Logo: Plausible Analytics

Plausible Analytics

Estonian open-source, cookieless web analytics (AGPLv3): lightweight script, EU-owned hosting on Hetzner/UpCloud/Bunny, managed Cloud plus self-hosted Community Edition.

Open sourceSelf-hosted

Plausible Analytics is a privacy-first web analytics product from Plausible Insights OÜ in Tartu, Estonia. It measures site traffic without cookies, without persistent identifiers, and without building user profiles. The managed Cloud product targets teams leaving Google Analytics who want a single readable dashboard rather than a full product-analytics or ad-attribution suite.

It exists as an EU-hosted, subscriber-funded alternative to Google Analytics. The browser sends page URL, referrer, and coarse device signals. Plausible derives a daily unique-visitor count by hashing IP and User-Agent with a salt that rotates and is deleted every 24 hours. Raw IPs and full User-Agents are not stored.

The concrete differentiator is that cookieless daily-hash design, plus an AGPL open-source Community Edition you can self-host if you do not want the Cloud extras (funnels, journeys, SSO, Sites API).

Cookieless by designEU-owned visitor hostsAGPLv3 open sourceSelf-host CEDPA automaticLightweight script

Shortlist when you need cookieless website analytics with EU-owned visitor hosting, a lightweight script, AGPL transparency, and either managed Cloud or self-hosted CE. Skip when you need heatmaps/session replay, multi-day user-level product analytics, HIPAA/BAA, free forever hosted analytics, or zero non-EU SaaS anywhere in vendor ops—consider Matomo-class (e.g. Friendly Analytics / Piwik PRO), Pirsch, or Simple Analytics depending on depth vs simplicity.

Key capabilities

No cookies, localStorage, or persistent IDs. Uniques use hash(daily_salt + domain + IP + UA); salt rotates every 24 hours and raw IP/UA are never stored—so analytics can often run without a consent banner, at the cost of no multi-day user stitching.

Vendor claims a script ~54× smaller than Google Analytics with real-time updates (~30s), sources, pages, devices, UTM channels, scroll-depth goals, and optional Google Search Console import—built for marketers who refuse GA4 report complexity.

Codeless page goals, file downloads, outbound clicks, custom events/properties, AI-referral traffic views, and (on higher Cloud plans) funnels, user journeys, and ecommerce revenue attribution—not session replay or in-app product analytics.

Cloud visitor data is processed on European-owned infrastructure: Hetzner (Germany), UpCloud (Finland), Bunny CDN (Slovenia). Plausible states visitor data never leaves the EU and is not stored on US hyperscalers.

Full codebase on GitHub; free CE for self-host (long-term releases ~twice yearly). Cloud-only features include advanced bot filtering, funnels/journeys, ecommerce revenue, SSO, and Sites API—self-host ops, backups, and upgrades are yours.

Public DPA applies to Cloud customers by use; CSV export and Stats API for BI; Business/Enterprise add higher API limits, raw event exports, managed proxy, and SAML SSO (Google Workspace, Okta, Microsoft Entra ID per docs).

At a glance

HQ
Tartu, Estonia
Legal entity
Plausible Insights OÜ (reg. 14709274)
Visitor hosts
Hetzner DE; UpCloud FI; Bunny SI
License
AGPLv3; Cloud + Community Edition
Commercial model
Pageview-based Cloud SaaS; free CE self-host
Tracking model
Cookieless; daily rotating hash; no PII stored

Best fit when

  • Teams replacing GA4 who want aggregate marketing metrics without cookies or user profiles
  • EU orgs that require visitor analytics on European-owned infrastructure (Hetzner/UpCloud/Bunny)
  • Sites that prioritize script weight, Core Web Vitals, and a one-page dashboard
  • Buyers who want AGPL auditability and optional Community Edition self-host exit
  • Agencies and multi-site operators needing shared links, team seats, and pageview-tiered Cloud plans
  • Procurement paths that value a public DPA, data policy, and subprocessor list over ISO/SOC certificates

Poor fit when

  • Product analytics needs: multi-day user identity, cohorts, retention, feature experiments
  • UX research that requires heatmaps, session replay, or rage-click recording
  • Healthcare or other programs that require HIPAA and a BAA (explicitly not offered)
  • Buyers who need free forever hosted analytics with no subscription
  • Orgs that forbid any US-linked SaaS in vendor account tooling (Postmark, Help Scout, etc. are listed)

Consider instead when

  • When: You need Matomo-depth features (heatmaps, session recording, heavy on-prem packaging)

    Consider: Friendly Analytics, Piwik PRO, or self-hosted Matomo

    Trade Plausible’s minimalism for plugin breadth and different operators.

  • When: You want a lean EU privacy analytics peer with a different stack or license posture

    Consider: Pirsch Analytics or Simple Analytics

    Compare hosting ownership, funnels/ecommerce gates, and self-host options side by side.

  • When: You only need edge-level basic counts and already run Cloudflare

    Consider: Cloudflare Web Analytics

    Simpler install path; US company and thinner marketing analytics surface.

  • When: You need free hosted analytics and accept Google’s data practices

    Consider: Google Analytics

    Different legal and commercial model—not an EU privacy substitute.

Jurisdiction & ownership

Legal entity
Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia
Governing law
Estonian / EU law context for the OÜ; confirm contract terms for governing law clauses
US parent / control
No known US parent
CLOUD Act exposure (indicative)
Medium
Hosting / residency
Visitor analytics: Hetzner (Falkenstein, Germany), UpCloud (Finland, DB/exports), Bunny (Slovenia, CDN/DNS/DDoS)—European-owned; vendor states visitor data never leaves the EU. Customer-account subprocessors include Paddle (payments), Postmark (email), Gravatar, optional Google (GA import), Help Scout, Nolt; site tools may include hCaptcha, Algolia, Mailchimp. SCCs claimed for non-EU processors.

No known US parent; bootstrapped Estonian OÜ. CLOUD Act indicative medium/partial because US-oriented customer SaaS appears in the public subprocessor list even though visitor metrics stay on EU-owned hosts. Not legal advice.

  • Independent security / no-logs auditNot found
  • ISO 27001Not found
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionVendor claimed
  • +3

Considerations & known limitations

  • MediumUS-linked customer-account subprocessors

    Visitor metrics stay on EU-owned hosts, but billing, email, support, and optional integrations use providers such as Postmark, Paddle, Help Scout, Gravatar, and Google—material for zero-US-processor policies.

  • MediumNo public ISO 27001 / SOC 2

    Compliance hub emphasizes product design and EU hosting rather than ISO/SOC certificates; orgs with mandatory cert checklists must request evidence or accept open-source + DPA packaging.

  • LowSelf-host CE feature and release lag

    CE is free but long-term releases (~twice yearly) and omits Cloud-only funnels, journeys, ecommerce revenue, SSO, and advanced bot filtering—ops burden sits with you.

  • LowNo multi-day user identity or replay

    Daily hash resets prevent cross-day visitor stitching by design; heatmaps/session replay are out of scope—teams needing those must add other tools.

  • MediumMisconfiguration can reintroduce personal data

    Passing emails, patient IDs, or other identifiers in URLs or custom properties undermines the non-PII model; vendor also states no HIPAA/BAA.

Open questions for due diligence

  • Which exact customer personal data categories does each account subprocessor (Postmark, Paddle, Help Scout, etc.) receive in production?
  • Can Enterprise contracts exclude optional integrations (Google, Help Scout) or pin subprocessor lists for regulated buyers?
  • Are independent pen-test reports or ISO/SOC roadmaps available under NDA?
  • What are contracted RPO/RTO and backup locations beyond the high-level Hetzner/UpCloud description?
  • For CE self-host: which Cloud-only features remain permanently out of CE versus merely delayed on the long-term release train?

Frequently Asked Questions

Plausible’s data policy and a published legal assessment argue that its cookieless, non-PII design means no analytics cookie banner is required under GDPR/ePrivacy for standard use. That depends on configuration: do not send emails, user IDs, or other personal data in URLs, event names, or custom properties. Banner necessity remains a legal judgment for your counsel—not a warranty from this directory.

For Cloud visitor analytics, Plausible names Hetzner (Germany) for servers, UpCloud (Finland) for database/export storage, and Bunny (Slovenia) for CDN/DNS/DDoS—all European-owned—and states visitor data never leaves the EU. Customer account flows use additional providers (e.g. Paddle payments, Postmark email, optional Help Scout, Google for GA import). Review the live privacy subprocessor list and DPA annex for DPIAs.

CE is free AGPL software you operate yourself (install, capacity, backups, upgrades; long-term releases about twice a year). Cloud-only or Cloud-stronger areas include continuous deploys, advanced bot/data-center filtering, marketing funnels, user journeys, ecommerce revenue goals, SSO, Sites API, and managed CDN. Choose CE for full infrastructure control; choose Cloud when ops cost and feature freshness matter more.

No for those workflows. Plausible is website analytics: traffic, campaigns, aggregate conversions. It does not offer multi-day user profiles, cohorts/retention, feature-flag experiments, heatmaps, or session replay. Use tools such as Mixpanel, Amplitude, PostHog, Hotjar, or Clarity for those jobs; keep Plausible for privacy-preserving marketing site metrics.

Hosted Cloud is a paid, pageview-tiered subscription funded only by customers (vendor states no ads, no data sales, no outside investors). A 30-day free trial is offered without a credit card. Community Edition is free to self-host under AGPL; you pay only your own infrastructure. Confirm current tiers and retention (e.g. multi-year data retention on higher plans) on plausible.io.

A public Data Processing Agreement applies automatically to Cloud use (acceptance by use; breach notice target within 48 hours per DPA text). On security/compliance pages reviewed for this entry, ISO 27001 and SOC 2 were not found as public certifications—procurement should request evidence if those attestations are mandatory.