What is the rl_anonymous_id cookie?
Stores the anonymous ID. By default, it would be the auto-generated unique ID by SDK for each visitor unless overridden via setAnonymousId API. All the subsequent event payloads will contain this data unless cleared from the storage.
Our October 2026 scan found it on 6 sites (0% of the 2,450 we scanned), set before any consent.
- Purpose
- Analytics
- Belongs to
- Rudderstack
- Set as
- First-party (under the site's own domain)
- Typical lifetime
- 12 months (vendor says: Session)
Sites that set rl_anonymous_id before consent
The highest-ranked 6 of 6 sites.
- tailscale.com7 tracking companies
- laravel.com7 tracking companies
- simplisafe.com31 tracking companies
- acorns.com20 tracking companies
- sanity.io3 tracking companies
- foreignpolicy.com22 tracking companies
How to stop it
Declining non-essential cookies in a site's consent banner should stop rl_anonymous_id being set on later visits. Blocking third-party cookies in your browser settings stops the third-party kind everywhere, and clearing cookies for a site removes any it already set.
Description from the Open Cookie Database (Apache 2.0).
Understanding this page
- How cookie lifetimes work, and why a 13-month _ga matters
What a cookie's "expires" field actually controls, why Google Analytics ships a 2-year default that many sites cut down to 13 months, and how Safari's 7-day cap on script-set cookies changes the picture.
- First-party vs third-party cookies (and why "first-party" still tracks you)
What the distinction actually means technically, why browsers only block one of the two, and how CNAME cloaking, server-side tagging and cookies like _ga let sites keep tracking under their own domain.
- How to block or limit trackers
Browser privacy settings, content blockers, Global Privacy Control and clearing cookies compared honestly — what each one actually stops, what it doesn't, and what it costs you in return.