Privacy Policy
Last updated: July 2026
Overview
Antlytics is a privacy-first web analytics service. We are committed to collecting only the data necessary to provide our service and to keeping that data secure. This policy describes what we collect, why, and your rights regarding that data.
Antlytics is operated by Antlytics Pty Ltd (ABN TBD), registered in Australia. Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) apply to our handling of personal information.
What we collect
Analytics data (on behalf of our customers)
When the Antlytics tracking snippet is installed on a website, we collect the following for each page view:
- URL path visited
- Referrer URL
- Country (derived from IP address — IP is not stored)
- Device type (mobile, tablet, or desktop)
- Browser and operating system (derived from User-Agent string)
- Anonymous session identifier stored in
sessionStorage— cleared when the browser tab is closed; never written to a cookie
If the website owner uses engagement tracking or custom events, we additionally collect:
- Scroll depth and time on page (aggregate engagement signals per pageview)
- Custom event names and properties the site owner chooses to send (for example
signup_click) — site owners are responsible for not including personal information in event properties
We do not collect or store IP addresses, names, email addresses, or any other directly identifying information from website visitors.
Account data (dashboard users)
When you create an Antlytics account we collect your email address and name via Clerk (our authentication provider). We store the sites you add and your subscription status.
AI provider keys (bring your own key)
If you connect an AI provider for Page Insights, your API key is stored encrypted (AES-256-GCM) and is only used to generate insights you request. When insights are generated, we send aggregate page statistics only (pageview counts, referrers, engagement metrics for the selected page) to the AI provider you chose — never raw visitor data, and never to a provider you have not connected. You can remove your key at any time from Settings → AI.
How we use data
- To display analytics reports to website owners in the Antlytics dashboard
- To calculate aggregate traffic metrics (visitors, page views, referrers, countries)
- To process payments and manage subscriptions via Stripe
- To send transactional emails: billing receipts, weekly traffic summaries (optional, unsubscribe in one click), usage alerts when you approach your plan's included pageviews, and security or rate-limit alerts — no marketing without consent
- To generate AI Page Insights when you request them, using the AI provider key you connected
Data retention
Analytics events are retained according to your plan tier: 6 months on Free, 2 years on Starter, and 3 years on Pro. Events older than your plan's retention window are permanently deleted by an automated weekly purge. Account data is retained while your account is active and for 30 days following deletion, after which it is permanently removed.
Model Context Protocol (MCP) access
When you connect Antlytics via the Model Context Protocol, the AI client (Claude, Cursor, ChatGPT, or another MCP-compatible tool) can query your site statistics, top pages, and top referrers on your behalf. Specifically, it may access:
- Aggregate visitor and pageview counts for your sites
- Top pages by pageviews
- Top referrers by visit count
The MCP server does not expose raw visitor data, IP addresses, user identifiers, or any information beyond the aggregated metrics already shown in your Antlytics dashboard. Access is read-only. You can revoke MCP access at any time from Settings → API tokens.
Third-party services
- Clerk — authentication; handles sign-in, sign-up, and session management
- Supabase — database and storage (hosted in Australia where available)
- Stripe — payment processing; we do not store card details
- Vercel — application hosting and edge network; processes requests (including ingest traffic) in transit
- Resend — transactional email delivery (receipts, summaries, alerts)
- Upstash — rate limiting; sees hashed request identifiers only, no analytics data
- Your chosen AI provider(Anthropic, OpenAI, Google, OpenRouter, or an OpenAI-compatible endpoint) — receives aggregate page statistics only when you generate AI Page Insights, under your own API key and that provider's terms
Each of these providers has their own privacy policy governing their handling of data. We do not sell data to third parties.
Your rights
Under the Australian Privacy Act and applicable laws you have the right to access, correct, or request deletion of personal information we hold about you. To exercise these rights, contact us at support@antlytics.com.
Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email to registered account holders. Continued use of the service after changes constitutes acceptance of the updated policy.
Contact
Questions about this policy: support@antlytics.com