nilly vs Swetrix

Compare nilly and Swetrix on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Fathom Analytics, Google Analytics

Logo: nilly

nilly

Switzerland· Web Analytics

Needs review

Shortlist nilly when you want Swiss-entity, cookieless, ultra-light site analytics with realtime dashboards, city geo, custom events, unlimited sites, and an API—without GA4 consent weight. Skip when you need self-host/open source, enterprise audit packs, or deep marketing-suite analytics; consider Plausible Analytics, Simple Analytics, or etracker instead.

Cookieless trackingSwiss-hosted (claimed)Swiss entitySub-1 kB scriptREST APISaaS only
Logo: Swetrix

Swetrix

United Kingdom· Web Analytics

Needs review

Shortlist Swetrix when you want cookieless traffic plus product-oriented tools (funnels, RUM, errors, optional Cloud replays) under a UK company with Hetzner DE hosting and AGPLv3 self-host CE. Skip when you need public ISO/SOC packs, zero US-group subprocessors, multi-year cookie retention cohorts, or free forever hosted analytics—consider Plausible Analytics or Simple Analytics for minimal traffic-only privacy analytics, or Matomo for heavyweight self-host control.

Cookieless trackingHetzner DE hostingOpen source (AGPLv3)Self-host CEFunnels + errors + RUMPublic DPA
nilly vs Swetrix: Snapshot
FeatureLogo: nillynillyLogo: SwetrixSwetrix
Country of originSwitzerlandUnited Kingdom
CategoryWeb AnalyticsWeb Analytics
Open sourceNoYes
Self-hostedNoYes
HeadquartersSwitzerlandUnited Kingdom
Legal entityLyo GmbH, Europaallee 41, 8004 Zürich (CHE-417.675.763)Swetrix Ltd (SC797389), Edinburgh, Scotland
Governing lawSwitzerland (terms)Not listed
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyVendor FAQ: analytics servers in Switzerland (multiple locations). Public site reverse-DNS: KreativMedia/METANET Zürich. Customer-account subprocessors named in privacy policy: Stripe (US payments), Mailerlite (email). Avatars via Gravatar. No full public subprocessor list for backups/monitoring/CDN.Cloud analytics data: Hetzner Online GmbH (Germany) per DPA/Data Policy. End User error monitoring sub-processor: Sentry / Functional Software Inc. (United States). Customer-side Privacy Policy list also includes Paddle (UK payments), Fastmail (Australia business email), AWS (US transactional/marketing email), OpenRouter (US optional AI chat). No known US parent.
Summary

Swiss privacy-first web analytics (Lyo GmbH): cookieless, sub-1kB tracking with realtime dashboards, city-level geo, custom events, unlimited sites, and a REST API as a lightweight Google Analytics alternative.

Cookieless, privacy-first web analytics from a UK company: traffic, funnels, errors, and performance on Hetzner in Germany, with AGPLv3 self-host Community Edition and optional Cloud session replays.

Tags
At a glance: nilly vs Swetrix
At a glanceLogo: nillynillyLogo: SwetrixSwetrix
HQZürich, Switzerland (Lyo GmbH)Edinburgh, United Kingdom
Legal entityLyo GmbH (CHE-417.675.763)Swetrix Ltd (SC797389)
Product modelSaaS web analytics (not self-hosted)Not listed
TrackingCookieless; no IP/fingerprint claimsNot listed
Hosting (claimed)Switzerland (multi-site)Not listed
Commercial modelTraffic-based plans; trial; no permanent free tierEvent-volume Cloud subscription; free self-host CE; timed trial
Live site notekandur.one (nilly branding; nilly.io DNS failed at research)Not listed
Governing lawNot listedScotland (Terms)
Primary hostingNot listedHetzner Online GmbH, Germany
LicenseNot listedAGPLv3 (Community Edition)
Open sourceNot listedYes — github.com/Swetrix/swetrix
Key capabilities: nilly vs Swetrix
Key capabilitiesLogo: nillynillyLogo: SwetrixSwetrix
Cookieless trackingYesYes
Swiss-hosted (claimed)YesNot listed
Swiss entityYesNot listed
Sub-1 kB scriptYesNot listed
REST APIYesNot listed
SaaS onlyYesNot listed
Hetzner DE hostingNot listedYes
Open source (AGPLv3)Not listedYes
Self-host CENot listedYes
Funnels + errors + RUMNot listedYes
Public DPANot listedYes

nilly

  • Sub-1 kB cookieless tracking script

    Vendor documents a client script under 1 kB with no cookies, no IP tracking, and no fingerprinting for site visitors. Suited to teams that want aggregate traffic metrics without analytics cookie banners; still get counsel for your jurisdiction and CMP setup.

  • Realtime dashboard with geo, tech, and campaigns

    Dashboards cover live visitors, overview metrics, top pages, referrers, UTM campaigns, geography from continent to city, and device/browser/OS breakdowns—enough for content and acquisition decisions without a full product-analytics suite.

  • Custom events, CSV export, and email reports

    Define custom events for conversion-style actions, export statistics as CSV, and receive email reports. Fits operators who need lightweight conversion signals and offline analysis rather than session replay or multi-step funnels.

  • REST API for stats, websites, and account

    Documented API endpoints (Bearer API key) manage stats queries (pageviews, visitors, referrers, events, geo, devices, and more), websites, and account objects—useful for internal dashboards or automations on traffic-based plans that include API access.

  • Unlimited websites on traffic-based plans

    Public pricing model is pageview-tier SaaS with unlimited websites per account and a short free trial—not a permanent free tier. Good for agencies or multi-brand operators who outgrow per-site free plans elsewhere; confirm current tiers on the vendor site.

Swetrix

  • Cookieless traffic analytics with hashed sessions

    Lightweight script captures pageviews, referrers/UTMs, devices, and city-level geo without cookies or client-side storage. Per the Data Policy, IP and User-Agent are hashed in memory with a daily rotating salt; only a random session id is stored—so you get sessions without long-term cross-day visitor retention.

  • Funnels, custom events, and goals

    Instrument signups, purchases, and other conversions as custom events; build multi-step funnels and goals in the dashboard. Useful for product and growth teams who need drop-off analysis without bolting on a second product-analytics SaaS.

  • Real-user performance and client error tracking

    Records Web Performance API timings (TTFB, DNS, TLS, render, full page load) and optional JavaScript errors with stack/context by page and browser. Bridges marketing traffic views with engineering signals that pure pageview tools omit.

  • Opt-in Cloud session replays with privacy modes

    Cloud projects can call startSessionReplay() to record DOM and interactions; default modes mask text/inputs. Replays are not created by ordinary pageviews—customers must enable them and own consent, masking, and page exclusions. Cloud-only versus Community Edition.

  • AGPLv3 open source with Docker self-host CE

    Core platform is public on GitHub under GNU AGPLv3; Community Edition deploys via official Docker docs with MySQL, ClickHouse, and Redis. CE includes core analytics, events, sessions, funnels, performance, and errors—but not all Cloud extras (replays, some alerts/org/AI features).

  • Alerts, API, GA import, and team access

    Configure alerts to email, Slack, Telegram, Discord, webhooks, or push; pull or push data via the API; import GA4 history; invite organisations with roles or share password-protected/public dashboards. Fits agencies and multi-site operators who outgrow single-user tools.

Assurance & compliance: nilly vs Swetrix
Assurance & complianceLogo: nillynillyLogo: SwetrixSwetrix
Independent security / no-logs audit
Not found

No public third-party audit report found for tracking claims.

Not found

Searched marketing, DPA, privacy, and data policy; no public independent audit PDF located. Open-source code is available for review.

ISO 27001
Not found

No vendor ISO 27001 certificate published on product site (underlying Swiss host DCs may be certified separately).

Not found

No public ISO 27001 certification claim found on primary pages.

SOC 2 / SOC 3
Not found
Not found

No public SOC 2/3 report found.

GDPR / EU data protection
Vendor claimed

Swiss entity; privacy policy includes GDPR rights language; cookieless visitor tracking claimed. Confirm DPA for B2B.

Vendor claimed

UK company; public GDPR/PECR discussion in Data Policy; cookieless design with non-stored IPs for standard analytics; Hetzner DE hosting; public DPA. Optional replays may be personal data depending on configuration—customer assesses legal basis.

US CLOUD Act exposure (indicative)
Partial

Swiss operator, no known US parent, Swiss-claimed analytics hosting; US SaaS subprocessors Stripe (payments) and Gravatar (avatars) on customer path. Not legal advice.

Partial

No known US parent; primary analytics on Hetzner DE. Material exception: Sentry (US) processes End User error data per DPA; Privacy Policy also lists AWS and OpenRouter (US) for customer email/AI. Indicative medium exposure—not a clean bill. Not legal advice.

Data processing agreement (B2B)
Not found

No public DPA download found; request from vendor.

Vendor claimed

Public DPA at swetrix.com/dpa incorporated by Terms; acceptance by use of Service; signed copy on request.

EU AI Act
Not applicable

Web analytics product; not marketed as an AI system.

Not applicable

Core product is web analytics, not an AI system. Optional Ask AI / OpenRouter is ancillary; confirm if your deployment enables it.

Swiss Made Software / Swiss Web labels
Vendor claimed

Cited on About and Swiss Union member page as recognition/labels—not a security audit.

Not listed
Considerations & known limitations: nilly vs Swetrix
Considerations & known limitationsLogo: nillynillyLogo: SwetrixSwetrix
Brand/domain transition (nilly.io vs kandur.one)
Medium

Product still branded nilly, but the live marketing/API host is kandur.one; nilly.io did not resolve in DNS during research. Verify tracking domains, docs, and status before production cutover.

Not listed
US SaaS on customer account path
Medium

Stripe (payments) and Gravatar (avatars) are US-group services. Visitor metrics are claimed Swiss-hosted and non-personal, but account/billing data is not Switzerland-only end-to-end.

Medium

Primary analytics hosting is Hetzner DE, but Sentry (US) is an End User error-tracking sub-processor on the DPA, and AWS/OpenRouter appear for customer email/AI. Orgs with strict no-US-cloud rules need explicit acceptance or self-host CE to avoid those paths.

Thin public assurance pack
Medium

No public ISO 27001/SOC 2, independent security audit, or DPA page found. Fine for many SMB shortlists; friction for regulated enterprise questionnaires.

Not listed
No self-host or open-source edition
Low

Cannot run on your own infra or audit server code from a public repo. Hard limit for sovereignty programs that require self-host.

Not listed
Small independent operator
Low

Founder-owned Swiss GmbH without VC narrative—positive for independence, but buyers should assess support SLAs, roadmap continuity, and single-vendor concentration.

Not listed
Session replay is opt-in and controller-ownedNot listed
Medium

Cloud replays can capture DOM and inputs unless masked. Customers must enable startSessionReplay(), configure privacy modes/exclusions, and provide notices/consent where required—misconfiguration can reintroduce personal data risk that standard cookieless pageviews avoid.

No public ISO/SOC or third-party auditNot listed
Medium

Assurance relies on first-party policies, Hetzner infrastructure claims, and open source. Enterprise questionnaires that hard-gate on certs will stall until materials are provided under NDA or produced.

Cloud vs Community Edition feature gapNot listed
Low

Self-host CE is free and covers core analytics, but replays and several Cloud growth/ops features are limited or Cloud-only. Budget and feature planning must not assume feature parity.

Daily salt rotation limits retention metricsNot listed
Low

Cookieless design deliberately prevents classic multi-day visitor retention. Teams that need that metric class need another product or consented identity.

Fit

nilly

Best fit when

  • Privacy-conscious SMBs and indie sites replacing GA4 with aggregate metrics only
  • Teams that want Swiss legal entity and Swiss-located analytics servers
  • Operators running many sites who benefit from unlimited websites on traffic tiers
  • Builders who need a simple REST API for pageviews, referrers, geo, and events
  • Sites prioritizing minimal JS weight and fewer analytics consent prompts

Poor fit when

  • Organizations that must self-host or review open-source analytics code
  • Buyers needing published ISO 27001/SOC 2 or a full public DPA/subprocessor pack
  • Marketing teams requiring session replay, heatmaps, or advanced e-commerce/ad sync suites
  • Enterprises that need SSO/SCIM, formal SLAs, and large-vendor assurance paperwork as table stakes

Consider instead when

  • When: You want open-source and/or self-host privacy analytics with a larger community

    Consider: Plausible Analytics or Pirsch Analytics

    nilly is proprietary SaaS only.

  • When: You want another European cookieless SaaS with a simple product story

    Consider: Simple Analytics

    Dutch peer; compare geo depth, API, and residency claims side by side.

  • When: You need deeper marketing, shop, and tag/consent analytics for EU enterprises

    Consider: etracker

    German suite-oriented alternative; heavier than nilly's lightweight dashboard.

  • When: You depend on free unlimited scale and Google ads/ecosystem integration

    Consider: Google Analytics (GA4)

    Different privacy and residency tradeoffs; not a sovereignty shortlist.

Swetrix

Best fit when

  • SMEs, agencies, and product teams replacing GA4 who need cookieless traffic stats without a cookie banner driven only by analytics
  • Engineering-minded buyers who want error tracking and real-user performance in the same privacy-first dashboard as pageviews
  • Teams that may enable Cloud session replays later but can treat them as explicit opt-in with their own legal basis
  • Operators willing to run Docker Community Edition (MySQL/ClickHouse/Redis) when Cloud commercial terms or feature limits do not fit
  • Buyers who need a public B2B DPA, API access, GA4 import, and multi-channel alerts under a UK legal entity

Poor fit when

  • Enterprises that require published ISO 27001 / SOC 2 certificates or independent audit PDFs before shortlist
  • Policies that forbid any US-group subprocessors (Sentry is listed for End User error data; AWS/OpenRouter appear for customer services)
  • Use cases that depend on long-term cookie-based retention or cross-device identity graphs
  • Buyers who only want free hosted analytics with no paid Cloud tier and no self-host operations burden
  • Sites that will run session replays on sensitive flows without capacity to configure masking, exclusions, and consent

Consider instead when

  • When: You only need minimal cookieless pageviews/referrers with the smallest possible product surface

    Consider: Plausible Analytics or Simple Analytics

    Swetrix adds funnels, errors, RUM, and Cloud replays; peers stay closer to pure traffic analytics.

  • When: You need deep on-prem control, plugins, and mature enterprise self-host packaging

    Consider: Matomo (self-host or managed EU hosts such as Matomo by Stackhero)

    Heavier ops and optional cookies; stronger fit for large controlled deployments.

  • When: You must stay inside Google advertising measurement and free GA4 ecosystem tooling

    Consider: Google Analytics

    Trade privacy, consent, and transfer complexity for ads integration and zero software fee.

Open questions for due diligence

nilly

  • Will Lyo GmbH sign a B2B DPA and provide a current full subprocessor list (including backups, monitoring, CDN)?
  • Is analytics data retained only on Swiss hosts, or are any DR/replicas outside Switzerland?
  • What is the durable public domain for tracking scripts and API (kandur.one vs nilly.io) for the next 12 months?
  • Are there enterprise features (SSO, roles, retention controls, MSA/SLA) beyond self-serve traffic plans?
  • Can the vendor provide any independent security assessment under NDA?

Swetrix

  • Can Enterprise contracts exclude or replace Sentry (and other US-group subprocessors) for End User data paths?
  • Are ISO 27001, SOC 2, or pen-test summaries available under NDA?
  • What is the exact backup/DR location topology beyond “secure backups” wording on the DPA?
  • Which Cloud-only features remain permanently out of CE versus delayed open-source release?
  • For session replay at your traffic volumes, what retention defaults and export/delete SLAs apply on your plan?