Privacy-friendly analytics is a measurement discipline. It keeps the questions useful, the dimensions coarse enough to avoid singling people out, and the retention and sharing rules visible to the team that operates the site.
A useful minimum
Measure
Pageviews, sources, coarse device and location categories, goals, revenue totals, Web Vitals and aggregate engagement.
Explain
State whether a number is a view, event, session estimate or approximate visitor count. Show the period, timezone and coverage.
Limit
Skip names, emails, account IDs, full URLs with query strings, session replay and identifiers that follow people between sites.
Review
Set a retention window, protect dashboards, document public sharing and test opt-out behavior before launch.
Questions aggregate analytics can answer
- Which pages and sources account for most recorded activity?
- When do views concentrate in the selected timezone?
- Where does an aggregate funnel lose activity?
- Did a release or campaign coincide with a change in volume or engagement?
Questions it should not pretend to answer
It cannot identify a visitor, prove that two sessions belong to one person, explain why a person acted, or reveal sensitive traits that were not legitimately collected as aggregate data. Small segments should be hidden, grouped or described cautiously.
See the architecture page; it describes Nanolytica's current tradeoffs. Read the cookieless guide to understand collection details.