Privacy-friendly analytics that just works.
Track pageviews and events without setting a single cookie, fingerprinting visitors, or storing personal data. GDPR and CCPA compliant out of the box.
Free forever for 10k events / month. No card.
Why most analytics tools aren't actually private
Google Analytics, Mixpanel, Heap, and most other major analytics tools work by setting a persistent cookie on every visitor's browser. That cookie identifies the same person across pages, sessions, and sites. It's how they compute things like "returning users" or "30-day retention."
The downside is everything privacy regulators care about: persistent identifiers, cross-site tracking, IP addresses stored alongside behavioral data, and a real obligation to show a cookie consent banner on every page. Plus the cookie banners themselves cost you 5–15% of your traffic in users who decline or bounce.
How Gizmo does it instead
Our tracker doesn't set cookies. It doesn't use localStorage. It doesn't fingerprint canvas, fonts, or hardware. We never store the visitor's IP address.
To count distinct visitors for a single day's metrics, we generate a per-day identifier by hashing the visitor's IP address, User-Agent, the site domain, and a daily-rotating salt. Only 16 hex characters of that hash survive — never the IP, never the User-Agent. The salt rotates at midnight UTC, so the same visitor on Monday and Tuesday looks like two different visitors. Counting works. Tracking doesn't.
visitor_id = sha256(daily_salt + utc_date + workspace_id + ip + user_agent).slice(0, 16)
Same approach as Plausible, Fathom, and Simple Analytics. Compliant with GDPR's anonymization standards. Does not require a cookie banner under the EU ePrivacy Directive.
What you get
Visitors, pageviews, bounce rate, average visit duration, top pages, top referrers, geo and device breakdowns. The numbers analytics products are supposed to give you.
Built-in MCP server. Connect Claude, Cursor, Codex, or any MCP-compatible assistant — your AI can install tracking, query stats, and tag sites for you.
Track 1 site or 100. We don't charge per project, and no plan caps the number of sites.
Drop one script. Sites auto-create from the first event — no project IDs, no setup wizards.
What about regulatory compliance?
No cookies, no PII, no cross-site identifiers. Anonymized visitor IDs that rotate daily satisfy GDPR's data- minimization requirements. No cookie banner needed under the ePrivacy Directive.
We don't sell personal information and we don't collect anything CCPA classifies as personal. Visitors to customer sites have no opt-out to exercise because there's nothing to opt out of.
Same as GDPR. Cookieless tracking is exempt from consent-banner requirements under Section 6 of PECR.
Cookieless analytics with anonymized identifiers fall under the "exempt" category in CNIL's guidance. No banner required.
For specifics, see our privacy policy. For everything else, our contact form.
Try privacy-friendly analytics
in two minutes.
10,000 events/month free, forever. Unlimited sites. Full MCP access. No card required.