Analyzati vs TelemetryDeck

Compare Analyzati and TelemetryDeck on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Matomo

Logo: Analyzati

Analyzati

Spain· Web Analytics

Needs review

Shortlist when you want Spanish/EU-legal SaaS web analytics with cookie-free daily uniques, city geo, AI referral views, and a public DPA—without self-hosting. Skip when you need open source, on-prem, multi-day retention/cohorts, or certified ISO/SOC evidence; consider Plausible Analytics or Matomo instead.

Cookie-free trackingEU entity (Spain)App on AWS ParisPublic DPAAI referral insightsSaaS only
Logo: TelemetryDeck

TelemetryDeck

Germany· Web Analytics

Needs review

Shortlist TelemetryDeck for multi-platform app analytics when on-device double-hash anonymization, cookieless signals, open SDKs, and a German-operated SaaS matter more than self-host or profile-heavy product suites. Skip when you need website-only simplicity (Plausible/Pirsch), full self-host control (Matomo/Plausible CE), or Mixpanel/Firebase-class identity and ecosystem depth—and have legal review the vendor’s “not personal data / not Art. 28 processor” DPA model plus AWS/Azure subprocessors.

Multi-platform app SDKsOn-device anonymizationCookieless signalsEU-operated (DE GmbH)Open-source client SDKsManaged SaaS (no self-host)
Analyzati vs TelemetryDeck: Snapshot
FeatureLogo: AnalyzatiAnalyzatiLogo: TelemetryDeckTelemetryDeck
Country of originSpainGermany
CategoryWeb AnalyticsWeb Analytics
Open sourceNoNo
Self-hostedNoNo
HeadquartersSpainGermany
Legal entityIncorporated in Barcelona, Spain (exact legal name not published on pages reviewed)TelemetryDeck GmbH, Von-der-Tann-Str. 54, 86159 Augsburg (HRB 37541)
Governing lawSpain / EU (GDPR referenced; confirm governing law clause in Terms)Germany (terms reference German law / Bayern courts; consumer protections may vary)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyVisitor/app data: AWS in Paris (vendor). Marketing site: Namecheap in Amsterdam. Backups described as EU. Other subprocessors named in privacy materials: Stripe (payments), AWS (email), Freshworks (support), hCaptcha (registration).Product analytics: Microsoft Azure Amsterdam (NL), AWS Frankfurt (DE), Hetzner Falkenstein and Nürnberg (DE) per Privacy FAQ. Website privacy policy lists Microsoft Ireland Operations Ltd, Amazon Web Services Inc (US entity), and Hetzner Online GmbH as hosters with claimed Art. 28 contracts for site hosting. Account-side: HubSpot Inc (US CRM), Brevo/Sendinblue GmbH (DE email), Stripe payments per terms.
Summary

Spanish cookie-free web analytics SaaS: real-time traffic, city-level geo, AI referral sources, and event tracking without cookies, stored IPs, or fingerprints.

German privacy-first app analytics SaaS: lightweight multi-platform SDKs, on-device double-hash anonymization, cookieless signals, and managed dashboards for mobile, desktop, and web products.

Tags
At a glance: Analyzati vs TelemetryDeck
At a glanceLogo: AnalyzatiAnalyzatiLogo: TelemetryDeckTelemetryDeck
HQ / entityBarcelona, Spain (EU entity claimed; exact registry name not on public pages reviewed)Not listed
Product typeHosted web analytics SaaSManaged app/web analytics SaaS
Open sourceNoNot listed
Self-hostNoNo (open-source client SDKs only)
App hostingAWS, Paris (vendor claim)Not listed
Commercial modelFreemium + pageview / site-count tiersFree tier + monthly event volume; plan-based query retention
DPAPublic; accepted via Terms of ServicePublic DPA/AVV asserting anonymized non-processor model; TOMs on request
HQNot listedAugsburg, Germany (TelemetryDeck GmbH)
Legal entityNot listedTelemetryDeck GmbH · HRB 37541 · VAT DE353418916
Hosting (vendor)Not listedAzure Amsterdam; AWS Frankfurt; Hetzner Falkenstein/Nürnberg
Key capabilities: Analyzati vs TelemetryDeck
Key capabilitiesLogo: AnalyzatiAnalyzatiLogo: TelemetryDeckTelemetryDeck
Cookie-free trackingYesNot listed
EU entity (Spain)YesNot listed
App on AWS ParisYesNot listed
Public DPAYesNot listed
AI referral insightsYesNot listed
SaaS onlyYesNot listed
Multi-platform app SDKsNot listedYes
On-device anonymizationNot listedYes
Cookieless signalsNot listedYes
EU-operated (DE GmbH)Not listedYes
Open-source client SDKsNot listedYes
Managed SaaS (no self-host)Not listedYes

Analyzati

  • Cookie-free uniques with daily rotating salt

    Counts daily unique visitors by hashing IP + User-Agent + domain with a salt that is destroyed every 24 hours. No cookies, localStorage, or device-persistent IDs; raw IP and full UA are not stored. Trade-off: no multi-day retention or new-vs-returning series.

  • City-level geo without retained IPs

    Derives continent, country, region, and city for maps and rankings from the request IP, then discards the IP. Useful for market mix reporting when you do not need ISP- or coordinate-level precision.

  • AI referral and channel acquisition views

    Breaks down how visitors arrive—search, referring sites, and AI assistants such as ChatGPT, Perplexity, Gemini, and Claude—so content teams can see discovery outside classic SEO referrers.

  • Real-time dashboard, events, export, and API

    Live visitor activity, page performance, device/browser/OS stats, custom events and campaigns, weekly email reports, data export, and API access on published plans. Integrations include a WordPress plugin and Google Tag Manager snippet placement.

  • Public B2B DPA with processor role

    A published Data Processing Agreement (effective August 2022) treats Analyzati as processor and the customer as controller for visitor measurement. Acceptance is tied to product use under the Terms of Service rather than a bespoke countersignature workflow.

TelemetryDeck

  • Multi-platform SDKs and HTTP signal ingest

    Official clients for Swift (Apple platforms including visionOS), Kotlin/Android, JavaScript, Flutter, React/React Native, Vue, and a one-line web snippet, with community Unity, Rust WASM, and Vapor clients. Any runtime can POST to the documented ingest API. Suits cross-platform product teams; not a drop-in replacement for a full marketing tag manager suite.

  • On-device salt-and-hash user anonymization

    Client SDKs salt and hash user identifiers on device; the server applies a second salt and hash so neither side can reverse the original ID. App analytics docs state IPs are never stored for signals; timestamps are rounded to the hour. Limit: publishers must not put personal data in custom metadata, or the anonymization model breaks for that payload.

  • Cookieless app and web tracking model

    No analytics cookies for product signals: apps keep a local anonymized identifier; web derives a hashed identifier from date, site, and partial IP context without storing full IPs. Aimed at leaner consent UX and simpler App Store privacy labels versus cookie-based trackers—still confirm legal posture for your jurisdiction and configuration.

  • Product dashboards, funnels, TQL, and notebooks

    Pre-built overview and AARRR-style customer journeys (acquisition, activation, retention, revenue), technical metrics (devices, versions, errors), visual funnel builder, Explore for raw signal types, TelemetryDeck Query Language for advanced insights, and Notebooks mixing live charts with markdown. Test mode separates IDE/dev traffic from production.

  • Volume-based SaaS with free tier and plan retention

    Commercial model is monthly event/signal volume with a free tier and paid plans that differ on included volume and how long data stays query-ready (cold storage may hold older data). Free accounts can stop ingesting when the budget is exhausted; paid plans warn and may auto-upgrade after sustained overage. Check current limits on the vendor dashboard—no self-host option.

Assurance & compliance: Analyzati vs TelemetryDeck
Assurance & complianceLogo: AnalyzatiAnalyzatiLogo: TelemetryDeckTelemetryDeck
Independent security / no-logs audit
Not found

No public third-party audit PDF or no-logs attestation found on official pages reviewed.

Not found

Vendor claims no IP storage and open SDK code for inspection; no public third-party no-logs or security audit report found in this pass.

ISO 27001
Not found

No ISO 27001 certificate claim located on homepage, privacy, or DPA pages.

Not found

No public ISO 27001 certificate page located.

SOC 2 / SOC 3
Not found

No SOC 2/3 report claim found on public trust materials.

Not found

No public SOC 2/3 report located.

GDPR / EU data protection
Vendor claimed

EU entity (Barcelona); public GDPR/PECR/CCPA compliance pages; anonymisation design documented; controller/processor roles in DPA.

Vendor claimed

EU (German) controller entity; privacy policy and Privacy FAQ document anonymization, non-storage of IPs for signals, and EU hosting regions. Vendor asserts analytics signals are not personal data—validate with counsel for your config.

US CLOUD Act exposure (indicative)
Partial

Spanish/EU vendor with no known US parent, but application hosting on AWS (Paris) and US-group subprocessors (Stripe, Freshworks, AWS email, hCaptcha). Residency ≠ ownership. Not legal advice.

Partial

German GmbH, no known US parent, EU regions named—but public hosters include AWS and Microsoft (US groups) and HubSpot (US) for CRM. Indicative medium exposure. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Public DPA effective 18 Aug 2022; vendor says acceptance is automatic via product use / ToS—no separate signature required.

Partial

Public DPA at telemetrydeck.com/dpa (German AVV prevails). Document asserts TelemetryDeck is not Art. 28 processor/joint controller because signals are anonymized; TOMs on request. Not a classic processor AVV—legal review required.

EU AI Act
Not applicable

Product reports AI *referral traffic*; it is not marketed as a high-risk AI system provider.

Not applicable

Product analytics / telemetry; not marketed as an AI system core offering.

Considerations & known limitations: Analyzati vs TelemetryDeck
Considerations & known limitationsLogo: AnalyzatiAnalyzatiLogo: TelemetryDeckTelemetryDeck
AWS and US-group subprocessors
Medium

Measurement app is on AWS Paris; account path also uses Stripe, Freshworks, AWS email, and hCaptcha. EU regions reduce some transfer friction but do not erase US-group provider diligence for many public-sector and bank questionnaires.

Not listed
No public ISO/SOC or independent audit
Medium

Security claims rely on vendor documentation (HTTPS, hashing, firewalls, backups). Organisations with mandatory cert evidence will need vendor outreach or a different shortlist.

Medium

No ISO 27001, SOC 2, or independent no-logs audit found publicly. Enterprise security questionnaires may need NDA materials or alternate assurance.

No multi-day visitor identity
Low

Daily salt rotation blocks persistent uniques. Expect gaps vs Google Analytics for returning users, frequency, and retention—by design.

Not listed
SaaS lock-in / no self-host
Low

No self-host edition found. Exit requires export/API migration to another tool; confirm export completeness in a trial.

Not listed
Exact registry name not on marketing pages
Low

Vendor states Barcelona incorporation but public pages reviewed did not display a full Spanish company registration string—collect CIF/NIF and full legal name during contracting.

Not listed
US-group cloud and CRM subprocessorsNot listed
Medium

Even with EU regions, AWS and Microsoft Azure are US-group providers; HubSpot processes customer CRM data in a US SaaS path. Buyers with strict no-US-cloud policies need written architecture confirmation or another vendor.

Anonymization / non-processor legal modelNot listed
Medium

Public DPA states TelemetryDeck is neither processor nor joint controller for service data. Strong if true for your configuration; risky if custom metadata reintroduces personal data or if counsel disagrees with the anonymization analysis.

Free-tier ingest hard-stopNot listed
Low

Free plans discard events after the included monthly budget; overage data is not recoverable. Production apps on free tier need monitoring or a paid plan.

No self-hosted productNot listed
Low

Only client SDKs are open source. Organizations that must keep analytics databases on-prem cannot use TelemetryDeck as a full stack.

Fit

Analyzati

Best fit when

  • Marketing sites and content properties that need page views, referrers, device mix, and city-level geo without analytics cookies
  • Teams replacing Google Analytics primarily for privacy/consent simplification rather than advanced product analytics
  • Agencies or freelancers who want multi-site hosted analytics with a freemium entry path
  • Buyers who want a published DPA and Spanish/EU legal entity on the order form
  • Content teams tracking discovery from AI assistants alongside classic channels

Poor fit when

  • Product or growth teams that require funnels, multi-day retention, cohorts, or cross-device identity
  • Organisations that mandate open-source code or self-hosted deployment
  • Procurement that will not accept AWS (US-group) or other US SaaS subprocessors even in EU regions
  • Security questionnaires that demand public ISO 27001 / SOC 2 reports or independent no-logs audits
  • Use cases needing session replay, heatmaps, or advertising audience export

Consider instead when

  • When: You need open-source analytics you can self-host and audit

    Consider: Plausible Analytics (self-host option) or Matomo

    Analyzati is SaaS-only with no public source release found.

  • When: You want a comparable cookie-free European SaaS peer for side-by-side trials

    Consider: Plausible Analytics or Simple Analytics

    Compare AI-referrer and geo depth, DPA wording, and hosting/subprocessor lists in each trial.

  • When: You need full-stack product analytics and advertising linkage

    Consider: Google Analytics (incumbent) or a dedicated product analytics suite

    Analyzati deliberately collects a minimal metric set and does not sell ad-tech profiles.

TelemetryDeck

Best fit when

  • Mobile/desktop/web app teams that instrument events in code (Swift, Kotlin, Flutter, RN, JS) rather than only a website script
  • Product orgs prioritizing cookieless, double-hashed identifiers and leaner App Store privacy narratives versus ad-tech SDKs
  • Teams leaving Firebase Analytics or Mixpanel who accept a simpler event model for privacy-oriented defaults
  • European buyers wanting a German legal entity and EU-region hosting (Azure NL, AWS Frankfurt, Hetzner DE) with public privacy docs
  • Indie and small teams that want a free tier to start and volume-based paid plans as signal volume grows

Poor fit when

  • Organizations that must self-host the full analytics stack on their own infrastructure
  • Website-only traffic measurement without native app SDKs (Plausible/Pirsch are usually better fits)
  • Buyers that require public ISO 27001/SOC 2 certificates or a conventional Art. 28 processor DPA without the vendor’s anonymization legal model
  • Teams needing deep identity graphs, CRM-style user profiles, or full product-analytics marketing suites
  • Workloads that forbid US-group cloud providers entirely (AWS and Microsoft Azure are in the public host list)

Consider instead when

  • When: You only need privacy-friendly website analytics with a simple script

    Consider: Plausible Analytics or Pirsch Analytics

    Stronger web-first UX; weaker native multi-platform SDK story than TelemetryDeck

  • When: You must self-host analytics and own the database

    Consider: Matomo (self-host) or Plausible Community Edition

    TelemetryDeck is managed SaaS only

  • When: You need Firebase/Google ecosystem depth or free crash+remote-config adjacency

    Consider: Firebase Analytics (accept Google jurisdiction and tracking model)

    Different privacy and lock-in trade-offs

  • When: You need enterprise product analytics with rich identity and experimentation packaging

    Consider: Mixpanel or Amplitude

    Heavier privacy/cookie surface; more suite features

Open questions for due diligence

Analyzati

  • What is the full Spanish legal entity name and company registry identifier for the order form?
  • Is a current written subprocessor list available beyond privacy-policy mentions (including backup regions and any CDN)?
  • Can the vendor provide ISO/SOC evidence or a third-party penetration test under NDA?
  • What is the analytics data retention window per plan, and what does the API export include?
  • Which governing law and venue apply under the current Terms of Service?

TelemetryDeck

  • Will counsel accept the public non-processor DPA/AVV model for your app’s identifier and metadata configuration?
  • Can TelemetryDeck provide TOMs, subprocessor list for the analytics plane, and any ISO/SOC or pen-test reports under NDA?
  • Which exact AWS/Azure services and accounts process customer organization data versus anonymized signals?
  • What contractual options exist to exclude or pin HubSpot and other US SaaS tools for account administration?
  • Current free-tier and paid plan event limits and retention windows for your expected volume (confirm on live plans UI)?