Vitrus
All featuresEverything Vitrus measures, one page each. AI trafficThe visitors GA4 files as direct. Proof layerThe query behind every number. Cookie-freeNo banner, no consent, no identifier. MCP for agentsLet an AI query your analytics, with receipts. CompareHow we stack up against the rest.
SaaS & startupsSignup funnel, CTAs, form drop-off. Content & blogsAre AI assistants citing you? E-commerceCheckout funnel and where carts die. AgenciesMany sites, shareable reports. DevelopersOne line, open source, self-hostable.
DocumentationInstall, events, funnels, digest. IntegrationsNext.js, WordPress, Shopify, Webflow and more. API referenceIngest and query endpoints. Self-hostingOne command, zero dependencies. SecurityWhat we collect, and what we never do. FAQShort answers.
Docs Pricing
Log in Get started
FeaturesCompareDocs PricingLog in

Legal

GDPR and KVKK

Our processing roles and the technical measures behind them.

This is not legal advice. It describes what the product actually does and can be used as a starting point, but assessing your obligations is your counsel's job. The technical claims are documented in detail in the privacy documentation.

Roles

ScenarioControllerProcessor
Cloud versionYou (the site owner)Vitrus
Self-hostedYouNone — the data never reaches us
Your Vitrus accountVitrus—

Why a consent banner may not be required

Consent obligations usually turn on access to terminal equipment (writing cookies or localStorage) and on processing personal data. Vitrus:

  • Uses no cookies or localStorage — nothing is written to the device
  • Mints no persistent identifier — the id changes every day
  • Never stores the IP address — it is only an input to a one-way hash
  • Does not profile individuals or stitch identities across devices

What that means in your specific context is a question for your counsel. We only document what the product does.

Strict mode

If your counsel wants the smallest possible footprint, strict mode drops country, screen size, referrer query strings and cross-day identity, and makes Do Not Track non-overridable. It is enforced server-side, so it holds even if the browser script is modified.

Technical and organisational measures

  • TLS in transit; server access by key-based SSH only
  • Tenant isolation is tested: one account cannot reach another's data, and that is verified automatically on every build
  • Passwords hashed with argon2id; changing a password invalidates every session
  • Site-owner identities (identify) are hashed one-way; the raw value never touches disk

Data subject requests

For your visitors: because there is no persistent identifier and no stored IP, locating a single visitor retroactively is technically impossible — which means less that we cannot honour a deletion request, and more that the data was never linkable to a person. For your own account data, write to us.

Other documents

Privacy policy Terms of service Data processing agreement Contact
Vitrus

Analytics that can prove what it says. Cookie-free, open-source core, self-hostable.

Product
FeaturesPricing CompareUse cases Self-hosted
Resources
DocumentationIntegrations API referenceSelf-hosting GitHub
Compare
vs. Google Analytics vs. Plausible vs. Umami vs. Rybbit vs. Matomo All comparisons →
Company
ContactSecurity PrivacyTerms GDPR / KVKKDPA
© 2026 Vitrus · core licensed Apache-2.0 · cookie-free, no consent banner required