Privacy Policy

Effective October 5, 2026 · Vexil LLC

This policy explains what Vexil LLC collects when you use AnyAnalytics, what we process for our customers about their players and visitors, and the choices you have.

1.Two kinds of data, two roles

  • Your account data (you, as a AnyAnalytics customer): Vexil LLC is the controller and decides how it's used, as described here.
  • Analytics data that our customers' games, apps and websites send us about their own players and visitors: the customer is the controller and Vexil LLC is their processor, handling it only on their instructions. If you're a player or visitor, please contact the game or website you used; we'll help them answer you.

2.What we collect about customers

  • Account: your name, email address, whether you've confirmed it, and a securely hashed password, plus the organizations you belong to, your role in them, and invitations you send or receive (with the invitee's email address).
  • Sign-in sessions: the IP address and browser (user agent) of each active session, to keep your account secure and let you recognise your sessions.
  • Billing: your plan and our payment processor's customer and subscription identifiers. To create your subscription we share your name, email address and organization name with the payment processor. Card details are entered on its pages and never reach our servers.
  • What you configure: projects, saved insights, dashboards, shared links, read API keys, alert settings and integration secrets (secrets and webhook addresses are stored encrypted).
  • How you use AnyAnalytics: pages you visit on our website and dashboard, and actions like signing up, creating a site or starting a checkout, measured with AnyAnalytics itself. When you're signed in, these are linked to your account id and name.
  • Account administration: records of actions Vexil LLC staff take on accounts (for example granting a plan or suspending an account for abuse), and the reason given.
  • Operational logs: request logs that include IP addresses and browser details, and error reports, used to run and secure the Service and rotated automatically (typically within days). IP addresses are also used for a few minutes at a time to apply rate limits.

3.Analytics data we process for customers

Depending on how a customer sets up our SDKs, events can include:

  • event names and the properties the customer chooses to send;
  • on websites, the pages viewed, their titles, and referrers;
  • a pseudonymous id for the player or visitor, and the user id the customer assigns after sign-in;
  • device and app details: platform, operating system, browser, app version, screen and language;
  • approximate location (country, region, city), derived from the IP address when the event arrives. The IP address itself is not stored with events;
  • if the customer connects their Stripe account: payments and refunds (amount, currency and Stripe ids), matched to the player or visitor who paid. No names, email addresses or card details are imported.

On websites our SDK keeps a random id, the current session and any events not yet sent in the browser's local storage. In cookieless mode it stores nothing in the browser; instead a one-day id is computed per site from a hash of a salt that changes daily (and is deleted after two days), the IP address and the browser, which can't be reversed or linked across days.

4.Cookies and local storage

  • Sign-in: aa.session_token keeps you signed in (up to 30 days, renewed as you use the dashboard) and aa.session_data caches your session for a few minutes.
  • Password-protected shared links: a cookie starting with aa_share_ remembers that you entered the password, for up to 12 hours.
  • Dashboard preferences in local storage, such as dismissed notices and chart views.
  • Our own analytics in local storage: a random id, the current session and unsent events (see "How you use AnyAnalytics" above). You can opt out on any page with ?anyanalytics_ignore=true.

5.How we use data

  • to provide the Service: store events, compute reports, send alerts and reports you set up;
  • to measure plan usage and bill for it;
  • to secure the Service, prevent abuse and fix problems;
  • to understand how our website and dashboard are used, and improve them;
  • to email you about your account, usage and important changes.

6.What we don't do

We don't sell personal data, don't use customers' analytics data for advertising, and don't combine one customer's data with another's.

7.Who we share data with

We use service providers for hosting, payments and email delivery, under contracts that protect your data and limit how they may use it. We may also disclose data when the law requires it.

8.How long we keep data

  • Account data: while your account exists. To close your account, email support@vexil.io; we delete it within 30 days.
  • Analytics data: for the history your plan includes plus 30 days, or less if a customer sets a shorter retention in project settings. Deleting a project deletes its analytics data right away. Data of organizations without a plan is kept until they choose one, delete it, or close their account.
  • Backups: deleted data can remain in our encrypted backups for up to 14 more days, until those backups expire.
  • Billing records: as long as tax and accounting law requires.

9.Your rights

Depending on where you live, you can ask to access, correct, export or delete your personal data, or object to or restrict how we use it. Customers can export or delete a player's or visitor's data directly in the dashboard (Settings → Data & privacy). You can also complain to your local data protection authority.

To exercise a right, email support@vexil.io.

10.Security and transfers

Data is encrypted in transit (HTTPS), secrets are encrypted at rest, passwords are hashed, and access is limited to what each person needs. Data is stored in the European Union. Vexil LLC is based in the United States, so our staff may access it from there; where data is transferred across borders, we use safeguards the law recognises, such as the European Commission's standard contractual clauses.

11.Children

The AnyAnalytics dashboard isn't meant for children. Customers whose games are played by children must get any consent the law requires before sending their data, and shouldn't send identifying data about them (see the Terms of Service).

12.Changes and contact

We'll post changes here and email customers about material ones. Questions: support@vexil.io, or write to Vexil LLC, 1209 Mountain Road Pl NE, Ste R, Albuquerque, NM 87110, United States.