Metrickle

Analytics without cookies or local storage

Add data-cookieless to the Metrickle script tag and nothing is written to the visitor's device: no cookies, no local storage. Visitors are counted on the server with a salted hash that changes every day, and the raw IP address is never stored.

acme.comcookieless mode · last 30 days
Visitors48,210▲ 27%
Conversion4.1%▲ 0.4 pts
Bounce rate38%
Top sources by visitors and conversions
SourceChartVisitorsConverted
google.com18,240702
Direct11,690561
utm_source=newsletter4,210298
github.com2,13064

Nothing stored on any visitor's device, and the numbers you need are still here: visitors, sources, campaigns, funnels and friction.

One attribute on the script tag

Cookieless mode is a switch on the script tag or the npm package. Pageviews, custom events, revenue, friction and accessibility settings are all still captured.

The script never sets a cookie in either mode. What cookieless mode turns off is browser storage, which standard mode uses to remember an anonymous id and the current session.

  • No cookies, no local storage, no session storage.
  • Same dashboard: visitors, sources, campaigns, goals, funnels and friction work as before.
  • Mix per app: run your marketing site cookieless and your signed-in product in standard mode.
<!-- One attribute: nothing stored on the device -->
<script defer
  src="https://app.metrickle.com/m.js"
  data-key="mk_pub_…"
  data-cookieless></script>

// npm: the same switch
init({ writeKey: "mk_pub_…", cookieless: true });

A salted hash that forgets everyone at midnight

Without an id on the device, the server works out who's who for one day at a time.

  1. A request arrives

    The script sends the event with no visitor id. The server sees the IP address and user agent, as every web server does.

  2. The server hashes it

    The visitor id is an HMAC of the day, the app, the IP address and the user agent, keyed with a secret that never leaves the server.

  3. The raw values are dropped

    The IP address is never stored. The user agent is reduced to browser, operating system and device type.

  4. Tomorrow, a new hash

    Because the day is part of the hash, the same person gets a new id each day. Nobody can be followed from one day to the next.

What you give up in cookieless mode

Counting without storage has costs, and it's better to know them up front. The biggest is that a visitor who comes back tomorrow counts as new, so returning-visitor numbers and multi-day retention only work in standard mode.

Sessions are approximated on the server by grouping each visitor's events into 30-minute blocks. Surveys and session replay need to remember things on the device, and replay needs consent, so both stay off.

What works in standard mode and in cookieless mode
FeatureStandard modeCookieless mode
Stored on the deviceAn anonymous id and session details in browser storageNothing
Visitors, pages, sources, campaignsYesYes
Goals, funnels, tasks and revenueYesYes
Friction, accessibility settings, heatmapsYesYes
SessionsTracked on the deviceApproximated on the server
Returning visitors across daysYesNo: the visitor hash changes daily
Retention cohortsYesNo: every day's visitors look new
In-app surveysYesNo: they need storage
Session replayYes, with consentNo: it needs storage and consent
Feedback widgetYesYes

The rest of the privacy defaults

Cookieless mode is one part of it. These apply in every mode.

DNT and GPC respected

Browsers sending Do Not Track or Global Privacy Control are opted out by default.

Bots filtered

Crawlers, headless browsers, uptime monitors and link previews are dropped before they reach your numbers.

Origin allowlists

Accept events only from the domains you list, so other websites can't send events into your app.

Erasure per person

A GDPR erasure request removes a data subject's events, and their replays in standard mode.

No field values

The script never reads what people type into forms, in either mode.

Small and deferred

11 KB gzipped and loaded with defer. In cookieless mode the replay code never loads at all.

Cookieless mode means Metrickle stores nothing on the device. Whether that changes what you need to ask visitors for depends on where you operate and what else your site does, so confirm your own obligations with whoever advises you on privacy law.

Common questions

Do I still need a cookie banner?

Cookieless mode means Metrickle stores nothing on the visitor's device, so it gives a banner nothing to ask about on its behalf. Whether you need a banner overall depends on the rest of your site and on the law where you operate. Please confirm that with whoever advises you.

How accurate are visitor counts without cookies?

Within a day, one person on one browser and network counts as one visitor. Two people behind the same network with identical browsers can count as one, and someone who switches network mid-day can count as two. Across days everyone counts as new, which is the point.

Does Metrickle store IP addresses?

No. The IP address is used only inside the salted hash and is never stored. Country comes from the network edge that received the request. The user agent is reduced to browser, operating system and device type.

Why are surveys and replay off in cookieless mode?

Surveys need to remember who has already been asked, and replay needs to tie a recording to one session on one device. Both need storage on the device, and replay also needs consent, so both stay off when nothing may be stored.

Does cookieless mode apply to mobile apps?

It's a web setting for the script tag and npm package. Mobile SDKs keep an anonymous id in app storage, and any app can send events over HTTP without one, in which case the server derives the same daily-rotating hash.

See where your apps break, and who they break for

Free to start. One script tag on the web, one SDK on mobile, and no cookie banner in cookieless mode.

Start tracking for free