Privacy by Design,
Not as an Afterthought
Most analytics tools were built to collect as much data as possible, then retrofitted with privacy settings. Argusmetrics was designed the other way around: privacy is the foundation, not the feature.
What we collect
Every data point we collect serves a specific analytical purpose. Nothing more. All data is aggregated. There are no individual visitor records.
What we never collect
These are hard technical constraints built into the system, not policy promises that could be changed by a terms update.
How visitor identification works
To count unique visitors without cookies, we use a daily-salted hash. Here is exactly how it works, no magic, no hidden steps.
SHA-256(daily_salt + domain + truncated_IP + user_agent)
Before anything else, the last octet of the visitor's IP is zeroed out. 203.0.113.42 becomes 203.0.113.0. This means up to 256 users on the same network subnet share the same starting point, making the hash far less precise, and impossible to reverse-map to an individual.
The salt for the day is derived from the current UTC date combined with your installation's SECRET_KEY, so it changes automatically at midnight UTC and is never stored anywhere. Because the date component changes daily, the same visitor produces a completely different hash on different days, making day-to-day tracking technically impossible, even with access to the database.
The domain of the site being tracked is included in the hash input. This guarantees that hashes are site-specific, a visitor to shop.example.com gets a different hash than the same visitor on blog.example.com. No cross-site data linkage is possible.
A server-side secret key, unique to each Argusmetrics installation, is added to the hash. Even if someone knows the algorithm, the daily salt, and the IP range, they cannot reproduce or reverse the hash without knowing this secret. It is never exposed to the browser or transmitted over the network.
The browser's user-agent string is included as the final hash input. This spreads visitors on the same truncated IP and day across more distinct hashes, and the raw user-agent string itself is never stored, only its contribution to the one-way hash.
This lets us accurately count unique visitors within a day while making it mathematically impossible to track the same person across multiple days. This approach follows the same daily-rotating-hash design used by other privacy-first analytics tools, and is modeled on the criteria French data protection authority CNIL has published for cookie-free audience-measurement tools to qualify for a consent exemption. No regulator has reviewed or endorsed Argusmetrics specifically. You remain responsible for assessing compliance for your own use case.
Skip the consent banner
Consent banners exist because of what a tool stores on, or reads from, a visitor's device. Argusmetrics stores nothing there: no cookies, no localStorage, no identifier of any kind.
The visitor's IP address is never stored. It is truncated, then hashed together with a salt that changes daily, and only the hash is kept. A visitor cannot be followed from one day to the next, cannot be singled out within their network, and produces a completely different hash on every site.
Whether that means your deployment needs no banner depends on how you configure it, what you choose to send, and your own legal advice. We can tell you exactly what the software does, and this page does. We cannot tell you what your obligations are.
Your visitors get a cleaner experience. You get data you can actually trust (no consent bias). Everyone wins.
Where your data lives
On servers we run, in one database, with nothing handed to anyone else. Here is what is under the hood.
Your analytics live in a single database we operate. Nothing is passed to advertising networks or data brokers, and country lookups happen locally instead of at a third-party service.
Data is stored in a managed PostgreSQL database with automated backups. Only aggregated event data is persisted, no raw visitor records.
All data in transit is encrypted via TLS 1.3. The tracking script communicates with the backend over HTTPS exclusively.
GDPR compliance
We've thought through the legal framework so you don't have to spend hours with your DPO.
You are the data controller for your website's analytics and we are your processor, handling only what is strictly necessary to produce your dashboard. Nothing is passed on to advertisers or data brokers.
Argusmetrics is self-hosted, so nobody else processes your visitors' data: it never leaves your server. If you run an instance for someone else, such as a client, you are their processor and will need an agreement with them. There is a draft in the repository to start from.
There is usually nothing to retrieve or delete for one visitor: the hash changes daily and is not linked to a person, so a single visitor's rows cannot be singled out even deliberately. If you send identifying data in custom properties, that is different, and it is yours to find and remove. Deleting a website deletes its data, and closing an account deletes everything, both immediately.
Everything else on this page is designed so it cannot identify a person. Custom event properties are different: they are whatever your site sends. Put a name, an email address or a user id in one and that is personal data you chose to send, stored as given. That field is under your control, not the product's.
Ready to analyze without compromising privacy?
Add one script to your site and start measuring, with no consent banner and without handing your visitors to anyone else.
View on GitHub