Incognito, Separate Chrome Profiles, or an Antidetect Browser: Where Each One Breaks
A reseller I swapped messages with last month had it organised. Five Chrome profiles, colour-coded avatars, one per marketplace account. A sixth thing he did in incognito because it "didn't leave traces". Separate email on each, separate password, and he logged out before switching every single time. No antidetect browser anywhere in the stack — he'd read the comparisons and decided incognito plus separate Chrome profiles covered it.
Four of the five got actioned inside a week.
His first question was which profile leaked. Wrong question — none of them did. Chrome did exactly what Chrome promises. It kept five cookie jars apart, cleanly. The platform simply never needed the cookies, because all five profiles were answering fingerprinting scripts with the same canvas hash, the same GPU renderer string, the same font list and the same screen geometry. Five tidily separated accounts. One machine. The machine is what got read.
I gave him a worse answer than he deserved on the first pass. Told him to audit his extensions, because that's where I'd been burned before, and he spent an evening finding nothing. The extensions were spotless. The machine was the whole story and I'd walked straight past it.
So here's the comparison, properly, with the failure point of each one named.
The one-line version of each
Incognito throws away session state when you close it. That's the feature. Nothing else.
Separate Chrome profiles keep state permanently apart — cookies, logins, extensions, history — in separate folders on one computer.
An antidetect browser gives each profile its own identity: different canvas, WebGL, audio and font answers, different screen geometry, different timezone, its own proxy and its own resolver. Then it keeps that state apart too.
Notice the shape. The first two work on what the browser remembers. The third works on what the browser is. If you want the ground-up definition of that third category, what an antidetect browser actually is covers it from scratch. This post is about the boundaries between them.
Incognito: an honest feature with a dishonest reputation
Incognito gets more grief than it deserves, mostly because people expect it to be something it never claimed to be. Google's own splash screen is pretty blunt: your activity might still be visible to the sites you visit, your employer and your ISP.
What irritates me is the vendor content that props incognito up as a straw man, knocks it over in two paragraphs, and sells you the upgrade. It teaches nobody the mechanism. Incognito isn't lying to you — it's answering a question you didn't ask.
What it genuinely does: fresh, temporary cookie jar. No history entries. Everything binned when the last incognito window closes — and that last bit trips people constantly, because all your incognito windows share one session. Open three, log into three different accounts, and you've built exactly the thing you were trying to avoid.
What it doesn't do — anything at all about identity. Same binary, same GPU, same fonts, same screen, same IP. Run any fingerprint checker in a normal window, then in incognito, and compare the hashes. They match. (Do this once. It's thirty seconds and it settles the argument better than any blog post.)
The one legitimate use in multi-account work: a clean-state window for checking how a page looks to a logged-out visitor. Good for that. Useless for holding an account.
Separate Chrome profiles: real isolation, exactly one layer deep
This is the one that deserves more credit than it usually gets — and it's also the one that gives people false confidence, which is a worse combination than incognito's plain uselessness.
A Chrome profile is a genuinely separate user directory. Its own cookies, its own localStorage and IndexedDB, its own saved logins, its own extensions, its own bookmarks. Log into account A in one and account B in another and there's no shared storage handing over the link. Chrome even shipped partitioned cookies (CHIPS) back in version 114, so third-party cookie state is scoped to the top-level site that set it — worth understanding if you care about how state actually gets keyed, and we wrote that up in the partitioned storage and CookieStore breakdown.
Here's what no amount of profile separation touches.
Every profile on that install renders the same canvas. Reports the same WebGL vendor and renderer. Produces the same audio output. Lists the same installed fonts — the OS owns those, not the profile. Same screen width, height, colour depth and device pixel ratio. Same core count, same platform string, same language list. And unless you've gone out of your way, the same public IP.
Which means five Chrome profiles look like five accounts on one clearly identifiable computer. Not five people. That's not a subtle signal a clever detector has to dig for — it's the most obvious pattern in the dataset.
There's a second layer nobody thinks about, too. Your TLS handshake has a stable shape per browser build, offered before any JavaScript runs, and it's identical across every profile. ClickzProtect, our sibling product, works the detection side of this and its comparison of browser and TLS fingerprinting explains why the two are independent identifiers.
What actually gets compared
| Signal the site reads | Incognito | Separate Chrome profiles | Antidetect browser |
|---|---|---|---|
| Cookies, localStorage, IndexedDB | Temporary, shared across incognito windows | Separate per profile | Separate per profile |
| Browsing history on the device | Not written | Separate per profile | Separate per profile |
| Canvas, WebGL, audio output | Identical | Identical | Different per profile |
| Installed font list | Identical | Identical | Gated to the spoofed platform's set |
| Screen size, colour depth, DPR | Identical | Identical | Different per profile |
| Timezone reported by JavaScript | Identical | Identical | Set per profile |
navigator properties | Identical | Identical | Different per profile |
| Outbound IP | Identical | Identical | Per-profile proxy you supply |
| DNS resolver | Identical | Identical | Per-profile DNS-over-HTTPS |
| WebRTC address exposure | Same | Same | Protected |
Two rows handled in the middle column, eight not. That ratio is the entire argument for an antidetect browser.
Where the antidetect browser layer picks up
JustBrowser is a custom Chromium engine with the spoofing written in C++ and compiled into the core, patched with every upstream Chromium release. Not an extension, not a JavaScript shim layered on top.
That distinction matters more than it sounds. An injected script has to lie over a real answer, and the seam shows: the override is enumerable, the prototype chain reads wrong, the timing is measurably off. A patch in the engine has no real answer underneath it to contradict. Real C++ engine patches at the canvas / WebGL / audio / font / screen layer, across 40+ identity parameters.
Two specifics that get guessed at constantly, so here they are straight. navigator.webdriver returns false — not undefined, false — patched unconditionally whether or not automation flags are set. And the font list is restricted to the spoofed platform's set at the engine level, covering CSS enumeration, the Font Access API and @font-face local() together, rather than a filtered array a determined enumerator walks around.
On top of the identity work: per-profile proxy routing (HTTP, HTTPS, SOCKS5), per-profile DNS-over-HTTPS in secure or automatic mode pointed at Cloudflare, Google, Quad9 or a resolver you choose, WebRTC protection, real-time profile health scoring, and cookie warm-up across 127 curated sites in six categories for accounts that need to look lived-in rather than born this morning. The DNS half is its own failure mode and we covered it separately in the DNS leak and proxy resolution guide.
The checker results we publish, so you can reproduce them instead of believing us: CreepJS 0% stealth and 0% headless, Whoer 90–100%, IPHey Trust "Good", BrowserLeaks no WebRTC leak.
And for the developers who arrive here: there's a local REST API on 127.0.0.1:36542, Bearer-authenticated from the app's AI page, with CDP for Playwright, Puppeteer and Selenium. Local only — nothing hosted to call. Starting a profile through it gives you a headless session unless you send {"headless": false}. I lost twenty minutes to that, watching a script run flawlessly and invisibly while I checked everything except the request body.
Picking between them, without overbuying
Real talk, since an antidetect browser comparison normally gets written by someone selling the most expensive option.
One account per platform, want work and personal separate? Second Chrome profile. Free, fine, nobody's linking anything. Stop reading.
Checking how a page renders logged-out? Incognito. That's the job it's actually good at.
Two accounts on a platform that tolerates two accounts? Chrome profiles will probably hold. Probably. Understand that you're relying on nobody looking, not on the setup being sound.
Multiple accounts on a platform that links them, scraping that gets challenged, ad verification across geographies, or QA across device and locale combinations? That's the line. Everything below it is hygiene; everything above it is identity, and identity is a different tool.
If you're running an antidetect browser to keep two personal Gmail accounts apart, you've hired a forklift to carry the shopping. Nothing wrong with the forklift. Wrong job.
The mistake I see most often isn't buying an antidetect browser too early. It's four months of bolting workarounds onto Chrome profiles — single-signal spoofing extensions, a VPN, a second laptop — and ending up with a stack nobody can reason about.
Antidetect browser setup order, if you're crossing that line
- Sort the address first and test it alone. A flagged IP poisons everything downstream. The detection signals glossary names what gets checked.
- Create the profile, assign that address to it. One address, one profile. Don't share.
- Match timezone and language to the exit geography before the first page load. This step feels like paperwork and it's the one that catches people. It caught me twice, on the same proxy pool, three weeks apart.
- Turn on WebRTC protection and per-profile DNS-over-HTTPS.
- Warm the profile up first. An account created in minute one of a blank browsing history is a pattern too.
- Verify against the checkers, then leave it alone. Rotating a stable fingerprint is its own way to get flagged.
The honest limits
Windows x64 and macOS on Apple Silicon only. There's no Linux build, which means "run it on a VPS" isn't a path — and no iOS or Android app either, so mobile identities aren't a thing here.
Pricing is one plan: $9.99/month or $99.99/year, unlimited profiles, unlimited cloud sync, free team seats. No free tier. The 7-day trial is the only free path and it wants a card up front — which some people will find disqualifying, and I'd rather say that here than let you find it at checkout. Free seats carry a real constraint too: a seat runs profiles the owner shares with it and nothing else — no cloud sync of its own, no API, no AI tab. Anyone needing their own profiles subscribes.
If you stop paying, your profiles stay on your machine and keep launching. You can keep up to five local profiles; cloud sync, team sharing and the API pause until you resubscribe. Take an encrypted export anyway before a long break.
And plainly, since the industry rarely says it: none of this makes you invisible. It makes each profile a different, internally consistent person. JustAnalytics — our analytics product — has a readable write-up on how cookieless tracking works that's worth reading precisely because it's from the other side of the fence.
Frequently Asked Questions
Does incognito mode hide my browser fingerprint?
No. Incognito is a storage feature, not an identity feature. It gives the session a temporary cookie jar and throws it away when every incognito window closes, so nothing lands in your history. While the session is open, the site reads exactly the same canvas hash, the same WebGL renderer string, the same font list, the same screen geometry and the same navigator properties it would read from your normal window — because it's the same browser on the same machine. Private from the person using your laptop, not from the site.
Do separate Chrome profiles stop my accounts from being linked?
They stop one linking method and leave the rest. Each Chrome profile gets its own cookies, localStorage, IndexedDB and logins, which is real isolation and genuinely worth using. What every profile shares is the machine: identical canvas and audio output, the same GPU renderer string, the same installed fonts, the same screen resolution and colour depth, and one outbound IP unless you've done something about it. That's a strong match, and it's the match that gets accounts grouped.
Is a Chrome profile the same thing as an antidetect browser profile?
Only the word is the same. A Chrome profile is a separate folder of state — bookmarks, cookies, extensions, logins. An antidetect profile is a separate identity: its own canvas, WebGL, audio and font answers, its own screen geometry and timezone, its own proxy and its own DNS resolver, all generated as a set that holds together. One separates what the browser remembers. The other changes what the browser is.
When is an antidetect browser overkill?
When you have one account per platform and you're mainly trying to keep work and personal life apart. A second Chrome profile does that for free and nobody is linking anything. The line is roughly the point where a platform's terms, a review team or an automated linking system would care that two accounts belong to one operator — multi-account selling, ad verification across geographies, scraping that gets challenged, QA across locales. Below that line, save the money.
Try JustBrowser
Antidetect browser on a custom Chromium engine, always current with upstream — not extension-based. Real C++ engine patches at the canvas / WebGL / audio / font / screen layer, so 40+ identity parameters are genuine, not faked. Local REST API with CDP for Playwright, Puppeteer, Selenium. One plan: $9.99/month or $99.99/year — unlimited profiles, free team seats, 7-day free trial, card required.
Get started → · How it differs from Multilogin / GoLogin / AdsPower
Related Posts
Ready to manage multiple accounts?
Seven days free, then $9.99/month — one plan, everything included.