DNT and GPC respected
Browsers sending Do Not Track or Global Privacy Control are opted out by default.
Add data-cookieless to the Metrickle script tag and nothing is written to the visitor's device: no cookies, no local storage. Visitors are counted on the server with a salted hash that changes every day, and the raw IP address is never stored.
| Source | Chart | Visitors | Converted |
|---|---|---|---|
| google.com | 18,240 | 702 | |
| Direct | 11,690 | 561 | |
| utm_source=newsletter | 4,210 | 298 | |
| github.com | 2,130 | 64 |
Nothing stored on any visitor's device, and the numbers you need are still here: visitors, sources, campaigns, funnels and friction.
Cookieless mode is a switch on the script tag or the npm package. Pageviews, custom events, revenue, friction and accessibility settings are all still captured.
The script never sets a cookie in either mode. What cookieless mode turns off is browser storage, which standard mode uses to remember an anonymous id and the current session.
<!-- One attribute: nothing stored on the device -->
<script defer
src="https://app.metrickle.com/m.js"
data-key="mk_pub_…"
data-cookieless></script>
// npm: the same switch
init({ writeKey: "mk_pub_…", cookieless: true });
Without an id on the device, the server works out who's who for one day at a time.
The script sends the event with no visitor id. The server sees the IP address and user agent, as every web server does.
The visitor id is an HMAC of the day, the app, the IP address and the user agent, keyed with a secret that never leaves the server.
The IP address is never stored. The user agent is reduced to browser, operating system and device type.
Because the day is part of the hash, the same person gets a new id each day. Nobody can be followed from one day to the next.
Counting without storage has costs, and it's better to know them up front. The biggest is that a visitor who comes back tomorrow counts as new, so returning-visitor numbers and multi-day retention only work in standard mode.
Sessions are approximated on the server by grouping each visitor's events into 30-minute blocks. Surveys and session replay need to remember things on the device, and replay needs consent, so both stay off.
| Feature | Standard mode | Cookieless mode |
|---|---|---|
| Stored on the device | An anonymous id and session details in browser storage | Nothing |
| Visitors, pages, sources, campaigns | Yes | Yes |
| Goals, funnels, tasks and revenue | Yes | Yes |
| Friction, accessibility settings, heatmaps | Yes | Yes |
| Sessions | Tracked on the device | Approximated on the server |
| Returning visitors across days | Yes | No: the visitor hash changes daily |
| Retention cohorts | Yes | No: every day's visitors look new |
| In-app surveys | Yes | No: they need storage |
| Session replay | Yes, with consent | No: it needs storage and consent |
| Feedback widget | Yes | Yes |
Cookieless mode is one part of it. These apply in every mode.
Browsers sending Do Not Track or Global Privacy Control are opted out by default.
Crawlers, headless browsers, uptime monitors and link previews are dropped before they reach your numbers.
Accept events only from the domains you list, so other websites can't send events into your app.
A GDPR erasure request removes a data subject's events, and their replays in standard mode.
The script never reads what people type into forms, in either mode.
11 KB gzipped and loaded with defer. In cookieless mode the replay code never loads at all.
Cookieless mode means Metrickle stores nothing on the device. Whether that changes what you need to ask visitors for depends on where you operate and what else your site does, so confirm your own obligations with whoever advises you on privacy law.
Cookieless mode means Metrickle stores nothing on the visitor's device, so it gives a banner nothing to ask about on its behalf. Whether you need a banner overall depends on the rest of your site and on the law where you operate. Please confirm that with whoever advises you.
Within a day, one person on one browser and network counts as one visitor. Two people behind the same network with identical browsers can count as one, and someone who switches network mid-day can count as two. Across days everyone counts as new, which is the point.
No. The IP address is used only inside the salted hash and is never stored. Country comes from the network edge that received the request. The user agent is reduced to browser, operating system and device type.
Surveys need to remember who has already been asked, and replay needs to tie a recording to one session on one device. Both need storage on the device, and replay also needs consent, so both stay off when nothing may be stored.
It's a web setting for the script tag and npm package. Mobile SDKs keep an anonymous id in app storage, and any app can send events over HTTP without one, in which case the server derives the same daily-rotating hash.
Free to start. One script tag on the web, one SDK on mobile, and no cookie banner in cookieless mode.
Start tracking for free