Privacy by design

Web analytics that is
GDPR compliant and cookie-free

Statalog collects no personal data, places no cookies, and never tracks your visitors across devices or sites. Full privacy compliance — built in, not bolted on.

GDPR Compliant
CCPA Compliant
PECR Compliant
No Cookie Banner
No Consent Needed

Privacy is built into every pageview

Four principles that shape every design decision.

No cookies — ever

We do not read or write any cookies. Visitors are identified by an ephemeral hash derived from IP + user-agent + a daily-rotating salt. The hash is not reversible and resets every 24 hours.

No personal data stored

Raw IPs are never saved to disk. We store country, region and (optionally) city — derived once and discarded. No names, no emails, no device IDs.

No cross-site tracking

Each site is an isolated namespace. A visitor on site A is not recognised on site B — even on the same Statalog instance. No advertising network involvement.

Your data stays yours

Whether self-hosted or cloud, your analytics data is not combined with anyone else's, not used to train models, and not sold. Export it any time.

Compliant with the regulations that matter

Whether you serve users in the EU, UK, California or elsewhere — Statalog is compliant by default.

EU

GDPR

The EU's General Data Protection Regulation. Because we process no personal data, Statalog sits outside the regulation's scope — no lawful basis required.

California

CCPA / CPRA

No sale of personal information, no data sharing with third-party advertisers, no targeted ads. Your California users are covered.

UK

PECR

The UK's Privacy and Electronic Communications Regulations require explicit consent for non-essential cookies. We use none.

Stop asking for cookie consent

Ship your site without a consent banner. Your visitors get a faster, cleaner experience — you get accurate analytics.