Skip to content

Website privacy & cookies

No optional analytics or advertising is configured in this website application. There is no optional tracking preference to save. Dismissing the notice only hides it until this page reloads; closing this panel does not give consent to anything.

Our source and public-response check is limited. Hosting logs, security challenges, enquiry handling and retention still need confirmation. The information pages are review-needed, not a complete approved privacy or cookie policy.

You can browse without an enquiry. The demo form explains whether it opens a mail draft or submits to a configured endpoint, and includes a clear-fields control. These website choices do not change consent on customer websites using INSIGHTS.

Website analytics your DPO will sign

Your consent banner hides most of your audience. Measure it anyway, lawfully.

INSIGHTS reports how your site is used across every visitor, consenting or not, as aggregate figures that are never personal data: no cookies, no identifiers, no fingerprinting, keys destroyed on a fixed clock, small groups withheld. Every number tells you which visitors it covers and whether it was counted or estimated.

One tag · No client-side storage or fingerprinting · Aggregate reports · Evidence pack for your reviewers

Overview · last 14 days
≈184,201RSE ±0.81%
Daily uniquesHLL estimate
731
PageviewsMeasured
By countryHLL estimate · RSE ±0.81%
United Kingdom74,912
Germany46,180
France35,704
Netherlands20,115
Luxembourg—

One group withheld: below the suppression threshold. Never inferred, never back-filled.

Illustrative aggregate view, not live customer data. Every live report states which visitors and which privacy window it covers.
The problem

Consent rates collapsed. Your analytics went dark. Your decisions did not stop.

Most visitors never click the banner, so conventional analytics now describes a shrinking, self-selected minority. Teams either guess, or quietly reach for fingerprinting and pay for it later.

INSIGHTS takes the third path. It measures the whole audience as aggregates that were never personal data in the first place: page-group traffic and within-window reach, derived from a per-window key that is cryptographically destroyed on a fixed schedule and audited when it happens. Nothing about an individual survives the window, and nothing is joined across windows.

Reports always say which visitors they cover. Security data is never repurposed as an audience, and no report can be walked back to a person.

Counted or estimated

Every figure tells you whether it was counted or estimated.

Pageviews are measured counters. Unique reach inside a privacy window is estimated with fixed-precision p=14 HyperLogLog sketches and shown with RSE ±0.81%. Monthly reach is modelled from a calibrated revisit factor and always carries a 90% confidence band; it is never presented as a count.

≈184,201RSE ±0.81%
Daily unique visitorsHLL estimate
12.4%
Bot-classified requestsMeasured

Illustrative figures. HLL estimates show their relative standard error and interval; counted request metrics are labelled measured and remain band-free.

The architecture

Three lanes. Three permissions. One tag.

Anonymous statistics, consent-accepted analytics and security each run under their own permission, keys and lifetime, and reports never blur them. That separation is what lets a reviewer say yes.

01

Anonymous statistics lane

The visitors who never answer your banner are still your audience. This lane counts their page groups and within-window reach with no cookie, no identifier and no cross-window linkage, under a controller attestation your DPO signs off once per configuration. Objections are honoured in the browser before anything is sent.

02

Consent-accepted lane

For visitors who accept analytics: measured pageviews and reach by page group, country, device and network. The SDK uses no client-side storage and no fingerprinting; a memory-only deduplication token updates a HyperLogLog sketch, and the salt that makes it work is destroyed at the end of every privacy window.

03

Security lane

Bots, abuse and scraping are measured regardless of consent, with separate keys and a 7-day raw-signal retention limit. Only bot_label and confidence cross into analytics. Security data is never repurposed as an audience.

What you cannot ask

Reports describe groups, never a person's history.

There is no visitor lookup, no session replay and no raw-event export. Those routes do not exist, and executable checks fail the build if they ever appear. That is the answer to the hardest question in your DPIA, and it is a property of the design, not a policy.

  • GET /visitors
  • GET /sessions
  • GET /events
  • GET /subject
  • GET /lookup
  • GET /export/raw

Operational query boundaries are covered by INV-007 and INV-012. Separately gated consented recent activity is outside the current beta scope.

Controls and evidence

Every privacy claim ships with the test that proves it.

A claim without a test is a claim we cannot evidence, so each one below is enforced in the release pipeline, and the destruction of every window key is written to a signed, hash-chained audit record you can hand to a regulator. Ask for the evidence pack; it is part of the product.

INV-001

No client-side storage

The browser beacon touches no cookie, no localStorage, no sessionStorage, no IndexedDB. Asserted by walking the minified bundle's AST, not by grepping source.

INV-002

No fingerprinting inputs

No canvas, no audio context, no font enumeration, no hardware or screen interrogation. The event schema is a closed allowlist with additionalProperties: false.

INV-003

The dedup token is never persisted

The operational token is restricted to process memory and zeroised after use. Release tests and store/log sweeps are designed to detect persistence. Ask for the actual results and their coverage, not just the test’s existence.

INV-007

Aggregate-only, k-thresholded

Operational reports return aggregate rows with small-group suppression and query restrictions. Separately gated consented features are not enabled by these aggregate reporting permissions.

INV-008

A two-field lane boundary

The security lane holds raw signals under its own short TTL. Its interface to the operational lane carries exactly two fields, a bot label and a confidence score, and is closed to additions.

INV-012

No operational subject lookup

Reports cannot look up a person or export raw events, in any lane. There is no profile API, consented or otherwise, behind the aggregate reporting permissions.

Bring your DPO. Leave with a yes.

Thirty minutes: the dashboard on a traffic profile like yours, the three-lane model, and the evidence pack your reviewers will ask for, so the conversation that usually takes a quarter takes an afternoon.