Your consent banner hides most of your audience. Measure it anyway, lawfully.
INSIGHTS reports how your site is used across every visitor, consenting or not, as aggregate figures that are never personal data: no cookies, no identifiers, no fingerprinting, keys destroyed on a fixed clock, small groups withheld. Every number tells you which visitors it covers and whether it was counted or estimated.
One tag · No client-side storage or fingerprinting · Aggregate reports · Evidence pack for your reviewers
One group withheld: below the suppression threshold. Never inferred, never back-filled.
Consent rates collapsed. Your analytics went dark. Your decisions did not stop.
Most visitors never click the banner, so conventional analytics now describes a shrinking, self-selected minority. Teams either guess, or quietly reach for fingerprinting and pay for it later.
INSIGHTS takes the third path. It measures the whole audience as aggregates that were never personal data in the first place: page-group traffic and within-window reach, derived from a per-window key that is cryptographically destroyed on a fixed schedule and audited when it happens. Nothing about an individual survives the window, and nothing is joined across windows.
Reports always say which visitors they cover. Security data is never repurposed as an audience, and no report can be walked back to a person.
Every figure tells you whether it was counted or estimated.
Pageviews are measured counters. Unique reach inside a privacy window is estimated with fixed-precision p=14 HyperLogLog sketches and shown with RSE ±0.81%. Monthly reach is modelled from a calibrated revisit factor and always carries a 90% confidence band; it is never presented as a count.
Illustrative figures. HLL estimates show their relative standard error and interval; counted request metrics are labelled measured and remain band-free.
Three lanes. Three permissions. One tag.
Anonymous statistics, consent-accepted analytics and security each run under their own permission, keys and lifetime, and reports never blur them. That separation is what lets a reviewer say yes.
Anonymous statistics lane
The visitors who never answer your banner are still your audience. This lane counts their page groups and within-window reach with no cookie, no identifier and no cross-window linkage, under a controller attestation your DPO signs off once per configuration. Objections are honoured in the browser before anything is sent.
Consent-accepted lane
For visitors who accept analytics: measured pageviews and reach by page group, country, device and network. The SDK uses no client-side storage and no fingerprinting; a memory-only deduplication token updates a HyperLogLog sketch, and the salt that makes it work is destroyed at the end of every privacy window.
Security lane
Bots, abuse and scraping are measured regardless of consent, with separate keys and a 7-day raw-signal retention limit. Only bot_label and confidence cross into analytics. Security data is never repurposed as an audience.
Reports describe groups, never a person's history.
There is no visitor lookup, no session replay and no raw-event export. Those routes do not exist, and executable checks fail the build if they ever appear. That is the answer to the hardest question in your DPIA, and it is a property of the design, not a policy.
GET /visitorsGET /sessionsGET /eventsGET /subjectGET /lookupGET /export/raw
Operational query boundaries are covered by INV-007 and INV-012. Separately gated consented recent activity is outside the current beta scope.
Every privacy claim ships with the test that proves it.
A claim without a test is a claim we cannot evidence, so each one below is enforced in the release pipeline, and the destruction of every window key is written to a signed, hash-chained audit record you can hand to a regulator. Ask for the evidence pack; it is part of the product.
No client-side storage
The browser beacon touches no cookie, no localStorage, no sessionStorage, no IndexedDB. Asserted by walking the minified bundle's AST, not by grepping source.
No fingerprinting inputs
No canvas, no audio context, no font enumeration, no hardware or screen interrogation. The event schema is a closed allowlist with additionalProperties: false.
The dedup token is never persisted
The operational token is restricted to process memory and zeroised after use. Release tests and store/log sweeps are designed to detect persistence. Ask for the actual results and their coverage, not just the test’s existence.
Aggregate-only, k-thresholded
Operational reports return aggregate rows with small-group suppression and query restrictions. Separately gated consented features are not enabled by these aggregate reporting permissions.
A two-field lane boundary
The security lane holds raw signals under its own short TTL. Its interface to the operational lane carries exactly two fields, a bot label and a confidence score, and is closed to additions.
No operational subject lookup
Reports cannot look up a person or export raw events, in any lane. There is no profile API, consented or otherwise, behind the aggregate reporting permissions.
Bring your DPO. Leave with a yes.
Thirty minutes: the dashboard on a traffic profile like yours, the three-lane model, and the evidence pack your reviewers will ask for, so the conversation that usually takes a quarter takes an afternoon.