Metrickle

Data and privacy

How Metrickle handles the analytics data your apps send about their visitors: what is collected, what is left out, and how you delete it.

Last updated:

About this page

This page explains how Metrickle handles analytics data: the data your apps send about their visitors, and how you can control and delete it. It describes how the product works today.

It is not Metrickle's privacy policy. The privacy policy, terms of service, data processing agreement and list of subprocessors are coming soon and will be linked from the trust center.

What is stored for each event

Each page view, click or custom event your app sends is stored with:

  • the app it belongs to, an event id, timestamps, the event type and name;
  • a visitor id, a session id and, only if your app sets one with identify, your own user id for that person;
  • the page path, the page URL without its query string, and the page title;
  • the full referrer URL and the referrer's domain;
  • UTM source, medium, campaign, term and content;
  • country, region and city, taken from Cloudflare's request data;
  • platform, device type, operating system, browser, app version, screen size and locale;
  • a revenue value and custom properties, if your app sends them;
  • accessibility setting flags, such as reduced motion or large text, and whether the visitor has been navigating by keyboard.

Survey answers are stored as events too.

What is not stored

  • IP addresses. The raw IP address is not stored with events.
  • User-agent strings. The raw user-agent string is not stored. It is reduced to the browser, operating system and device type.
  • Query strings. Page URLs are stored without them.
  • Form input. The web script never reads the values of form fields.
  • Private text. Text inside elements marked data-mk-mask or data-private is never captured.
  • Bot traffic. Requests from known bots, or with no user agent, are dropped.

Cookieless mode

Add data-cookieless to the web script tag and nothing is stored on the visitor's device: no cookies, no local storage and no session storage.

  • Visitors are counted with an id made by hashing the day, the app, the IP address and the user agent together with a secret key held by Metrickle (HMAC-SHA256). The id changes every day, so visits on different days are not linked.
  • The raw IP address is never stored.
  • Sessions are approximated in 30-minute windows.
  • Surveys and session replay are turned off for visitors in cookieless mode.

What the web script stores in the browser

Outside cookieless mode, the web script keeps a few values in the browser so it can recognise a returning visitor, group events into sessions and remember choices. It does not set cookies.

Browser storage used by the Metrickle web script outside cookieless mode
KeyStoragePurpose
mk_aidLocal storageA random visitor id.
mk_uidLocal storageYour user id for the visitor, only if your app sets one with identify.
mk_sidLocal storageThe current session id. A new session starts after 30 minutes without activity.
mk_optoutLocal storageRemembers that the visitor opted out, so nothing more is sent.
mk_consentLocal storageRemembers whether the visitor has consented to session replay.
mk_surveysLocal storageWhich surveys the visitor has seen or answered, so they are not asked again too often.
mk_kbdSession storageRemembers, for the current tab, that the visitor has been navigating by keyboard.
mk_rp_seq: followed by the session idSession storageNumbers session replay chunks in order. Only used when replay is recording.

Visitors' choices

  • The web script honours Do Not Track and Global Privacy Control by default: if either is switched on, the visitor is opted out.
  • Your app can offer an opt-out. Once a visitor opts out, the choice is remembered.
  • Session replay waits for the visitor's consent by default (see below).

Session replay

Session replay records how a page changes during a visit so you can watch it back. It is designed to leave out personal data by default:

  • It is off by default and switched on per app.
  • It records a sample of sessions, 10% by default.
  • It waits for consent by default. Your site calls metrickle.consent({ replay: true }) when the visitor agrees.
  • Every input is masked, and all page text is masked by default. You can opt specific text in with data-mk-unmask.
  • Elements marked data-mk-block are replaced with placeholders and not recorded.
  • Canvas content and fonts are not recorded.
  • It never records visitors in cookieless mode.
  • Recordings are stored as compressed chunks in private Cloudflare R2 storage, and are only served through the dashboard API to people who are signed in.

Heatmaps, feedback and surveys

  • Heatmaps are off by default. When switched on, they record where a click landed, a selector for the element clicked, and a masked version of the element's label.
  • Feedback can include a screenshot if the visitor chooses to attach one: a PNG, JPEG or WebP image of up to 2 MB, stored in private Cloudflare R2 storage.
  • Survey answers are stored as events, alongside the visitor's other events.

How long data is kept, and deleting it

There is currently no automatic retention period. Data is kept until you delete it or erase a visitor's data. Configurable data retention is on our roadmap.

Erasing one person's data

Workspace owners and admins can erase a person's data by their visitor id or by your user id. This deletes:

  • their events, including survey answers;
  • their session replay recordings and the index that lists them;
  • their feedback reports, with any screenshots.

Deleting an app

When an app is deleted, its events, session replays and feedback screenshots are purged in the background.

AI

Metrickle does not send your analytics data to an AI provider.

You can connect your own AI assistant to Metrickle over MCP. The assistant reads your data with an API token you create, and can only see what you can see. Which AI provider receives that data is your choice.

Metrickle's own team has an optional tool that drafts emails to Metrickle's customers. It sends account-level customer information to Anthropic's API to write those drafts. It does not send any of your visitors' event data or email addresses.

Services Metrickle uses

Third-party services used to run Metrickle
ServiceUsed for
CloudflareHosting, storage and sending email.
AnthropicOptional, and only for drafting Metrickle's own emails to its customers, as described above.
GitHub and GoogleSigning in to the dashboard, only if you choose to sign in with them.

metrickle.com loads no external fonts, no third-party CDNs and no advertising trackers.

How we measure our own sites

Metrickle measures metrickle.com with Metrickle, in cookieless mode, so nothing is stored on your device when you visit this site.

The dashboard at app.metrickle.com sends only an opaque user id to identify you, not your name or email address.

Outreach emails Metrickle sends include a one-click unsubscribe header, and their unsubscribe links are signed so they cannot be forged.

Questions

For questions about how Metrickle handles data, email privacy@metrickle.com.