Legal

Privacy Policy

What Analytica collects, why, and how long it stays. This covers dashboard accounts and the cookieless tracker installed on customer sites.

Last updated September 24, 2026

Who this applies to

Analytica is a product analytics service. This policy describes two groups of people: customers who create an account, and visitors whose activity is measured on a site or app that installs the Analytica tracker.

If you install the tracker, you decide what to measure on your property. You are responsible for telling your visitors about that measurement and for having a lawful basis to do it. Analytica processes that visitor data to provide the service to you.

Account information

When you create or use an Analytica account, we store:

  • Your name, email address, and a hash of your password.
  • Organization membership, team invites, and project settings you configure.
  • Billing details handled by Lemon Squeezy when you upgrade. Analytica stores the customer reference needed to manage your plan, not your full card number.

Signing in sets an httpOnly session cookie named analytica_session. It expires after 7 days and is used only to keep you logged in to the dashboard. The analytics tracker does not set this cookie.

Visitor analytics

The tracker does not set a persistent analytics cookie. A daily session id is a hash of a salt, the date, the project, the IP address, and the user agent. The raw IP address is not written to the database.

Depending on how a project is configured, events can include:

  • Pageviews, including path and UTM parameters present on the URL.
  • Custom events and properties the site chooses to send.
  • An optional identified user id and traits, only when the site calls analytica.identify.
  • Heatmap clicks, scroll depth, and movement as aggregated, normalized coordinates. Input fields and elements marked data-analytica-mask are skipped.

Parsed device and browser details may be stored with the event. We do not sell visitor data and we do not use it for advertising profiles.

How long we keep it

Analytics events are deleted on the retention window of the project's plan: 30 days on Free, 180 days on Starter, and 730 days on Premium. Account records stay while the account is open. You can export events as CSV or NDJSON, and Premium projects can send scheduled copies to a webhook or email address you configure.

Who else receives data

We share data only as needed to run Analytica:

  • Lemon Squeezy, to process paid subscriptions and invoices.
  • The email service configured for the deployment, for invites, alerts, and export mail.
  • Webhook or email destinations you add under Settings → Exports.
  • Infrastructure that hosts the collector, worker, database, and dashboard.

We may also disclose information if required by law, or to investigate abuse of the collector, such as quota evasion or requests from origins you have not allowed.

Your choices

Account holders can update project settings, remove teammates, export data, and cancel a paid plan from the billing portal. To ask about account data or this policy, email privacy@analytica.dev.

Visitors who do not want to be measured should use the controls offered by the site they are visiting. Analytica does not drop a cookie that a banner can simply reject; the site owner chooses whether to load the tracker.

Changes

If this policy changes, the updated text will be posted on this page with a new date. The Terms of Use explain the contract for using the product.

Privacy Policy·Terms of Use