nilly vs Tinylytics

Compare nilly and Tinylytics on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Fathom Analytics, Google Analytics

Logo: nilly

nilly

Switzerland· Web Analytics

Needs review

Shortlist nilly when you want Swiss-entity, cookieless, ultra-light site analytics with realtime dashboards, city geo, custom events, unlimited sites, and an API—without GA4 consent weight. Skip when you need self-host/open source, enterprise audit packs, or deep marketing-suite analytics; consider Plausible Analytics, Simple Analytics, or etracker instead.

Cookieless trackingSwiss-hosted (claimed)Swiss entitySub-1 kB scriptREST APISaaS only
Logo: Tinylytics

Tinylytics

United Kingdom· Web Analytics

Needs review

Shortlist Tinylytics when you want cookieless page analytics plus bundled uptime/SSL/content checks for a handful of small sites, with primary data on Hetzner in Germany and founder support. Skip when you need self-host/open source, formal ISO/SOC packs, or enterprise multi-tenant governance—consider Plausible Analytics or Simple Analytics instead.

Cookieless analyticsPrimary host: Hetzner DEUptime + SSL monitoringBroken-link crawlsSaaS only (no self-host)Solo-founder UK
nilly vs Tinylytics: Snapshot
FeatureLogo: nillynillyLogo: TinylyticsTinylytics
Country of originSwitzerlandUnited Kingdom
CategoryWeb AnalyticsWeb Analytics
Open sourceNoNo
Self-hostedNoNo
HeadquartersSwitzerlandUnited Kingdom
Legal entityLyo GmbH, Europaallee 41, 8004 Zürich (CHE-417.675.763)Vincent Ritter Consulting (service brand; terms state not separately incorporated yet)
Governing lawSwitzerland (terms)Not clearly stated as a single governing-law clause on the public terms page; confirm contractually
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyVendor FAQ: analytics servers in Switzerland (multiple locations). Public site reverse-DNS: KreativMedia/METANET Zürich. Customer-account subprocessors named in privacy policy: Stripe (US payments), Mailerlite (email). Avatars via Gravatar. No full public subprocessor list for backups/monitoring/CDN.Primary analytics storage: Hetzner Falkenstein (Germany). CDN/security: Cloudflare. Error monitoring: Sentry.io. Payments: Paddle and Lemon Squeezy (Stripe company). Optional: IPinfo geo fallback for API hits; opt-in AI Insights via xAI and Google Gemini. No public backup-provider detail beyond that stack.
Summary

Swiss privacy-first web analytics (Lyo GmbH): cookieless, sub-1kB tracking with realtime dashboards, city-level geo, custom events, unlimited sites, and a REST API as a lightweight Google Analytics alternative.

Privacy-first cookieless web analytics for small sites, with bundled uptime/SSL checks, content monitoring, events, and founder support—hosted primarily on Hetzner in Germany.

Tags
At a glance: nilly vs Tinylytics
At a glanceLogo: nillynillyLogo: TinylyticsTinylytics
HQZürich, Switzerland (Lyo GmbH)Not listed
Legal entityLyo GmbH (CHE-417.675.763)Not listed
Product modelSaaS web analytics (not self-hosted)Not listed
TrackingCookieless; no IP/fingerprint claimsNot listed
Hosting (claimed)Switzerland (multi-site)Not listed
Commercial modelTraffic-based plans; trial; no permanent free tierPaid site-count plans; short trial; no permanent free tier
Live site notekandur.one (nilly branding; nilly.io DNS failed at research)Not listed
HQ / operatorNot listedVincent Ritter Consulting, United Kingdom
LaunchedNot listed12 June 2023 (live counters on homepage)
Primary hostingNot listedHetzner, Falkenstein, Germany
DeploymentNot listedManaged SaaS only (not open source, not self-hosted)
DifferentiatorsNot listedAnalytics + uptime/SSL/content monitoring + widgets
Key capabilities: nilly vs Tinylytics
Key capabilitiesLogo: nillynillyLogo: TinylyticsTinylytics
Cookieless trackingYesYes
Swiss-hosted (claimed)YesNot listed
Swiss entityYesNot listed
Sub-1 kB scriptYesNot listed
REST APIYesNot listed
SaaS onlyYesYes
Primary host: Hetzner DENot listedYes
Uptime + SSL monitoringNot listedYes
Broken-link crawlsNot listedYes
Solo-founder UKNot listedYes

nilly

  • Sub-1 kB cookieless tracking script

    Vendor documents a client script under 1 kB with no cookies, no IP tracking, and no fingerprinting for site visitors. Suited to teams that want aggregate traffic metrics without analytics cookie banners; still get counsel for your jurisdiction and CMP setup.

  • Realtime dashboard with geo, tech, and campaigns

    Dashboards cover live visitors, overview metrics, top pages, referrers, UTM campaigns, geography from continent to city, and device/browser/OS breakdowns—enough for content and acquisition decisions without a full product-analytics suite.

  • Custom events, CSV export, and email reports

    Define custom events for conversion-style actions, export statistics as CSV, and receive email reports. Fits operators who need lightweight conversion signals and offline analysis rather than session replay or multi-step funnels.

  • REST API for stats, websites, and account

    Documented API endpoints (Bearer API key) manage stats queries (pageviews, visitors, referrers, events, geo, devices, and more), websites, and account objects—useful for internal dashboards or automations on traffic-based plans that include API access.

  • Unlimited websites on traffic-based plans

    Public pricing model is pageview-tier SaaS with unlimited websites per account and a short free trial—not a permanent free tier. Good for agencies or multi-brand operators who outgrow per-site free plans elsewhere; confirm current tiers on the vendor site.

Tinylytics

  • Cookie-free unique hits with rotating salts

    Page views and unique hits without tracking cookies or fingerprinting. Uniques combine truncated request signals with a 12-hour rotating salt and one-way hash, reset daily at midnight UTC; visitor IPs are not stored in hits. Suited to indie sites that want trendable uniques without consent banners for analytics cookies.

  • Thunder Clap uptime, SSL, and domain alerts

    In-house multi-region health checks (default every 10 minutes) confirm downtime before emailing, plus SSL expiry notices and domain monitoring. Ultra can shorten intervals. Replaces a separate uptime tool for small fleets—but false downs can occur if WAFs block the Tinylytics monitor user-agent.

  • Daily content crawl for broken links and mixed content

    Subscribed sites can crawl up to 50 pages (two levels deep) on a daily cadence, flagging broken links and mixed HTTP assets on HTTPS pages, with ignore lists and re-check. Ultra adds optional AI spell-check on visible copy—keep it off if AI subprocessors are out of policy.

  • Attribute-based event tracking (beta)

    Enable events on the embed script and mark elements with data-tinylytics-event using category.action names (optional values for downloads). No GTM required; beacon mode helps navigations. Still beta—expect API/schema changes and incomplete capture under aggressive blockers.

  • Public stats, kudos, hit counters, API, and webhooks

    Share passcode-protected public stats, embed hit counters and kudos buttons, export CSV, call the documented API, and push signed webhooks for visits, events, and monitoring. Built for transparent blogs and light automation rather than enterprise BI warehouses.

Assurance & compliance: nilly vs Tinylytics
Assurance & complianceLogo: nillynillyLogo: TinylyticsTinylytics
Independent security / no-logs audit
Not found

No public third-party audit report found for tracking claims.

Not found

No public third-party security or no-logs audit report found on official docs.

ISO 27001
Not found

No vendor ISO 27001 certificate published on product site (underlying Swiss host DCs may be certified separately).

Not found

No ISO 27001 claim found on privacy, compliance, or hosting pages.

SOC 2 / SOC 3
Not found
Not found

No SOC 2/3 report or claim found on public site.

GDPR / EU data protection
Vendor claimed

Swiss entity; privacy policy includes GDPR rights language; cookieless visitor tracking claimed. Confirm DPA for B2B.

Vendor claimed

Vendor documents GDPR-oriented design (cookieless, data minimisation, EU primary host, deletion). Not independent certification.

US CLOUD Act exposure (indicative)
Partial

Swiss operator, no known US parent, Swiss-claimed analytics hosting; US SaaS subprocessors Stripe (payments) and Gravatar (avatars) on customer path. Not legal advice.

Partial

UK operator, no known US parent, primary host Hetzner DE; partial exposure via Cloudflare, Sentry, Lemon Squeezy/Paddle, optional IPinfo and opt-in US AI APIs. Not legal advice.

Data processing agreement (B2B)
Not found

No public DPA download found; request from vendor.

Not found

No public DPA/downloadable processor agreement found; ask the vendor before B2B rollout.

EU AI Act
Not applicable

Web analytics product; not marketed as an AI system.

Not applicable

Core product is analytics/monitoring; optional AI insights are secondary and opt-in.

Swiss Made Software / Swiss Web labels
Vendor claimed

Cited on About and Swiss Union member page as recognition/labels—not a security audit.

Not listed
Considerations & known limitations: nilly vs Tinylytics
Considerations & known limitationsLogo: nillynillyLogo: TinylyticsTinylytics
Brand/domain transition (nilly.io vs kandur.one)
Medium

Product still branded nilly, but the live marketing/API host is kandur.one; nilly.io did not resolve in DNS during research. Verify tracking domains, docs, and status before production cutover.

Not listed
US SaaS on customer account path
Medium

Stripe (payments) and Gravatar (avatars) are US-group services. Visitor metrics are claimed Swiss-hosted and non-personal, but account/billing data is not Switzerland-only end-to-end.

Medium

Cloudflare, Sentry, payment processors (incl. Lemon Squeezy/Stripe group), optional IPinfo and opt-in xAI/Gemini mean the stack is not EU-only end-to-end despite Hetzner primary storage.

Thin public assurance pack
Medium

No public ISO 27001/SOC 2, independent security audit, or DPA page found. Fine for many SMB shortlists; friction for regulated enterprise questionnaires.

Not listed
No self-host or open-source edition
Low

Cannot run on your own infra or audit server code from a public repo. Hard limit for sovereignty programs that require self-host.

Not listed
Small independent operator
Low

Founder-owned Swiss GmbH without VC narrative—positive for independence, but buyers should assess support SLAs, roadmap continuity, and single-vendor concentration.

Not listed
Solo-founder operational concentrationNot listed
Medium

Service is provided by Vincent Ritter Consulting / a solo developer. Support is personal and fast for indies, but bus-factor and formal SLA expectations differ from larger vendors.

No public ISO/SOC/audit or DPA packNot listed
Medium

Enterprise security questionnaires will hit gaps until the vendor supplies audits and a B2B DPA under NDA or email.

Scale and feature boundariesNot listed
Low

Content crawls are depth/page limited; event tracking is beta; fair-usage applies to extreme hit volumes; no self-host escape hatch.

Optional AI shares aggregated analyticsNot listed
Low

AI Insights and related AI spell-check are opt-in and send aggregated (not visitor PII per vendor) data to third-party AI providers—leave disabled under strict AI policies.

Fit

nilly

Best fit when

  • Privacy-conscious SMBs and indie sites replacing GA4 with aggregate metrics only
  • Teams that want Swiss legal entity and Swiss-located analytics servers
  • Operators running many sites who benefit from unlimited websites on traffic tiers
  • Builders who need a simple REST API for pageviews, referrers, geo, and events
  • Sites prioritizing minimal JS weight and fewer analytics consent prompts

Poor fit when

  • Organizations that must self-host or review open-source analytics code
  • Buyers needing published ISO 27001/SOC 2 or a full public DPA/subprocessor pack
  • Marketing teams requiring session replay, heatmaps, or advanced e-commerce/ad sync suites
  • Enterprises that need SSO/SCIM, formal SLAs, and large-vendor assurance paperwork as table stakes

Consider instead when

  • When: You want open-source and/or self-host privacy analytics with a larger community

    Consider: Plausible Analytics or Pirsch Analytics

    nilly is proprietary SaaS only.

  • When: You want another European cookieless SaaS with a simple product story

    Consider: Simple Analytics

    Dutch peer; compare geo depth, API, and residency claims side by side.

  • When: You need deeper marketing, shop, and tag/consent analytics for EU enterprises

    Consider: etracker

    German suite-oriented alternative; heavier than nilly's lightweight dashboard.

  • When: You depend on free unlimited scale and Google ads/ecosystem integration

    Consider: Google Analytics (GA4)

    Different privacy and residency tradeoffs; not a sovereignty shortlist.

Tinylytics

Best fit when

  • Indie blogs, portfolios, and side projects that want simple cookieless stats without Google Analytics
  • Small sites that also want uptime, SSL expiry, and broken-link checks in the same tool
  • Operators who prefer founder-answered support and lightweight embeds over enterprise marketing stacks
  • Teams OK with managed EU primary hosting and willing to review named US-group subprocessors (CDN, payments, optional AI)
  • Agencies managing a modest number of client sites with public stats or kudos-style engagement widgets

Poor fit when

  • Orgs that require self-hosted collectors or open-source audit of the full analytics stack
  • Procurement needing published ISO 27001, SOC 2, independent audits, or a downloadable DPA out of the box
  • Very high-traffic properties needing contractual capacity/SLA commitments beyond fair-usage conversation
  • Policies that ban Cloudflare/Sentry/US payment or optional US AI APIs on any data path
  • Teams that need session replay, heatmaps, or deep advertising attribution (Clarity/GA territory)

Consider instead when

  • When: You need open-source and optional self-hosting of the analytics stack

    Consider: Plausible Analytics

    Estonian product with Cloud plus Community Edition self-host; less bundling of uptime/content monitors.

  • When: You want European cookieless analytics with a simpler analytics-only scope

    Consider: Simple Analytics

    Strong privacy positioning; compare feature depth and monitoring separately.

  • When: You need free-at-scale marketing analytics, ads integrations, or attribution depth

    Consider: Google Analytics (incumbent) — or stay on a privacy tool if GA is disallowed

    Different privacy and sovereignty profile entirely.

  • When: You need session replay or heatmaps and accept that privacy model

    Consider: Microsoft Clarity or specialised replay tools

    Tinylytics deliberately avoids fingerprinting-style session products.

Open questions for due diligence

nilly

  • Will Lyo GmbH sign a B2B DPA and provide a current full subprocessor list (including backups, monitoring, CDN)?
  • Is analytics data retained only on Swiss hosts, or are any DR/replicas outside Switzerland?
  • What is the durable public domain for tracking scripts and API (kandur.one vs nilly.io) for the next 12 months?
  • Are there enterprise features (SSO, roles, retention controls, MSA/SLA) beyond self-serve traffic plans?
  • Can the vendor provide any independent security assessment under NDA?

Tinylytics

  • Will Vincent Ritter Consulting sign a GDPR Article 28 DPA and provide a current subprocessor list under contract?
  • Are backups/DR and email delivery fully covered by the named providers, or are there additional hosts?
  • Is there any roadmap for independent security review, SOC 2, or ISO 27001?
  • What contractual terms apply for accounts consistently above the fair-usage hit threshold?
  • For AI Insights: exact retention, regions, and processor terms at xAI and Google for the paid API plans used?