# Cookieless tracker reference (pa.js)

> How the cookieless pa.js tracker works and when it sends nothing, with links to every script attribute, the JavaScript API, modules, SPA support and debugging.

`pa.js` is the browser tracker. It's open source (MIT), a few kilobytes,
and it:

- sends **one small request per pageview or event** to
  `https://privatusanalytics.com/api/event`, and
  [retries it](/docs/tracker/payload#retries) a few times if the server
  answers with an error,
- uses **no cookies, `localStorage`, `sessionStorage`, IndexedDB or
  fingerprinting APIs** (canvas, WebGL, fonts, audio, battery). The one
  exception is the [opt-out flag](/docs/tracker/opt-out) a visitor sets
  themselves,
- makes **no request to any third party**.

```html
<script defer src="https://privatusanalytics.com/js/pa.js" data-site="pa_YOURSITEID"></script>
```

## Reference

- [Script attributes](/docs/tracker/attributes): every `data-` option.
- [JavaScript API](/docs/tracker/javascript-api): `track`, `pageview`,
  `props`, `optOut`, `ready` and the queue stub.
- [Modules](/docs/tracker/modules): `engage`, `auto`, `vitals`, `clicks`.
- [Single-page apps](/docs/tracker/spa) and [manual mode](/docs/tracker/manual-mode).
- [Exclusions, masking and URLs](/docs/tracker/exclusions-and-masking):
  domains, excluded paths, masks, query parameters, canonical URLs, hash
  routing.
- [Debug mode](/docs/tracker/debug), [CSP](/docs/tracker/csp),
  [versioning and SRI](/docs/tracker/versioning-and-sri),
  [opt-out](/docs/tracker/opt-out).
- [What the tracker sends](/docs/tracker/payload): the exact request
  body.

## When the tracker sends nothing

The tracker stays silent (and says why in the console with
`data-debug="true"`) when:

| Reason | Details |
|---|---|
| `missing data-site` | The script tag has no `data-site` |
| `opted out` | The visitor [opted out](/docs/tracker/opt-out) in this browser |
| `localhost` | The page is on `localhost`, `127.*`, `[::1]`, `0.0.0.0`, a `.local` host or `file://`, and neither `data-debug` nor `data-allow-local` is set |
| `domain not in data-domains` | You set `data-domains` and this hostname isn't in it |
| `automated browser` | `navigator.webdriver` is set, or PhantomJS, Nightmare or Cypress is detected |
| excluded path | The path matches `data-exclude` |

It also waits for a prerendered page to become visible before sending
anything (`prerenderingchange`), and sends a fresh pageview when a page is
restored from the back/forward cache.

## Open source

The tracker source, tests and build are public. Every file starts with a
comment naming Privatus Analytics: we don't disguise the script or offer
ways to hide it from blockers. See
[Ad blockers](/docs/troubleshooting/ad-blockers).
