No cookies. No device identifiers.

Privacy by Design,
Not as an Afterthought

Most analytics tools were built to collect as much data as possible, then retrofitted with privacy settings. Argusmetrics was designed the other way around: privacy is the foundation, not the feature.

What we collect

Every data point we collect serves a specific analytical purpose. Nothing more. All data is aggregated. There are no individual visitor records.

Page URL
Which page was visited, without query strings that could contain personal data.
Referrer
Where visitors came from, search engines, social media, or direct.
Country
Country-level location only, never city, region, or precise location.
Browser
Browser family (Chrome, Firefox, Safari), not the full user-agent string.
Device type
Desktop, tablet, or mobile, nothing more specific.
Screen size
Viewport width bucketed into ranges, not an exact pixel dimension.

What we never collect

These are hard technical constraints built into the system, not policy promises that could be changed by a terms update.

No raw IP addresses
IP addresses are immediately truncated to a /24 subnet and are never stored in any log or database.
No cookies, ever
We set zero cookies. No session cookies, no tracking cookies, no preference cookies.
No device fingerprinting
We do not read canvas, WebGL, audio, font, or any other fingerprinting vector.
No cross-site tracking
Each site's data is siloed. A visitor on site A cannot be linked to a visit on site B.
No identifiers
No names, email addresses or usernames are collected. The exception is what you choose to put in custom properties yourself.
No persistent user IDs
Visitor hashes are non-persistent by design. They reset every 24 hours. See below for details.

How visitor identification works

To count unique visitors without cookies, we use a daily-salted hash. Here is exactly how it works, no magic, no hidden steps.

The hash formula: SHA-256(daily_salt + domain + truncated_IP + user_agent)
1
IP address is truncated to /24 subnet

Before anything else, the last octet of the visitor's IP is zeroed out. 203.0.113.42 becomes 203.0.113.0. This means up to 256 users on the same network subnet share the same starting point, making the hash far less precise, and impossible to reverse-map to an individual.

2
Combined with a daily salt that rotates every 24 hours UTC

The salt for the day is derived from the current UTC date combined with your installation's SECRET_KEY, so it changes automatically at midnight UTC and is never stored anywhere. Because the date component changes daily, the same visitor produces a completely different hash on different days, making day-to-day tracking technically impossible, even with access to the database.

3
Combined with your site's domain

The domain of the site being tracked is included in the hash input. This guarantees that hashes are site-specific, a visitor to shop.example.com gets a different hash than the same visitor on blog.example.com. No cross-site data linkage is possible.

4
Combined with your account's SECRET_KEY

A server-side secret key, unique to each Argusmetrics installation, is added to the hash. Even if someone knows the algorithm, the daily salt, and the IP range, they cannot reproduce or reverse the hash without knowing this secret. It is never exposed to the browser or transmitted over the network.

5
Combined with the visitor's user-agent string

The browser's user-agent string is included as the final hash input. This spreads visitors on the same truncated IP and day across more distinct hashes, and the raw user-agent string itself is never stored, only its contribution to the one-way hash.

Result: same visitor = same hash today; different hash tomorrow

This lets us accurately count unique visitors within a day while making it mathematically impossible to track the same person across multiple days. This approach follows the same daily-rotating-hash design used by other privacy-first analytics tools, and is modeled on the criteria French data protection authority CNIL has published for cookie-free audience-measurement tools to qualify for a consent exemption. No regulator has reviewed or endorsed Argusmetrics specifically. You remain responsible for assessing compliance for your own use case.

No cookie banner required

Skip the consent banner

Consent banners exist because of what a tool stores on, or reads from, a visitor's device. Argusmetrics stores nothing there: no cookies, no localStorage, no identifier of any kind.

The visitor's IP address is never stored. It is truncated, then hashed together with a salt that changes daily, and only the hash is kept. A visitor cannot be followed from one day to the next, cannot be singled out within their network, and produces a completely different hash on every site.

Whether that means your deployment needs no banner depends on how you configure it, what you choose to send, and your own legal advice. We can tell you exactly what the software does, and this page does. We cannot tell you what your obligations are.

Your visitors get a cleaner experience. You get data you can actually trust (no consent bias). Everyone wins.

🚫
No annoying popups.
Users who dismiss cookie banners are not counted, giving you skewed data. With Argusmetrics, every visit is measured equally.
No cookies set
No IP address stored, in any form
Nothing written to the visitor's device
All data stays on your own server

Where your data lives

On servers we run, in one database, with nothing handed to anyone else. Here is what is under the hood.

One database, no data brokers

Your analytics live in a single database we operate. Nothing is passed to advertising networks or data brokers, and country lookups happen locally instead of at a third-party service.

PostgreSQL 16

Data is stored in a managed PostgreSQL database with automated backups. Only aggregated event data is persisted, no raw visitor records.

Encrypted in Transit

All data in transit is encrypted via TLS 1.3. The tracking script communicates with the backend over HTTPS exclusively.

GDPR compliance

We've thought through the legal framework so you don't have to spend hours with your DPO.

Data Controller

You are the data controller for your website's analytics and we are your processor, handling only what is strictly necessary to produce your dashboard. Nothing is passed on to advertisers or data brokers.

Data Processing Agreement

Argusmetrics is self-hosted, so nobody else processes your visitors' data: it never leaves your server. If you run an instance for someone else, such as a client, you are their processor and will need an agreement with them. There is a draft in the repository to start from.

Right to Erasure

There is usually nothing to retrieve or delete for one visitor: the hash changes daily and is not linked to a person, so a single visitor's rows cannot be singled out even deliberately. If you send identifying data in custom properties, that is different, and it is yours to find and remove. Deleting a website deletes its data, and closing an account deletes everything, both immediately.

Custom properties are the exception

Everything else on this page is designed so it cannot identify a person. Custom event properties are different: they are whatever your site sends. Put a name, an email address or a user id in one and that is personal data you chose to send, stored as given. That field is under your control, not the product's.

Ready to analyze without compromising privacy?

Add one script to your site and start measuring, with no consent banner and without handing your visitors to anyone else.

View on GitHub