Pirsch Analytics vs Pulse by Ciphera

Compare Pirsch Analytics and Pulse by Ciphera on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Fathom Analytics, Google Analytics

Logo: Pirsch Analytics

Pirsch Analytics

Germany· Web Analytics

Needs review

Shortlist Pirsch when you want German-operated, cookie-free web analytics with funnels/events, agency white-label, and a public DPA—hosted on Hetzner per vendor docs. Skip when you need free full-product self-host, session replay/heatmaps, or a stack with zero US-group subprocessors; consider Plausible or Simple Analytics instead.

Cookie-free hashingOpen-source core (AGPL)Hetzner DE hosting (claimed)Server-side trackingAgency white-labelPublic DPA/AVV
Logo: Pulse by Ciphera

Pulse by Ciphera

Belgium· Web Analytics

Needs review

Shortlist Pulse when you want cookieless traffic analytics plus uptime and Lighthouse in one Belgian-operated, Swiss-hosted SaaS and can accept a closed managed backend. Skip when you need full self-hosting or GA-style user-level history; consider Plausible Analytics or Simple Analytics instead.

EU-operatedCookielessOpen-source clientSwiss-hosted dataNo analytics cookies
Pirsch Analytics vs Pulse by Ciphera: Snapshot
FeatureLogo: Pirsch AnalyticsPirsch AnalyticsLogo: Pulse by CipheraPulse by Ciphera
Country of originGermanyBelgium
CategoryWeb AnalyticsWeb Analytics
Open sourceYesYes
Self-hostedNoNo
HeadquartersGermanyBelgium
Legal entityEmvi Software GmbH (Nickelstraße 1b, 33378 Rheda-Wiedenbrück; HRB 11575, AG Gütersloh)Ciphera BV
Governing lawGermany / EU GDPRBelgian law (GDPR); Swiss FADP for infrastructure location
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
EU-hosted statusNot listedPartial
Hosting / residencyAnalytics: Hetzner Online GmbH, Germany (vendor claims Nuremberg/Falkenstein). Account/ops subprocessors named in privacy policy include AWS SES (Amazon Web Services EMEA), Google Workspace (Google Cloud EMEA), Stripe, Inc. (US), Intuition Machines, Inc. (US CAPTCHA), and Datev eG (DE).Primary compute and object storage on Exoscale in Switzerland (Zurich). Encrypted backups and domain registration via Infomaniak (Switzerland). CDN/DNS/DDoS via Bunny (Slovenia HQ, global edge for transient IPs). Payments via Mollie (Netherlands). GitHub (US) for public source code only, per Trust page.
Summary

Cookie-free web analytics from Emvi Software GmbH in Germany: hash-based visitor IDs, open-source core, Hetzner-hosted SaaS with funnels, events, and agency white-label.

Cookie-free web analytics with traffic, funnels, uptime and Lighthouse checks in one Belgian-operated, Swiss-hosted dashboard.

Tags
At a glance: Pirsch Analytics vs Pulse by Ciphera
At a glanceLogo: Pirsch AnalyticsPirsch AnalyticsLogo: Pulse by CipheraPulse by Ciphera
HQRheda-Wiedenbrück, GermanyDiegem, Belgium (Ciphera BV)
Legal entityEmvi Software GmbHCiphera BV (KBO/BCE 1013.721.660)
CategoryWeb analytics (SaaS)Not listed
Open sourceCore library AGPL-3.0; full SaaS commercialNot listed
Self-hostEnterprise on-prem option; not free CENot listed
Commercial modelUsage-based (monthly page views); trial availableFree Hobby tier; paid plans by traffic scale
Primary hosting (claimed)Hetzner Germany (Nuremberg/Falkenstein)Not listed
FoundedNot listed18 September 2024 (CBE)
Primary data regionNot listedSwitzerland (Exoscale Zurich)
LicenseNot listedAGPL-3.0 client; managed backend closed
CookielessNot listedYes (vendor claim: no cookies, no fingerprinting)
Data residency regionsNot listedSwitzerland (Exoscale primary; Infomaniak backups)
Key capabilities: Pirsch Analytics vs Pulse by Ciphera
Key capabilitiesLogo: Pirsch AnalyticsPirsch AnalyticsLogo: Pulse by CipheraPulse by Ciphera
Cookie-free hashingYesNot listed
Open-source core (AGPL)YesNot listed
Hetzner DE hosting (claimed)YesNot listed
Server-side trackingYesNot listed
Agency white-labelYesNot listed
Public DPA/AVVYesNot listed
EU-operatedNot listedYes
CookielessNot listedYes
Open-source clientNot listedYes
Swiss-hosted dataNot listedYes
No analytics cookiesNot listedYes

Pirsch Analytics

  • Cookie-free 24-hour visitor hashing

    Recognizes visitors without cookies by hashing IP, User-Agent, date, and a per-site salt into a short ID. The vendor states IPs are not stored and cross-site linkage is blocked by the salt; sessions expire after 24 hours so long-term profiles are not built. Best for sites that want aggregate traffic metrics without a dedicated analytics cookie banner—confirm ePrivacy/TTDSG fit with counsel.

  • Server-side and script integrations

    Instrument via JS snippet, CMS plugins (e.g. WordPress, Shopify, Webflow, Framer), or backend SDKs/API (Go library and other stacks). Server-side collection improves resilience when ad blockers strip client scripts. Tradeoff: backend integration costs more engineering time than a single script tag.

  • Funnels, events, goals, and tag segmentation

    Goes past pageviews with custom events, conversion goals, multi-step funnels, session path exploration, outbound/download/404 tracking, and tags for A/B tests or channel segmentation. Webhooks and email reports push insights into existing tools. Some advanced metrics (e.g. custom event metrics, e-commerce revenue tracking) sit on higher commercial tiers—verify the live feature matrix.

  • Agency white-label and shared dashboards

    Custom domains, themes, logos, and broader white-label options let agencies present analytics under their own brand. Public dashboards and unique access links support clients without full account sprawl; roles/teams scale collaboration. Strong fit for multi-client portfolios; less relevant for a single personal blog.

  • Migration imports, API, and unlimited retention (stated)

    Import historical data from Google Analytics, Plausible, or Fathom; export CSV; use the REST API and SDKs for custom pipelines. Pricing docs state unlimited data retention across Standard, Plus, and Enterprise. Limits are usage-based on monthly page views (events and a share of session extensions count)—plan for growth, not perpetual free volume.

Pulse by Ciphera

  • Cookieless traffic dashboard

    Pageviews, unique-visitor estimates, referrers, UTM campaigns, device or browser splits, and country-level geo from a single script tag, without cookies or fingerprinting according to Ciphera's privacy docs.

  • Journeys and conversion funnels

    Step-by-step path columns and multi-step funnels with drop-off analysis, filterable by page, country, device, or referrer for privacy-preserving conversion debugging.

  • Uptime monitors with alert routes

    Built-in uptime checks with downtime and recovery alerts to email, Slack, Discord, or a webhook, so availability sits beside traffic in one console.

  • Daily Lighthouse and Core Web Vitals

    Scheduled mobile and desktop Lighthouse runs with performance, accessibility, best-practices, SEO scores, and Core Web Vitals trends without a separate RUM product.

  • Inspectable AGPL client and read API

    Dashboard and tracking script are AGPL-3.0 on GitHub; Ciphera also documents a public read API, CLI, and export paths while keeping the managed backend closed.

Assurance & compliance: Pirsch Analytics vs Pulse by Ciphera
Assurance & complianceLogo: Pirsch AnalyticsPirsch AnalyticsLogo: Pulse by CipheraPulse by Ciphera
Independent security / privacy audit
Not found

Open-source core allows code review; no public third-party audit PDF located in this research pass.

Not found

Trust page states no independent audit yet; Tessera self-audit published; independent audit planned.

ISO 27001
Not found

No ISO 27001 certificate or registry entry found on official trust pages reviewed.

Not found

Ciphera explicitly states it holds no ISO 27001 certification.

SOC 2 / SOC 3
Not found

No public SOC 2/3 report referenced on official pages reviewed.

Not found

Ciphera explicitly states it holds no SOC 2 certification.

GDPR / EU data protection
Vendor claimed

German controller/processor Emvi Software GmbH; cookie-free hashing design; public DPA; German Hetzner hosting claims. Vendor also cites CCPA/PECR/Schrems II—treat as claims, confirm with counsel.

Vendor claimed

Belgian controller; privacy policy describes GDPR/FADP bases and Pulse processor role. Not legal advice.

US CLOUD Act exposure (indicative)
Partial

EU entity / no known US parent and Hetzner DE analytics hosting, but privacy policy names AWS SES, Google Workspace, Stripe, and Intuition Machines (US-group services) for email/CAPTCHA/payments. Not legal advice.

Partial

EU (Belgian) entity with no known US parent; primary hosts are European (Exoscale, Infomaniak, Bunny, Mollie). Residual paths: GitHub (US) for source code only; Bunny global edge for transient IPs. Indicative only, not legal advice.

Data processing agreement (B2B)
Vendor claimed

Downloadable English DPA and German AVV PDFs linked from docs.pirsch.io/privacy.

On request / NDA

Privacy policy: DPA available on request at privacy@ciphera.net for Pulse processor relationships.

EU AI Act
Not applicable

Classical web analytics product; not marketed as an AI system.

Not applicable

Web analytics product; not an AI system product page.

Considerations & known limitations: Pirsch Analytics vs Pulse by Ciphera
Considerations & known limitationsLogo: Pirsch AnalyticsPirsch AnalyticsLogo: Pulse by CipheraPulse by Ciphera
US-group account/ops subprocessors
Medium

Even with German analytics hosting claims, customer email, CAPTCHA, and payments involve AWS, Google, Stripe, and Intuition Machines. Sovereign or “no US cloud” policies need explicit exception handling or Enterprise architecture review.

Not listed
No public ISO/SOC or third-party audit
Medium

Procurement teams that require ISO 27001 or SOC 2 evidence will need vendor questionnaires or NDA materials; public pages did not show those certs.

Not listed
Open-source core ≠ free full self-host
Low

Teams assuming AGPL means free on-prem of the entire product may be surprised; full on-prem is positioned as Enterprise.

Not listed
Fingerprinting still needs legal fit review
Low

Cookie-free hashing is not automatically lawful everywhere without information/consent analysis. Banner removal should be validated for your jurisdiction and tag stack.

Not listed
Page-view usage limits
Low

Plans are metered on monthly page views (with events and partial session extensions counting). Hitting the cap can restrict dashboard access until upgrade or cycle reset—model traffic before cutover.

Not listed
Managed backend is not open sourceNot listed
Medium

You can audit the browser script and dashboard code, but not the operated ingestion and storage service. Procurement that requires full-stack self-host or full server auditability should look elsewhere.

No ISO/SOC or independent audit yetNot listed
Medium

Ciphera publishes threat models, a warrant canary, and a subprocessor list, but explicitly has no ISO 27001 or SOC 2 and no completed independent audit. Enterprise security reviews will need questionnaires and a signed DPA.

Primary data residency is Switzerland, not EU/EEANot listed
Low

Swiss adequacy covers many GDPR transfer questions, but policies that hard-require EU/EEA datacenter soil will classify this as partial rather than EU-hosted.

Marketing vs privacy wording conflictsNot listed
Low

Product FAQ pages disagree on whether custom events ship today and whether a DPA is needed. Prefer privacy@ and the privacy policy for legal commitments until Ciphera aligns the FAQs.

Fit

Pirsch Analytics

Best fit when

  • EU sites replacing Google Analytics that need pageviews, campaigns, events, and funnels without analytics cookies
  • Agencies needing multi-site dashboards, client access links, and white-label branding
  • Teams that can instrument server-side or proxy scripts for better ad-blocker resilience
  • Buyers who want a German GmbH, downloadable DPA, and Hetzner-Germany residency claims for analytics data
  • Orgs evaluating Enterprise SAML, raw data access, or on-prem/managed private deployment

Poor fit when

  • Teams that require a free, full-product self-hosted community edition (core library ≠ full SaaS)
  • Product or UX research needing session replay, heatmaps, or persistent cross-site user identity
  • Procurement policies that forbid any US-group subprocessor (email CAPTCHA/billing still touch AWS/Google/Stripe/Intuition Machines)
  • Heavy product-analytics / multi-product identity graphs (closer to Amplitude/Mixpanel class tools)

Consider instead when

  • When: You need a free full-stack self-hosted analytics product with AGPL community edition

    Consider: Plausible Analytics (CE) or other open full products in your shortlist

    Pirsch open-sources the tracking core; on-prem of the full product is Enterprise-scoped.

  • When: You want the simplest possible privacy-first metrics with a Dutch vendor

    Consider: Simple Analytics

    Fewer advanced funnel/white-label features; different packaging tradeoffs.

  • When: You need heatmaps or session replay more than classical web analytics

    Consider: Hotjar, Microsoft Clarity, or EU UX-analytics peers

    Expect heavier consent and data-minimization review.

  • When: You must stay inside Google’s advertising and BigQuery measurement ecosystem

    Consider: Google Analytics / Google Tag Manager stack

    Opposite privacy and transfer posture—only if legal review accepts it.

Pulse by Ciphera

Best fit when

  • EU or Swiss organisations replacing GA4 primarily to remove analytics cookies and consent-banner friction
  • Teams that want traffic, funnels, uptime, and Lighthouse scores in one vendor console
  • Buyers who need a Belgian legal entity and named European subprocessors rather than a US cookieless SaaS
  • Sites that can work with aggregate and month-scoped visitor estimates instead of persistent user IDs
  • Engineering leads who want the browser script and dashboard code on GitHub under AGPL-3.0 for inspection

Poor fit when

  • Organisations that must self-host the full analytics backend (Pulse's managed core is closed)
  • Product analytics use cases that need durable cross-visit identity, cohorting, or GA4 BigQuery-style user exports
  • Buyers requiring completed ISO 27001, SOC 2, or a published independent security audit today
  • Teams that need EU/EEA soil specifically rather than Swiss residency (primary data is in Switzerland)

Consider instead when

  • When: You need a mature EU cookieless analytics product with an official full-stack self-host option

    Consider: Plausible Analytics

    Plausible (Estonia) is the common self-host plus SaaS peer; Pulse keeps the backend managed-only.

  • When: You want a minimal Dutch cookieless counter without uptime or Lighthouse bundles

    Consider: Simple Analytics

    Closer peer for strictly analytics SaaS; Pulse differentiates with ops-style panels.

  • When: You need enterprise analytics with strong EU residency controls and heavier compliance packaging

    Consider: Piwik PRO or Friendly Analytics

    Heavier Matomo-class or Swiss-hosted peers when Pulse's startup assurance set is too thin.

Open questions for due diligence

Pirsch Analytics

  • Can Enterprise on-prem exclude AWS SES / Google Workspace / Stripe / CAPTCHA US-group dependencies for the customer’s deployment?
  • Is any ISO 27001, SOC 2, or independent penetration-test summary available under NDA?
  • Exact data centers, backup locations, and encryption-key custody for multi-tenant SaaS—beyond marketing Hetzner claims?
  • Which feature flags on Standard vs Plus vs Enterprise apply to funnels, A/B tags, e-commerce metrics, and white-label depth at contract time?

Pulse by Ciphera

  • Will Ciphera sign your standard DPA and return the full registered-address subprocessor appendix on request?
  • What is the retention and deletion SLA for a single customer's Pulse project data after contract end?
  • When is the planned independent security audit scheduled, and will the report be public?
  • Are Google Search Console, Bing, or CDN analytics panels generally available, or only mentioned in some marketing copy?