Data and privacy
How Metrickle handles the analytics data your apps send about their visitors: what is collected, what is left out, and how you delete it.
Last updated:
About this page
This page explains how Metrickle handles analytics data: the data your apps send about their visitors, and how you can control and delete it. It describes how the product works today.
It is not Metrickle's privacy policy. The privacy policy, terms of service, data processing agreement and list of subprocessors are coming soon and will be linked from the trust center.
What is stored for each event
Each page view, click or custom event your app sends is stored with:
- the app it belongs to, an event id, timestamps, the event type and name;
- a visitor id, a session id and, only if your app sets one with
identify, your own user id for that person; - the page path, the page URL without its query string, and the page title;
- the full referrer URL and the referrer's domain;
- UTM source, medium, campaign, term and content;
- country, region and city, taken from Cloudflare's request data;
- platform, device type, operating system, browser, app version, screen size and locale;
- a revenue value and custom properties, if your app sends them;
- accessibility setting flags, such as reduced motion or large text, and whether the visitor has been navigating by keyboard.
Survey answers are stored as events too.
What is not stored
- IP addresses. The raw IP address is not stored with events.
- User-agent strings. The raw user-agent string is not stored. It is reduced to the browser, operating system and device type.
- Query strings. Page URLs are stored without them.
- Form input. The web script never reads the values of form fields.
- Private text. Text inside elements marked
data-mk-maskordata-privateis never captured. - Bot traffic. Requests from known bots, or with no user agent, are dropped.
Cookieless mode
Add data-cookieless to the web script tag and nothing is stored on the visitor's device: no cookies, no local storage and no session storage.
- Visitors are counted with an id made by hashing the day, the app, the IP address and the user agent together with a secret key held by Metrickle (HMAC-SHA256). The id changes every day, so visits on different days are not linked.
- The raw IP address is never stored.
- Sessions are approximated in 30-minute windows.
- Surveys and session replay are turned off for visitors in cookieless mode.
What the web script stores in the browser
Outside cookieless mode, the web script keeps a few values in the browser so it can recognise a returning visitor, group events into sessions and remember choices. It does not set cookies.
| Key | Storage | Purpose |
|---|---|---|
mk_aid | Local storage | A random visitor id. |
mk_uid | Local storage | Your user id for the visitor, only if your app sets one with identify. |
mk_sid | Local storage | The current session id. A new session starts after 30 minutes without activity. |
mk_optout | Local storage | Remembers that the visitor opted out, so nothing more is sent. |
mk_consent | Local storage | Remembers whether the visitor has consented to session replay. |
mk_surveys | Local storage | Which surveys the visitor has seen or answered, so they are not asked again too often. |
mk_kbd | Session storage | Remembers, for the current tab, that the visitor has been navigating by keyboard. |
mk_rp_seq: followed by the session id | Session storage | Numbers session replay chunks in order. Only used when replay is recording. |
Visitors' choices
- The web script honours Do Not Track and Global Privacy Control by default: if either is switched on, the visitor is opted out.
- Your app can offer an opt-out. Once a visitor opts out, the choice is remembered.
- Session replay waits for the visitor's consent by default (see below).
Session replay
Session replay records how a page changes during a visit so you can watch it back. It is designed to leave out personal data by default:
- It is off by default and switched on per app.
- It records a sample of sessions, 10% by default.
- It waits for consent by default. Your site calls
metrickle.consent({ replay: true })when the visitor agrees. - Every input is masked, and all page text is masked by default. You can opt specific text in with
data-mk-unmask. - Elements marked
data-mk-blockare replaced with placeholders and not recorded. - Canvas content and fonts are not recorded.
- It never records visitors in cookieless mode.
- Recordings are stored as compressed chunks in private Cloudflare R2 storage, and are only served through the dashboard API to people who are signed in.
Heatmaps, feedback and surveys
- Heatmaps are off by default. When switched on, they record where a click landed, a selector for the element clicked, and a masked version of the element's label.
- Feedback can include a screenshot if the visitor chooses to attach one: a PNG, JPEG or WebP image of up to 2 MB, stored in private Cloudflare R2 storage.
- Survey answers are stored as events, alongside the visitor's other events.
How long data is kept, and deleting it
There is currently no automatic retention period. Data is kept until you delete it or erase a visitor's data. Configurable data retention is on our roadmap.
Erasing one person's data
Workspace owners and admins can erase a person's data by their visitor id or by your user id. This deletes:
- their events, including survey answers;
- their session replay recordings and the index that lists them;
- their feedback reports, with any screenshots.
Deleting an app
When an app is deleted, its events, session replays and feedback screenshots are purged in the background.
AI
Metrickle does not send your analytics data to an AI provider.
You can connect your own AI assistant to Metrickle over MCP. The assistant reads your data with an API token you create, and can only see what you can see. Which AI provider receives that data is your choice.
Metrickle's own team has an optional tool that drafts emails to Metrickle's customers. It sends account-level customer information to Anthropic's API to write those drafts. It does not send any of your visitors' event data or email addresses.
Services Metrickle uses
| Service | Used for |
|---|---|
| Cloudflare | Hosting, storage and sending email. |
| Anthropic | Optional, and only for drafting Metrickle's own emails to its customers, as described above. |
| GitHub and Google | Signing in to the dashboard, only if you choose to sign in with them. |
metrickle.com loads no external fonts, no third-party CDNs and no advertising trackers.
How we measure our own sites
Metrickle measures metrickle.com with Metrickle, in cookieless mode, so nothing is stored on your device when you visit this site.
The dashboard at app.metrickle.com sends only an opaque user id to identify you, not your name or email address.
Outreach emails Metrickle sends include a one-click unsubscribe header, and their unsubscribe links are signed so they cannot be forged.
Questions
For questions about how Metrickle handles data, email privacy@metrickle.com.