nilly vs Plausible Analytics

Compare nilly and Plausible Analytics on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Fathom Analytics, Google Analytics

Logo: nilly

nilly

Switzerland· Web Analytics

Needs review

Shortlist nilly when you want Swiss-entity, cookieless, ultra-light site analytics with realtime dashboards, city geo, custom events, unlimited sites, and an API—without GA4 consent weight. Skip when you need self-host/open source, enterprise audit packs, or deep marketing-suite analytics; consider Plausible Analytics, Simple Analytics, or etracker instead.

Cookieless trackingSwiss-hosted (claimed)Swiss entitySub-1 kB scriptREST APISaaS only
Logo: Plausible Analytics

Plausible Analytics

Estonia· Web Analytics

Needs review

Shortlist when you need cookieless website analytics with EU-owned visitor hosting, a lightweight script, AGPL transparency, and either managed Cloud or self-hosted CE. Skip when you need heatmaps/session replay, multi-day user-level product analytics, HIPAA/BAA, free forever hosted analytics, or zero non-EU SaaS anywhere in vendor ops—consider Matomo-class (e.g. Friendly Analytics / Piwik PRO), Pirsch, or Simple Analytics depending on depth vs simplicity.

Cookieless by designEU-owned visitor hostsAGPLv3 open sourceSelf-host CEDPA automaticLightweight script
nilly vs Plausible Analytics: Snapshot
FeatureLogo: nillynillyLogo: Plausible AnalyticsPlausible Analytics
Country of originSwitzerlandEstonia
CategoryWeb AnalyticsWeb Analytics
Open sourceNoYes
Self-hostedNoYes
HeadquartersSwitzerlandEstonia
Legal entityLyo GmbH, Europaallee 41, 8004 Zürich (CHE-417.675.763)Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia
Governing lawSwitzerland (terms)Estonian / EU law context for the OÜ; confirm contract terms for governing law clauses
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyVendor FAQ: analytics servers in Switzerland (multiple locations). Public site reverse-DNS: KreativMedia/METANET Zürich. Customer-account subprocessors named in privacy policy: Stripe (US payments), Mailerlite (email). Avatars via Gravatar. No full public subprocessor list for backups/monitoring/CDN.Visitor analytics: Hetzner (Falkenstein, Germany), UpCloud (Finland, DB/exports), Bunny (Slovenia, CDN/DNS/DDoS)—European-owned; vendor states visitor data never leaves the EU. Customer-account subprocessors include Paddle (payments), Postmark (email), Gravatar, optional Google (GA import), Help Scout, Nolt; site tools may include hCaptcha, Algolia, Mailchimp. SCCs claimed for non-EU processors.
Summary

Swiss privacy-first web analytics (Lyo GmbH): cookieless, sub-1kB tracking with realtime dashboards, city-level geo, custom events, unlimited sites, and a REST API as a lightweight Google Analytics alternative.

Estonian open-source, cookieless web analytics (AGPLv3): lightweight script, EU-owned hosting on Hetzner/UpCloud/Bunny, managed Cloud plus self-hosted Community Edition.

Tags
At a glance: nilly vs Plausible Analytics
At a glanceLogo: nillynillyLogo: Plausible AnalyticsPlausible Analytics
HQZürich, Switzerland (Lyo GmbH)Tartu, Estonia
Legal entityLyo GmbH (CHE-417.675.763)Plausible Insights OÜ (reg. 14709274)
Product modelSaaS web analytics (not self-hosted)Not listed
TrackingCookieless; no IP/fingerprint claimsNot listed
Hosting (claimed)Switzerland (multi-site)Not listed
Commercial modelTraffic-based plans; trial; no permanent free tierPageview-based Cloud SaaS; free CE self-host
Live site notekandur.one (nilly branding; nilly.io DNS failed at research)Not listed
Visitor hostsNot listedHetzner DE; UpCloud FI; Bunny SI
LicenseNot listedAGPLv3; Cloud + Community Edition
Tracking modelNot listedCookieless; daily rotating hash; no PII stored
Key capabilities: nilly vs Plausible Analytics
Key capabilitiesLogo: nillynillyLogo: Plausible AnalyticsPlausible Analytics
Cookieless trackingYesYes
Swiss-hosted (claimed)YesNot listed
Swiss entityYesNot listed
Sub-1 kB scriptYesYes
REST APIYesNot listed
SaaS onlyYesNot listed
EU-owned visitor hostsNot listedYes
AGPLv3 open sourceNot listedYes
Self-host CENot listedYes
DPA automaticNot listedYes

nilly

  • Sub-1 kB cookieless tracking script

    Vendor documents a client script under 1 kB with no cookies, no IP tracking, and no fingerprinting for site visitors. Suited to teams that want aggregate traffic metrics without analytics cookie banners; still get counsel for your jurisdiction and CMP setup.

  • Realtime dashboard with geo, tech, and campaigns

    Dashboards cover live visitors, overview metrics, top pages, referrers, UTM campaigns, geography from continent to city, and device/browser/OS breakdowns—enough for content and acquisition decisions without a full product-analytics suite.

  • Custom events, CSV export, and email reports

    Define custom events for conversion-style actions, export statistics as CSV, and receive email reports. Fits operators who need lightweight conversion signals and offline analysis rather than session replay or multi-step funnels.

  • REST API for stats, websites, and account

    Documented API endpoints (Bearer API key) manage stats queries (pageviews, visitors, referrers, events, geo, devices, and more), websites, and account objects—useful for internal dashboards or automations on traffic-based plans that include API access.

  • Unlimited websites on traffic-based plans

    Public pricing model is pageview-tier SaaS with unlimited websites per account and a short free trial—not a permanent free tier. Good for agencies or multi-brand operators who outgrow per-site free plans elsewhere; confirm current tiers on the vendor site.

Plausible Analytics

  • Cookieless measurement with daily rotating visitor hash

    No cookies, localStorage, or persistent IDs. Uniques use hash(daily_salt + domain + IP + UA); salt rotates every 24 hours and raw IP/UA are never stored—so analytics can often run without a consent banner, at the cost of no multi-day user stitching.

  • Lightweight script and single-page traffic dashboard

    Vendor claims a script ~54× smaller than Google Analytics with real-time updates (~30s), sources, pages, devices, UTM channels, scroll-depth goals, and optional Google Search Console import—built for marketers who refuse GA4 report complexity.

  • Goals, custom events, funnels, and revenue on Cloud

    Codeless page goals, file downloads, outbound clicks, custom events/properties, AI-referral traffic views, and (on higher Cloud plans) funnels, user journeys, and ecommerce revenue attribution—not session replay or in-app product analytics.

  • EU-owned visitor hosting (Hetzner, UpCloud, Bunny)

    Cloud visitor data is processed on European-owned infrastructure: Hetzner (Germany), UpCloud (Finland), Bunny CDN (Slovenia). Plausible states visitor data never leaves the EU and is not stored on US hyperscalers.

  • AGPLv3 open source with Community Edition self-host

    Full codebase on GitHub; free CE for self-host (long-term releases ~twice yearly). Cloud-only features include advanced bot filtering, funnels/journeys, ecommerce revenue, SSO, and Sites API—self-host ops, backups, and upgrades are yours.

  • Automatic DPA, Stats API, exports, and enterprise SSO

    Public DPA applies to Cloud customers by use; CSV export and Stats API for BI; Business/Enterprise add higher API limits, raw event exports, managed proxy, and SAML SSO (Google Workspace, Okta, Microsoft Entra ID per docs).

Assurance & compliance: nilly vs Plausible Analytics
Assurance & complianceLogo: nillynillyLogo: Plausible AnalyticsPlausible Analytics
Independent security / no-logs audit
Not found

No public third-party audit report found for tracking claims.

Not found

Open-source code and security overview published; no public independent pen-test or no-logs audit PDF found on compliance/security pages.

ISO 27001
Not found

No vendor ISO 27001 certificate published on product site (underlying Swiss host DCs may be certified separately).

Not found

No ISO 27001 claim located on security or compliance hub pages reviewed.

SOC 2 / SOC 3
Not found
Not found

No SOC 2/3 claim located on security or compliance hub pages reviewed.

GDPR / EU data protection
Vendor claimed

Swiss entity; privacy policy includes GDPR rights language; cookieless visitor tracking claimed. Confirm DPA for B2B.

Vendor claimed

EU entity; cookieless non-PII design; public data policy, DPA, and vendor-published legal assessment on GDPR/ePrivacy positioning.

US CLOUD Act exposure (indicative)
Partial

Swiss operator, no known US parent, Swiss-claimed analytics hosting; US SaaS subprocessors Stripe (payments) and Gravatar (avatars) on customer path. Not legal advice.

Partial

Estonian OÜ, no known US parent; visitor data on EU-owned Hetzner/UpCloud/Bunny. Partial/medium because customer-account subprocessors include US-oriented SaaS (e.g. Postmark, Help Scout, Gravatar, optional Google). Indicative only—not legal advice.

Data processing agreement (B2B)
Not found

No public DPA download found; request from vendor.

Vendor claimed

Public DPA applies automatically to Cloud customers by use of the service; lists processor duties and 48-hour breach notification target.

EU AI Act
Not applicable

Web analytics product; not marketed as an AI system.

Not applicable

Website analytics product; not marketed as an AI system under the AI Act.

Swiss Made Software / Swiss Web labels
Vendor claimed

Cited on About and Swiss Union member page as recognition/labels—not a security audit.

Not listed
Considerations & known limitations: nilly vs Plausible Analytics
Considerations & known limitationsLogo: nillynillyLogo: Plausible AnalyticsPlausible Analytics
Brand/domain transition (nilly.io vs kandur.one)
Medium

Product still branded nilly, but the live marketing/API host is kandur.one; nilly.io did not resolve in DNS during research. Verify tracking domains, docs, and status before production cutover.

Not listed
US SaaS on customer account path
Medium

Stripe (payments) and Gravatar (avatars) are US-group services. Visitor metrics are claimed Swiss-hosted and non-personal, but account/billing data is not Switzerland-only end-to-end.

Not listed
Thin public assurance pack
Medium

No public ISO 27001/SOC 2, independent security audit, or DPA page found. Fine for many SMB shortlists; friction for regulated enterprise questionnaires.

Not listed
No self-host or open-source edition
Low

Cannot run on your own infra or audit server code from a public repo. Hard limit for sovereignty programs that require self-host.

Not listed
Small independent operator
Low

Founder-owned Swiss GmbH without VC narrative—positive for independence, but buyers should assess support SLAs, roadmap continuity, and single-vendor concentration.

Not listed
US-linked customer-account subprocessorsNot listed
Medium

Visitor metrics stay on EU-owned hosts, but billing, email, support, and optional integrations use providers such as Postmark, Paddle, Help Scout, Gravatar, and Google—material for zero-US-processor policies.

No public ISO 27001 / SOC 2Not listed
Medium

Compliance hub emphasizes product design and EU hosting rather than ISO/SOC certificates; orgs with mandatory cert checklists must request evidence or accept open-source + DPA packaging.

Self-host CE feature and release lagNot listed
Low

CE is free but long-term releases (~twice yearly) and omits Cloud-only funnels, journeys, ecommerce revenue, SSO, and advanced bot filtering—ops burden sits with you.

No multi-day user identity or replayNot listed
Low

Daily hash resets prevent cross-day visitor stitching by design; heatmaps/session replay are out of scope—teams needing those must add other tools.

Misconfiguration can reintroduce personal dataNot listed
Medium

Passing emails, patient IDs, or other identifiers in URLs or custom properties undermines the non-PII model; vendor also states no HIPAA/BAA.

Fit

nilly

Best fit when

  • Privacy-conscious SMBs and indie sites replacing GA4 with aggregate metrics only
  • Teams that want Swiss legal entity and Swiss-located analytics servers
  • Operators running many sites who benefit from unlimited websites on traffic tiers
  • Builders who need a simple REST API for pageviews, referrers, geo, and events
  • Sites prioritizing minimal JS weight and fewer analytics consent prompts

Poor fit when

  • Organizations that must self-host or review open-source analytics code
  • Buyers needing published ISO 27001/SOC 2 or a full public DPA/subprocessor pack
  • Marketing teams requiring session replay, heatmaps, or advanced e-commerce/ad sync suites
  • Enterprises that need SSO/SCIM, formal SLAs, and large-vendor assurance paperwork as table stakes

Consider instead when

  • When: You want open-source and/or self-host privacy analytics with a larger community

    Consider: Plausible Analytics or Pirsch Analytics

    nilly is proprietary SaaS only.

  • When: You want another European cookieless SaaS with a simple product story

    Consider: Simple Analytics

    Dutch peer; compare geo depth, API, and residency claims side by side.

  • When: You need deeper marketing, shop, and tag/consent analytics for EU enterprises

    Consider: etracker

    German suite-oriented alternative; heavier than nilly's lightweight dashboard.

  • When: You depend on free unlimited scale and Google ads/ecosystem integration

    Consider: Google Analytics (GA4)

    Different privacy and residency tradeoffs; not a sovereignty shortlist.

Plausible Analytics

Best fit when

  • Teams replacing GA4 who want aggregate marketing metrics without cookies or user profiles
  • EU orgs that require visitor analytics on European-owned infrastructure (Hetzner/UpCloud/Bunny)
  • Sites that prioritize script weight, Core Web Vitals, and a one-page dashboard
  • Buyers who want AGPL auditability and optional Community Edition self-host exit
  • Agencies and multi-site operators needing shared links, team seats, and pageview-tiered Cloud plans
  • Procurement paths that value a public DPA, data policy, and subprocessor list over ISO/SOC certificates

Poor fit when

  • Product analytics needs: multi-day user identity, cohorts, retention, feature experiments
  • UX research that requires heatmaps, session replay, or rage-click recording
  • Healthcare or other programs that require HIPAA and a BAA (explicitly not offered)
  • Buyers who need free forever hosted analytics with no subscription
  • Orgs that forbid any US-linked SaaS in vendor account tooling (Postmark, Help Scout, etc. are listed)

Consider instead when

  • When: You need Matomo-depth features (heatmaps, session recording, heavy on-prem packaging)

    Consider: Friendly Analytics, Piwik PRO, or self-hosted Matomo

    Trade Plausible’s minimalism for plugin breadth and different operators.

  • When: You want a lean EU privacy analytics peer with a different stack or license posture

    Consider: Pirsch Analytics or Simple Analytics

    Compare hosting ownership, funnels/ecommerce gates, and self-host options side by side.

  • When: You only need edge-level basic counts and already run Cloudflare

    Consider: Cloudflare Web Analytics

    Simpler install path; US company and thinner marketing analytics surface.

  • When: You need free hosted analytics and accept Google’s data practices

    Consider: Google Analytics

    Different legal and commercial model—not an EU privacy substitute.

Open questions for due diligence

nilly

  • Will Lyo GmbH sign a B2B DPA and provide a current full subprocessor list (including backups, monitoring, CDN)?
  • Is analytics data retained only on Swiss hosts, or are any DR/replicas outside Switzerland?
  • What is the durable public domain for tracking scripts and API (kandur.one vs nilly.io) for the next 12 months?
  • Are there enterprise features (SSO, roles, retention controls, MSA/SLA) beyond self-serve traffic plans?
  • Can the vendor provide any independent security assessment under NDA?

Plausible Analytics

  • Which exact customer personal data categories does each account subprocessor (Postmark, Paddle, Help Scout, etc.) receive in production?
  • Can Enterprise contracts exclude optional integrations (Google, Help Scout) or pin subprocessor lists for regulated buyers?
  • Are independent pen-test reports or ISO/SOC roadmaps available under NDA?
  • What are contracted RPO/RTO and backup locations beyond the high-level Hetzner/UpCloud description?
  • For CE self-host: which Cloud-only features remain permanently out of CE versus merely delayed on the long-term release train?