Cookieless by default
The browser tracker does not set tracking cookies. Collection can stay disabled until your site grants consent when that is legally or contractually required.
Privacy
Slimlytics is designed to answer site-analytics questions without building cross-site identity profiles or capturing more than you need.
The browser tracker does not set tracking cookies. Collection can stay disabled until your site grants consent when that is legally or contractually required.
No cross-site tracking, no device fingerprinting for identity, no form-field capture, and no session replay. Those are non-goals — not delayed features we quietly enable later.
Common secret and identity query parameters (tokens, emails, session keys, and similar) are stripped before URLs are stored. Prefer not putting personal data in URLs at all.
Visitor identifiers are derived from privacy-reduced inputs with a rotating server secret and stay scoped to each site. Raw IPs are used only transiently for abuse controls and coarse location when enabled.
Defaults
Configure retention, export site data, delete site data, and delete an anonymous visitor’s events when needed. When you self-host, the data never leaves the infrastructure you choose.
Initialize the tracker with collection disabled when consent is required. Call the tracker consent API only after the visitor grants analytics consent. Revocation stops new events immediately; deleting prior data is a separate server-side operation.
Create an account and see privacy-first analytics on your own terms.