Logo: TelemetryDeck

TelemetryDeck

German privacy-first app analytics SaaS: lightweight multi-platform SDKs, on-device double-hash anonymization, cookieless signals, and managed dashboards for mobile, desktop, and web products.

TelemetryDeck is a managed analytics service for mobile, desktop, and web applications. You instrument significant moments in product code by sending signals through official SDKs or an HTTP ingest API. The product is operated by TelemetryDeck GmbH in Augsburg, Germany.

It exists for app developers who want lean usage analytics without advertising-style tracking. SDKs cover Swift, Kotlin/Android, JavaScript, Flutter, and React Native, among others.

The concrete differentiator is on-device double-hash anonymization and cookieless signals, aimed at product and engineering dashboards rather than website marketing analytics.

Multi-platform app SDKsOn-device anonymizationCookieless signalsEU-operated (DE GmbH)Open-source client SDKsManaged SaaS (no self-host)

Shortlist TelemetryDeck for multi-platform app analytics when on-device double-hash anonymization, cookieless signals, open SDKs, and a German-operated SaaS matter more than self-host or profile-heavy product suites. Skip when you need website-only simplicity (Plausible/Pirsch), full self-host control (Matomo/Plausible CE), or Mixpanel/Firebase-class identity and ecosystem depth—and have legal review the vendor’s “not personal data / not Art. 28 processor” DPA model plus AWS/Azure subprocessors.

Key capabilities

Official clients for Swift (Apple platforms including visionOS), Kotlin/Android, JavaScript, Flutter, React/React Native, Vue, and a one-line web snippet, with community Unity, Rust WASM, and Vapor clients. Any runtime can POST to the documented ingest API. Suits cross-platform product teams; not a drop-in replacement for a full marketing tag manager suite.

Client SDKs salt and hash user identifiers on device; the server applies a second salt and hash so neither side can reverse the original ID. App analytics docs state IPs are never stored for signals; timestamps are rounded to the hour. Limit: publishers must not put personal data in custom metadata, or the anonymization model breaks for that payload.

No analytics cookies for product signals: apps keep a local anonymized identifier; web derives a hashed identifier from date, site, and partial IP context without storing full IPs. Aimed at leaner consent UX and simpler App Store privacy labels versus cookie-based trackers—still confirm legal posture for your jurisdiction and configuration.

Pre-built overview and AARRR-style customer journeys (acquisition, activation, retention, revenue), technical metrics (devices, versions, errors), visual funnel builder, Explore for raw signal types, TelemetryDeck Query Language for advanced insights, and Notebooks mixing live charts with markdown. Test mode separates IDE/dev traffic from production.

Commercial model is monthly event/signal volume with a free tier and paid plans that differ on included volume and how long data stays query-ready (cold storage may hold older data). Free accounts can stop ingesting when the budget is exhausted; paid plans warn and may auto-upgrade after sustained overage. Check current limits on the vendor dashboard—no self-host option.

At a glance

HQ
Augsburg, Germany (TelemetryDeck GmbH)
Legal entity
TelemetryDeck GmbH · HRB 37541 · VAT DE353418916
Product type
Managed app/web analytics SaaS
Self-host
No (open-source client SDKs only)
Hosting (vendor)
Azure Amsterdam; AWS Frankfurt; Hetzner Falkenstein/Nürnberg
Commercial model
Free tier + monthly event volume; plan-based query retention
DPA
Public DPA/AVV asserting anonymized non-processor model; TOMs on request

Best fit when

  • Mobile/desktop/web app teams that instrument events in code (Swift, Kotlin, Flutter, RN, JS) rather than only a website script
  • Product orgs prioritizing cookieless, double-hashed identifiers and leaner App Store privacy narratives versus ad-tech SDKs
  • Teams leaving Firebase Analytics or Mixpanel who accept a simpler event model for privacy-oriented defaults
  • European buyers wanting a German legal entity and EU-region hosting (Azure NL, AWS Frankfurt, Hetzner DE) with public privacy docs
  • Indie and small teams that want a free tier to start and volume-based paid plans as signal volume grows

Poor fit when

  • Organizations that must self-host the full analytics stack on their own infrastructure
  • Website-only traffic measurement without native app SDKs (Plausible/Pirsch are usually better fits)
  • Buyers that require public ISO 27001/SOC 2 certificates or a conventional Art. 28 processor DPA without the vendor’s anonymization legal model
  • Teams needing deep identity graphs, CRM-style user profiles, or full product-analytics marketing suites
  • Workloads that forbid US-group cloud providers entirely (AWS and Microsoft Azure are in the public host list)

Consider instead when

  • When: You only need privacy-friendly website analytics with a simple script

    Consider: Plausible Analytics or Pirsch Analytics

    Stronger web-first UX; weaker native multi-platform SDK story than TelemetryDeck

  • When: You must self-host analytics and own the database

    Consider: Matomo (self-host) or Plausible Community Edition

    TelemetryDeck is managed SaaS only

  • When: You need Firebase/Google ecosystem depth or free crash+remote-config adjacency

    Consider: Firebase Analytics (accept Google jurisdiction and tracking model)

    Different privacy and lock-in trade-offs

  • When: You need enterprise product analytics with rich identity and experimentation packaging

    Consider: Mixpanel or Amplitude

    Heavier privacy/cookie surface; more suite features

Jurisdiction & ownership

Legal entity
TelemetryDeck GmbH, Von-der-Tann-Str. 54, 86159 Augsburg (HRB 37541)
Governing law
Germany (terms reference German law / Bayern courts; consumer protections may vary)
US parent / control
No known US parent
CLOUD Act exposure (indicative)
Medium
Hosting / residency
Product analytics: Microsoft Azure Amsterdam (NL), AWS Frankfurt (DE), Hetzner Falkenstein and Nürnberg (DE) per Privacy FAQ. Website privacy policy lists Microsoft Ireland Operations Ltd, Amazon Web Services Inc (US entity), and Hetzner Online GmbH as hosters with claimed Art. 28 contracts for site hosting. Account-side: HubSpot Inc (US CRM), Brevo/Sendinblue GmbH (DE email), Stripe payments per terms.

No known US parent; German GmbH with named managing directors Lisa Figas and Daniel Jilg. Indicative CLOUD Act exposure is medium because of US-group cloud (AWS, Microsoft) and HubSpot, despite EU regions and EU legal entity. Not legal advice.

  • Independent security / no-logs auditNot found
  • ISO 27001Not found
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionVendor claimed
  • +3

Considerations & known limitations

  • MediumUS-group cloud and CRM subprocessors

    Even with EU regions, AWS and Microsoft Azure are US-group providers; HubSpot processes customer CRM data in a US SaaS path. Buyers with strict no-US-cloud policies need written architecture confirmation or another vendor.

  • MediumAnonymization / non-processor legal model

    Public DPA states TelemetryDeck is neither processor nor joint controller for service data. Strong if true for your configuration; risky if custom metadata reintroduces personal data or if counsel disagrees with the anonymization analysis.

  • MediumNo public ISO/SOC or independent audit

    No ISO 27001, SOC 2, or independent no-logs audit found publicly. Enterprise security questionnaires may need NDA materials or alternate assurance.

  • LowFree-tier ingest hard-stop

    Free plans discard events after the included monthly budget; overage data is not recoverable. Production apps on free tier need monitoring or a paid plan.

  • LowNo self-hosted product

    Only client SDKs are open source. Organizations that must keep analytics databases on-prem cannot use TelemetryDeck as a full stack.

Open questions for due diligence

  • Will counsel accept the public non-processor DPA/AVV model for your app’s identifier and metadata configuration?
  • Can TelemetryDeck provide TOMs, subprocessor list for the analytics plane, and any ISO/SOC or pen-test reports under NDA?
  • Which exact AWS/Azure services and accounts process customer organization data versus anonymized signals?
  • What contractual options exist to exclude or pin HubSpot and other US SaaS tools for account administration?
  • Current free-tier and paid plan event limits and retention windows for your expected volume (confirm on live plans UI)?

Frequently Asked Questions

According to TelemetryDeck’s Privacy FAQ and anonymization docs, app signal pipelines do not store IP addresses, and user identifiers are double-hashed (device salt + server salt) so the original value cannot be reconstructed. Signals include an anonymized user id, event type, hour-rounded timestamp, device/app metadata, and optional publisher-defined parameters. You must avoid sending emails, names, or other personal content in custom metadata. Web requests may use partial IP information only to derive coarse location/hashing context; full IPs are still documented as not stored. Treat this as vendor documentation—validate against your threat model and counsel.

TelemetryDeck publishes a public Data Processing Agreement (English convenience translation; German AVV prevails) and states TOMs are available on request. The same document asserts that, from TelemetryDeck’s perspective, service data is anonymized, that TelemetryDeck is neither a GDPR processor nor joint controller, and that Art. 26/28 therefore do not apply. Procurement teams that require a conventional processor AVV should review this model carefully with counsel rather than assuming a standard SaaS processor relationship.

The Privacy FAQ places product infrastructure on Azure (Amsterdam), AWS (Frankfurt), and Hetzner (Falkenstein/Nürnberg). The company privacy policy lists Microsoft Ireland, Amazon Web Services, Inc., and Hetzner Online GmbH as hosters, with DPAs claimed for website hosting. Account/CRM paths include HubSpot (US) and newsletter via Brevo (DE); payments use Stripe. EU regions and a German GmbH reduce some risks, but US-group cloud and SaaS keep indicative CLOUD Act exposure at medium—not “EU-only infrastructure.”

Client SDKs are open source on GitHub (permissive licenses; Swift client uses modified MIT without attribution). Supported first-party platforms include Apple platforms via Swift, Android/Kotlin, JS, Flutter, React/React Native, Vue, and web. Ingest is also possible via raw HTTP. The hosted dashboard and backend are commercial SaaS—there is no official self-host of the full product. If you need to run analytics on your own servers, evaluate Matomo, Plausible Community Edition, or similar instead.

TelemetryDeck sells primarily on monthly event volume. On free plans, once the included event budget is used up, the vendor FAQ states the account is restricted immediately: further events are discarded and not recoverable (warnings at ~80% usage). Paid plans generally keep ingesting past the included amount, warn by email, and may auto-upgrade after going over for two months in a row; extreme spikes (documented as ~20× included volume) can trigger temporary collection stops. Retention windows (how long data stays queryable) also vary by plan. Confirm current thresholds in the live plans UI.

Choose Plausible or Pirsch for website-only privacy analytics with a simpler script model and less mobile-SDK focus. Choose Mixpanel/Amplitude/Firebase when you need deep product-analytics suites, identity graphs, or ecosystem integrations and accept their privacy/cookie trade-offs. Choose TelemetryDeck when native/multi-platform app SDKs, cookieless anonymized signals, German operation, and a managed app-centric dashboard matter more than self-hosting or enterprise marketing-analytics depth.