Analyzati vs Swetrix

Compare Analyzati and Swetrix on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Fathom Analytics, Google Analytics, Matomo

Logo: Analyzati

Analyzati

Spain· Web Analytics

Needs review

Shortlist when you want Spanish/EU-legal SaaS web analytics with cookie-free daily uniques, city geo, AI referral views, and a public DPA—without self-hosting. Skip when you need open source, on-prem, multi-day retention/cohorts, or certified ISO/SOC evidence; consider Plausible Analytics or Matomo instead.

Cookie-free trackingEU entity (Spain)App on AWS ParisPublic DPAAI referral insightsSaaS only
Logo: Swetrix

Swetrix

United Kingdom· Web Analytics

Needs review

Shortlist Swetrix when you want cookieless traffic plus product-oriented tools (funnels, RUM, errors, optional Cloud replays) under a UK company with Hetzner DE hosting and AGPLv3 self-host CE. Skip when you need public ISO/SOC packs, zero US-group subprocessors, multi-year cookie retention cohorts, or free forever hosted analytics—consider Plausible Analytics or Simple Analytics for minimal traffic-only privacy analytics, or Matomo for heavyweight self-host control.

Cookieless trackingHetzner DE hostingOpen source (AGPLv3)Self-host CEFunnels + errors + RUMPublic DPA
Analyzati vs Swetrix: Snapshot
FeatureLogo: AnalyzatiAnalyzatiLogo: SwetrixSwetrix
Country of originSpainUnited Kingdom
CategoryWeb AnalyticsWeb Analytics
Open sourceNoYes
Self-hostedNoYes
HeadquartersSpainUnited Kingdom
Legal entityIncorporated in Barcelona, Spain (exact legal name not published on pages reviewed)Swetrix Ltd (SC797389), Edinburgh, Scotland
Governing lawSpain / EU (GDPR referenced; confirm governing law clause in Terms)Not listed
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyVisitor/app data: AWS in Paris (vendor). Marketing site: Namecheap in Amsterdam. Backups described as EU. Other subprocessors named in privacy materials: Stripe (payments), AWS (email), Freshworks (support), hCaptcha (registration).Cloud analytics data: Hetzner Online GmbH (Germany) per DPA/Data Policy. End User error monitoring sub-processor: Sentry / Functional Software Inc. (United States). Customer-side Privacy Policy list also includes Paddle (UK payments), Fastmail (Australia business email), AWS (US transactional/marketing email), OpenRouter (US optional AI chat). No known US parent.
Summary

Spanish cookie-free web analytics SaaS: real-time traffic, city-level geo, AI referral sources, and event tracking without cookies, stored IPs, or fingerprints.

Cookieless, privacy-first web analytics from a UK company: traffic, funnels, errors, and performance on Hetzner in Germany, with AGPLv3 self-host Community Edition and optional Cloud session replays.

Tags
At a glance: Analyzati vs Swetrix
At a glanceLogo: AnalyzatiAnalyzatiLogo: SwetrixSwetrix
HQ / entityBarcelona, Spain (EU entity claimed; exact registry name not on public pages reviewed)Not listed
Product typeHosted web analytics SaaSNot listed
Open sourceNoYes — github.com/Swetrix/swetrix
Self-hostNoNot listed
App hostingAWS, Paris (vendor claim)Not listed
Commercial modelFreemium + pageview / site-count tiersEvent-volume Cloud subscription; free self-host CE; timed trial
DPAPublic; accepted via Terms of ServiceNot listed
HQNot listedEdinburgh, United Kingdom
Legal entityNot listedSwetrix Ltd (SC797389)
Governing lawNot listedScotland (Terms)
Primary hostingNot listedHetzner Online GmbH, Germany
LicenseNot listedAGPLv3 (Community Edition)
Key capabilities: Analyzati vs Swetrix
Key capabilitiesLogo: AnalyzatiAnalyzatiLogo: SwetrixSwetrix
Cookie-free trackingYesNot listed
EU entity (Spain)YesNot listed
App on AWS ParisYesNot listed
Public DPAYesNot listed
AI referral insightsYesNot listed
SaaS onlyYesNot listed
Cookieless trackingNot listedYes
Hetzner DE hostingNot listedYes
Open source (AGPLv3)Not listedYes
Self-host CENot listedYes
Funnels + errors + RUMNot listedYes
Public DPANot listedYes

Analyzati

  • Cookie-free uniques with daily rotating salt

    Counts daily unique visitors by hashing IP + User-Agent + domain with a salt that is destroyed every 24 hours. No cookies, localStorage, or device-persistent IDs; raw IP and full UA are not stored. Trade-off: no multi-day retention or new-vs-returning series.

  • City-level geo without retained IPs

    Derives continent, country, region, and city for maps and rankings from the request IP, then discards the IP. Useful for market mix reporting when you do not need ISP- or coordinate-level precision.

  • AI referral and channel acquisition views

    Breaks down how visitors arrive—search, referring sites, and AI assistants such as ChatGPT, Perplexity, Gemini, and Claude—so content teams can see discovery outside classic SEO referrers.

  • Real-time dashboard, events, export, and API

    Live visitor activity, page performance, device/browser/OS stats, custom events and campaigns, weekly email reports, data export, and API access on published plans. Integrations include a WordPress plugin and Google Tag Manager snippet placement.

  • Public B2B DPA with processor role

    A published Data Processing Agreement (effective August 2022) treats Analyzati as processor and the customer as controller for visitor measurement. Acceptance is tied to product use under the Terms of Service rather than a bespoke countersignature workflow.

Swetrix

  • Cookieless traffic analytics with hashed sessions

    Lightweight script captures pageviews, referrers/UTMs, devices, and city-level geo without cookies or client-side storage. Per the Data Policy, IP and User-Agent are hashed in memory with a daily rotating salt; only a random session id is stored—so you get sessions without long-term cross-day visitor retention.

  • Funnels, custom events, and goals

    Instrument signups, purchases, and other conversions as custom events; build multi-step funnels and goals in the dashboard. Useful for product and growth teams who need drop-off analysis without bolting on a second product-analytics SaaS.

  • Real-user performance and client error tracking

    Records Web Performance API timings (TTFB, DNS, TLS, render, full page load) and optional JavaScript errors with stack/context by page and browser. Bridges marketing traffic views with engineering signals that pure pageview tools omit.

  • Opt-in Cloud session replays with privacy modes

    Cloud projects can call startSessionReplay() to record DOM and interactions; default modes mask text/inputs. Replays are not created by ordinary pageviews—customers must enable them and own consent, masking, and page exclusions. Cloud-only versus Community Edition.

  • AGPLv3 open source with Docker self-host CE

    Core platform is public on GitHub under GNU AGPLv3; Community Edition deploys via official Docker docs with MySQL, ClickHouse, and Redis. CE includes core analytics, events, sessions, funnels, performance, and errors—but not all Cloud extras (replays, some alerts/org/AI features).

  • Alerts, API, GA import, and team access

    Configure alerts to email, Slack, Telegram, Discord, webhooks, or push; pull or push data via the API; import GA4 history; invite organisations with roles or share password-protected/public dashboards. Fits agencies and multi-site operators who outgrow single-user tools.

Assurance & compliance: Analyzati vs Swetrix
Assurance & complianceLogo: AnalyzatiAnalyzatiLogo: SwetrixSwetrix
Independent security / no-logs audit
Not found

No public third-party audit PDF or no-logs attestation found on official pages reviewed.

Not found

Searched marketing, DPA, privacy, and data policy; no public independent audit PDF located. Open-source code is available for review.

ISO 27001
Not found

No ISO 27001 certificate claim located on homepage, privacy, or DPA pages.

Not found

No public ISO 27001 certification claim found on primary pages.

SOC 2 / SOC 3
Not found

No SOC 2/3 report claim found on public trust materials.

Not found

No public SOC 2/3 report found.

GDPR / EU data protection
Vendor claimed

EU entity (Barcelona); public GDPR/PECR/CCPA compliance pages; anonymisation design documented; controller/processor roles in DPA.

Vendor claimed

UK company; public GDPR/PECR discussion in Data Policy; cookieless design with non-stored IPs for standard analytics; Hetzner DE hosting; public DPA. Optional replays may be personal data depending on configuration—customer assesses legal basis.

US CLOUD Act exposure (indicative)
Partial

Spanish/EU vendor with no known US parent, but application hosting on AWS (Paris) and US-group subprocessors (Stripe, Freshworks, AWS email, hCaptcha). Residency ≠ ownership. Not legal advice.

Partial

No known US parent; primary analytics on Hetzner DE. Material exception: Sentry (US) processes End User error data per DPA; Privacy Policy also lists AWS and OpenRouter (US) for customer email/AI. Indicative medium exposure—not a clean bill. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Public DPA effective 18 Aug 2022; vendor says acceptance is automatic via product use / ToS—no separate signature required.

Vendor claimed

Public DPA at swetrix.com/dpa incorporated by Terms; acceptance by use of Service; signed copy on request.

EU AI Act
Not applicable

Product reports AI *referral traffic*; it is not marketed as a high-risk AI system provider.

Not applicable

Core product is web analytics, not an AI system. Optional Ask AI / OpenRouter is ancillary; confirm if your deployment enables it.

Considerations & known limitations: Analyzati vs Swetrix
Considerations & known limitationsLogo: AnalyzatiAnalyzatiLogo: SwetrixSwetrix
AWS and US-group subprocessors
Medium

Measurement app is on AWS Paris; account path also uses Stripe, Freshworks, AWS email, and hCaptcha. EU regions reduce some transfer friction but do not erase US-group provider diligence for many public-sector and bank questionnaires.

Not listed
No public ISO/SOC or independent audit
Medium

Security claims rely on vendor documentation (HTTPS, hashing, firewalls, backups). Organisations with mandatory cert evidence will need vendor outreach or a different shortlist.

Not listed
No multi-day visitor identity
Low

Daily salt rotation blocks persistent uniques. Expect gaps vs Google Analytics for returning users, frequency, and retention—by design.

Not listed
SaaS lock-in / no self-host
Low

No self-host edition found. Exit requires export/API migration to another tool; confirm export completeness in a trial.

Not listed
Exact registry name not on marketing pages
Low

Vendor states Barcelona incorporation but public pages reviewed did not display a full Spanish company registration string—collect CIF/NIF and full legal name during contracting.

Not listed
US-group subprocessors (Sentry, AWS, OpenRouter)Not listed
Medium

Primary analytics hosting is Hetzner DE, but Sentry (US) is an End User error-tracking sub-processor on the DPA, and AWS/OpenRouter appear for customer email/AI. Orgs with strict no-US-cloud rules need explicit acceptance or self-host CE to avoid those paths.

Session replay is opt-in and controller-ownedNot listed
Medium

Cloud replays can capture DOM and inputs unless masked. Customers must enable startSessionReplay(), configure privacy modes/exclusions, and provide notices/consent where required—misconfiguration can reintroduce personal data risk that standard cookieless pageviews avoid.

No public ISO/SOC or third-party auditNot listed
Medium

Assurance relies on first-party policies, Hetzner infrastructure claims, and open source. Enterprise questionnaires that hard-gate on certs will stall until materials are provided under NDA or produced.

Cloud vs Community Edition feature gapNot listed
Low

Self-host CE is free and covers core analytics, but replays and several Cloud growth/ops features are limited or Cloud-only. Budget and feature planning must not assume feature parity.

Daily salt rotation limits retention metricsNot listed
Low

Cookieless design deliberately prevents classic multi-day visitor retention. Teams that need that metric class need another product or consented identity.

Fit

Analyzati

Best fit when

  • Marketing sites and content properties that need page views, referrers, device mix, and city-level geo without analytics cookies
  • Teams replacing Google Analytics primarily for privacy/consent simplification rather than advanced product analytics
  • Agencies or freelancers who want multi-site hosted analytics with a freemium entry path
  • Buyers who want a published DPA and Spanish/EU legal entity on the order form
  • Content teams tracking discovery from AI assistants alongside classic channels

Poor fit when

  • Product or growth teams that require funnels, multi-day retention, cohorts, or cross-device identity
  • Organisations that mandate open-source code or self-hosted deployment
  • Procurement that will not accept AWS (US-group) or other US SaaS subprocessors even in EU regions
  • Security questionnaires that demand public ISO 27001 / SOC 2 reports or independent no-logs audits
  • Use cases needing session replay, heatmaps, or advertising audience export

Consider instead when

  • When: You need open-source analytics you can self-host and audit

    Consider: Plausible Analytics (self-host option) or Matomo

    Analyzati is SaaS-only with no public source release found.

  • When: You want a comparable cookie-free European SaaS peer for side-by-side trials

    Consider: Plausible Analytics or Simple Analytics

    Compare AI-referrer and geo depth, DPA wording, and hosting/subprocessor lists in each trial.

  • When: You need full-stack product analytics and advertising linkage

    Consider: Google Analytics (incumbent) or a dedicated product analytics suite

    Analyzati deliberately collects a minimal metric set and does not sell ad-tech profiles.

Swetrix

Best fit when

  • SMEs, agencies, and product teams replacing GA4 who need cookieless traffic stats without a cookie banner driven only by analytics
  • Engineering-minded buyers who want error tracking and real-user performance in the same privacy-first dashboard as pageviews
  • Teams that may enable Cloud session replays later but can treat them as explicit opt-in with their own legal basis
  • Operators willing to run Docker Community Edition (MySQL/ClickHouse/Redis) when Cloud commercial terms or feature limits do not fit
  • Buyers who need a public B2B DPA, API access, GA4 import, and multi-channel alerts under a UK legal entity

Poor fit when

  • Enterprises that require published ISO 27001 / SOC 2 certificates or independent audit PDFs before shortlist
  • Policies that forbid any US-group subprocessors (Sentry is listed for End User error data; AWS/OpenRouter appear for customer services)
  • Use cases that depend on long-term cookie-based retention or cross-device identity graphs
  • Buyers who only want free hosted analytics with no paid Cloud tier and no self-host operations burden
  • Sites that will run session replays on sensitive flows without capacity to configure masking, exclusions, and consent

Consider instead when

  • When: You only need minimal cookieless pageviews/referrers with the smallest possible product surface

    Consider: Plausible Analytics or Simple Analytics

    Swetrix adds funnels, errors, RUM, and Cloud replays; peers stay closer to pure traffic analytics.

  • When: You need deep on-prem control, plugins, and mature enterprise self-host packaging

    Consider: Matomo (self-host or managed EU hosts such as Matomo by Stackhero)

    Heavier ops and optional cookies; stronger fit for large controlled deployments.

  • When: You must stay inside Google advertising measurement and free GA4 ecosystem tooling

    Consider: Google Analytics

    Trade privacy, consent, and transfer complexity for ads integration and zero software fee.

Open questions for due diligence

Analyzati

  • What is the full Spanish legal entity name and company registry identifier for the order form?
  • Is a current written subprocessor list available beyond privacy-policy mentions (including backup regions and any CDN)?
  • Can the vendor provide ISO/SOC evidence or a third-party penetration test under NDA?
  • What is the analytics data retention window per plan, and what does the API export include?
  • Which governing law and venue apply under the current Terms of Service?

Swetrix

  • Can Enterprise contracts exclude or replace Sentry (and other US-group subprocessors) for End User data paths?
  • Are ISO 27001, SOC 2, or pen-test summaries available under NDA?
  • What is the exact backup/DR location topology beyond “secure backups” wording on the DPA?
  • Which Cloud-only features remain permanently out of CE versus delayed open-source release?
  • For session replay at your traffic volumes, what retention defaults and export/delete SLAs apply on your plan?