
You clear your cookies, close the browser, and assume you have a clean slate — yet some trackers recognize you the moment you return. That is the trick of a supercookie: a way to follow you that ordinary “clear cookies” does not erase. Our GetMyPassword team explains what a supercookie is, why it is hard to shake, and how to limit it.

What a supercookie is
A supercookie is a tracking method that is much harder to delete than a normal cookie. A regular cookie sits in your browser, and you can clear it in a click. A supercookie is different: it is either tucked into storage that survives a normal cleanup, or injected into your traffic further upstream, so the tracker can re-identify you even after you wipe your cookies. Same goal as a cookie — recognizing you — but built to be persistent.
How it sticks around
Supercookies take a couple of broad forms. Some are persistent identifiers stashed in odd corners of the browser that quietly “respawn” a deleted tracker — sometimes called zombie cookies. Others are injected by a network: a provider can tag your outgoing requests with a unique header that follows you across sites, something you cannot delete from your end at all. Either way, the point is to outlive the cleanup that stops a normal cookie.
Why it matters for privacy
- It tracks you across sites and builds a profile even after you clear cookies.
- It is hard to escape — the usual privacy steps may not remove it.
- You may not consent — network-injected ones happen without any choice in your browser.
- It feeds the same machine as other tracking — more data about you in more hands.
A normal cookie is a sticky note you can throw away. A supercookie is written in a place you cannot easily reach — which is exactly why it is worth knowing it exists.
How to limit supercookies
You cannot kill every supercookie, but you can shrink the target. Browse over HTTPS, which blocks many network-injected trackers from reading or tagging your traffic. Use a browser with strong tracking protection and anti-fingerprinting, clear site data regularly, and consider private DNS on untrusted networks. None of this guards your accounts, though — that still takes a unique password from our password generator on each one and two-factor authentication. Privacy tools reduce tracking; strong passwords keep the accounts themselves safe.
Frequently asked questions
What is a supercookie?
It is a tracking method that is much harder to delete than a normal cookie. It either hides in storage that survives a cleanup or is injected into your traffic by a network, so a tracker can re-identify you even after you clear your cookies.
Does clearing cookies remove a supercookie?
Often not. That is the whole point — supercookies are built to outlive a normal “clear cookies.” Strong tracking protection, HTTPS and clearing site data help, but a network-injected supercookie cannot be deleted from your browser at all.
How do I protect myself from supercookies?
Browse over HTTPS, use a browser with strong tracking protection and anti-fingerprinting, clear site data regularly, and consider private DNS on untrusted networks. These reduce tracking, while strong unique passwords and two-factor authentication protect the accounts themselves.



