# PostHog

> Records what people do inside an application, releases individual features to selected groups and works out whether the change had an effect, so the decision about the next step rests on measured numbers instead of the loudest opinion in the room.

- Vendor: PostHog, Inc., San Francisco, California, with the subsidiary PostHog GmbH (limited company), Munich
- Canonical URL: https://www.convios.com/en/toolbox/posthog
- Language version: https://www.convios.com/de/werkzeugkasten/posthog
- Area: Product & engineering · Cluster: product analytics and feature flags
- Role: Off-the-shelf product · Origin: Established, AI retrofitted
- As of: 2026-08-19 · Reviewed: 2026-08-19 · Author: Dr. Oliver Gausmann, Convios GmbH
- Toolbox: https://www.convios.com/en/toolbox — Markdown: https://www.convios.com/en/toolbox.md

## Verdict

Strengthens the core product: Nobody buys product analytics for its own sake. It gets bought because the question of which feature actually gets used is otherwise settled at the table. The tool itself stays interchangeable, since Amplitude, Mixpanel and Statsig answer the same question. What lands in the core product is the wiring. A flag that releases a feature to five per cent of users sits in shipped code and helps decide what a customer gets to see. The ability to roll changes out in doses and pull them back grows into the product and stays there after a change of vendor. No edge comes out of it, because competitors get the same interface for the same money. The ability to let the numbers overrule your own favourite idea is not for sale in any case.

## Suitability by company size

- Solo: suitable — The free allowance carries the purpose in full and asks for no card. On 19 August 2026 the vendor puts it at one million events, 5,000 session recordings, one million flag requests and 100,000 captured exceptions a month. Anyone working alone rarely exceeds that. The limit that bites first is retention: the free plan holds one year, so the year-on-year comparison is already missing in the second year of operation.
- Mid-market: suitable — This is where the use case sits. No minimum commitment, no annual contract, six projects and seven years of retention as soon as a card is on file. Ten million events a month cost around 324 US dollars under the published tiers. The calculation is decided elsewhere all the same: SAML sign-in starts at 750 US dollars a month, the activity log at 250 US dollars a month with seven days of retention. A thirty-person firm pays three figures for the analysis and four figures for auditability.
- Enterprise: suitable with caveats — The functionality holds up; procurement trips over three points. Role-based access control together with user provisioning via SCIM exists only in the Enterprise package by quote, SAML sign-in from Scale upwards, and the activity log holds seven days on Boost, which is shorter than any audit cycle. On top comes a decision taken before all others: the region is chosen at sign-up, and moving later from the US to the EU region requires the Scale package and is carried out by a vendor engineer. Anyone inheriting a developer team's setup inherits the place of processing with it.

## Vendor staying power

Funded: Six years in market, a dated round of 70 million US dollars on 9 June 2025 and a German subsidiary with its own register entry. The legal documents are maintained: sub-processor list dated 12 June 2026, terms of service and privacy notice both dated 29 June 2026. The handling of its own security incident in June 2026 is publicly documented. The figures on the number of teams and on earnings are the company's own.

- Legal entity and registered office: PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, United States (source: https://posthog.com/privacy, as of 2026-06-29)
- German subsidiary in the commercial register: PostHog GmbH (limited company), Amtsgericht (local court) München HRB 306893, Oskar-von-Miller-Ring 20, 80333 Munich, managing director James Hawkins; seat moved to Munich on 6 November 2025, previously Amtsgericht Charlottenburg HRB 273221 B (source: https://www.northdata.de/PostHog+GmbH, as of 2026-08-19)
- Founding: founded in 2020, batch W20 of the investor Y Combinator; by the company's own count 190,254 teams use the products (source: https://posthog.com/about, as of 2026-08-19)
- Last reported equity round: 70 million US dollars Series D led by Stripe, with Y Combinator, GV and Formus Capital, announced on 9 June 2025; the valuation of 920 million US dollars is the company's own figure (source: https://posthog.com/blog/series-d, as of 2025-06-09)
- Maintenance state of the legal documents: sub-processor list dated 12 June 2026, terms of service and privacy notice both dated 29 June 2026 (source: https://posthog.com/subprocessors, as of 2026-06-12)
- Documented incident and how it was handled: Security advisory PSA-2026-00001 of 2 June 2026, severity critical, resolved: security researchers exploited CVE-2026-7899 in an outdated Chromium build that ran without a sandbox to generate heatmaps, and read credentials from the environment variables of a Kubernetes pod. The company's own investigation via AWS CloudTrail and Wiz, together with the researchers' confirmation, found no customer data was accessed; the credentials were rotated. (source: https://posthog.com/handbook/company/security-advisories, as of 2026-06-02)

## Cost of leaving

Moderate: The events come out. Batch exports write the raw stream to S3, BigQuery, Snowflake, Databricks, Redshift, Postgres and Azure Blob Storage, and past periods can be backfilled. What the export leaves behind is everything that gives the numbers meaning: the funnel definitions, the cohorts, the insights, the maths behind an experiment and the session recordings. The expensive part sits in your own source code in any case. Every call that captures an event lives there, and every flag is evaluated at a point that steers a release. Anyone who only analyses moves in a few days. Anyone carrying flags deep in the product replaces call sites while it runs, and a wrongly evaluated condition is then a production incident rather than a gap in a report.

## Regulation and data

| Point | Finding | Evidence | As of |
|---|---|---|---|
| Data processing agreement | publicly readable in full, binding only once generated inside the account — The contract text sits on the page without any login. The same page records that this version does not bind on its own and that only the copy generated and countersigned inside the account counts. The step is self-service and free of charge; a free account is enough. For the file it remains a condition all the same: without it there is no agreement, even once the text has been read. PostHog, Inc. acts as processor within it, countersigned by the VP Operations. One peculiarity shows up when forwarding it to a legal department: the page offers the agreement in several joke versions, the one meant for lawyers is one choice among them, and the vendor itself advises against sending the others. | partially evidenced | 2026-08-19 |
| Storage location | EU in Frankfurt or US in Virginia, chosen once at sign-up — Both regions are available on every plan including the free one, at no extra cost. The choice is made at sign-up and becomes a one-way street after that: moving a project from the US to the EU region requires the Scale or Enterprise package, because a vendor engineer carries out the move. A developer team starting quickly therefore settles the place of processing before anybody from data protection is asked, and the correction costs from 750 US dollars a month. Two limits on the EU choice sit in the sub-processor list: Cloudflare routes traffic through worldwide edge locations whose position the operator determines, and the AI features run with providers in the United States regardless of the region chosen. | partially evidenced | 2026-08-19 |
| Subprocessors | complete public list with purpose and location, spread over three tables — The list in its version of 12 June 2026 names every recipient with purpose and place of processing. For the core there are five: Amazon Web Services as sole data centre operator, with Germany for the EU region, plus Wiz for vulnerability detection, PlanetScale for database monitoring, Modal Labs for isolated code execution and Cloudflare for delivery. Two further tables sit behind tabs and load only after a click, which is easy to miss during a review. The second lists the processors behind the AI features, the third the group's own: Hiberly Ltd. in the United Kingdom and PostHog GmbH in Germany. The contract announces changes fourteen days in advance, an objection is possible within seven days and, in case of dispute, leads to a right to terminate the affected service. | evidenced | 2026-06-12 |
| Third-country transfer | EU-US Data Privacy Framework and standard contractual clauses, both anchored in the contract — Under clause 10.3 the data processing agreement confirms self-certification under the EU-US Data Privacy Framework together with the UK and Swiss extensions, and obliges the vendor to maintain it and to give notice without delay should it end. Independently of that, clause 10.4 treats the standard contractual clauses under Module 2 as incorporated in full, with Irish law and Irish courts for those clauses. Should either basis fall away, clause 10.9 expressly provides for moving to another one. Which of the named recipients operates on which of the two bases is not assigned individually in the public documents. | evidenced | 2026-08-19 |
| Training on customer data | customer content feeds the vendor's own models by default, an objection works only prospectively — Here it pays to lay two documents side by side, and the difference between them is the most valuable finding in this profile. Under clause 2.1.3 the data processing agreement records that the vendor permits no third party and no sub-processor to use customer data to fine-tune or develop models. Anyone reading only that leaves the meeting reassured. Under clause 5.1 the terms of service grant the vendor itself a worldwide, royalty-free licence to use customer content for the development, testing and training of its own models. That is the default. An objection is possible through the settings inside the product and works only for the future; for models already trained there is expressly no duty to retrain or delete. The commitment given is to aggregate or de-identify the content beforehand. The reassurance sits in the agreement about processing, the licence in the agreement about the service. | partially evidenced | 2026-06-29 |
| Retention and deletion | no period after the end of the contract quantified — Clause 9.1 of the data processing agreement undertakes to return customer data at the end of the services on request, to provide self-service functionality for doing so, or to delete it. No period is stated there, and exceptions for legal duties, ongoing disputes and combating abuse are expressly reserved. The privacy notice stays with the formula that data is kept as long as the purposes require and refers to an enquiry for anything more precise. Two figures are given elsewhere: after an account is deleted the data stored about it is removed within thirty days, and live retention in the product runs to one year on the free plan and seven years on the paid one. Anyone needing a post-termination period for the file negotiates it into the main contract. | partially evidenced | 2026-08-19 |
| Certifications | SOC 2 Type 2, report via the trust portal after access is granted — One recognised attestation for the vendor itself, externally audited, with a named period: the reporting period runs from 1 June to 31 May each year, and the most recent report covers controls as of 31 May 2026. The trust portal names no further standards; ISO 27001 and ISO/IEC 42001 do not appear there on 19 August 2026. Alongside the SOC 2 report sits a penetration test report. The documentation calls the report publicly available while the portal itself requires access to be granted for both reports; those two statements do not match. For a first pass in procurement the naming is enough; for the file the route runs through the portal. | partially evidenced | 2026-08-19 |
| EU AI Act, Article 50 | no statement on the regulation, although AI generates answers inside the product — The vendor runs an AI assistant for queries, an analysis product for applications built on language models, and image analysis of session recordings. The terms of service and privacy notice of 29 June 2026 regulate training on customer content at length; neither says anything about Regulation (EU) 2024/1689 or its amending Regulation (EU) 2026/1744, and there is no page dedicated to it. The transparency duties under Article 50 have applied since August 2026. Here they fall first on the operator, because the AI faces the customer's own team rather than end customers, so the labelling can be set without any action by the vendor. Anyone carrying wording from the assistant into customer communication leaves that frame and bears the classification alone. | partially evidenced | 2026-06-29 |
| Audit logging | activity log from the Boost package upwards, holding seven days there — What is recorded: invitations, role changes, changes to sign-in, SAML and SCIM, the management of projects and keys, and every change to flags, experiments and insights, each with person, timestamp and the value before and after. The log hangs off the platform packages: seven days on Boost for 250 US dollars a month, two months on Scale for 750 US dollars, sixty months on Enterprise by quote. Export runs as CSV or Excel and continuously into a security analysis system; the manual export is available only in the project view and is not provided for the whole organisation. Once the period expires the entries are permanently removed, per the vendor. Seven days is shorter than any audit cycle demanding evidence, which is what turns the export into a condition of purchase here. | partially evidenced | 2026-08-19 |

## Cost

- Entry: Free and without a card, with a monthly free allowance the vendor puts at one million events, 5,000 session recordings, one million flag requests and 100,000 exceptions on 19 August 2026. Above that a usage price per event applies which falls with volume: 0.00005 US dollars between one and two million, 0.0000343 up to fifteen million, 0.000009 above 250 million. Ten million events a month cost around 324 US dollars under those tiers. (as of 2026-08-19)
- Where it gets expensive: The platform packages, not the volume. SAML sign-in starts at Scale with 750 US dollars a month, role-based access control together with user provisioning via SCIM arrives only at Enterprise by quote, and the activity log requires Boost at 250 US dollars a month. Every security questionnaire asks about those three points, and all of them sit outside the usage price. The second expensive point is the change of region: moving a project from the US to the EU region requires Scale and therefore costs more than the analysis itself. One minute of thought at sign-up saves 9,000 US dollars a year.

## Three routes compared

### Amplitude, the vendor with the frame agreement

Amplitude and Mixpanel answer the same question and already sit in many companies' frame agreements. Corporates stay with them because the contract there includes what sits in packages here: roles and permissions, sign-in through the company directory service, a log with usable retention, a named contact with a committed response time. On top comes an argument that has nothing to do with the product and counts in procurement all the same: with a listed company, the viability check rests on public figures rather than on a press release. This is paid for with an annual contract, a minimum commitment and an entry price you cannot learn without a conversation. The difference shows most clearly for a small team: there, one side starts at zero and the other at a signature.

### The tools for language models, when the product is one

Anyone building a product on language models finds the young class where this tool has only recently joined in. Braintrust and Langfuse from this catalogue measure calls, cost and answer quality and score evaluations against fixed test sets, with the scoring itself coming from a model again. The price difference is quantified: on 19 August 2026 Braintrust names a free tier with fourteen days of retention and 249 US dollars a month for the next one, while Langfuse is open source and runs self-hosted. What has to be given up is the other half, meaning funnels, cohorts, flags and experiments across the whole product. Two tools side by side end up costing more than one that does both, and they force the same user identifier to be maintained in two systems.

### A collector at the edge, Postgres behind it

Small technically, difficult economically. A collector as a worker on Cloudflare Pages from this catalogue takes the events, Supabase holds them in Postgres, n8n distributes them onwards, and the analyses are built with Claude Code or Cursor in a few days. Reckoned at a 1,200 euro day rate and ten person-days that comes to roughly 12,000 euros once, plus a low three-figure amount a year to run it. Against that stand 324 US dollars a month at ten million events, and below one million events the vendor costs nothing. Building it yourself breaks at three points. Postgres no longer carries funnel and cohort queries across tens of millions of events; from there on a column store is needed and somebody to operate it. Nobody rebuilds session recording, because it drags in capturing screen content along with masking input fields. And the erasure duty under Article 17 demands a chain that removes a person across every table and backup, which is the longest piece of work in a self-build and a button in a finished product. Anyone who only wants to count page views is still better off building it and skipping the tool entirely.

Recommendation by size:

- Solo: Take it: the free allowance carries the purpose without a card.
- Mid-market: Buy it, but settle the region before the first event.
- Enterprise: Settle the package and the region first, then talk about events.

## Context

- Implements method: [Activation as the Retention Lever](https://www.convios.com/en/methods/activation-as-retention-lever) — Activation and retention can only be asserted for as long as nobody measures them, and this tool is the usual place where the assertion turns into a curve.
- Implements method: [Funnel Math Instead of Close Rate](https://www.convios.com/en/methods/funnel-math) — The maths behind a funnel decides which step is worth any work at all, and it needs an event trail laid down before the analysis starts.
- Implements method: [Growth Loops Instead of Funnels (PLG)](https://www.convios.com/en/methods/growth-loops) — A growth loop is built and measured through flags and experiments, which makes the choice of tool here at once the choice of release mechanism.
- Implements method: [Regulatory Density Test](https://www.convios.com/en/methods/regulatory-density-test) — The density of evidence duties decides whether the log, the role model and the EU region are add-ons or conditions of purchase, and that is exactly what the jump to the next package hangs on here.
- Alternative: Plausible Analytics
- Alternative: [Langfuse](https://www.convios.com/en/toolbox/langfuse)
- Alternative: Supabase
- Displaces: The weekly report from a spreadsheet that somebody pulls together by hand once a month, The switch for a new feature as a hard-wired condition in the source code, The question of why users drop off, guessed in the team without any recording at all

## Evidence

- Legal entity, registered office and the vendor's role as controller for the website and self-managed installations, plus the retention formula and the clause on using customer content for development and training — https://posthog.com/privacy (as of 2026-06-29)
- Clause 5.1 of the terms of service: worldwide, royalty-free licence to use customer content for the development, testing and training of the vendor's own models, with an objection possible and effective only prospectively — https://posthog.com/terms (as of 2026-06-29)
- Processing by PostHog, Inc., the prohibition on third parties and sub-processors using customer data for models, standard contractual clauses under Module 2 with Irish law, self-certification under the EU-US Data Privacy Framework, return or deletion at the end of the services without a period, and the note that only the copy generated inside the account is binding — https://posthog.com/dpa (as of 2026-08-19)
- Sub-processors with purpose and place of processing across three tables: Amazon Web Services with Germany for the EU region, Wiz, PlanetScale, Modal Labs and Cloudflare for the core; OpenAI, Google, Anthropic, Microsoft and Cloudflare for the AI features; Hiberly Ltd. and PostHog GmbH as the group's own — https://posthog.com/subprocessors (as of 2026-06-12)
- Free allowance per product, usage tiers per event, one year of retention on the free plan and seven years on the paid one, sign-in via Google, GitHub and GitLab on every plan — https://posthog.com/pricing (as of 2026-08-19)
- Platform packages Boost at 250 US dollars and Scale at 750 US dollars a month, Enterprise by quote, with the assignment of SAML, role-based access control, SCIM and the activity log retention periods of seven days, two months and sixty months — https://posthog.com/platform-packages (as of 2026-08-19)
- Scope of the activity log, permanent removal once the retention period expires, and the restriction of manual export to the project view — https://posthog.com/docs/settings/activity-logs (as of 2026-08-19)
- Moving between regions only with the Scale or Enterprise package and carried out by a vendor engineer, while moving within a region is self-service on every plan — https://posthog.com/docs/settings/projects (as of 2026-08-19)
- The vendor's recommendation of the EU region in Frankfurt where the General Data Protection Regulation applies, tools for transforming data before storage, and removal of account data within thirty days of deletion — https://posthog.com/docs/privacy/data-storage (as of 2026-08-19)
- SOC 2 Type 2 following an external audit, reporting period from 1 June to 31 May, and the most recent report covering controls as of 31 May 2026 — https://posthog.com/docs/privacy/soc2 (as of 2026-08-19)
- Destinations of the batch exports and the option to backfill past periods — https://posthog.com/docs/cdp/batch-exports (as of 2026-08-19)
- Self-hosting via Docker Compose under an MIT licence without support and without the paid features, with the vendor recommending the managed version above 300,000 events a month — https://posthog.com/docs/self-host (as of 2026-08-19)
- Security advisory PSA-2026-00001 of 2 June 2026 with the sequence of events, the scope and the result of the company's own investigation — https://posthog.com/handbook/company/security-advisories (as of 2026-06-02)
- The round of 70 million US dollars led by Stripe with Y Combinator, GV and Formus Capital, and the valuation by the company's own account — https://posthog.com/blog/series-d (as of 2025-06-09)
- Founding year, batch at the investor Y Combinator and the number of teams by the company's own account — https://posthog.com/about (as of 2026-08-19)
- Register entry of the German subsidiary with register court, number, address, management and change of seat — https://www.northdata.de/PostHog+GmbH (as of 2026-08-19)
- Braintrust's pricing tiers on 19 August 2026 as the comparison benchmark for the AI-native class — https://www.braintrust.dev/pricing (as of 2026-08-19)
