Skip to main content

TRUST CENTER

Clear answers about privacy, data, and trust.

See how tinyanalytics handles analytics data, where the privacy model has limits, and which infrastructure details are still being verified before publication.

Last reviewed: July 2026

The privacy promise

No cookies. No raw IP storage. No cross-site profile.

tinyanalytics starts with a cookieless collection model and explains the optional features that can change a customer’s consent analysis.

  • No analytics cookies by default
  • No raw IP storage in analytics data
  • No cross-site visitor profile

At a glance

Default collection
Cookieless analytics
Raw IP
Used in memory, then discarded
Identity
One-way derived estimate
Optional identity
Supplied by the customer

Optional features and customer-supplied personal data can change this baseline. Feature flags use browser storage for sticky assignments.

DOCUMENTS

Policies and review resources

Public documents link directly. Operational material that is still being verified is clearly marked and available through the contact route.

TRUST PRACTICES

Mechanisms, limits, and open work

Each area separates what the product does today from the details still being reconciled for public release.

Privacy by design

  • No analytics cookies by default
  • No raw IP storage in analytics data
  • No cross-site visitor profile

Data handling

  • Data minimisation by default
  • Customer-controlled event payloads
  • Bot activity kept separate

Cookieless identity & accuracy

  • One-way derived identifier
  • No device identifier by default
  • Stable identity is customer-supplied

Customer configuration & consent

  • Customers choose custom data
  • Feature flags use browser storage
  • Consent depends on configuration

AI & SQL safeguards

  • AI referrals are click-throughs
  • Crawler reads are not citations
  • Generated SQL is read-only

Retention & deletion

  • Policy categories are public
  • Exact product terms under review
  • Current details available on request

Infrastructure & vendors

  • No unverified region claim
  • Vendor data flows under review
  • Public list in preparation

Incident & privacy enquiries

  • Security reports accepted
  • Privacy questions routed
  • Review documents on request

INFRASTRUCTURE

A verified provider list is in progress

We will publish infrastructure and subprocessors only when the provider, purpose, region, contractual path, and operational data flow agree.

We would rather publish a smaller truth than a larger guess.

The brand direction calls for an EU trust story, but the provider, region, ownership, and complete subprocessor path are not yet verified. This page does not turn that direction into a public claim before the evidence exists.

Request current details

Publication checklist

  • Legal entity and operating country
  • Hosting provider and data region
  • CDN, email, support, AI, and backup flows
  • Subprocessor purpose and safeguards
  • Retention, deletion, and incident processes

Status: verification and publication preparation

SECURITY & PRIVACY

Have a security or privacy question?

Report a suspected issue, ask about data handling, or request the current material available for a vendor review.