Open an Incognito window, visit a fingerprint test, and compare the result with your normal window. The hash is the same. The GPU is the same, the fonts are the same, the screen, the timezone and the IP are the same. Incognito changes what your browser remembers; it does not change what your browser is. Here is the exact line between the two, and what that means if you use private windows to keep accounts apart.
What Incognito actually does
Chrome's own description is precise: a private window does not save your browsing history, cookies and site data, or information entered in forms, and it drops the cookies and site data it collected when you close the last private window. Extensions are off unless you allow them. Downloads and bookmarks are kept.
That is a statement about storage. Inside the private window the site can still set cookies and use local storage; they just live in a temporary jar that is emptied at the end. During the session a site sees a fresh visitor with no history. After the session, the jar is gone. Nothing in that list touches the signals a fingerprint is built from.
What it leaves exactly the same
| Signal | In a normal window | In Incognito | Why |
|---|---|---|---|
| User-Agent and Client Hints | Chrome 152 on macOS | Chrome 152 on macOS | Same binary, same OS |
| Screen, cores, memory | 2560×1440, 10, 8 GB | Same | Same hardware |
| Canvas and WebGL | Hash A, Apple M2 | Hash A, Apple M2 | Same GPU, driver and renderer |
| Fonts | Your installed set | Same | Read from the OS |
| Timezone and language | Asia/Shanghai, zh-CN | Same | Read from the OS |
| IP and WebRTC | Your connection | Same | Same network path |
| Cookies and storage | Persistent | Temporary | The only difference |
Every row except the last is identical. The Lab will give you the same fingerprint identifier in both windows, because the identifier is built from the rows that do not change.
The part that does change, and why it does not help
Incognito is not invisible. Sites have spent years finding ways to tell that a window is private, because publishers with metered paywalls wanted to stop readers from resetting their free-article counter. The techniques change (an early one based on the file-system API was closed in Chrome 76, and others based on storage quotas followed), but the pattern is stable: private windows behave slightly differently from normal ones in ways scripts can measure.
So the one thing Incognito does change is a flag that says "this person opened a private window". Combined with an unchanged fingerprint and an unchanged IP, that is not a new identity. It is the same identity, now marked as trying to look like a new one.
A site that keeps a fingerprint-based record recognises the private window as the same browser the moment it loads. The empty cookie jar tells it only that you cleared, or never kept, its cookie.
A two-minute experiment
- Open the Lab in a normal window and note the fingerprint identifier and the Canvas hash.
- Open a private window and load the Lab again.
- Compare. The identifier, the Canvas and WebGL rows, the fonts and the network rows will match.
- Now clear cookies in the normal window and reload. The identifier still matches, because none of its inputs were cookies.
See your fingerprint with and without Incognito
Run the Lab in both windows. The rows that match are the ones a site uses to recognise you regardless of cookies.
So what does separate two identities?
Three things have to be different at the same time, and Incognito gives you one of them for the length of a session:
- Storage. Cookies, local storage, IndexedDB, cache and service workers. Incognito isolates these temporarily; a separate browser profile isolates them permanently.
- Fingerprint. User-Agent, Client Hints, screen, GPU, Canvas, fonts, timezone, language. Incognito changes none of them. A second identity needs a second, internally consistent set.
- Network. IP and WebRTC. Incognito changes neither. A second identity needs its own exit, with WebRTC agreeing with it.
Two accounts that share any of the three are linkable. Two accounts that share all three, with one of them in a private window, are the same account with a flag on it. The full checklist is in Browser profile isolation.
When Incognito is the right tool
It is a good tool for what it was built for: borrowing a computer, checking a price without personalisation, logging into a second account for five minutes on your own machine, or keeping a search out of your history. For those, the temporary jar is exactly what you want and the unchanged fingerprint does not matter.
It is the wrong tool for running accounts that must never be connected, for the simple reason above: every signal a risk system uses to connect them stays the same.
How Mango Browser handles this
Mango starts where Incognito stops. Every profile is a fully separate browser directory, so cookies, storage, cache and extensions never cross between profiles, and they persist between sessions instead of vanishing when you close a window. Each profile also carries its own fingerprint: a Canvas seed that is unique to the profile yet identical on every draw, a WebGL renderer from a pool of real GPUs for the profile's operating system, a font list from that OS, and User-Agent and Client Hints that describe one coherent browser.
Bind a proxy to the profile and the network story follows: the HTTP IP, the WebRTC candidate, the timezone and the language all describe the exit. Open the Lab inside two Mango profiles and you get two different identifiers, which is the result that Incognito can never give you.