Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does PostHog Work in China? PIPL Cross-Border, Automated Decisions & Data Residency

PostHog's SDK is reachable from China, but the behavioral events, session recordings, and person properties you send it are evaluated and stored on PostHog Cloud in the US or EU, never mainland China — making it a PIPL cross-border transfer and an Article 24 automated decision about what each user sees. A compliance-first look at the lawful in-country path.

Does PostHog work in China?

PostHog's SDK is reachable from China, but the behavioral events, session recordings, person properties, and feature-flag context you send it are evaluated and stored on PostHog Cloud in the US or EU — so every China user is both a cross-border transfer of their personal information and an Article 24 automated decision about what they see, not a speed question.

PostHog is a product-analytics platform — analytics, session replay, feature flags, and experiments — and by default it runs on PostHog Cloud, whose only regions are the US and the EU (Frankfurt), with none in mainland China. You hand it your users' events, recordings, and the targeting context behind each flag and experiment; that makes you the handler of a PIPL cross-border transfer (Articles 38–40) and of an Article 24 automated decision that picks each user's experience from their profile — with consent (Articles 13/23) and, for a CIIO or high-volume handler, in-country storage duties on top. The lawful lever is to keep the flag-evaluation and user data in-country — PostHog is open-source and self-hostable, or route China users through a licensed domestic alternative, with minimized context and the Article 24 opt-out — not to make the offshore SDK reachable.

This is a risk map, not a verdict — settle the specifics with counsel. Our China team can map your exposure →

What PostHog's own documentation says about China

FactPrimary source
PostHog is open-source and self-hostable, but self-hosted deployments are now officially unsupported. PostHog's self-host docs state “PostHog is open-source and freely available for anyone to host themselves” and describe a Docker Compose deployment under an MIT license, while also noting self-hosted deployments are “officially unsupported,” with “no customer support for product, infrastructure, or other questions for self-hosted instances.” PostHog steers teams to PostHog Cloud. PostHog — Self-host docs (posthog.com), retrieved 2026-10-10
PostHog Cloud hosts data only in the US or the EU (Frankfurt) — there is no mainland-China region. PostHog's GDPR docs recommend “PostHog Cloud EU – a managed version of PostHog that's hosted on servers based in Frankfurt” and note “you can use PostHog Cloud US”; they also state “Names and email addresses are obviously personal data” and “IP addresses can be considered personal data under GDPR,” and session replay takes a full DOM snapshot where “General text is not masked by default.” PostHog — GDPR & session replay privacy docs (posthog.com), retrieved 2026-10-10
Sending a China user's events and targeting context offshore is a PIPL cross-border transfer — and the flag or experiment decision is automated decision-making. Uploading their behavioral data and attributes to US or EU servers triggers PIPL Articles 38–40 on you, the handler (notice, a separate consent, a transfer mechanism), while a flag, experiment, or personalized experience is an Article 24 automated decision and profiling that must stay transparent, be refusable, and offer a non-profiled option. PIPL Articles 38–40 and Article 24 (21YunBox cross-border explainer), retrieved 2026-10-10
A CIIO or high-volume handler owes an in-country storage duty an offshore profile store cannot meet. The Cybersecurity Law Article 39 (formerly Article 37) requires personal information collected in China to be stored in China; the 2025 amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, with its substance unchanged. China Cybersecurity Law Article 39 (formerly 37), retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a product that runs PostHog for users in mainland China, the first question is usually whether its SDK and ingestion endpoints can be reached — and largely they can. But reachability is not where the China decision is made. What decides it is what happens to the user context and behavior you hand PostHog: the autocaptured events, the session recordings, the person properties, and the targeting context you send to evaluate a feature flag or an experiment. PostHog is a product-analytics platform — product analytics, session replay, feature flags, and experiments — and by default it runs on PostHog Cloud, hosted in the United States or the EU (Frankfurt), with no mainland-China region. That puts three distinct questions on the table: a cross-border transfer of your China users’ personal information, an automated decision about what each of them sees, and the consent and residency duties that follow.

PostHog's self-host documentation stating that PostHog is open-source and freely available for anyone to host themselves, that it offers a Docker Compose deployment under an MIT license, and that self-hosted deployments are officially unsupported
PostHog's own self-host documentation states: “PostHog is open-source and freely available for anyone to host themselves.” The same page describes a Docker Compose deployment under an MIT license, while noting self-hosted deployments are “officially unsupported” and steering teams to PostHog Cloud — whose only regions are the US and the EU (Frankfurt), with none in mainland China. Source: posthog.com — Self-host docs

PostHog in China at a glance

What decides it In PostHog's own terms — and China's law
What you send it Autocaptured behavioral events, session recordings (PostHog takes a full snapshot of the page's DOM, and its docs note “General text is not masked by default”), person properties, and the targeting context — distinct ID, properties, cohort — you send to evaluate a flag or experiment. PostHog's own docs state “Names and email addresses are obviously personal data” and “IP addresses can be considered personal data under GDPR.” Once the user is a person in mainland China, all of it is personal information.
Where it goes Offshore. By default PostHog runs on PostHog Cloud, which PostHog hosts in the United States or the EU — “a managed version of PostHog that's hosted on servers based in Frankfurt.” Those two are the only regions PostHog operates; there is no mainland-China region. Events, recordings, and person profiles accumulate there into a persistent offshore store.
It decides what each user sees A feature flag, an experiment variant, or a personalized experience is chosen for each user from their properties or cohort — automated decision-making and profiling under PIPL Article 24, which requires transparency and fairness, a way for the individual to refuse, and, where a decision is based on profiling, an option not to be targeted by personal characteristics.
Consent, residency & the profile store Session replay and non-essential event capture need a lawful basis and consent (PIPL Articles 13/23) — a buried “by using this product” is not enough. A critical information infrastructure operator or high-volume handler also owes an in-country storage duty (Cybersecurity Law Article 39, formerly Article 37) that a growing offshore person-profile store cannot satisfy.
The lawful path Reachability is not the axis. Keep flag-evaluation and user data on an in-country path — self-host the open-source engine in China where you have the operations capability, or route China users through a licensed in-country alternative — minimize and pseudonymize the context you send, honor the Article 24 opt-out, and deliver the app itself in-country on ICP-filed infrastructure. 21YunBox maps, localizes, and delivers; licensing and legal conclusions sit with your counsel.

What you actually send — your users’ attributes and behavior

PostHog is not a page to render; it is an instrumentation layer that watches what your users do. Its SDKs autocapture behavioral events — pageviews, clicks, form interactions — and, with session replay enabled, take a full snapshot of the page’s DOM and record what changes thereafter. PostHog’s own privacy documentation is candid that “General text is not masked by default”; input fields are masked (“we mask these by default”), but a recording can still carry a great deal about a person. On top of the events, PostHog builds person profiles keyed to a distinct ID and enriched with person properties — and its GDPR docs say outright that “Names and email addresses are obviously personal data” and that “IP addresses can be considered personal data under GDPR.” For feature flags and experiments, your app sends the user’s targeting context — the distinct ID, person properties, and cohort membership — so PostHog can decide which flag value or experiment variant that user receives; the resulting exposure and experiment events stream back and are stored.

Where does all of it land? By default, on PostHog Cloud. PostHog’s GDPR guidance recommends “PostHog Cloud EU – a managed version of PostHog that’s hosted on servers based in Frankfurt,” and notes “you can use PostHog Cloud US” — those are the only two regions PostHog operates, and neither is in mainland China. So whether you pick US or EU, your China users’ events, recordings, and profiles rest offshore and keep accumulating. (Server-side SDKs can evaluate some flags locally by first downloading the flag definitions, but the person context and the analytics and exposure events are still sent to PostHog — local evaluation trims round-trips, not the data that reaches the vendor.)

It’s a cross-border transfer — and an automated decision — under PIPL

Two of China’s rules bite at once here, and most teams only see one. First, the cross-border transfer. The moment a person in mainland China is recorded, identified, or evaluated, you upload their behavioral data and attributes to PostHog’s US or EU infrastructure. Under the Personal Information Protection Law that is a cross-border transfer of personal information (数据出境), and the duty is on you, the handler — not on PostHog. Articles 38–40 require notice, a separate consent distinct from any general terms, and one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification. Above the regulatory thresholds, or where the data qualifies as “important data,” the data-export security assessment (数据出境安全评估) may apply before anything leaves.

Second — and this is the prong unique to flags, experiments, and personalization — Article 24 governs automated decision-making. A feature flag that turns a capability on for one cohort and off for another, an experiment that assigns a variant, or a personalized experience driven by a person’s profile is a decision made automatically about what that individual sees, based on their characteristics. Article 24 requires that such decisioning be transparent and fair, that the individual can refuse it, and that where a decision or push is based on profiling, the individual is offered an option not to be targeted by their personal characteristics. Running an experiment on a China segment, or personalizing from a PostHog profile, is profiling under Article 24. Stacked on both is consent: session replay and non-essential analytics need a lawful basis and the user’s consent under Articles 13 and 23. And a growing offshore store of person profiles raises a residency question — the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization article was renumbered by the 2025 amendment, in force since January 1, 2026, with its substance unchanged) requires personal information collected in China to be stored in China for a critical information infrastructure operator or high-volume handler. None of this turns on how fast the SDK answers; it turns on whether the data had a lawful basis to leave the country.

Reaching the SDK isn’t the question — keeping the decisioning in-country is

So “can we reach PostHog from China?” is the wrong test. The productive question is how to keep your China users’ data, and the decisions made from it, on a lawful, in-country footing — and PostHog gives you an unusually strong lever, because it is genuinely open-source. Its own documentation states “PostHog is open-source and freely available for anyone to host themselves,” with a Docker Compose deployment under an MIT license. That means the flag-evaluation and the event and profile store can, in principle, run inside China rather than offshore. Be clear-eyed about the current posture, though: PostHog now steers teams to PostHog Cloud and says self-hosted deployments are “officially unsupported,” with “no customer support for product, infrastructure, or other questions for self-hosted instances.” An in-country self-hosted deployment is therefore an operations commitment, not a checkbox.

The lawful path is to keep the decisioning and the user data on an in-country path — self-host the open-source engine in China where you have the capability to run and maintain it, or route China users through a licensed in-country experimentation and analytics alternative — while minimizing and pseudonymizing the targeting context you send (evaluate with the least identifying context, ideally no raw identifiers), obtaining the Article 13/23 consent, and honoring the Article 24 right to refuse profiling. What this is not is a tunnel that ships the same data offshore anyway; that keeps the SDK responsive and leaves every PIPL duty exactly where it was. This is a risk map, not a verdict: whether a transfer mechanism, in-country storage, or a reworked consent and opt-out flow applies to your deployment depends on what context and events you actually send, how much, and to whom — settle the specifics with counsel before you build.

The lawful path — map, localize, deliver

There is a lawful way to run product analytics, flags, and experiments for a China-facing product, and it has a shape. First, map: our China team inventories what you send PostHog — which events and recordings, which person properties, and the targeting context behind each flag and experiment — where it is evaluated and stored, how it is used to decide what each user sees, whether it is building a persistent offshore profile store, and on what consent basis. We frame the technical picture; you settle the legal conclusions with counsel.

Then localize: keep China-user flag-evaluation and data on an in-country path. Because PostHog is open-source, that can mean self-hosting the engine inside China where you have the operations capability to run and maintain it, or routing China users through a licensed in-country analytics and experimentation alternative — in either case minimizing and pseudonymizing the context you send, and honoring the Article 24 right to a non-profiled option. Localizing means keeping the decisioning and the user data on an in-country path — never a tunnel that ships the data offshore anyway. Where a license bears on the domestic alternative, that sits with a licensed domestic operator and your counsel; 21YunBox is advisory there.

Then deliver: the China-facing app that loads the PostHog SDK, runs the flags, and consumes the decisions is itself a public-facing service in the mainland, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery — the 21YunBox Optimizer, in front of the stack you already run, with no rebuild and no re-platform. The result is a product-analytics and experimentation setup that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind. We are a compliant overlay and partner — not a competitor to PostHog.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is PostHog blocked in China?
No — PostHog's SDK and ingestion endpoints are generally reachable from the mainland, so reachability is not the issue. The compliance question is that your China users' events, session recordings, person properties, and feature-flag context are sent to and stored on PostHog Cloud in the US or EU, which makes each user both a cross-border transfer of personal information under PIPL and an Article 24 automated decision about what they see. Treat the specifics as a risk to confirm with counsel.
Can I self-host PostHog in China to keep the data in-country?
In principle, yes — PostHog is open-source and self-hostable (“PostHog is open-source and freely available for anyone to host themselves”), so the flag-evaluation and the event and profile store can run inside China rather than offshore. Be realistic about the current posture, though: PostHog now steers teams to PostHog Cloud and says self-hosted deployments are “officially unsupported,” so an in-country deployment is an operations commitment. The alternative is a licensed in-country analytics and experimentation path. 21YunBox helps you map the exposure and stand up the in-country option.
Why is a feature flag or experiment a compliance issue and not just analytics?
Because it decides what each user sees. A flag that enables a capability for one cohort, an experiment that assigns a variant, or a profile-driven personalization is automated decision-making under PIPL Article 24 — which requires transparency, a way to refuse, and, where the decision is based on profiling, an option not to be targeted by personal characteristics. Running that on China users from their attributes is profiling, on top of the cross-border transfer of the data itself.

ARTICLES RELATED TO POSTHOG

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.