Analyzati vs Plausible Analytics

Compare Analyzati and Plausible Analytics on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Fathom Analytics, Google Analytics, Matomo

Logo: Analyzati

Analyzati

Spain· Web Analytics

Needs review

Shortlist when you want Spanish/EU-legal SaaS web analytics with cookie-free daily uniques, city geo, AI referral views, and a public DPA—without self-hosting. Skip when you need open source, on-prem, multi-day retention/cohorts, or certified ISO/SOC evidence; consider Plausible Analytics or Matomo instead.

Cookie-free trackingEU entity (Spain)App on AWS ParisPublic DPAAI referral insightsSaaS only
Logo: Plausible Analytics

Plausible Analytics

Estonia· Web Analytics

Needs review

Shortlist when you need cookieless website analytics with EU-owned visitor hosting, a lightweight script, AGPL transparency, and either managed Cloud or self-hosted CE. Skip when you need heatmaps/session replay, multi-day user-level product analytics, HIPAA/BAA, free forever hosted analytics, or zero non-EU SaaS anywhere in vendor ops—consider Matomo-class (e.g. Friendly Analytics / Piwik PRO), Pirsch, or Simple Analytics depending on depth vs simplicity.

Cookieless by designEU-owned visitor hostsAGPLv3 open sourceSelf-host CEDPA automaticLightweight script
Analyzati vs Plausible Analytics: Snapshot
FeatureLogo: AnalyzatiAnalyzatiLogo: Plausible AnalyticsPlausible Analytics
Country of originSpainEstonia
CategoryWeb AnalyticsWeb Analytics
Open sourceNoYes
Self-hostedNoYes
HeadquartersSpainEstonia
Legal entityIncorporated in Barcelona, Spain (exact legal name not published on pages reviewed)Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia
Governing lawSpain / EU (GDPR referenced; confirm governing law clause in Terms)Estonian / EU law context for the OÜ; confirm contract terms for governing law clauses
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyVisitor/app data: AWS in Paris (vendor). Marketing site: Namecheap in Amsterdam. Backups described as EU. Other subprocessors named in privacy materials: Stripe (payments), AWS (email), Freshworks (support), hCaptcha (registration).Visitor analytics: Hetzner (Falkenstein, Germany), UpCloud (Finland, DB/exports), Bunny (Slovenia, CDN/DNS/DDoS)—European-owned; vendor states visitor data never leaves the EU. Customer-account subprocessors include Paddle (payments), Postmark (email), Gravatar, optional Google (GA import), Help Scout, Nolt; site tools may include hCaptcha, Algolia, Mailchimp. SCCs claimed for non-EU processors.
Summary

Spanish cookie-free web analytics SaaS: real-time traffic, city-level geo, AI referral sources, and event tracking without cookies, stored IPs, or fingerprints.

Estonian open-source, cookieless web analytics (AGPLv3): lightweight script, EU-owned hosting on Hetzner/UpCloud/Bunny, managed Cloud plus self-hosted Community Edition.

Tags
At a glance: Analyzati vs Plausible Analytics
At a glanceLogo: AnalyzatiAnalyzatiLogo: Plausible AnalyticsPlausible Analytics
HQ / entityBarcelona, Spain (EU entity claimed; exact registry name not on public pages reviewed)Not listed
Product typeHosted web analytics SaaSNot listed
Open sourceNoNot listed
Self-hostNoNot listed
App hostingAWS, Paris (vendor claim)Not listed
Commercial modelFreemium + pageview / site-count tiersPageview-based Cloud SaaS; free CE self-host
DPAPublic; accepted via Terms of ServiceNot listed
HQNot listedTartu, Estonia
Legal entityNot listedPlausible Insights OÜ (reg. 14709274)
Visitor hostsNot listedHetzner DE; UpCloud FI; Bunny SI
LicenseNot listedAGPLv3; Cloud + Community Edition
Tracking modelNot listedCookieless; daily rotating hash; no PII stored
Key capabilities: Analyzati vs Plausible Analytics
Key capabilitiesLogo: AnalyzatiAnalyzatiLogo: Plausible AnalyticsPlausible Analytics
Cookie-free trackingYesNot listed
EU entity (Spain)YesNot listed
App on AWS ParisYesNot listed
Public DPAYesNot listed
AI referral insightsYesNot listed
SaaS onlyYesNot listed
Cookieless by designNot listedYes
EU-owned visitor hostsNot listedYes
AGPLv3 open sourceNot listedYes
Self-host CENot listedYes
DPA automaticNot listedYes
Lightweight scriptNot listedYes

Analyzati

  • Cookie-free uniques with daily rotating salt

    Counts daily unique visitors by hashing IP + User-Agent + domain with a salt that is destroyed every 24 hours. No cookies, localStorage, or device-persistent IDs; raw IP and full UA are not stored. Trade-off: no multi-day retention or new-vs-returning series.

  • City-level geo without retained IPs

    Derives continent, country, region, and city for maps and rankings from the request IP, then discards the IP. Useful for market mix reporting when you do not need ISP- or coordinate-level precision.

  • AI referral and channel acquisition views

    Breaks down how visitors arrive—search, referring sites, and AI assistants such as ChatGPT, Perplexity, Gemini, and Claude—so content teams can see discovery outside classic SEO referrers.

  • Real-time dashboard, events, export, and API

    Live visitor activity, page performance, device/browser/OS stats, custom events and campaigns, weekly email reports, data export, and API access on published plans. Integrations include a WordPress plugin and Google Tag Manager snippet placement.

  • Public B2B DPA with processor role

    A published Data Processing Agreement (effective August 2022) treats Analyzati as processor and the customer as controller for visitor measurement. Acceptance is tied to product use under the Terms of Service rather than a bespoke countersignature workflow.

Plausible Analytics

  • Cookieless measurement with daily rotating visitor hash

    No cookies, localStorage, or persistent IDs. Uniques use hash(daily_salt + domain + IP + UA); salt rotates every 24 hours and raw IP/UA are never stored—so analytics can often run without a consent banner, at the cost of no multi-day user stitching.

  • Lightweight script and single-page traffic dashboard

    Vendor claims a script ~54× smaller than Google Analytics with real-time updates (~30s), sources, pages, devices, UTM channels, scroll-depth goals, and optional Google Search Console import—built for marketers who refuse GA4 report complexity.

  • Goals, custom events, funnels, and revenue on Cloud

    Codeless page goals, file downloads, outbound clicks, custom events/properties, AI-referral traffic views, and (on higher Cloud plans) funnels, user journeys, and ecommerce revenue attribution—not session replay or in-app product analytics.

  • EU-owned visitor hosting (Hetzner, UpCloud, Bunny)

    Cloud visitor data is processed on European-owned infrastructure: Hetzner (Germany), UpCloud (Finland), Bunny CDN (Slovenia). Plausible states visitor data never leaves the EU and is not stored on US hyperscalers.

  • AGPLv3 open source with Community Edition self-host

    Full codebase on GitHub; free CE for self-host (long-term releases ~twice yearly). Cloud-only features include advanced bot filtering, funnels/journeys, ecommerce revenue, SSO, and Sites API—self-host ops, backups, and upgrades are yours.

  • Automatic DPA, Stats API, exports, and enterprise SSO

    Public DPA applies to Cloud customers by use; CSV export and Stats API for BI; Business/Enterprise add higher API limits, raw event exports, managed proxy, and SAML SSO (Google Workspace, Okta, Microsoft Entra ID per docs).

Assurance & compliance: Analyzati vs Plausible Analytics
Assurance & complianceLogo: AnalyzatiAnalyzatiLogo: Plausible AnalyticsPlausible Analytics
Independent security / no-logs audit
Not found

No public third-party audit PDF or no-logs attestation found on official pages reviewed.

Not found

Open-source code and security overview published; no public independent pen-test or no-logs audit PDF found on compliance/security pages.

ISO 27001
Not found

No ISO 27001 certificate claim located on homepage, privacy, or DPA pages.

Not found

No ISO 27001 claim located on security or compliance hub pages reviewed.

SOC 2 / SOC 3
Not found

No SOC 2/3 report claim found on public trust materials.

Not found

No SOC 2/3 claim located on security or compliance hub pages reviewed.

GDPR / EU data protection
Vendor claimed

EU entity (Barcelona); public GDPR/PECR/CCPA compliance pages; anonymisation design documented; controller/processor roles in DPA.

Vendor claimed

EU entity; cookieless non-PII design; public data policy, DPA, and vendor-published legal assessment on GDPR/ePrivacy positioning.

US CLOUD Act exposure (indicative)
Partial

Spanish/EU vendor with no known US parent, but application hosting on AWS (Paris) and US-group subprocessors (Stripe, Freshworks, AWS email, hCaptcha). Residency ≠ ownership. Not legal advice.

Partial

Estonian OÜ, no known US parent; visitor data on EU-owned Hetzner/UpCloud/Bunny. Partial/medium because customer-account subprocessors include US-oriented SaaS (e.g. Postmark, Help Scout, Gravatar, optional Google). Indicative only—not legal advice.

Data processing agreement (B2B)
Vendor claimed

Public DPA effective 18 Aug 2022; vendor says acceptance is automatic via product use / ToS—no separate signature required.

Vendor claimed

Public DPA applies automatically to Cloud customers by use of the service; lists processor duties and 48-hour breach notification target.

EU AI Act
Not applicable

Product reports AI *referral traffic*; it is not marketed as a high-risk AI system provider.

Not applicable

Website analytics product; not marketed as an AI system under the AI Act.

Considerations & known limitations: Analyzati vs Plausible Analytics
Considerations & known limitationsLogo: AnalyzatiAnalyzatiLogo: Plausible AnalyticsPlausible Analytics
AWS and US-group subprocessors
Medium

Measurement app is on AWS Paris; account path also uses Stripe, Freshworks, AWS email, and hCaptcha. EU regions reduce some transfer friction but do not erase US-group provider diligence for many public-sector and bank questionnaires.

Not listed
No public ISO/SOC or independent audit
Medium

Security claims rely on vendor documentation (HTTPS, hashing, firewalls, backups). Organisations with mandatory cert evidence will need vendor outreach or a different shortlist.

Not listed
No multi-day visitor identity
Low

Daily salt rotation blocks persistent uniques. Expect gaps vs Google Analytics for returning users, frequency, and retention—by design.

Not listed
SaaS lock-in / no self-host
Low

No self-host edition found. Exit requires export/API migration to another tool; confirm export completeness in a trial.

Not listed
Exact registry name not on marketing pages
Low

Vendor states Barcelona incorporation but public pages reviewed did not display a full Spanish company registration string—collect CIF/NIF and full legal name during contracting.

Not listed
US-linked customer-account subprocessorsNot listed
Medium

Visitor metrics stay on EU-owned hosts, but billing, email, support, and optional integrations use providers such as Postmark, Paddle, Help Scout, Gravatar, and Google—material for zero-US-processor policies.

No public ISO 27001 / SOC 2Not listed
Medium

Compliance hub emphasizes product design and EU hosting rather than ISO/SOC certificates; orgs with mandatory cert checklists must request evidence or accept open-source + DPA packaging.

Self-host CE feature and release lagNot listed
Low

CE is free but long-term releases (~twice yearly) and omits Cloud-only funnels, journeys, ecommerce revenue, SSO, and advanced bot filtering—ops burden sits with you.

No multi-day user identity or replayNot listed
Low

Daily hash resets prevent cross-day visitor stitching by design; heatmaps/session replay are out of scope—teams needing those must add other tools.

Misconfiguration can reintroduce personal dataNot listed
Medium

Passing emails, patient IDs, or other identifiers in URLs or custom properties undermines the non-PII model; vendor also states no HIPAA/BAA.

Fit

Analyzati

Best fit when

  • Marketing sites and content properties that need page views, referrers, device mix, and city-level geo without analytics cookies
  • Teams replacing Google Analytics primarily for privacy/consent simplification rather than advanced product analytics
  • Agencies or freelancers who want multi-site hosted analytics with a freemium entry path
  • Buyers who want a published DPA and Spanish/EU legal entity on the order form
  • Content teams tracking discovery from AI assistants alongside classic channels

Poor fit when

  • Product or growth teams that require funnels, multi-day retention, cohorts, or cross-device identity
  • Organisations that mandate open-source code or self-hosted deployment
  • Procurement that will not accept AWS (US-group) or other US SaaS subprocessors even in EU regions
  • Security questionnaires that demand public ISO 27001 / SOC 2 reports or independent no-logs audits
  • Use cases needing session replay, heatmaps, or advertising audience export

Consider instead when

  • When: You need open-source analytics you can self-host and audit

    Consider: Plausible Analytics (self-host option) or Matomo

    Analyzati is SaaS-only with no public source release found.

  • When: You want a comparable cookie-free European SaaS peer for side-by-side trials

    Consider: Plausible Analytics or Simple Analytics

    Compare AI-referrer and geo depth, DPA wording, and hosting/subprocessor lists in each trial.

  • When: You need full-stack product analytics and advertising linkage

    Consider: Google Analytics (incumbent) or a dedicated product analytics suite

    Analyzati deliberately collects a minimal metric set and does not sell ad-tech profiles.

Plausible Analytics

Best fit when

  • Teams replacing GA4 who want aggregate marketing metrics without cookies or user profiles
  • EU orgs that require visitor analytics on European-owned infrastructure (Hetzner/UpCloud/Bunny)
  • Sites that prioritize script weight, Core Web Vitals, and a one-page dashboard
  • Buyers who want AGPL auditability and optional Community Edition self-host exit
  • Agencies and multi-site operators needing shared links, team seats, and pageview-tiered Cloud plans
  • Procurement paths that value a public DPA, data policy, and subprocessor list over ISO/SOC certificates

Poor fit when

  • Product analytics needs: multi-day user identity, cohorts, retention, feature experiments
  • UX research that requires heatmaps, session replay, or rage-click recording
  • Healthcare or other programs that require HIPAA and a BAA (explicitly not offered)
  • Buyers who need free forever hosted analytics with no subscription
  • Orgs that forbid any US-linked SaaS in vendor account tooling (Postmark, Help Scout, etc. are listed)

Consider instead when

  • When: You need Matomo-depth features (heatmaps, session recording, heavy on-prem packaging)

    Consider: Friendly Analytics, Piwik PRO, or self-hosted Matomo

    Trade Plausible’s minimalism for plugin breadth and different operators.

  • When: You want a lean EU privacy analytics peer with a different stack or license posture

    Consider: Pirsch Analytics or Simple Analytics

    Compare hosting ownership, funnels/ecommerce gates, and self-host options side by side.

  • When: You only need edge-level basic counts and already run Cloudflare

    Consider: Cloudflare Web Analytics

    Simpler install path; US company and thinner marketing analytics surface.

  • When: You need free hosted analytics and accept Google’s data practices

    Consider: Google Analytics

    Different legal and commercial model—not an EU privacy substitute.

Open questions for due diligence

Analyzati

  • What is the full Spanish legal entity name and company registry identifier for the order form?
  • Is a current written subprocessor list available beyond privacy-policy mentions (including backup regions and any CDN)?
  • Can the vendor provide ISO/SOC evidence or a third-party penetration test under NDA?
  • What is the analytics data retention window per plan, and what does the API export include?
  • Which governing law and venue apply under the current Terms of Service?

Plausible Analytics

  • Which exact customer personal data categories does each account subprocessor (Postmark, Paddle, Help Scout, etc.) receive in production?
  • Can Enterprise contracts exclude optional integrations (Google, Help Scout) or pin subprocessor lists for regulated buyers?
  • Are independent pen-test reports or ISO/SOC roadmaps available under NDA?
  • What are contracted RPO/RTO and backup locations beyond the high-level Hetzner/UpCloud description?
  • For CE self-host: which Cloud-only features remain permanently out of CE versus merely delayed on the long-term release train?