When to stop tracking unsigned sessions
Unsigned traffic is catnip. It makes charts look populous. It is also where consent is thinnest, bots are densest, and stitching fantasies are born. Teams in GB have to take PECR and UK GDPR seriously; “we might identify them later” is not a storage policy.
A stop rule we use in class
Keep unsigned events for seven days if they help you debug onboarding copy. After that, aggregate or drop. If a session has not become a known account, it should not occupy a row next to paying customers in your identity table. Sample, do not hoard.
Exceptions exist: a marketing site with a documented lawful basis and a short retention, or a security log that is not mixed into product analytics. Mixing security logs into the same funnel you show the board is how you invent ghost users.
Cost is a moral issue too
Warehouse bills rise because nobody deleted curiosity. That money could have paid a researcher to watch ten known users complete the job. We would rather you stop the firehose. Feature Gating Ledger in the Loose leaf pack assumes you already made this cut.
If legal counsel in your company wants a different window, take theirs. Our seven-day classroom default is a starting argument, not a statute. Put the chosen window in the chart footnote so a new hire does not “fix” it back to forever.