Meta Pixel & Conversions API
Built to send user behavior and hashed identifiers to Meta for ad targeting. The Conversions API moves collection server-side, bypassing browser-based blocking; repeatedly implicated in receiving sensitive data.
verified 2026-06-08 · grade set per the published methodology
How the grade breaks down
How little it collects, and whether collection is purpose-bound.
Whether it respects GPC, consent state, and tracking-prevention signals.
Cookieless vs. persistent IDs, cross-site linkage, fingerprinting risk.
Where data lives and whether it is shared with third parties.
How verifiable and documented its real behavior is.
At a glance
The Meta Pixel transmits page views, events, and hashed user identifiers to Meta to power cross-site ad targeting and measurement, feeding Meta’s advertising graph. The Conversions API (CAPI) sends the same data from the server, which bypasses browser-level ad and tracker blocking and is harder to intercept client-side. The pixel has been repeatedly implicated in transmitting sensitive information (including from health and finance sites) when implemented without strict field controls. It requires consent and does not honor GPC by default. This is a technical description of how the tools operate.
Sources & basis for grade
Grades reflect documented behavior, vendor documentation, and ad.rip scans as of the date above. Each assessment is reproducible and vendors may request correction.
- Meta Pixel & Conversions API (CAPI) documentation
- Meta Advanced Matching (hashed PII) docs
- Public reporting on Meta Pixel sensitive-data transmission (2022-2023)