Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm working on Plausible Analytics: https://plausible.io

It's an open source, simple (all metrics on one page), lightweight (1.4 KB), no cookies (no need for cookie banner) and no private data collected (no need for GDPR consent) alternative to Google Analytics.

The code is on GitHub https://github.com/plausible-insights/plausible/



Congrats. Interesting project, looks great.

Could you comment on how you achieve GDPR compliance without the need of me getting a user consent from my visitors? I was always assuming that using a hosted solution like Plausible for analytics will at least result in the visitor IP address leaking to the service provider ... and for this I'd need consent if including your script?


Thank you!

Here's how we've done it. There's no legal precedent but we believe this makes us compliant:

To enhance the visitor privacy, we don’t actually store the raw visitor IP address in our database or logs. We run it through a one-way hash function to scramble the raw IP addresses and make them impossible to recover.

To further enhance privacy, we add the website domain to the IP hash.

We also add the User-Agent string to the hash.

We've shared more details on this here https://plausible.io/data-policy


Thanks. Had a lot on your site before posting, but didn't find that details. Perhaps you should add a link/hint on the frontpage regarding how you address GDPR compliance. (I'm not a lawyer, so I'm not qualified to judge on the solution.)


Thanks for the feedback. We link to it from the top menu under "Why Plausible" as "GDPR / CCPA Compliant" but perhaps there could be a better placement for it. Thanks again!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: