Analitic

Privacy

Updated 19.09.2026

Analitic collects visit statistics without cookies and without personal data. Here is exactly what is collected and what happens to it.

What is collected

Each pageview sends one request to our server. It carries:

  • the page address, minus any query parameters you have not asked us to track
  • where the visitor came from, and UTM tags if the link had them
  • country, region and city, resolved from a database on our own server
  • device type, operating system, browser and screen width
  • browser language
  • an amount and a currency, but only if you sent a payment event yourself

What is not collected

  • the visitor IP address is never stored: it goes into a hash and is dropped immediately
  • nothing is written to the visitor browser, neither cookies nor localStorage, unless you turn on the data-persist attribute
  • the script neither collects nor sends a visitor's name, email or phone — none of it is read in the browser
  • what a visitor does on other websites

How a visitor is recognised without cookies

The visitor id is a hash of four things: a secret salt, the site id, the IP address and the browser string. The salt rotates every 24 hours and is not kept afterwards.

The consequence is the point: tomorrow the same person gets a different id, and the two visits cannot be joined by us, by you, or by anyone. There is nothing to consent to, because there is nothing to link.

The exception is the data-persist attribute. It stores an id in your own site localStorage so a payment can be tied back to the first source. You switch it on; it is off by default.

Account holder data

This part is different: you have an account with us. We keep your email, your name, your sign-in history and the IP of your dashboard session, so that you can log in and see where you logged in from. None of this touches your visitors statistics.

Payment data

You send the payment event from your own server. Besides the amount it may carry the buyer's email, their id in your system and their name — so that we find the right visitor instead of creating a second one.

How it works today: if you send them, those values are stored on the visitor record in the clear and are visible to you under Visitors. We use them only to match and to show them back to you — they go nowhere else and are combined with nothing.

What we plan to change: keep only a hash of the email. Matching works the same way, and the address can no longer be read out of the database.

Until then, do not send what you would rather not have stored. A visitor id or your own customer number is enough to attach a payment to a channel; the email is not needed for that.

Where the data lives

The servers are in Paris, France, inside the GDPR jurisdiction. The geolocation database sits on the same server, so a visitor address is never sent to any outside service.

How long it is kept

Detailed events are kept for as many days as your plan allows, after which a scheduled job deletes them. Daily summaries remain.

One exception: the record of a visitor who paid is not deleted along with the events — otherwise revenue would stop matching the channel that won the customer. It keeps the amounts, the first source, and whatever you sent yourself: email, name, your own customer id. Deleting the site or the account removes them.

Deleting your account and data

There is a delete button under Profile. Type your own email address and the account goes, together with every site, event, visitor, goal and funnel. You do not have to ask us, and it cannot be undone.

A single site you can delete yourself, in its settings: all of its statistics goes with it.

Message us on Telegram

Who else gets the data

Nobody. We do not sell it, do not pass it to ad networks and do not use it to train models.

Contacts

For anything about data, deletion included, write to: