Sessions measured
Connections already routed through a VPN, proxy or hosting network 48.2% 4,669
Browsers that exposed an IP address through WebRTC 43% 581
Connections whose DNS resolution looked inconsistent with the tunnel 35.2% 1,703
Visitors with working IPv6 connectivity 16.6% 1,055
Visitors whose IPv6 path bypassed their IPv4 tunnel 0.5% 1,055

The single most striking figure is WebRTC. It is a browser feature that can reveal an IP address independently of any VPN tunnel, it is enabled by default almost everywhere, and a large share of the browsers we measured were exposing one — including many that were connected through a VPN at the time. People who have taken the trouble to run a VPN are frequently still leaking around it.

IPv6 tells the opposite story. Adoption among the visitors we measured is low, and precisely because so few connections carry working IPv6, IPv6-specific leaks are rare in absolute terms. That balance shifts as adoption grows.

How privacy-tested browsers actually score

The privacy test runs four independent checks and grades the result:

Overall grade Share Sessions
Excellent (4 of 4 checks passed) 4.8% 43
Good (3 of 4) 48.8% 435
Fair (2 of 4) 29% 259
Poor (0–1 of 4) 17.4% 155

Only 4.8% of graded sessions passed all four checks. This is a self-selecting audience — people who deliberately visit a privacy testing site skew far more careful than the general population — which makes the result more sobering, not less. If this is what an interested, motivated group looks like, the untested majority is unlikely to be doing better.

Method, and what these numbers are not

Each completed test contributes exactly one aggregate outcome. The recorded shape permits only booleans, small fixed enums and bounded counts, so an IP address or fingerprint cannot be stored alongside a result even by mistake — the boundary schema rejects any field outside that allowlist rather than storing it.

Three limits are worth stating plainly:

  • Self-selection. Visitors to a privacy testing site are not a random sample of internet users. Read every figure as "among people who chose to test", never as a population estimate.
  • Repeat testing. Someone who changes a setting and retests contributes more than one result. We do not de-duplicate across sessions.
  • The DNS figure is a consistency check. It compares what independent endpoints observe about a connection; it does not directly observe which resolver an operating system queried. Read it as an indicator, not a verdict.

Test your own browser

Every number above came from a test you can run yourself, right now, in the browser you are reading this in:

Nothing you run is tied to you: results are counted, not stored against an identity.

Frequently Asked Questions

Where does this data come from?
From the privacy tools on this site. When a test finishes, one aggregate result is recorded — for example 'a WebRTC leak was detected' — and nothing else. No IP address, no fingerprint, no hostname and no free-form text is stored with it, because the schema only permits booleans, small fixed enums and bounded counts. The figures on this page are counts of those results.
How do you know these are real people and not bots?
Automated traffic is excluded before anything is counted. Requests that declare automation are flagged when they arrive, and crawler cohorts that hide behind ordinary browser identifiers are identified afterwards by their behaviour — a single visitor touching dozens of language versions in one day is not a person. Only the remaining human sessions reach these numbers.
Why is a percentage sometimes missing?
Any measurement with fewer than 100 sessions behind it is left out entirely rather than shown with a caveat. A percentage drawn from a handful of runs is noise, and presenting it as a finding would undermine the numbers that are solid.
How current are these figures?
They are recomputed periodically rather than on every page view, and the measurement window is stated below. That keeps the page fast and identical for every visitor, at the cost of not being live to the minute.
Can I cite or reuse these numbers?
Yes. Please link back to this page so readers can see the sample sizes and method. If you need a specific breakdown that is not published here, get in touch.

This content is AI-generated and may contain inaccuracies. We do our best to keep it accurate and up to date.