Tracking did not end when headlines talked about “the death of the cookie.” In 2026 some browsers block third-party cookies by default. Chrome, still the most common browser, largely did not. Google walked back a forced phase-out, then retired most of the Privacy Sandbox ad APIs meant to replace cookies. Old tools still work in many places. New ones filled the gaps. The business of knowing who you are across sites did not close.
This map is for a reader who wants the machinery, not a silver bullet. Oernoe publishes it at [https://www.oernoe.com/blog](https://www.oernoe.com/blog). We operate Search, Health, Chat, AI, Docs, Drive, and Tracker. Angel Mejia Rodriguez founded the company; Anoepal operates it.
## What “tracking” means in practice
Tracking is any technique that lets a company recognize you, or a close stand-in, across time or sites. Recognition can be a name, email, cookie, mobile advertising identifier, hashed phone number, login graph, or browser fingerprint. Ads get priced on that recognition. Conversion gets claimed on it. Profiles get sold on it.
You do not have to be famous or click “accept all.” A script can load, an app can ask the OS for an ID, a form field can be hashed. The person in the profile is often a probability. That is still enough to follow you.
## Cookies: third-party, first-party, and the 2026 split
A cookie is a small piece of data a site stores in your browser. A first-party cookie belongs to the site in the address bar. A third-party cookie belongs to another domain—usually an ad, analytics, or social pixel—embedded on that page.
Safari has restricted third-party cookies for years. Firefox partitions them. Brave blocks a large class of them. Chrome is different: after years of timelines, Google did not turn them off for everyone. In 2026 they remain available by default in Chrome, with settings if you go looking. “Cookies are dead” is a bad slogan.
Where third-party cookies are weak, first-party cookies are not. Sites set their own IDs. Analytics tags write first-party cookies. Consent banners often authorize more than people read. Publishers share IDs through redirects, server-to-server posts, or “authenticated” identity products. The cookie still exists. The party label changed.
CHIPS—Cookies Having Independent Partitioned State—is a Privacy Sandbox leftover that still helps. A partitioned cookie can remember you in an embed on one site without becoming a global ID. Useful for some widgets. Not a replacement for the rest of this stack.
## Pixels, tags, and the quiet HTTP request
A tracking pixel is a tiny image or script that fires on load or on an action. The request can carry cookies, a referrer, a click ID, and extra URL parameters.
In 2026 many of those pixels still fire. Meta, Google, TikTok, LinkedIn, and a long tail of customer-data platforms still ship tags. When a browser blocks the third-party cookie, the same companies lean on first-party pixels, server-side tagging, and email or phone matching. Blocking one request is useful. It is not the whole job.
Server-side tagging means the publisher’s server talks to ad domains instead of your browser. Your blocker sees fewer third-party hosts. The event can still go onward. An extension is not “done.”
## First-party IDs and the email as a skeleton key
If a company can get a stable identifier you reuse, it does not need a third-party cookie. Email is the obvious one. Phone numbers are next. Loyalty accounts, retailer logins, and “sign in with” buttons all produce IDs that can be hashed and matched.
You buy or subscribe. The merchant has your email. An ad platform has a hashed list. The sides match—onboarding, or identity resolution, depending on who is selling it. It works where third-party cookies are blocked. It works if you never clicked an ad, as long as the merchant uploaded a list. A privacy-respecting search box is only one piece. Queries can stay out of an ad profile while purchases still join you to one.
## Mobile advertising IDs
Phones have advertising identifiers: IDFA on Apple’s side, GAID on Google’s. Apple’s App Tracking Transparency prompt made IDFA harder to get without asking. Many apps still ask. Many more moved to first-party IDs, SKAdNetwork-style signals, and account data.
On Android you can reset or limit the advertising ID. Plenty of people never do. Apps still send device signals. Measurement still uses email, phone, and “this device logged into this account.” Locking down the browser while every app has full permission closes one door and leaves the hallway open.
## Login graphs: the account is the tracker
A login graph maps accounts, devices, and sessions to one person or household. Google has one because Gmail, YouTube, Android, and Chrome can share an account. Apple, Meta, and Microsoft have theirs. Retailers with their own SSO have smaller ones.
Once you are logged in, the company does not need a fingerprint to know a new laptop is you. Even “signed-out” surfaces can be tied back when you later sign in. People skip this when they change browsers and keep the same always-on phone account. The account is a stronger graph than a cookie.
## Fingerprinting: when the browser describes itself too well
Fingerprinting uses attributes that are not a stored ID: screen size, fonts, canvas or WebGL output, audio stack, time zone, language, installed codecs, how the GPU draws a hidden scene. Individually, each signal is weak. Together they can be rare enough to recognize a browser over time.
Some browsers randomize or block the noisiest APIs. A fingerprint is also brittle; updates change it. Serious ad companies treat it as a hint, then bind it to a login or email when they can. In 2026 it is not a superweapon and it is not gone.
## Privacy Sandbox and Topics-style replacements
Google spent years pitching Privacy Sandbox as the way Chrome could drop third-party cookies without starving ads. Topics grouped recent browsing into coarse interest labels. Protected Audience tried on-device auctions. Attribution Reporting tried to measure conversions without a full cross-site ID.
Adoption stayed low. In 2025 Google said it would retire most of those ad APIs. Through 2026, Topics and several siblings have been in deprecation and removal. CHIPS, FedCM, and Private State Tokens remain more relevant as plumbing than as a new ad ID.
The honest 2026 sentence is not “Sandbox replaced cookies.” It is “cookies were never fully removed in Chrome, and the replacement program mostly wound down.” Tracking moved to first-party IDs, pixels, lists, and accounts. Leftover Topics calls are history flushing through the pipes.
## Data brokers and the market behind the page
A data broker sells information about people: addresses, inferred income, “in-market” labels, app installs, location traces, and joinable IDs. Some of it starts as public records. A lot starts as a form, a warranty card, an app permission, a voter file, or a partner feed.
Brokers sit underneath ads and “know your customer” tools. A site you never heard of can buy a segment that includes you. Some U.S. state laws let you demand deletion or a stop to sale, with varying teeth. European rules are stricter on paper and uneven in practice. A single browser setting does not empty that market. Use the rights you have. Treat unsolicited people-search sites as hostile until proven otherwise.
## What this looks like in a normal day
You unlock a phone already signed into an account. Apps send analytics. A news site in Chrome loads a first-party cookie, a consent manager, and pixels. A logged-in search for a medical symptom can sit on the account. Later you buy shoes while logged in; the retailer hashes your email for an ad platform. A social app shows the same shoes. No third-party cookie had to survive the day. The email and the login graph were enough. That is ordinary, not a spy novel.
## Practical steps that still matter
Start with accounts. Sign out of big identity providers when you do not need them. Use separate browser profiles for the logged-in life and the wandering life.
Use a browser that defaults to less sharing—Firefox, Brave, or Safari—and a maintained blocker such as uBlock Origin. On the phone, deny tracking prompts you do not mean, reset advertising IDs, and delete apps you do not open.
Treat email as an identifier. Aliases help. A password manager stops one breach from unlocking the graph.
A VPN hides your IP from sites and from your ISP. It does not hide you after you log in, and it does not stop a pixel that already has your cookie. Use one for a network problem. Do not use one as a personality.
For search, use an engine built not to turn queries into ad profiles. That is the job Oernoe Search is designed for. We do not claim a bigger index than Google, and we do not claim Search quiets the rest of the internet.
Be precise about Oernoe. Search is built not to build ad profiles from your queries. The marketing site at www.oernoe.com may show ads. For the rules, read [/legal/privacy](https://www.oernoe.com/legal/privacy) and [/legal/cookies](https://www.oernoe.com/legal/cookies). A blog post is not a contract.
## What “reduced” tracking is, and what it is not
Third-party cookies are weaker in 2026 than in 2018, especially outside Chrome. That is real progress. It is not privacy.
The industry replaced a convenient cross-site cookie with first-party IDs, uploaded lists, login graphs, mobile identifiers, and leftover measurement APIs. Some replacements leak less. Some are just harder to see. Brokers and fingerprinting still exist. A consent banner designed to exhaust you is not informed consent.
You can still make the pile smaller: different tools, medical queries kept out of an ad account, a different email at checkout. None of that requires believing a press release. The companion pieces in this journal cover tools and how to compare search engines. Then use the settings. A map is only useful if you walk it.
This map is for a reader who wants the machinery, not a silver bullet. Oernoe publishes it at [https://www.oernoe.com/blog](https://www.oernoe.com/blog). We operate Search, Health, Chat, AI, Docs, Drive, and Tracker. Angel Mejia Rodriguez founded the company; Anoepal operates it.
## What “tracking” means in practice
Tracking is any technique that lets a company recognize you, or a close stand-in, across time or sites. Recognition can be a name, email, cookie, mobile advertising identifier, hashed phone number, login graph, or browser fingerprint. Ads get priced on that recognition. Conversion gets claimed on it. Profiles get sold on it.
You do not have to be famous or click “accept all.” A script can load, an app can ask the OS for an ID, a form field can be hashed. The person in the profile is often a probability. That is still enough to follow you.
## Cookies: third-party, first-party, and the 2026 split
A cookie is a small piece of data a site stores in your browser. A first-party cookie belongs to the site in the address bar. A third-party cookie belongs to another domain—usually an ad, analytics, or social pixel—embedded on that page.
Safari has restricted third-party cookies for years. Firefox partitions them. Brave blocks a large class of them. Chrome is different: after years of timelines, Google did not turn them off for everyone. In 2026 they remain available by default in Chrome, with settings if you go looking. “Cookies are dead” is a bad slogan.
Where third-party cookies are weak, first-party cookies are not. Sites set their own IDs. Analytics tags write first-party cookies. Consent banners often authorize more than people read. Publishers share IDs through redirects, server-to-server posts, or “authenticated” identity products. The cookie still exists. The party label changed.
CHIPS—Cookies Having Independent Partitioned State—is a Privacy Sandbox leftover that still helps. A partitioned cookie can remember you in an embed on one site without becoming a global ID. Useful for some widgets. Not a replacement for the rest of this stack.
## Pixels, tags, and the quiet HTTP request
A tracking pixel is a tiny image or script that fires on load or on an action. The request can carry cookies, a referrer, a click ID, and extra URL parameters.
In 2026 many of those pixels still fire. Meta, Google, TikTok, LinkedIn, and a long tail of customer-data platforms still ship tags. When a browser blocks the third-party cookie, the same companies lean on first-party pixels, server-side tagging, and email or phone matching. Blocking one request is useful. It is not the whole job.
Server-side tagging means the publisher’s server talks to ad domains instead of your browser. Your blocker sees fewer third-party hosts. The event can still go onward. An extension is not “done.”
## First-party IDs and the email as a skeleton key
If a company can get a stable identifier you reuse, it does not need a third-party cookie. Email is the obvious one. Phone numbers are next. Loyalty accounts, retailer logins, and “sign in with” buttons all produce IDs that can be hashed and matched.
You buy or subscribe. The merchant has your email. An ad platform has a hashed list. The sides match—onboarding, or identity resolution, depending on who is selling it. It works where third-party cookies are blocked. It works if you never clicked an ad, as long as the merchant uploaded a list. A privacy-respecting search box is only one piece. Queries can stay out of an ad profile while purchases still join you to one.
## Mobile advertising IDs
Phones have advertising identifiers: IDFA on Apple’s side, GAID on Google’s. Apple’s App Tracking Transparency prompt made IDFA harder to get without asking. Many apps still ask. Many more moved to first-party IDs, SKAdNetwork-style signals, and account data.
On Android you can reset or limit the advertising ID. Plenty of people never do. Apps still send device signals. Measurement still uses email, phone, and “this device logged into this account.” Locking down the browser while every app has full permission closes one door and leaves the hallway open.
## Login graphs: the account is the tracker
A login graph maps accounts, devices, and sessions to one person or household. Google has one because Gmail, YouTube, Android, and Chrome can share an account. Apple, Meta, and Microsoft have theirs. Retailers with their own SSO have smaller ones.
Once you are logged in, the company does not need a fingerprint to know a new laptop is you. Even “signed-out” surfaces can be tied back when you later sign in. People skip this when they change browsers and keep the same always-on phone account. The account is a stronger graph than a cookie.
## Fingerprinting: when the browser describes itself too well
Fingerprinting uses attributes that are not a stored ID: screen size, fonts, canvas or WebGL output, audio stack, time zone, language, installed codecs, how the GPU draws a hidden scene. Individually, each signal is weak. Together they can be rare enough to recognize a browser over time.
Some browsers randomize or block the noisiest APIs. A fingerprint is also brittle; updates change it. Serious ad companies treat it as a hint, then bind it to a login or email when they can. In 2026 it is not a superweapon and it is not gone.
## Privacy Sandbox and Topics-style replacements
Google spent years pitching Privacy Sandbox as the way Chrome could drop third-party cookies without starving ads. Topics grouped recent browsing into coarse interest labels. Protected Audience tried on-device auctions. Attribution Reporting tried to measure conversions without a full cross-site ID.
Adoption stayed low. In 2025 Google said it would retire most of those ad APIs. Through 2026, Topics and several siblings have been in deprecation and removal. CHIPS, FedCM, and Private State Tokens remain more relevant as plumbing than as a new ad ID.
The honest 2026 sentence is not “Sandbox replaced cookies.” It is “cookies were never fully removed in Chrome, and the replacement program mostly wound down.” Tracking moved to first-party IDs, pixels, lists, and accounts. Leftover Topics calls are history flushing through the pipes.
## Data brokers and the market behind the page
A data broker sells information about people: addresses, inferred income, “in-market” labels, app installs, location traces, and joinable IDs. Some of it starts as public records. A lot starts as a form, a warranty card, an app permission, a voter file, or a partner feed.
Brokers sit underneath ads and “know your customer” tools. A site you never heard of can buy a segment that includes you. Some U.S. state laws let you demand deletion or a stop to sale, with varying teeth. European rules are stricter on paper and uneven in practice. A single browser setting does not empty that market. Use the rights you have. Treat unsolicited people-search sites as hostile until proven otherwise.
## What this looks like in a normal day
You unlock a phone already signed into an account. Apps send analytics. A news site in Chrome loads a first-party cookie, a consent manager, and pixels. A logged-in search for a medical symptom can sit on the account. Later you buy shoes while logged in; the retailer hashes your email for an ad platform. A social app shows the same shoes. No third-party cookie had to survive the day. The email and the login graph were enough. That is ordinary, not a spy novel.
## Practical steps that still matter
Start with accounts. Sign out of big identity providers when you do not need them. Use separate browser profiles for the logged-in life and the wandering life.
Use a browser that defaults to less sharing—Firefox, Brave, or Safari—and a maintained blocker such as uBlock Origin. On the phone, deny tracking prompts you do not mean, reset advertising IDs, and delete apps you do not open.
Treat email as an identifier. Aliases help. A password manager stops one breach from unlocking the graph.
A VPN hides your IP from sites and from your ISP. It does not hide you after you log in, and it does not stop a pixel that already has your cookie. Use one for a network problem. Do not use one as a personality.
For search, use an engine built not to turn queries into ad profiles. That is the job Oernoe Search is designed for. We do not claim a bigger index than Google, and we do not claim Search quiets the rest of the internet.
Be precise about Oernoe. Search is built not to build ad profiles from your queries. The marketing site at www.oernoe.com may show ads. For the rules, read [/legal/privacy](https://www.oernoe.com/legal/privacy) and [/legal/cookies](https://www.oernoe.com/legal/cookies). A blog post is not a contract.
## What “reduced” tracking is, and what it is not
Third-party cookies are weaker in 2026 than in 2018, especially outside Chrome. That is real progress. It is not privacy.
The industry replaced a convenient cross-site cookie with first-party IDs, uploaded lists, login graphs, mobile identifiers, and leftover measurement APIs. Some replacements leak less. Some are just harder to see. Brokers and fingerprinting still exist. A consent banner designed to exhaust you is not informed consent.
You can still make the pile smaller: different tools, medical queries kept out of an ad account, a different email at checkout. None of that requires believing a press release. The companion pieces in this journal cover tools and how to compare search engines. Then use the settings. A map is only useful if you walk it.
O
Oernoe Editorial Team
Technology experts committed to building privacy-first solutions and helping users understand how digital services work. Passionate about creating transparent, ethical platforms.
Get in touchRelated Articles
Want to Learn More?
Explore our complete guides and knowledge base for more insights on privacy, technology, and best practices.
Browse Our Guides