Privacy Policy
Simplytics is built so that we know as little as possible about the people who visit the websites we track. This page explains exactly what we collect and what happens to it.
Visitors of websites that use Simplytics
- No cookies. Our tracking script sets no cookies and stores nothing in your browser.
- What is sent: the page you viewed, the referring site, a timestamp, and any
utm_*campaign parameters that were on the link. If the site owner has set up custom events, the event's name is sent when you trigger one. A short "still reading" ping carries how long the tab has been active. Clicking a link to another site, or to a downloadable file, sends that link's address — including its query string, minus anything that looks like a token, a password or an email address, which is stripped before it is stored. - Coarse location and device stats: at the network edge we read a two-letter country code provided by Cloudflare and derive a device class (desktop, mobile, tablet) and browser family from the user-agent. Only daily aggregate counts are stored — the user-agent and IP address themselves are never saved.
- How visitors are counted: we compute an anonymous hash from a truncated IP address (last part removed), the browser's user-agent, and the website's domain, salted with a value that changes every day. The same person cannot be recognised across days, across websites, or identified at all.
- You can refuse to be counted at all. Turn on Global Privacy Control in your browser and the Simplytics script sends nothing — it stops before making any request, so nothing about your visit reaches us. It is free, needs no account, and works on every site that honours it. How to turn it on, including the one case where a site owner can override it. This is what the UK PECR “statistical purposes” exception asks for: a simple free way to object.
- Raw data is deleted nightly. Individual visit records are only needed to count unique visitors within a day. They are deleted automatically by the nightly job once their day has ended in the site's own timezone — never more than 48 hours. Page-journey records used for funnels lose their visitor identifier within two nights and are deleted after 90 days.
- What is kept, and it is more than three numbers: daily counts per site of views, visitors and sessions, and daily counts broken down by page path, referring host, country, device class, browser, operating system, campaign (
utm_source/medium/campaign), custom event name, and outbound-link or download target. Every one of those is a count with no person attached to it — but a page path can itself be revealing (/invoice/1234), so it is named here rather than summarised as "anonymous daily totals". These aggregates are kept for as long as the account exists.
Simplytics account holders
- Account data: your email address and your subscription status. Nothing else. Sign in with Google or GitHub and we ask them for the address and nothing else — no name, no picture, no profile. Sign in with an emailed link and no third party is involved at all.
- Sign-in links: if you ask for one, we store a one-way hash of the link's token alongside your address for 15 minutes. The link works once. The hash is deleted the night it expires, and it cannot be turned back into a working link.
- Cookies on simplytics.dev itself: one HttpOnly session cookie so you stay signed in, and — during a Google or GitHub sign-in only — two short-lived HttpOnly cookies that carry the OAuth state (10 minutes) and the page you were heading for (5 minutes). Signing in by emailed link sets only the session cookie. All of them are on our own site; none is ever set on a site you track.
- Payments are processed by Dodo Payments. We never see or store card details.
- Deletion: you can delete your account and its data yourself at any time from the Account page, which also cancels any subscription. It is gone from the live database immediately. Backups are the honest exception: Cloudflare's point-in-time restore keeps a rolling window of recent database states (at most 30 days), and a whole-database export is written weekly to private EU storage and deleted 90 days later. Neither is ever queried, and no feature can read them — they exist only to recover from a disaster — but they do mean the honest promise is gone everywhere within 90 days, not gone instantly. We would rather say that than claim a completeness the system does not deliver.
Other companies involved
Named in full, including the two that only ever see an account holder rather than a visitor:
- Cloudflare — hosting, the database, and the edge that serves every page and beacon.
- Dodo Payments — merchant of record for subscriptions. They handle card details; we never see them.
- Resend — sends the emails you have opted into, and the ones about your subscription.
- DuckDuckGo — when you open your own dashboard, your browser fetches a favicon from
icons.duckduckgo.comfor each referring site in your Top Sources list. That request tells DuckDuckGo the referring hostname and your IP address. It happens in the dashboard only, never on a site you track. - jsDelivr — serves the charting library the dashboard draws with, pinned to an exact version and checked against a hash. Again: dashboard only.
No advertising network, no data broker, no analytics-on-our-analytics. A visitor to a site you track is never in contact with anything except Cloudflare's edge. The subprocessor list says what each company gets and where it sits.
Where data is stored, and who can reach it
All analytics data lives in a Cloudflare D1 database whose primary storage is located in the European Union (Warsaw, Poland). Pages are delivered through Cloudflare's global network.
Simplytics is operated by one person based in India. Storage stays in the EU, but running the service — deploying code, investigating a fault, answering a support email — means reading that EU-hosted database from India. Under the GDPR that access is itself an international transfer: what counts is that the data is made available to someone in a third country, not where the disk sits. India has no EU adequacy decision and is not covered by UK adequacy regulations. This is written down because you may need it for your own records, and because no amount of EU hosting would make it untrue.
What limits it: the primary database stays in the European Union, and the only personal data held about you as an account holder is your email address and your subscription status. What does not limit it is a promise that has not been made — there are no Standard Contractual Clauses behind this yet, no transfer risk assessment, and no EU or UK representative appointed. Claiming any of those would be worth less than saying nothing. The data-processing agreement says the same thing in the place a customer's lawyer will look for it.
GDPR
For visitor data, the website owner using Simplytics is the data controller and Simplytics acts as a processor. Because no personal data is stored — identifiers are anonymised, rotated daily, and raw records deleted nightly — no consent banner is required on tracked websites. For account data, Simplytics is the controller.
Why we are allowed to hold your account data
GDPR Article 13 asks a controller to name a lawful basis for each purpose rather than one for the whole page, so here they are separately.
| What | Why we hold it | Lawful basis |
|---|---|---|
| Your email address and subscription status | To give you an account and charge you for it | Performance of a contract — Art 6(1)(b) |
| Sign-in link hashes and session records | To sign you in and keep the account from being taken over | Legitimate interests — Art 6(1)(f), ours and yours in a secure account |
| Weekly digest and traffic spike alerts | Because you switched them on | Consent — Art 6(1)(a), withdrawable at any time |
| Onboarding and win-back emails | To help you set up, and to ask once whether you want to stay | Legitimate interests — Art 6(1)(f), with an opt-out in every message |
| Billing and tax records | Because tax law requires the seller to keep them | Legal obligation — Art 6(1)(c) |
| Bounce and spam-complaint records | To stop mailing an address that rejected us, which protects delivery for everyone else | Legitimate interests — Art 6(1)(f) |
Scroll the table sideways to see the lawful basis.
Where the basis is legitimate interests you have the right to object, and for the marketing ones objecting is a single click: every such email carries a link that stops all of them, and the account page has the same switch. Where the basis is consent you can withdraw it at any time, and withdrawing does not affect anything sent before you did.
How long we keep it
- Raw visit rows — deleted every night, once the day they belong to has ended in the site's own timezone. The rows exist to tell a returning visitor from a new one within a single day, so a day's rows are kept while that day is still running, and the job that clears them runs at midnight UTC. That puts the real figure between about one and two days, and never more than 48 hours. This said “hours, not days” until 2026-09-15, and that was never true for any site: a day's first row is more than a day old by the time its day is over.
- Funnel journey rows — the visitor identifier is dropped by the second nightly run, so within two nights; the rows themselves are deleted after 90 days.
- Analytics aggregates — kept for as long as the account exists. They are counts with nobody attached.
- Your email address and subscription status — until you delete the account.
- Sign-in link hashes — 15 minutes, then deleted the night they expire.
- Sessions — until you sign out or the session expires.
- Billing records — kept as long as tax law requires, which is longer than your account. This is the one thing deleting your account does not remove, and it is the one thing we are not allowed to remove.
- Bounce and spam-complaint records — kept after account deletion on purpose. It is one row saying “never mail this address”, and forgetting it would mean mailing an address that already told us to stop.
- Backups — a rolling point-in-time window (at most 30 days) and a weekly export deleted 90 days after it is written. So 90 days is the outer edge of everything above.
Your rights
Under the GDPR and the UK GDPR you can ask for a copy of your data, to have it corrected, to have it deleted, to restrict what we do with it, to object to processing based on legitimate interests, and to receive it in a portable form. Where we rely on consent you can withdraw it.
Most of these you can exercise yourself without asking anyone: full CSV export at any time, the email toggles on the account page, and account deletion from the same page. For anything else, email nikhil@simplytics.dev and you will get an answer within one month. There is no charge and no form.
Two limits worth stating rather than leaving you to discover. Visitor data is de-identified within two days at the outside, so for a visitor we usually cannot locate the data to act on a request — that is a consequence of the design, not a refusal. And erasure reaches the live database immediately but backups only as they age out, which is what the 90 days above means.
If we get it wrong, you can complain about us. In the UK that is the Information Commissioner's Office (ico.org.uk/make-a-complaint). In the EU it is the supervisory authority for the country you live in; the European Data Protection Board keeps the list (edpb.europa.eu). You do not have to raise it with us first, though we would rather you did.
Is giving us this data required?
Your email address is: it is the account, and there is no way to have one without it. Everything else is optional — the digest, the spike alerts, your timezone, and how many sites you add. Nothing is fed into automated decision-making and nothing is profiled.
Who we are
For your account data the controller is Simplytics, which is not a company: it is one person, based in India, and the about page says so plainly. The contact point for anything in this policy, including every right above, is nikhil@simplytics.dev.
Article 13 expects more than that, and the rest is missing. We publish no postal address. We have appointed no EU representative and no UK representative, which a controller outside both is normally expected to have. There are no Standard Contractual Clauses behind the operator access described further up. There is no data protection officer, though at this size one is not required. None of those exists, and rather than print a plausible-looking placeholder we are naming the gaps — a made-up address would be worth less to you than this paragraph. If you need any of them before you can buy, say so and you will get a straight answer about whether and when.
Contact
Questions about privacy or data requests: nikhil@simplytics.dev