Security
Written for whoever has to approve this. Short, specific, and without the word "military-grade" anywhere.
Per event: the page path and query string, a referrer, page title, screen size, browser language, a coarse device/OS/browser bucket, a country code if your proxy provides one, and any properties you explicitly attach to a custom event.
Access is resolved before any metric runs, not filtered afterwards. Every query
carries the site id as a bound parameter, and a site you cannot reach returns
404 rather than 403 — a 403 would confirm
that the site exists.
This is enforced by a build gate (gate:tenant-leak) that fails CI
if a query can reach the events table without a resolved site id. Isolation is a test, not a
convention.
Cloud data is stored in the EU. Retention follows your plan and old events are deleted, not archived. Self-hosting means no data reaches us at all — including the optional AI summary, which can run against a local model.
Kept deliberately short: Hetzner (hosting, Germany), Paddle (payments, merchant of record), Resend (transactional email). If you enable an LLM provider with your own key, that provider becomes a sub-processor of yours, not of ours — and what reaches it is an aggregated evidence bundle, never raw visitor data.
Email [email protected]. Please include enough detail to reproduce. We will confirm within three working days, and we will not pursue anyone acting in good faith. The core is open source — you are welcome to read it before you trust it.
Related: Privacy policy · DPA · GDPR / KVKK