ADAM PULSE Knowledge Base
Security · Privacy · Browsers · Network Monitoring

What does Incognito mode actually hide, and who can still see your browsing?

Short answer

Incognito mode is private from the next person who opens your browser. It is not private from the internet.

When you close an Incognito window, Chrome does not add the sites you visited to your normal browsing history, and it discards the cookies and site data created during that session. That is genuinely useful, and it is the whole of what it promises.

What it does not do is erase records created outside your browser. The website you visited may keep a server log. Your employer may run a firewall, a DNS filter or endpoint software. Your internet provider carries the connection. A search engine receives your search. If you sign into an account, that service knows exactly who you are. And anything you downloaded is still sitting on the disk.

So the useful question is not "does Incognito save my history?" It is:

Which history, stored where, and controlled by whom?

That is what the rest of this article answers, layer by layer.

What actually happens when you open an Incognito window

What does Incognito mode actually do?

It opens a separate, temporary browsing session that does not write to your normal browser profile.

During the session Chrome still keeps cookies and site data, because websites need them to log you in, keep a basket, or remember a language choice. The difference is what happens at the end: when you close every Incognito window, that session's data is discarded rather than merged into your profile.

Chrome's own Incognito landing page states it in three lines:

Chrome won't save:

Your browsing history · Cookies and site data · Information entered in forms

What does the Incognito screen say now?

This matters, because the wording changed and a lot of older advice quotes the old version.

The current text reads:

Others who use this device won't see your activity, so you can browse more privately. This won't change how data is collected by websites you visit and the services they use, including Google. Downloads, bookmarks and reading list items will be saved.

That middle sentence did not exist before Chrome 122, released in February 2024. The earlier wording said only that other people using the device would not see your activity — which is what led a great many people to believe Incognito hid them from websites too.

Why did the wording change?

Because of litigation. Brown v. Google was a class action alleging that Google collected data from Incognito users despite the impression its disclosures gave.

Three things about it are routinely reported wrongly, so be precise:

Does Incognito save your browsing history?

Is my Incognito browsing in my Chrome history?

No, not after the session ends. That part works exactly as advertised.

But "not in Chrome's history" is a much narrower statement than "no record exists." Those are the two claims people conflate, and the rest of this article is the gap between them.

Are Incognito downloads saved?

The file is saved. The history entry is not. This trips up more people than any other item on the list.

Chrome does not write Incognito downloads into its persistent download history — the component that records downloads is never created for an Incognito session at all. So chrome://downloads will not show it later.

The downloaded file itself stays on the disk until someone deletes it. Chrome says so directly in its own download bubble: "Anyone using this device can see downloaded files."

Bookmarks and reading list items you create in Incognito also persist into your normal profile.

Does Incognito save passwords?

No. Form data and autofill entries from the session are not retained. If your password manager is a browser extension you have allowed to run in Incognito, that is a separate system with its own storage.

Who can still see what: the layers

This is the section that actually answers the question people are asking. A single web request passes through a series of parties, and Incognito only affects the first one.

What Incognito mode affects in the path of a web request A web request passes from your device, through the browser, then your employer network and its security systems, then your internet provider, and finally the website. Incognito mode clears only the local browser history on your own device. Every other party in the path is unaffected and keeps whatever it would normally keep. Your device Local browser history Employer network, DNS, firewall, EDR Internet provider Website and the services it uses ✕ cleared when the session ends — and this is the only box that is Incognito changes the dashed box. It changes nothing to the right of it.
Incognito mode clears local browser history. Every other party in the path keeps whatever it would normally keep.

Who can still have a record of my Incognito browsing?

Where a record of an Incognito session can still exist, and whether Incognito affects it
Where Is there potentially a record? Does Incognito change it?
Chrome's normal browsing history No, after the session closes Yes — this is what it does
Cookies and site data from the session Discarded when the session ends Yes
Form and autofill entries Not retained Yes
Files you downloaded Yes — the file stays on disk No
Bookmarks and reading list items you saved Yes No
The website's own server logs Yes No
Account activity, if you signed in Yes No
Employer or school network systems Yes No
Firewall, secure web gateway, proxy Yes No
DNS resolver logs Yes No
Your internet provider Yes No
Endpoint security or monitoring software Yes No
Router or Wi-Fi equipment, if it logs Yes No

Chrome's own summary of the same point is shorter:

Your activity might still be visible to: Websites you visit · Your employer or school · Your internet service provider

Can my employer see what I browse in Incognito?

Potentially, yes — and Incognito does nothing to prevent it.

Incognito is a setting inside one application. It does not switch off the corporate firewall, the DNS filter, the secure web gateway, the proxy, the VPN, or the endpoint detection software running on the laptop. All of those sit outside the browser and see traffic regardless of which browser mode produced it.

On a managed device the position is stronger still: enterprise management can log browser activity directly, and can disable Incognito mode outright by policy.

If the practical question behind this is "will my employer find out," the honest answer is that it depends entirely on what they have deployed and whether anyone looks — not on whether you used Incognito.

Can my school see Incognito browsing?

Same answer, same reasons. A school-managed network and a school-managed device both sit outside the browser session.

Can my internet provider see what I do in Incognito?

Incognito does not hide anything from your ISP. But be precise about what an ISP can see, because "your ISP can see everything you do" is an overstatement in 2026.

Practically everything is HTTPS now, so the contents of a page — what you read, what you typed, what was returned — are encrypted between your browser and the site. What remains visible to a network intermediary is largely destination and metadata: which servers you connected to, when, and how much data moved.

DNS is where this gets interesting, and it is the part most articles get wrong.

Does Incognito encrypt my DNS lookups?

No. Incognito does not change DNS behaviour at all.

Chrome does have a Secure DNS feature, and its default is "automatic" mode — which means Chrome upgrades to encrypted DNS-over-HTTPS only if your existing DNS provider supports it, and silently falls back to unencrypted DNS if it does not. It is also unavailable entirely on managed devices or where parental controls are configured.

So on a corporate network pointing at a corporate resolver, or a home connection using an ISP resolver that does not support DoH, your DNS lookups are still going out in the clear — in Incognito exactly as much as outside it.

Can the website tell I am using Incognito?

Separate that into two questions, because only one of them matters.

Whether a site can detect Incognito has been a running cat-and-mouse game; browsers have repeatedly closed detection methods as they were found.

The question that actually matters is different, and the answer is not in doubt: Incognito does not stop the website from seeing your visit. The site still receives the connection, still sees your IP address, and still logs whatever it logs. Chrome says so in the Incognito disclosure itself — it "won't change how data is collected by websites you visit and the services they use, including Google."

Signing in, IP addresses and tracking

What if I sign into Google, Facebook or Amazon while in Incognito?

Then that service knows exactly who you are, and Incognito is irrelevant to it.

This is the single biggest misconception about private browsing, so it is worth stating flatly:

Incognito isolates the browser session. It does not erase your identity after you have voluntarily identified yourself to a website.

If you sign in, the service can associate that session's activity with your account and process it according to its policies and your account settings. Incognito neither prevents that nor conceals it.

Does Incognito hide my IP address?

No.

Private browsing and IP privacy are unrelated technologies. Incognito controls what your browser keeps locally; your IP address is how the network knows where to send the response.

There is a piece of stale advice circulating on this. Google did propose a feature called IP Protection — earlier called Gnatcatcher — which would have masked a user's IP address from certain third-party domains in Incognito. In April 2025 Google said it planned to launch it that year. In October 2025 Google retired it, along with several other Privacy Sandbox technologies, and the code was removed from Chrome in version 145 in March 2026.

It is worth understanding what it would have done even if it had shipped, because the description was narrower than the name suggests: it would only have masked your IP from listed third-party tracker domains, only for users signed into a Google account, and never from the site you actually visited or from your ISP.

Does Incognito stop cookies?

Partly, and this part is genuinely stronger than people assume.

Chrome blocks third-party cookies by default in Incognito, and has since May 2020. First-party cookies still work during the session — sites need them — and all of them are discarded when it ends.

Outside Incognito the picture is different: Google abandoned its plan to deprecate third-party cookies in regular browsing in April 2025, and reaffirmed that position later that year. Regular Chrome browsing still allows third-party cookies unless you change the setting yourself.

Does Incognito stop tracking?

Not universally, and it is not designed to.

Blocking third-party cookies removes one common tracking mechanism. It does not address fingerprinting, first-party analytics, server-side logging, tracking tied to an account you signed into, or network-level identification.

Some browsers add more to their private modes than Chrome does — see the comparison below. But private browsing as a category should not be described as anti-tracking technology, and certainly not as anonymity technology.

Chrome, Safari, Firefox and Edge are not the same

Is Safari Private Browsing the same as Chrome Incognito?

The local behaviour is broadly similar — Safari does not remember the pages you visited, your search history, or AutoFill information from a private window.

Apple layers additional protections on top, which Chrome's Incognito does not match: known trackers are blocked, and there are protections aimed at fingerprinting. Separately, Apple's iCloud Private Relay — a paid iCloud feature, not part of Private Browsing — does mask the IP address from sites and from the network operator, which is the thing Incognito explicitly does not do.

Is Firefox Private Browsing the same as Incognito?

Again, similar locally: history and cookies from the session go when the window closes. Firefox additionally blocks tracking cookies by default in private windows through Enhanced Tracking Protection.

Mozilla is also unusually candid about the limits, and its framing is the right one to carry away: private browsing is aimed at keeping session information out of ordinary persistent browser storage. It does not claim to defeat every scenario.

What about Edge InPrivate?

Edge is built on the same Chromium engine, so the local behaviour matches closely, with Microsoft's own tracking-prevention settings applied on top.

Which private mode is most private?

The honest answer is that the differences between them are small relative to the thing they all share: none of them affects anything past your own device. Choosing a browser is not a substitute for understanding the layers above.

Incognito versus a VPN

What is the difference between Incognito and a VPN?

They solve different problems, and neither solves the other's.

Does a VPN plus Incognito make me anonymous?

No.

Together they cover more ground: local history is not retained, and your local network and ISP see an encrypted tunnel to the VPN provider rather than your destinations. What neither addresses:

Anonymity is a much harder property than either tool provides, and treating the pair as anonymity is how people get into trouble.

Recovery, forensics and what is left behind

Can Incognito history be recovered?

Be careful with confident answers in either direction here.

By design, Incognito keeps its cache and session state in memory rather than writing it to disk. Chromium's own design documentation says this makes it "quite difficult" to extract information about an Incognito session even if the application crashes.

Note the hedge. "Quite difficult" is the browser project's own wording, and it is not the same as impossible. Two things are worth adding honestly:

So: designed to stay in memory, described by its own authors as difficult rather than impossible to recover, and historically not perfect at it.

Does deleting my Incognito history erase network logs?

There is nothing to delete in the browser — that is the point of the mode — and it would make no difference if there were. Server logs, DNS logs, firewall logs and ISP records are held by other parties, on their systems, under their retention policies. Nothing you do on your own device reaches them.

Can investigators recover Incognito browsing?

This article is not legal advice, and the accurate answer is that it does not usually depend on the browser at all. The records that tend to matter in an investigation are the ones held by third parties — the site, the network operator, the service you signed into — and those are obtained from those parties, not from your browser profile.

What Incognito actually protects you from

A short, honest list. Incognito is genuinely good at these:

And what it is not for:

If you actually need the activity not to be observed

Match the tool to the layer you care about.

On a work device or work network

Assume it is observable, and act accordingly. If something is genuinely personal, do it on a personal device on a personal connection. This is not paranoia — it is the reasonable reading of a device your employer administers and a network they operate. Most acceptable-use policies say so explicitly.

For the local-device problem

Incognito is the correct tool, and it works.

For the network-visibility problem

A VPN moves the observation point. It does not eliminate it, and it introduces a new party to trust — choose deliberately, and read what the provider says it retains.

For the identity problem

Do not sign in. Nothing else on this list compensates for signing in.

What businesses should take from this

Two practical points, because this comes up in policy conversations more than in technical ones.

If you run a network, do not rely on Incognito being invisible to you — but do document what you actually monitor. The gap between what employees assume and what an organisation logs is where grievances start. An acceptable-use policy that says plainly what is captured, how long it is kept and who can see it costs nothing and prevents the argument.

If you handle regulated data, private browsing is not a control. It does not satisfy a confidentiality requirement, it produces no audit trail, and the absence of local history can actively work against you when you need to evidence what happened. Where a requirement calls for controlled and logged access, Incognito is the opposite of what is being asked for.

Frequently asked questions

Does Incognito mode really hide your browsing history?

It hides it from your own browser, and only after the session ends. Chrome does not add Incognito sites to your normal history and discards the session's cookies and site data. It does not remove records held anywhere else, including the website's server logs, your employer's network systems, your internet provider, or any account you signed into.

Can anyone see my Incognito history?

Potentially yes. Chrome itself lists websites you visit, your employer or school, and your internet service provider as parties whose visibility Incognito does not change. Incognito only affects what your own browser keeps on your own device.

Can my employer see websites I visit in Incognito?

Potentially yes, and Incognito does nothing to prevent it. Incognito is a setting inside one application. It does not disable a corporate firewall, DNS filter, secure web gateway, proxy, VPN or endpoint detection software, all of which sit outside the browser. On a managed device, enterprise policy can also log browser activity directly and can disable Incognito entirely.

Can my school see Incognito browsing?

Yes, on the same basis as an employer. A managed network and a managed device both operate outside the browser session.

Can my ISP see my Incognito history?

Incognito hides nothing from your internet provider. What an ISP can see is mostly destination and connection metadata rather than page contents, because almost all traffic is HTTPS encrypted. DNS lookups may also be visible if your resolver does not support encrypted DNS.

Can my Wi-Fi owner or router see Incognito browsing?

Potentially. Whoever operates the network can observe connection metadata and, depending on the equipment and configuration, may log it. Incognito does not change what the network sees.

Does Incognito hide my IP address?

No. Private browsing and IP privacy are unrelated. Google proposed a feature called IP Protection that would have masked the IP address from certain third-party domains in Incognito, but retired it in October 2025 and removed the code from Chrome in version 145 in March 2026.

Does Incognito hide my searches from Google?

No. If you run a search, the search engine receives it. If you are signed into a Google account, the activity can be associated with that account. Chrome's own Incognito disclosure states that Incognito does not change how data is collected by the websites you visit and the services they use, including Google.

What happens if I sign into an account while in Incognito?

The service knows exactly who you are, and Incognito becomes irrelevant to it. Incognito isolates the browser session; it does not erase your identity after you have voluntarily identified yourself to a website.

Can websites tell that I am using Incognito?

Detection has been a repeated cat-and-mouse issue and browsers have closed methods as they were found. The more important point is that Incognito does not stop the website from seeing your visit at all. The site still receives the connection, still sees your IP address, and still logs what it logs.

Does Incognito stop cookies?

Chrome blocks third-party cookies by default in Incognito, and has since May 2020. First-party cookies still work during the session because sites need them, and all session cookies are discarded when the last Incognito window closes.

Does Incognito stop tracking?

Not universally, and it is not designed to. Blocking third-party cookies removes one mechanism. It does not address fingerprinting, first-party analytics, server-side logging, tracking tied to an account you signed into, or identification at the network level.

Are Incognito downloads saved?

The file is saved; the history entry is not. Chrome does not write Incognito downloads to its persistent download history, so they will not appear in your downloads list later. The downloaded file remains on the device until deleted, and Chrome's own download bubble warns that anyone using the device can see downloaded files.

Does Incognito save passwords or form data?

No. Information entered in forms during the session is not retained.

Can Incognito history be recovered?

By design Incognito keeps its cache and session state in memory rather than writing to disk, and Chromium's own design documentation says this makes extraction quite difficult even after a crash. That is not the same as impossible. No Chromium documentation addresses operating system memory paging, swap files or hibernation images, and Chrome has shipped bugs where Incognito state did reach disk.

Does deleting Incognito history erase network logs?

No. Server logs, DNS logs, firewall logs and ISP records are held by other parties on their own systems under their own retention policies. Nothing done on your device affects them.

Does Incognito encrypt my DNS lookups?

No, Incognito does not change DNS behaviour. Chrome's Secure DNS default is automatic mode, which upgrades to encrypted DNS only if your existing resolver supports it and silently falls back to unencrypted DNS otherwise. It is unavailable entirely on managed devices or where parental controls are configured.

Is Safari Private Browsing the same as Chrome Incognito?

Locally they are broadly similar. Safari adds protections Chrome's Incognito does not match, including blocking known trackers and protections aimed at fingerprinting. Apple's iCloud Private Relay, which does mask the IP address, is a separate paid iCloud feature rather than part of Private Browsing.

Is Firefox Private Browsing the same as Incognito?

Locally similar, with Enhanced Tracking Protection blocking tracking cookies by default in private windows. Mozilla is candid that private browsing aims to keep session information out of ordinary persistent browser storage rather than to defeat every scenario.

What is the difference between Incognito and a VPN?

Incognito controls what your browser keeps locally after a session and changes nothing about the network. A VPN changes which network path your traffic takes and what your local network and ISP can observe, and does nothing about local browser storage or about what the destination site logs.

Does a VPN plus Incognito make you anonymous?

No. The website still sees and logs your visit, signing into an account identifies you regardless, and the VPN provider now occupies the position your ISP did and can potentially log the same connection metadata. You have moved the trust rather than removed it.

What is the difference between Incognito and deleting your browser history?

Deleting history removes records after the fact from the profile they were written into. Incognito avoids writing them to that profile in the first place. Neither affects records held by anyone else.

Does Incognito protect you from malware?

No. Incognito has no security function. A file downloaded in Incognito is exactly as dangerous as the same file downloaded normally, and it remains on the device.

Does Incognito prevent browser fingerprinting?

Chrome's Incognito does not claim to. Some other browsers add fingerprinting protections to their private modes, but private browsing as a category should not be treated as anti-fingerprinting technology.

What information is left behind after an Incognito session?

On the device: any files you downloaded, and any bookmarks or reading list items you created. Elsewhere: the website's server logs, activity associated with any account you signed into, and whatever your network operator, DNS resolver, security software and internet provider record in the normal course.

Was there a lawsuit about Chrome Incognito?

Yes. Brown v. Google alleged that Google collected data from Incognito users despite its disclosures. It settled on injunctive relief only, with no class settlement fund and no claims process. Google agreed to change policies, clarify disclosures and remediate certain retained data. Chrome's Incognito wording was changed in version 122 in February 2024 to add that Incognito does not change how data is collected by websites and the services they use, including Google.

Should a business rely on Incognito as a privacy control?

No. It does not satisfy a confidentiality requirement, produces no audit trail, and the absence of local history can work against you when you need to evidence what happened. Where a requirement calls for controlled and logged access, Incognito is the opposite of what is being asked for.

References

Primary sources only — Google's and Chromium's own documentation, Mozilla, Apple, and the court record. Where a widely repeated claim is out of date, the reference is the document that supersedes it.

  1. Google — Browse in Incognito mode— Chrome's own description of what Incognito retains and does not retain, the third-party cookie default, and the statement that organizations managing your network may be able to observe your activity.
  2. Google — Manage Chrome safety and security— the Secure DNS setting: "By default, secure DNS in Chrome is turned on in automatic mode", with fallback to unencrypted lookup, and unavailable on managed devices.
  3. Chromium — new tab and Incognito interface strings— the source of the Incognito landing page wording, including the sentence added in Chrome 122 about data collection by websites and their services.
  4. Google — More intuitive privacy and security controls in Chrome— 19 May 2020, announcing third-party cookie blocking by default in Incognito, roughly four years before the settlement it is often attributed to.
  5. Google Privacy Sandbox — Update on plans for Privacy Sandbox technologies— 17 October 2025. Confirms IP Protection was retired along with several other technologies.
  6. Google Privacy Sandbox — Next steps for Privacy Sandbox and tracking protections— 22 April 2025. The decision to maintain the existing approach to third-party cookies in Chrome rather than deprecate them.
  7. Chromium — Disk cache design document— the in-memory cache used for Incognito, described by Chromium as making extraction "quite difficult" after a crash. Note the hedge.
  8. United States Court of Appeals for the Ninth Circuit — Brown v. Salcido, No. 24-5692— 20 April 2026. Describes the Brown v. Google settlement as resolving the certified class's injunctive relief claim, with named plaintiffs arbitrating individually and absent class members retaining damages claims.
  9. Mozilla — Private Browsing— Firefox's private mode, including Enhanced Tracking Protection blocking tracking cookies by default, and Mozilla's own account of the limits.
  10. Apple — Browse privately in Safari— Safari Private Browsing, and the tracker and fingerprinting protections layered on top of it.
Prepared by ADAM Pulse (USA Telecom Consulting LLC)

Managed network and security services, SDVOSB. We build and document the monitoring layer this article describes — firewall, DNS and endpoint visibility, retention that matches your obligations, and an acceptable-use position your staff can actually read. If your organisation cannot currently answer "what do we log, for how long, and who can see it", that is the place to start. Support: (888) 989-4872 · support@adampulse.us