Privacy is the baseline

Useful analytics without turning visitors into product.

No cookies

No persistent storage on visitor devices—skip the cookie theater.

No personal data

We do not collect IPs for storage, fingerprints, or cross-site identity.

IP handling

Addresses are anonymized in memory for coarse geo, then discarded.

Bot filtering

Crawlers and automation are filtered so metrics reflect humans.

GDPR posture

Designed to reduce consent friction while staying respectful of regulation.

CCPA posture

No sale of personal information—because we are not collecting it.

Data ownership

Export anytime. Remove your account and the data goes with it.

Transparent script

Read the tracker—what you ship is what runs.

Customer accounts (B2B)

For signed-in customers we store account email, name, and workspace membership. You can export workspace metadata from Account and delete your account from there.

Subprocessors

Depending on your workspace: Stripe may process billing (when enabled); your configured mail provider delivers invitations and alerts; optional QR images for two-factor setup may be requested from api.qrserver.com when you enable 2FA.