Privacy

Analytics without the surveillance model

Slimlytics is designed to answer site-analytics questions without building cross-site identity profiles or capturing more than you need.

Cookieless by default

The browser tracker does not set tracking cookies. Collection can stay disabled until your site grants consent when that is legally or contractually required.

What we deliberately skip

No cross-site tracking, no device fingerprinting for identity, no form-field capture, and no session replay. Those are non-goals — not delayed features we quietly enable later.

Sensitive data redaction

Common secret and identity query parameters (tokens, emails, session keys, and similar) are stripped before URLs are stored. Prefer not putting personal data in URLs at all.

Site-scoped visitor IDs

Visitor identifiers are derived from privacy-reduced inputs with a rotating server secret and stay scoped to each site. Raw IPs are used only transiently for abuse controls and coarse location when enabled.

Defaults

Built-in privacy highlights

  • No cross-site tracking or advertising profiles
  • No session replay or form-field capture
  • Sensitive query parameters redacted before storage
  • Do Not Track and Global Privacy Control respected
  • Site-scoped visitor IDs with rotating secrets
  • Do Not Track and Global Privacy Control are respected
  • Site owners control retention, export, and deletion

Your control as a site owner

Configure retention, export site data, delete site data, and delete an anonymous visitor’s events when needed. When you self-host, the data never leaves the infrastructure you choose.

Consent integration

Initialize the tracker with collection disabled when consent is required. Call the tracker consent API only after the visitor grants analytics consent. Revocation stops new events immediately; deleting prior data is a separate server-side operation.

Measure without the guilt hangover

Create an account and see privacy-first analytics on your own terms.