100% GDPR, CCPA & PECR Compliant

Privacy Policy

Last Updated: September 3, 2026

1. Our Privacy Philosophy

Analytika ("we", "us", or "our") was founded on a simple principle: you shouldn't have to sacrifice user privacy to get accurate business intelligence. Traditional web analytics platforms track users across the internet, harvest personally identifiable information (PII), and rely on intrusive tracking cookies.

Analytika operates completely differently. Our telemetry is 100% cookieless, stores zero personal information from your website visitors, and requires no cookie consent banners under GDPR, CCPA, or PECR.

2. How We Anonymize Website Visitor Data

When a visitor loads a website tracked by Analytika, our lightweight script generates aggregated statistical measurements without identifying individuals.

Cryptographic Anonymization:
  • No Raw IP Storage: Visitor IP addresses are immediately combined with a daily rotating salt and hashed via SHA-256 in volatile memory. Raw IP addresses are never written to disk or database tables.
  • Zero Tracking Cookies: We do not place cookies, local storage identifiers, or canvas fingerprints on website visitors.
  • Daily Reset: Because salts rotate daily, a visitor cannot be tracked across different days or different websites.

3. Information We Collect

A. Website Visitors (Aggregated Telemetry)

  • Page URL & Entry / Exit Paths
  • HTTP Referrer domain & UTM tags
  • Country & City (anonymized geographic lookup)
  • Device Category, Operating System & Browser Name
  • Custom telemetry event names & values (e.g. revenue amounts)

B. Account Holders (Analytika Customers)

  • Account email address (for passwordless OTP authentication)
  • Full Name or Organization Name (optional)
  • Tracked domain names and site configuration settings
  • Subscription status and billing interval (managed via Polar.sh)

4. What We Never Collect or Sell

We believe your business data belongs solely to you. We strictly guarantee:

  • We never sell, rent, or monetize your analytics or telemetry data to third parties, advertisers, or data brokers.
  • We never track individuals across different websites.
  • We never store credit card numbers on our servers (all billing is securely handled by our authorized Merchant of Record, Polar.sh).

5. Security & Cloud Infrastructure

We adhere to the highest security standards to ensure your analytics are protected:

  • Encryption: All telemetry in transit is encrypted using modern TLS 1.3, and all persistent data is encrypted at rest using AES-256.
  • Enterprise Data Centers: Infrastructure is hosted in SOC-2 Type II and ISO-27001 certified cloud environments with 24/7 monitoring.
  • PCI-DSS Compliance: Payment processing is handled by Polar.sh, maintaining Level 1 PCI-DSS compliance.

6. Data Ownership, Retention & Deletion

You own 100% of your data. We retain website analytics events according to your plan retention policy (up to 365 days).

When you delete a website or delete your account in Settings → Account → Delete Account, our system immediately executes a permanent hard purge across all databases, permanently expunging all associated records with zero recovery window.

7. Contact Our Privacy Team

If you have any questions regarding this Privacy Policy or wish to exercise your GDPR/CCPA data rights, please contact us at:

privacy@analytika.me or support@analytika.me