Live web analytics. Built for Privacy first.
Every conversion's source in seconds. No names, emails or phones.
- Google / cpc70633%
- Direct49824%
- Instagram33116%
- Newsletter22411%
- Google / organic1989%
- Facebook / cpc924%
- Unattributed653%
Why websites switch
Live in seconds
A paid order is on the dashboard within seconds, not tomorrow.
In the EU, and yours
European hosting. Raw rows and a public API.
No cookie before a yes
No cookie and no local storage until the visitor accepts analytics cookies. Session stitching without a cookie is off unless you turn it on.
No names, emails, phones
Personal fields are dropped in the browser and again on the server, for everyone.
Two paths
| What | Declined analytics cookies, or not answered | Accepted analytics cookies |
|---|---|---|
| WHAT IS STORED ON USER'S DEVICE | Nothing stored | One first-party cookie |
| For how long | Nothing stored | 395 days |
| Session stitching | Off, unless you turn it on. Then a keyed hash for 7 days. | First-party cookie, 395 days |
Side by side
Google Analytics 4 as its public documentation described it on 28 September 2026. Script sizes measured the same day.
Plans that grow with your traffic
Every plan has the live dashboard and every conversion's source. Larger plans add sites, team members, history and the API.
-
Solo
Talk to us about the Solo plan9€ /month
90€ /year
9€before, 7,50€ /monthCustom
- One site
- 2 years of data retention
- Live dashboard: visits, pages, sources, locations, devices
- Real-time view of the last 30 minutes
- Revenue, orders and products
- Every conversion's source, by last click
- Custom events, key events and funnels
- Filters and period comparison
-
Team
Talk to us about the Team plan14€ /month
140€ /year
14€before, 11,67€ /monthCustom
- Everything in Solo
- Up to 3 sites
- Up to 3 team members
- 3 years of data retention
- Viewer and admin roles, by invitation
- Consent report
- Public API
-
Pro
Talk to us about the Pro plan19€ /month
190€ /year
19€before, 15,83€ /monthCustom
- Everything in Team
- Up to 10 sites
- Up to 10 team members
- 4 years of data retention
- Alternative attribution models Coming soon
-
Scale
Talk to us about the Scale planCustom
- Everything in Pro
- 10+ sites
- 10+ team members
- Higher API limits
- Priority support
Prices in euros, excluding VAT. Annual billing is ten months for twelve.
See your website this clearly.
Data facts
What Insights does with a visitor's data, stated the way the code does it. Written for a website owner's lawyer or DPO, and kept current: last reviewed 7 October 2026.
How it works
One script, one collector, one database, one screen. Nothing in between belongs to anyone else.
-
One script, on your own domain
You add one script, served from
insights.yourwebsite.com, a subdomain of your own site, or through your own web server. It loads asynchronously and weighs 2,8 KB. It speaks GA4's dataLayer, so the e-commerce events your site already pushes for Google Tag Manager arrive here unchanged. -
A collector in the EU sorts the visit
Each hit is stored on its own. A visit is stitched across pageviews only if you turn session stitching on, or if the visitor has accepted analytics cookies.
-
Stored encrypted, in the EU, yours
Every event and session is a row in our own database on the same European infrastructure, encrypted on disk with a key that is itself kept on an encrypted volume. Backups stay encrypted within EU. Nothing is sent to a third party, and nothing is used for any purpose but your reports.
-
Live on your dashboard
A purchase shows up seconds after it happens, and its source within minutes. Closed periods are cached, so last month opens in tens of milliseconds; while today is on screen, the dashboard refreshes itself every ten seconds. The same numbers are yours through the API.
One visit, two paths, in full
Insights reads Google Consent Mode's analytics_storage signal, the one your banner already sends, so there is nothing new to ask the visitor. Not answered yet counts as declined. This is exactly what is kept on each path.
| What happens | Declined analytics cookies, or not answered | Accepted analytics cookies |
|---|---|---|
| On the visitor's device | Nothing is written: no cookie, no local storage, no pixel. Screen and viewport size are read only if you have turned session stitching on. | One first-party cookie, _nicid: a random identifier on your own domain, set once and kept for 395 days. Nothing else. |
| How the visitor is recognised | Off unless you turn it on. If you do, pageviews are stitched by a keyed hash of the IP address, the browser's headers and the screen size, deleted after 7 days. No identifier outlives it, and nothing follows the visitor to another site. You decide this as controller, and you inform your visitors. | By the cookie's identifier and, when signed in to your website, by your customer id. Both are hashed with a secret key before they are stored; the raw values are never written. |
| IP address | Stored with the session record and deleted by the database within 24 hours. | Stored with the session record and deleted within 24 hours. Never shared. |
| Returning visitors | Not recognised, unless you have turned session stitching on. Then only within 7 days, and only by the hash above. | Recognised for 395 days, and across devices when signed in to your website. |
| Location | Country, region and city are looked up on our own server from an offline IP database. | |
| Personal data | Dropped, not stored. Names, emails, phones, addresses, dates of birth, tax and social-security numbers and other tools' visitor ids are removed from the event data in the browser before anything is sent, and again by the collector for whatever slipped through. For every visitor, whatever they answered. Page addresses are stored as the browser reports them. | |
| Other websites | Never. The identifier is minted per site and the cookie is first-party on your domain, so Insights cannot see a visitor on any other site, and nobody else can see them on yours. | |
| Changing their mind | A session recorded after consent is withdrawn is stored without the cookie's identifier and without the customer id. If it is withdrawn mid-visit, the visitor's id is replaced with a fresh random one on the spot. The cookie itself stays on the device until it expires or the visitor clears it. | |
And you see the split. The Consent report shows how many sessions accepted everything, accepted some categories, rejected everything or never answered, against the previous period, and every other report can be filtered by it.
The facts your DPO will ask for
Written to be pasted into a privacy policy or handed to a lawyer. Each line is what the code does, not what we hope it does.
- Roles
- Your company is the controller. Netstudio E.E. is the processor, and the Data Processing Agreement is part of the terms.
- Hosting
- UpCloud Oy, a Finnish provider named as sub-processor in the terms, in a data centre inside the European Union. Storage, processing and backups all on that infrastructure.
- Transfers
- None. No visitor data is sent to any third party, inside or outside the EU. Geolocation runs from an offline database on our own server.
- Encryption
- TLS in transit. The database tables sit on an encrypted storage policy, and the key lives on an encrypted volume that is unlocked at boot.
- Identifiers
- Without analytics consent: no identifier, unless you turn session stitching on. If you do, only the keyed hash above, for 7 days. Turning it on is your instruction as controller.
- Retention
- IP address: deleted within 24 hours on every session. Keyed hash of IP address, browser headers and screen size: 7 days, and only if you have turned session stitching on. Cookie: 395 days on the device. Events and sessions: for your plan's data retention period, and deleted on request.
- Personal data
- No directly identifying data is collected on purpose: a fixed list of personal keys, any key containing email, phone or password, and any email-shaped value are discarded by the script and by the collector. IP addresses and pseudonymous identifiers are processed as described above.
- Cross-site, cross-device
- No cross-site tracking of any kind. Cross-device only when your website signs the customer in and they granted analytics consent.
- Access
- Per-account membership with viewer and admin roles, by invitation only. Netstudio support can look at your dashboard only in a read-only session that is logged at both ends.
- Certification
- Netstudio E.E. is certified to ISO/IEC 27001:2022. The certificate is public.