Alceris Analytics vs Offen Fair Web Analytics

Compare Alceris Analytics and Offen Fair Web Analytics on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Fathom Analytics, Google Analytics, Matomo, Mixpanel

Logo: Alceris Analytics

Alceris Analytics

Germany· Web Analytics

Needs review

Shortlist when you need German-operated, cookieless pageview/event analytics with a free monthly allowance and one-line install. Skip when you need self-hosting, open-source core, enterprise cert packs, or deep product analytics—consider Plausible, Simple Analytics, Pirsch, or Matomo instead.

Cookieless by designEU-operated (Germany)Realtime dashboardFree tier (volume-capped)SaaS only (no self-host)
Logo: Offen Fair Web Analytics

Offen Fair Web Analytics

Germany· Web Analytics

Needs review

Shortlist when you want self-hosted, Apache-2.0 analytics that only measures after opt-in, encrypts events in the browser, and lets visitors open their own data in the Auditorium. Skip when you need cookieless full-coverage metrics, session replay/heatmaps, or zero-ops managed EU hosting—consider Plausible, Pirsch, or Friendly Analytics instead.

Opt-in onlyBrowser E2E encryptionSelf-hostedApache-2.0Visitor data accessBerlin-based project
Alceris Analytics vs Offen Fair Web Analytics: Snapshot
FeatureLogo: Alceris AnalyticsAlceris AnalyticsLogo: Offen Fair Web AnalyticsOffen Fair Web Analytics
Country of originGermanyGermany
CategoryWeb AnalyticsWeb Analytics
Open sourceNoYes
Self-hostedNoYes
HeadquartersGermanyGermany
Legal entityManuel Bauer, Innere Passauer Str. 45, 94315 Straubing, Germany (VAT DE353601960)Public legal notice lists Frederik Ring, Berlin (offen.software); product authors Frederik Ring and Hendrik Niefeld—no separate GmbH name verified on imprint
Governing lawGermanyGermany (indicative from Berlin imprint)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyVendor claims analytics data is stored and served only on European servers and aggregated on arrival. Named external paths: Paddle (paid billing MoR) and optional Google Search Console. No official named infrastructure/subprocessor inventory beyond those; public site IP/ASN currently associated with netcup GmbH (Germany). DNS nameservers observed on Hetzner.Product is operator self-hosted (your VPS/cloud/on-prem). No Offen multi-tenant analytics SaaS or vendor subprocessor list for visitor events. Related marketing site (offen.software) names Hetzner Online GmbH (Germany) as host—not the analytics data path. Optional community deploys include Heroku (operator choice).
Summary

German cookieless website analytics SaaS: aggregate pageviews, events, and UTM campaigns without cookies or IP logs, operated from Straubing with EU-oriented hosting claims.

Open-source, self-hosted web analytics with opt-in consent, browser-side end-to-end encryption, and a shared Auditorium so visitors can see and control their own usage data.

Tags
At a glance: Alceris Analytics vs Offen Fair Web Analytics
At a glanceLogo: Alceris AnalyticsAlceris AnalyticsLogo: Offen Fair Web AnalyticsOffen Fair Web Analytics
HQStraubing, GermanyNot listed
Legal entityManuel Bauer (sole operator)Not listed
DeploymentHosted SaaS onlyNot listed
Open sourceProduct SaaS closed; WP plugin on WordPress.orgNot listed
Commercial modelFree volume-capped tier; paid via PaddleNot listed
Governing lawGermany (per terms)Not listed
HQ / authorsNot listedBerlin, Germany (Frederik Ring & Hendrik Niefeld)
LicenseNot listedApache-2.0 (code/docs); logo CC-BY-NC-ND-4.0
DeliveryNot listedSelf-host only (binary, Docker, community deploys)
Consent modelNot listedOpt-in only; first-party cookies
Default retentionNot listed6 months (configurable shorter)
Funding noteNot listedNLnet NGI support (project-stated)
Key capabilities: Alceris Analytics vs Offen Fair Web Analytics
Key capabilitiesLogo: Alceris AnalyticsAlceris AnalyticsLogo: Offen Fair Web AnalyticsOffen Fair Web Analytics
Cookieless by designYesNot listed
EU-operated (Germany)YesYes
Realtime dashboardYesNot listed
Free tier (volume-capped)YesNot listed
SaaS only (no self-host)YesNot listed
Opt-in onlyNot listedYes
Browser E2E encryptionNot listedYes
Self-hostedNot listedYes
Apache-2.0Not listedYes
Visitor data accessNot listedYes

Alceris Analytics

  • Cookieless aggregation without IP storage

    Per the privacy policy, Alceris does not set cookies, session IDs, or similar client storage; IPs are not logged; the full User-Agent is not stored. Only aggregated fields such as page URL, referrer, parsed browser/OS, language, and timezone-based country are retained—aimed at sites that want stats without an analytics cookie banner.

  • One-line async script, deferred events, WordPress plugin

    Install via a single async script from alceris.com with your site data-id (docs include a deferred alceris() queue so early events are not lost). WordPress operators can use the official plugin and paste the dashboard site ID. SaaS-only—there is no self-hosted server package.

  • Realtime pageviews and custom events with metadata

    Pageviews and events are processed immediately into the dashboard. Custom events are sent with alceris('event', name, { ...metadata }), useful for button clicks, form steps, or content attributes without building a full product-analytics stack.

  • UTM campaigns, outbound links, and cross-domain flows

    UTM parameters are extracted for campaign reporting; outbound link clicks are tracked automatically; cross-domain tracking follows visitors across owned domains. Scope is web traffic measurement—not session replay or heatmaps.

  • Optional Google Search Console and first-party proxy

    Connect Search Console to import query impressions, clicks, and terms (data removed on unlink). Docs also describe reverse-proxying script.js and the img.alceris.com data endpoint through your own domain so ad-blockers are less likely to drop hits—at the cost of operating that proxy yourself.

Offen Fair Web Analytics

  • Opt-in only collection with first-party cookies

    No analytics events are recorded until the visitor actively consents. Cookies are first-party and the tracker is meant to run on a same-site subdomain so third-party cookie restrictions and cross-site tracking models do not apply. Visitors who never opt in leave no usage trail—expect lower absolute volumes than cookieless tools that measure by default.

  • Browser-side end-to-end encryption of usage events

    Clients encrypt usage data before it leaves the browser; the server stores ciphertext and cannot decrypt events alone. Only the visitor (via their cookie) and the matching operator account can open that visitor's data in the Auditorium. Practical impact: a compromised database or overly broad ops access does not yield plaintext browsing histories the way a typical self-hosted analytics DB would.

  • Auditorium for both operators and visitors

    Operators see aggregates across pages where the installation is active (unique users/sessions, top pages, filters). Each opted-in visitor can open the same style of UI for their own data only, with plain-language metric explanations, and can delete data or fully opt out later. This is the fair design point: measurement is not a one-way glass.

  • Essential metrics without IP or User-Agent capture

    Dashboards cover real-time activity, page views, unique users and sessions, bounce rate, returning users, top pages, referrers, UTM campaign/source, landing and exit pages, weekly retention, and load time. Location is country-level from timezone mapping; mobile share uses orientation capability—not IP geolocation or UA parsing. No heatmaps, session replay, or warehouse-grade product analytics.

  • Lightweight self-host: binary, Docker, SQLite or SQL

    Production installs use a single binary (Linux/Windows/macOS) or the offen/offen image; docs also cover Heroku, Uberspace, and YunoHost. Default store is SQLite; MySQL and Postgres are supported. AutoTLS can request Let's Encrypt certificates. Config is environment variables or offen.env. You own uptime, backups, SMTP for password reset, and the subdomain layout.

  • Multi-site accounts, teams, and short retention

    One installation can cover multiple websites with shared team access. Default retention is six months with automatic deletion; operators can shorten retention (e.g. 12 weeks, 30 days, 7 days) knowing shorter values purge older events on startup. Consent banner appearance is customizable; UI locales include EN, DE, FR, ES, PT, and VI.

Assurance & compliance: Alceris Analytics vs Offen Fair Web Analytics
Assurance & complianceLogo: Alceris AnalyticsAlceris AnalyticsLogo: Offen Fair Web AnalyticsOffen Fair Web Analytics
Independent security / no-logs audit
Not found

No public third-party audit of cookieless/no-IP claims found

Not found

No public third-party audit PDF found; coordinated disclosure via SECURITY.md email only.

ISO 27001
Not found

No ISO 27001 claim on public site/security pages (none published)

Not found

No public ISO 27001 certification claim found on official site or docs.

SOC 2 / SOC 3
Not found

No SOC 2/3 report referenced publicly

Not found

No public SOC 2/3 report found.

GDPR / EU data protection
Vendor claimed

German controller; cookieless/no-IP design claims on privacy policy (last updated 2022). Not legal advice—confirm with counsel and DPA.

Vendor claimed

EU authors; opt-in, data minimization (no IP/UA), visitor access/erasure, short default retention, Datensparsamkeit framing. Self-host means operator remains controller—confirm your legal basis and notice.

US CLOUD Act exposure (indicative)
Partial

EU sole proprietor, no known US parent; vendor EU-hosting claims and DE-associated hosting for the public site. Optional Google Search Console involves Google; Paddle handles payments; infrastructure subprocessors not fully named. Indicative only—not legal advice.

Partial

EuropeanStack assessment: no known US parent; product not delivered as US-hosted vendor SaaS. Operator-chosen infrastructure (including optional Heroku/US cloud) can still create CLOUD Act paths for stored ciphertext/metadata. Not legal advice.

Data processing agreement (B2B)
Not found

No public DPA page or in-product DPA download found; ask vendor before production use

Not applicable

No multi-tenant vendor analytics processing relationship documented; operator self-hosts and is typically controller. Custom development/support via offen.software is separate from a standard SaaS DPA.

EU AI Act
Not applicable

Web analytics measurement product; not marketed as an AI system

Not applicable

Web analytics metrics product; not an AI system product.

Considerations & known limitations: Alceris Analytics vs Offen Fair Web Analytics
Considerations & known limitationsLogo: Alceris AnalyticsAlceris AnalyticsLogo: Offen Fair Web AnalyticsOffen Fair Web Analytics
Solo / small-operator continuity
Medium

Imprint shows an individual operator in Straubing. Terms provide service as-is with email support on reasonable effort and reserve the right to modify or discontinue the service. Practical impact: backup exports and an exit plan matter more than with a large SaaS vendor.

Not listed
Thin public compliance packaging
Medium

No ISO/SOC claims, no independent audit, no public DPA template, and no named infrastructure subprocessor list despite terms referring to third-party hardware/storage vendors. Practical impact: slower security review for regulated buyers.

Not listed
Optional Google Search Console path
Low

Connecting Search Console pulls query metrics from Google into Alceris. Leave it disconnected if US providers are out of policy for any analytics-adjacent data.

Not listed
Billing via Paddle MoR
Low

Paid plans are contracted with Paddle, not Alceris directly. Review Paddle's terms and data role for finance/procurement.

Not listed
WordPress plugin maintenance signal
Low

WordPress.org lists the plugin as not tested with the latest major WP releases and few active installs. Prefer manual script install or re-test thoroughly on your WP version.

Not listed
Opt-in undercounts absolute trafficNot listed
High

Visitors who never consent generate no events. Growth and content KPIs will not match cookieless tools or GA-style default measurement—treat as design, not a misconfiguration.

You own uptime, backups, and secretsNot listed
Medium

No managed Offen cloud. Operators must run HTTPS/subdomain layout, set OFFEN_SECRET for stable sessions, configure SMTP for resets, and back up SQLite/SQL—plus avoid reverse proxies that log IPs if minimization is a goal.

E2E crypto is vendor-claimed architectureNot listed
Medium

Browser-side encryption and server inability to decrypt are core claims from project docs/README, not independently audited in public materials found. Security-sensitive orgs should review source or commission assessment.

Hosting choice reintroduces cloud jurisdictionNot listed
Medium

Self-host on US-group cloud or Heroku means CLOUD Act/subprocessor analysis shifts to your host even though Offen itself is Berlin-based OSS without a vendor SaaS region map.

No public ISO/SOC or audit packNot listed
Low

Procurement checklists that require vendor ISO 27001/SOC 2 will stall; evidence is open source and design docs, not cert registry entries.

Essential metrics onlyNot listed
Medium

No heatmaps, session replay, advanced funnels, or product-analytics warehouse features. Wrong tool if the shortlist criterion is UX research depth rather than fair traffic statistics.

Fit

Alceris Analytics

Best fit when

  • Small-to-medium websites that want aggregate traffic and event stats without analytics cookies
  • Teams replacing GA for basic reporting (pages, referrers, UTMs) under a German legal entity
  • Operators who value a free volume-capped tier and Paddle-billed paid upgrades
  • Sites that may reverse-proxy the script/data endpoints to reduce ad-blocker loss
  • WordPress sites willing to validate the plugin against their WP version

Poor fit when

  • Organisations that must self-host analytics or run an open-source core under their own ops
  • Buyers needing public ISO 27001/SOC 2, independent audits, or a ready DPA/subprocessor pack
  • Product teams requiring funnels, session replay, heatmaps, or multi-product analytics depth
  • Procurement processes that reject solo-operator vendors or optional US integrations (Google Search Console)

Consider instead when

  • When: You want a more established cookieless SaaS brand with stronger public compliance packaging

    Consider: Plausible Analytics or Simple Analytics

    Similar lightweight privacy analytics category; different ownership and documentation maturity

  • When: You need self-hosted or on-prem control of the analytics stack

    Consider: Matomo (self-hosted) or catalog Matomo hosting variants

    Alceris is cloud-only; proxying the script still sends data to Alceris

  • When: You need German-hosted open-source cookieless analytics with a different product surface

    Consider: Pirsch Analytics

    Peer German privacy-analytics option for side-by-side evaluation

  • When: You need full GA4-class product and marketing analytics depth

    Consider: Google Analytics (accept its data model) or a heavier EU suite

    Alceris intentionally stays narrow

Offen Fair Web Analytics

Best fit when

  • Public-sector, media, NGO, or mission-driven sites that need visitor-visible transparency and strict opt-in
  • EU teams that must keep analytics off third-party trackers and can run a small always-on instance
  • Operators who want first-party subdomain cookies, CSP-aware embedding, and no IP/User-Agent collection
  • Organisations evaluating fair-processing design over maximum measurement coverage
  • Teams comfortable with SQLite or SQL self-host ops (binary or Docker) and publishing their own privacy notice

Poor fit when

  • Product or growth teams that require near-complete traffic measurement without consent friction
  • Needs for heatmaps, session replay, funnels, or ad-ecosystem attribution comparable to Hotjar/Mixpanel/GA
  • Buyers seeking a vendor-managed multi-tenant analytics cloud with SLAs and a signed vendor DPA as processor
  • Large enterprises that require public ISO 27001/SOC 2 or third-party security audit packs before shortlist

Consider instead when

  • When: You want privacy-oriented analytics with managed EU hosting and lower consent friction

    Consider: Plausible Analytics or Pirsch Analytics

    Typically optimised for simpler cookieless or low-friction models and hosted plans; less radical visitor Auditorium design than Offen.

  • When: You need EU hosted privacy analytics with operator support and less self-host burden

    Consider: Friendly Analytics

    European catalog peer oriented to hosted privacy analytics; compare consent model and feature depth to Offen’s opt-in + E2E approach.

  • When: You need deep product analytics, funnels, or session UX tooling rather than fair traffic metrics

    Consider: Hotjar, Mixpanel, or a full GA4 stack (with legal review)

    Different category: richer product/UX analytics, different jurisdiction and subprocessor profile.

Open questions for due diligence

Alceris Analytics

  • Will the vendor sign a B2B DPA and provide a current named subprocessor list (hosting, backups, email)?
  • Which exact EU data-centre operators and regions process customer analytics data today?
  • Is there any independent assessment of the no-cookie / no-IP-storage claims?
  • What is the support SLA or roadmap process for a solo-operated product?
  • Is the WordPress plugin still maintained for current WordPress majors?

Offen Fair Web Analytics

  • Will your traffic and KPI model tolerate opt-in-only measurement after a pilot on a non-critical property?
  • Where will you host the instance (EU on-prem/VPS vs US-group cloud), and who holds OFFEN_SECRET and DB backups?
  • Do procurement rules require third-party audits or ISO/SOC that Offen does not publish?
  • Do you need a signed vendor DPA as processor, or is controller-only self-host acceptable to counsel?
  • Is subdomain + CSP (script-src/frame-src + unsafe-inline styles for the banner) feasible on your main site?