Privacy
What we collect, and what we don’t
No cookies and no personal data. Here’s every field our script sends, and what we never collect.
What our script sends
This list is generated from our script’s own allowlist, so it’s always complete. Fields from optional features are only sent if you turn them on.
20 fields
With every pageview
Always
- site
- Your site’s ID.
- Example: site-field-notes
- id
- A random ID for this pageview, held in memory only.
- Example: k3v9x2m1q8
- path
- Page path, without the query string.
- Example: /notes/the-slow-web
- navigation
- How the page was reached: full load, in-app navigation or the Back button.
- Example: load
- referrer
- Referring domain only, not the full URL.
- Example: news.ycombinator.com
- utm
- UTM parameters in the page URL, if any.
- Example: source: newsletter
- adClickId
- Which ad click ID was in the URL, if any. Never its value.
- Example: gclid
- touchScreen
- Whether the device has a touch screen, to tell tablets from laptops.
- Example: true
When the visitor leaves the page
Always
- pageViewId
- The ID of the pageview this message belongs to.
- Example: k3v9x2m1q8
- visibleMs
- Time the page was visible, sent when it’s hidden or closed.
- Example: 104000
With custom events
If you send events
- name
- Event name, such as signup, or the name of a clicked element.
- Example: signup
- recordedBy
- Whether the event came from your code or was tracked automatically.
- Example: page
- properties
- Custom properties for the event. Can’t contain personal data.
- Example: plan: pro
- revenue
- Revenue amount and currency.
- Example: 49.00 EUR
From optional features
Only if turned on
- lcpMs
- Largest Contentful Paint, in ms.
- Example: 1900
- inpMs
- Interaction to Next Paint, in ms.
- Example: 120
- cls
- Cumulative Layout Shift.
- Example: 0.04
- depthPercent
- Scroll depth, as a percentage of the page.
- Example: 75
- message
- JavaScript error message, with personal data removed.
- Example: x is not a function
- source
- File, line and column where the error was thrown.
- Example: app.js:12:40
Processed, never stored
Every browser request includes these. We keep only what we derive from them.
IP addressbecomes Country
Used in memory to look up the country and count unique visitors, then discarded.
User-Agentbecomes Browser, OS and device type
The string a browser sends to identify itself. We keep only these three values.
Country data from DB-IP. IP Geolocation by DB-IP
What we never collect
- No cookies, localStorage or other browser storage
- No stored IP addresses
- No full User-Agent strings
- No names, email addresses or user IDs
- No form inputs
- No copies of your pages
- No city or region
- No visitor ID that lasts more than a day
Data retention
We keep pageviews and events for 3 years, then delete them. Your dashboard shows up to 3 years of history.