Skip to content

Privacy

How cookieless analytics measures without tracking people

Every privacy claim we make has a technical explanation. This page describes exactly what happens to a pageview, what we store, what we never store, and how you can check it yourself.

The data journey

Every visitor request, including requests from the EU, EEA, UK and Switzerland, is processed in our US region. The IP address and user agent are used in memory while the request is handled, and dropped before the minimized event is stored.

  1. Step 1 · Anywhere
    Visitor’s browser
    • Page URL and referrer
    • UTM parameters
    • Screen width and language
    • Your custom event properties
    • No cookies or local storage
    • No fingerprinting APIs
    • No third-party requests
  2. Step 2 · United States
    Ingest, in memory
    • Country from the Cloudflare header
    • User agent → browser, OS, device
    • Bot checks and your traffic rules
    • In-memory visit key
    • IP address dropped after the request
    • Full user agent dropped after the request
    • PII scrubbed, query strings trimmed
  3. Step 3 · Queued in the US region
    Minimized event
    • The minimized event only
    • No IP address
    • No raw user agent
    • No visit key or salt
  4. Step 4 · United States
    Storage and dashboard
    • Pages, sources, campaigns
    • Country and device categories
    • Random visit ID (one day at most)
    • Event properties
    • Nothing that identifies a person
    • Nothing that links days, sites or devices

What we collect, and what we never collect

Collected (after minimization)

  • Page. Hostname and path. Query strings removed except campaign parameters and your allowlist. Fragment removed unless you use hash routing.
  • Referrer. Domain and path of the referring page. Query removed, internal referrers blanked.
  • Campaign. UTM parameters and ref. Ad click IDs (gclid, msclkid, fbclid) are reduced to a yes/no flag.
  • Location. Country only, from the country header our network provider (Cloudflare) adds to each request. No region, city or coordinates.
  • Technology. Browser, operating system (family and major version), device type, screen size range, language.
  • Engagement. Visible time on page and scroll depth in 10% bands.
  • Events. Names and up to 30 typed properties you choose to send, after PII scrubbing.

Never collected or stored

  • IP addresses. Used in memory for bot checks and the daily visit key, then dropped. Never written to disk, logs, queues or databases, not even for bots.
  • Full user agents. Parsed into categories in memory, then dropped.
  • Cookies and device storage. No cookies, localStorage, sessionStorage or IndexedDB (except a visitor’s own opt-out choice).
  • Fingerprints. No canvas, WebGL, font, audio or battery APIs, and no extra client hints.
  • Persistent identifiers. Nothing that lasts beyond one day, or links sites or devices. No user profiles.
  • Precise location. No coordinates.
  • Third-party requests. The tracker talks only to Privatus Analytics.

PII scrubber. Before anything is stored, paths, referrers, titles and event properties are checked for email addresses, long identifiers, token-like strings and long digit runs such as phone or card numbers. Matches are replaced with placeholders like [redacted-email], and each site sees how many redactions happened so leaks can be fixed at the source.

How visits are counted

  1. Each UTC day we generate a random 256-bit salt. It exists only in memory and is destroyed at the end of the day, plus a 30-minute grace period.
  2. For each hit we compute HMAC(daily salt, site, IP, user agent) in memory and look it up in a memory-only store with a 30-minute inactivity timeout, capped at midnight UTC.
  3. A new visit gets a random visit ID that is not derived from that key. Only the random ID is stored.
  4. When the salt is destroyed, nothing can link stored visits back to a device or to each other across days.

This is pseudonymous data: heavily minimized and not linkable beyond one day. We don’t describe it as anonymous.

Every field we store

Adding a stored field requires a written review of its purpose, minimization and retention. This is the current list.

FieldPurposeMinimizationRetention
Hostname, pathPagesQuery stripped except allowlist, PII scrubbed, path masksPlan
Referrer host and pathSourceswww. and m. stripped, query dropped, internal blankedPlan
UTM parameters, ref, paid clickCampaignsClick IDs reduced to a yes/no flagPlan
CountryLocationFrom the Cloudflare country header, IP droppedPlan
Device, browser, OS (with major versions), screen rangeTechnologyRaw user agent dropped, screen bucketedPlan
Visit IDVisitsRandom UUID, one UTC day at mostPlan
Event propertiesEventsUp to 30 keys, typed, PII scrubbedPlan
Filter countersBots, rules, redactionsAggregates only, no IP13 months
Visit key (memory store)Visit continuityHMAC key, 30-minute timeoutOne day at most
Daily salt (memory store)Visit keyNever persisted1 day + 30 minutes

“Plan” retention: 6 months on Free, unlimited while subscribed on paid plans, with per-site overrides.

Verify it yourself

  1. Open this page’s developer tools and go to the Application (or Storage) tab. You’ll find no cookies and nothing in local storage for this site.
  2. Switch to the Network tab, filter by /api/event and reload. You’ll see one small request per pageview.
  3. Open the request payload. It contains only the fields on the right: no identifiers, no fingerprint.
  4. Read the tracker’s source. It’s MIT-licensed and short enough to read in one sitting. See open source.

Try the cookie and tracker scanner on your own site, too.

Example request payload (a pageview)
{
  "s": "pa_7Q2K9XH3AB",
  "t": "pageview",
  "u": "https://example.com/pricing?utm_source=newsletter",
  "r": "https://news.example.org/",
  "l": "en-US",
  "w": 1440
}

s is the site, t the hit type, u the page with non-campaign query parameters removed in the browser, r the referrer, l the language and w the screen width. Full reference in the docs.

Where your data lives

US storage and processing, and transfer safeguards.

Compliance hub

GDPR, ePrivacy, US state laws and more.

Data Processing Agreement

Included in our terms.

Start measuring without cookies

No cookies, no fingerprinting and no consent banner needed for measurement.

The free plan includes 10k events a month, 10 sites, 3 team members and 6 months of history. No card required.