Track
Privacy and data
Cookieless mode, excluding your own traffic, bots, and exporting or deleting a person's data.
AnyAnalytics is built to collect what you need for good numbers and little else. This page explains what's stored, the switches you have, and how to answer a person who asks for their data.
What's stored on the device
By default, the script tag and the JavaScript SDK keep a small record in the browser's localStorage: a random anonymous id, the user id if you called identify(), the current session, and events waiting to be sent. The anonymous id and session (not the user id) are also kept in two first-party cookies on your domain, so a visitor stays the same person across your subdomains (see Subdomains; data-cookie-domain="false" turns them off). The game and mobile SDKs keep the same things in the app's own storage.
Cookieless mode
Cookieless mode stores nothing at all in the visitor's browser: no cookies, no localStorage. Add data-cookieless to the script tag:
<script defer src="https://api.anyanalytics.org/script.js" data-key="vxw_YOUR_WRITE_KEY" data-cookieless></script>Or pass cookieless: true to the JavaScript SDK:
analytics.init({
writeKey: "vxw_YOUR_WRITE_KEY",
host: "https://api.anyanalytics.org",
cookieless: true,
});How visitors are counted
- Each visitor gets an id made from a one-way hash of their IP address, their browser's user agent and your project, mixed with a random value that changes every day. The IP address itself isn't kept.
- The same browser keeps one id for the day. The next day it gets a new one, and the two can't be linked. Ids from different projects can't be linked either.
- Sessions still work: a new one starts after 30 minutes without activity.
What you give up
- Returning visitors and retention only cover a single day, since a visitor can't be recognized across days.
identify()only lasts for the current page. Call it again after each page load.- Events that couldn't be sent (because the visitor went offline) are lost when the page reloads, since there's nowhere to keep them.
Note
Whether you need a consent banner depends on where you and your visitors are and on what else your site does. Check your local rules; this page isn't legal advice.
Excluding your own traffic
Keep your own visits and your team's out of the numbers in two ways:
- Per browser. Open any page of your site with
?anyanalytics_ignore=trueonce, and the script tag stops tracking that browser. Use?anyanalytics_ignore=falseto undo it. You can also do it from Settings → Traffic filters. Repeat it in each browser you use. - By IP address. In Settings → Traffic filters, list your office, home or test machines: one IP address or CIDR range (like
203.0.113.0/24) per line, IPv4 or IPv6, up to 100 entries. Events from those addresses are dropped before they're stored. Changes apply within a minute.
IP exclusion needs the visitor's real address. If you send events through your own proxy, see Locations and IP addresses.
Bots and automated traffic
You don't need to set anything up for this. The script tag doesn't run in automated browsers, and when events arrive we drop those from search engine crawlers, link previews, uptime monitors, AI crawlers and known referrer-spam sites. Scripted HTTP clients are dropped when they claim to be a web browser. See What gets filtered out.
IP addresses
We use the IP address of each request to work out an approximate location (country, region and city). The address itself is never stored with your events. Events sent from server code get no location from the request, since a server's address says nothing about your user.
What's kept from URLs
URLs often carry things that shouldn't end up in analytics: password-reset tokens, login codes, email addresses. Before a page URL or referrer is recorded, the SDK removes the fragment (#…) and every query parameter except utm_source, utm_medium, utm_campaign, utm_term, utm_content and ref. Ad click ids like gclid are recorded by name only, never their value.
The JavaScript SDK's urlQueryParams option lets you keep extra parameters you know are safe.
Exporting or erasing a person's data
When someone asks for their data, find them in Persons (search by user id or a property such as email) and open their profile. Owners and admins see two buttons:
| Button | What it does |
|---|---|
| Export data (JSON) | Downloads everything recorded about the person: their profile, ids and every event with its properties and context. |
| Erase data | Permanently deletes every event, session, property and id of the person. Report totals drop accordingly. This can't be undone. |
Erasing removes what's already stored. If the person's device keeps sending events with the same id, they'll appear again, so stop tracking them in your app as well (for example by calling reset()).
Data retention
Each project keeps its data until you say otherwise. To keep less, open Settings → Data & privacy and pick how long to keep events: 30, 90 or 180 days, or 1, 2 or 3 years. Older events are deleted every day, along with the sessions and visitor activity built from them, and reports can't look further back afterwards. Shortening the period deletes the older data within a day of saving.
Your responsibilities
For the data you collect about your own visitors and players, you decide what's tracked and why, and we process it on your behalf. That usually means:
- Telling your users what you collect, in your own privacy policy.
- Asking for consent where your local rules require it.
- Not sending data you don't need, especially sensitive personal data, in properties.
- Answering access and deletion requests, with the tools above.
Rules differ by country, so check the ones that apply to you. Our privacy policy and terms describe how we handle data on our side.