What don't you collect?
The list that matters more than the one about what we do collect.
No cookies. None. Not for measurement, not for “functionality”.
No IP address on disk. The address is used in memory for the country lookup and the daily hash, then dropped. The stored event has nowhere to put one - there’s no field for it.
No identifier that survives the day. The visitor hash is rebuilt from a new salt every UTC day, and the old salt is unrecoverable. Nobody can join Tuesday’s visitors to Monday’s, including us.
No cross-site tracking. Your domain is part of the hash input, so the same person on two customers’ sites is two unrelated numbers. There’s no network, no shared audience, no lookalike anything.
No user profiles and no user-level reports. There’s no screen anywhere that shows you one person’s path through the site as a person. Reports are counts.
No session replay, no heatmaps, no scroll recordings, no mouse tracking. Not a roadmap item - a decision.
No fingerprinting beyond that daily hash. No canvas, no fonts, no audio context, no device enumeration.
No third-party requests from the script. It talks to one endpoint. Even the little source icons in the dashboard are proxied through our own origin, so the site that referred your visitor never hears about it.
No advertising anything. We don’t sell it, share it, or hand it to a data broker. Ever. The whole privacy model is built on there being nothing worth taking.
The one thing we can’t promise not to collect is what you send us yourself. If you put a customer’s email into a custom property, it lands in the database. Don’t.
More on privacy and the law
Didn't answer it? Email help@feasible.lol. A person reads it, and if the answer belongs here we'll add it.