stalkyoursaas

Privacy

Short version: we do not know who your visitors are, and we could not tell you if you asked.

What we store about your visitors

For each event: the page path, the referring domain, a coarse device and browser label, a country code if your CDN supplies one, timings for requests your site made, and the text of any error that occurred.

How a visitor is identified

By a hash of a daily-rotating secret, the site id, the IP address and the user agent. The secret changes at midnight UTC, so the same person is a different, unlinkable value tomorrow. The same person on two different sites produces two unrelated values. The raw IP address is used to compute that hash and is never written to disk.

Cookies

None on your visitors. We set one cookie on you, the account holder, to keep you logged in. Because nothing is stored on a visitor’s device, you do not need a consent banner for us.

URLs

Query strings are dropped in the browser before sending and dropped again on our server. Numeric and UUID path segments are replaced (/order/8812 becomes /order/:id) so nothing identifying survives in a path.

Retention

Raw events are deleted after 90 days by default, and you can shorten that in Settings. Daily summaries are kept while your account exists. Deleting a site deletes everything belonging to it immediately. Deleting your account deletes all of it.

Who else sees it

Nobody. There is no ad network, no data broker, no third-party analytics on this app. Data is stored with Turso and the app runs on Vercel; those two hold it because they host it, not because they use it.

Contact

Email the address on the account you signed up with, and we will answer from the same place.

Last updated 31 August 2026.