Logo: Tinylytics

Tinylytics

Privacy-first cookieless web analytics for small sites, with bundled uptime/SSL checks, content monitoring, events, and founder support—hosted primarily on Hetzner in Germany.

Tinylytics is a privacy-first web analytics SaaS for small websites, personal blogs, and indie projects. Solo developer Vincent Ritter launched it in June 2023. The service is provided by Vincent Ritter Consulting in the United Kingdom.

It exists for small sites that want page views, probabilistic unique hits, referrers, and country-level geography without tracking cookies. Unique hits use a one-way hash with a salt that rotates every 12 hours. IP addresses are not stored in hits.

The concrete differentiator is that small-site packaging with bundled uptime and SSL checks plus founder support, hosted primarily on Hetzner in Germany.

Cookieless analyticsPrimary host: Hetzner DEUptime + SSL monitoringBroken-link crawlsSaaS only (no self-host)Solo-founder UK

Shortlist Tinylytics when you want cookieless page analytics plus bundled uptime/SSL/content checks for a handful of small sites, with primary data on Hetzner in Germany and founder support. Skip when you need self-host/open source, formal ISO/SOC packs, or enterprise multi-tenant governance—consider Plausible Analytics or Simple Analytics instead.

Key capabilities

Page views and unique hits without tracking cookies or fingerprinting. Uniques combine truncated request signals with a 12-hour rotating salt and one-way hash, reset daily at midnight UTC; visitor IPs are not stored in hits. Suited to indie sites that want trendable uniques without consent banners for analytics cookies.

In-house multi-region health checks (default every 10 minutes) confirm downtime before emailing, plus SSL expiry notices and domain monitoring. Ultra can shorten intervals. Replaces a separate uptime tool for small fleets—but false downs can occur if WAFs block the Tinylytics monitor user-agent.

Subscribed sites can crawl up to 50 pages (two levels deep) on a daily cadence, flagging broken links and mixed HTTP assets on HTTPS pages, with ignore lists and re-check. Ultra adds optional AI spell-check on visible copy—keep it off if AI subprocessors are out of policy.

Enable events on the embed script and mark elements with data-tinylytics-event using category.action names (optional values for downloads). No GTM required; beacon mode helps navigations. Still beta—expect API/schema changes and incomplete capture under aggressive blockers.

Share passcode-protected public stats, embed hit counters and kudos buttons, export CSV, call the documented API, and push signed webhooks for visits, events, and monitoring. Built for transparent blogs and light automation rather than enterprise BI warehouses.

At a glance

HQ / operator
Vincent Ritter Consulting, United Kingdom
Launched
12 June 2023 (live counters on homepage)
Primary hosting
Hetzner, Falkenstein, Germany
Deployment
Managed SaaS only (not open source, not self-hosted)
Commercial model
Paid site-count plans; short trial; no permanent free tier
Differentiators
Analytics + uptime/SSL/content monitoring + widgets

Best fit when

  • Indie blogs, portfolios, and side projects that want simple cookieless stats without Google Analytics
  • Small sites that also want uptime, SSL expiry, and broken-link checks in the same tool
  • Operators who prefer founder-answered support and lightweight embeds over enterprise marketing stacks
  • Teams OK with managed EU primary hosting and willing to review named US-group subprocessors (CDN, payments, optional AI)
  • Agencies managing a modest number of client sites with public stats or kudos-style engagement widgets

Poor fit when

  • Orgs that require self-hosted collectors or open-source audit of the full analytics stack
  • Procurement needing published ISO 27001, SOC 2, independent audits, or a downloadable DPA out of the box
  • Very high-traffic properties needing contractual capacity/SLA commitments beyond fair-usage conversation
  • Policies that ban Cloudflare/Sentry/US payment or optional US AI APIs on any data path
  • Teams that need session replay, heatmaps, or deep advertising attribution (Clarity/GA territory)

Consider instead when

  • When: You need open-source and optional self-hosting of the analytics stack

    Consider: Plausible Analytics

    Estonian product with Cloud plus Community Edition self-host; less bundling of uptime/content monitors.

  • When: You want European cookieless analytics with a simpler analytics-only scope

    Consider: Simple Analytics

    Strong privacy positioning; compare feature depth and monitoring separately.

  • When: You need free-at-scale marketing analytics, ads integrations, or attribution depth

    Consider: Google Analytics (incumbent) — or stay on a privacy tool if GA is disallowed

    Different privacy and sovereignty profile entirely.

  • When: You need session replay or heatmaps and accept that privacy model

    Consider: Microsoft Clarity or specialised replay tools

    Tinylytics deliberately avoids fingerprinting-style session products.

Jurisdiction & ownership

Legal entity
Vincent Ritter Consulting (service brand; terms state not separately incorporated yet)
Governing law
Not clearly stated as a single governing-law clause on the public terms page; confirm contractually
US parent / control
No known US parent
CLOUD Act exposure (indicative)
Medium
Hosting / residency
Primary analytics storage: Hetzner Falkenstein (Germany). CDN/security: Cloudflare. Error monitoring: Sentry.io. Payments: Paddle and Lemon Squeezy (Stripe company). Optional: IPinfo geo fallback for API hits; opt-in AI Insights via xAI and Google Gemini. No public backup-provider detail beyond that stack.

No known US parent of the UK operator. CLOUD Act exposure is medium/partial because of named US-group subprocessors and optional US AI APIs—not because core DB hosting is in the US. Indicative only; not legal advice.

  • Independent security / no-logs auditNot found
  • ISO 27001Not found
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionVendor claimed
  • +3

Considerations & known limitations

  • MediumUS-group subprocessors on the data path

    Cloudflare, Sentry, payment processors (incl. Lemon Squeezy/Stripe group), optional IPinfo and opt-in xAI/Gemini mean the stack is not EU-only end-to-end despite Hetzner primary storage.

  • MediumSolo-founder operational concentration

    Service is provided by Vincent Ritter Consulting / a solo developer. Support is personal and fast for indies, but bus-factor and formal SLA expectations differ from larger vendors.

  • MediumNo public ISO/SOC/audit or DPA pack

    Enterprise security questionnaires will hit gaps until the vendor supplies audits and a B2B DPA under NDA or email.

  • LowScale and feature boundaries

    Content crawls are depth/page limited; event tracking is beta; fair-usage applies to extreme hit volumes; no self-host escape hatch.

  • LowOptional AI shares aggregated analytics

    AI Insights and related AI spell-check are opt-in and send aggregated (not visitor PII per vendor) data to third-party AI providers—leave disabled under strict AI policies.

Open questions for due diligence

  • Will Vincent Ritter Consulting sign a GDPR Article 28 DPA and provide a current subprocessor list under contract?
  • Are backups/DR and email delivery fully covered by the named providers, or are there additional hosts?
  • Is there any roadmap for independent security review, SOC 2, or ISO 27001?
  • What contractual terms apply for accounts consistently above the fair-usage hit threshold?
  • For AI Insights: exact retention, regions, and processor terms at xAI and Google for the paid API plans used?

Frequently Asked Questions

The product is designed to run without tracking cookies and without storing visitor IPs in hits; unique identification uses short-lived salted hashes. The vendor markets this as a GDPR-oriented, consent-light setup for analytics cookies. You still need your own legal assessment (especially for any other scripts on the page) and should read their privacy and unique-hits docs—not treat the marketing claim as legal advice.

Primary hosting is Hetzner in Falkenstein, Germany. Public docs also list Cloudflare (CDN/security), Sentry (errors, customer ID), Paddle and Lemon Squeezy (payments), optional IPinfo for unresolved API geo lookups, and optional xAI/Google Gemini if AI Insights or related AI features are enabled. Core storage is EU; the full path is not US-cloud-free.

No. Tinylytics is a closed-source managed SaaS only. If you need to run the collector in your own VPC or audit the full codebase, shortlist Plausible's self-hosted Community Edition or other open-source analytics stacks instead.

There is no permanent free tier; a short trial covers all features without a credit card. Paid plans are tiered mainly by number of sites and team/ops extras (e.g. team access, custom monitor intervals, spike alerts). Hits are marketed as unlimited on paid plans, with a soft fair-usage review for consistently extreme volume rather than automatic overage billing. Confirm current plan limits on the official site.

Content crawls are capped (order of tens of pages depth-limited), event tracking is beta, and public materials lack ISO 27001, SOC 2, independent audits, and a published DPA. The operator is a solo UK consultancy brand. Fine for indie and small agency use; weak for regulated enterprises that need formal assurance packs or multi-million-hit contractual SLAs without a conversation.