Privacy-friendly web analytics tools

Entry price is the lowest monthly price the vendor lists; “Free” means a free plan or free self-hosting. “At 100k” is the monthly price for 100,000 units, as the vendor bills them. Dates under statuses, prices and script sizes show when we checked them. See how we check every value.

What this page means by privacy-friendly

Three conditions put a tool on this page. Its tracking script sets no cookies and leaves no lasting identifier in the browser in the default setup. Its vendor does not say that the tool collects personal data. And its vendor does not say that a consent banner is required.

Only the first is something we check ourselves, by looking at what the script does. The other two are statements from the vendor’s documentation and privacy pages, shown on tool cards as the vendor’s position rather than as a finding of this directory. For three tools here one of those statements carries a limit, shown on the card as “Partly”: it may hold only for part of the product.

Two things follow. A tool can be missing from this page because its vendor writes carefully, not because its product collects more. And a tool on this page can still receive personal data, because what you send matters as much as what the tool sets.

No cookies does not always mean no identifier

Four tools in the directory set no cookies and still keep a lasting identifier in the visitor’s browser, in local storage: Pretty Insights, TinyAnalytics, Databuddy and Rybbit. Their Cookieless column reads “No”, so they are not on this page, even where the vendor describes the tool as free of cookies.

A cookie is one of several places a script can write to. A value in local storage outlives the tab and the browser session, has no expiry date of its own, and recognises the same browser until something clears it. The technique does not settle the legal question either: the European Data Protection Board’s guidelines on the technical scope of Article 5(3) of the ePrivacy Directive state that the article does not apply exclusively to cookies, but also to similar technologies.

This is why the Cookieless column follows the script rather than the documentation, and why each of those four cards says what the script stores. The methodology describes the check.

Where the data goes

None of the three conditions says where data is kept, for how long or who else touches it. Fifteen of the tools here also appear on the page for tools that store data in the EU. Ten can be installed on your own server, and there the location is wherever you install them; nine of those publish their source code and appear among the open-source tools. Retention sits on the cards, where the Data retention row shows the period on the cheapest paid plan. Subprocessors, such as the hosting provider behind a service, are not in our data at all.

How to choose

Start from the condition you cannot negotiate, then compare the rest.

  1. Decide which of the three properties you need. If nothing may be stored in the browser, the Cookieless column is the filter; if the concern is where data lands, start from the EU storage page.
  2. Read the vendor’s wording rather than the label. A statement about personal data may cover the tracking script and say nothing about account data or a feature you were planning to switch on.
  3. Check what you will send yourself. Event properties, page addresses with tokens in them and features that attach a visit to a signed-in user carry personal data into a tool that collects none by itself.
  4. Check the rest of the page: embedded video, chat widgets and advertising tags come with storage of their own.
  5. Then compare hosting, retention and price at your traffic, in the unit each vendor bills.

Questions and answers

How is this different from the list of cookieless tools?

The cookieless page uses one condition: what the tracking script stores in the browser by default. This page keeps that condition and adds two vendor statements, about personal data and about consent banners, so it is a shorter list from that pool. A tool can be cookieless and still be absent from here, because its vendor makes no plain statement about personal data.

Does this mean that no personal data is collected?

No. It means the vendor says so. The server that receives a tracking request sees the visitor’s IP address whether or not the tool stores it, and several vendors state that they use it only to compute a hash. Beyond that, what leaves your site is your decision: event properties and page addresses can carry personal data into a tool that collects none on its own.

That depends on the rules where you and your visitors are, on everything else your pages load and on how you configure the tool. Consent rules in the EU are not limited to cookies, and data protection law can apply to an IP address. Where a vendor states that no banner is needed, the card shows that as the vendor’s position; check it against the rules that apply to you. This directory does not give legal advice.

Can I check this myself?

Yes. Open your site in a private window with the developer tools on the storage panel, load two or three pages and look at cookies, local storage and session storage. A lasting identifier survives a reload and is still there when you come back.

Other collections