Skip to content

What Crustat collects, and what it doesn't

A plain breakdown of what the browser sends, what the server adds, and what Crustat never touches at all.

What the browser sends

Crustat sets no cookies and stores nothing on a visitor’s device. The script sends four kinds of event, each a small piece of plain text.

A page view, when a page opens, or the address changes in a single-page app:

FieldNotes
Page URLThe server keeps only the hostname and path (up to 512 characters), plus the three UTM tags below. The rest of the query string and anything after # are thrown away.
ReferrerWhere the visitor came from, if the browser shares it. Only its hostname is kept. In a single-page app, later views send your own previous page instead, used only to tell they aren’t new arrivals and for visitor paths.
Window widthHelps tell a phone from a computer.

A leave, when the tab is hidden or closed, or a single-page app moves on: the page being left, the whole seconds it was visible (at most 30 minutes), and a yes or no for whether the visitor clicked, typed, scrolled or touched it. Never what they did or where.

An outbound click, on a link to another site, or a mailto: or tel: link: the page it was on, and where the link goes, without its query string or anything after #.

A custom event, when something you chose to track happens: a click or form with data-crustat-event, a file download, a crustat("Name") call, or a rule from the Events tab. It carries the page and the event’s name, up to 60 characters, like Download price-list.pdf. A form event says the form was sent, never what was typed. See track clicks, forms and sales.

Any event can also carry an “automated browser” flag, which testing tools and scrapers set.

That’s the entire payload. No form fields, no page text, no mouse positions.

After the first page view, the script also fetches a small file with your site’s event rules. It’s the same for every visitor and carries nothing about them.

Nothing is stored on the device

No cookies, and nothing written to localStorage, sessionStorage or anything like it. The script keeps no visitor id, so there’s nothing on the device to recognise next time.

It checks one localStorage flag, which a site owner can set on their own browser to ignore their own visits. For visitors it’s always empty, and Crustat never writes it on a visitor’s device. See do I need a cookie banner for Crustat?.

What the server adds

FieldWhere it comes from
Country, region, citySupplied by Cloudflare’s network from the connection. Only the place names are kept.
NetworkThe provider or hosting company the visit came through, like AS13335 Cloudflare, Inc.. Used to spot traffic from servers rather than people.
Browser, system, device typeRead from the user agent, names only, with the window width as a fallback for the device.
Visitor id16 characters of a SHA-256 hash of that day’s salt, the site, the IP address and the user agent. The same person shows up once per day on one site, and can’t be followed across days or sites.
UTM tagsutm_source, utm_medium and utm_campaign, lowercased and cut to 100 characters. utm_term and utm_content are ignored. See track campaigns with UTM tags.
ChannelSearch, Social, Email, Paid, AI, Referral or Direct, from the referrer and UTM tags.

Known bots are dropped on arrival and never stored. Automated browsers, server traffic and copies of your site on other addresses are stored with a tag and left out of your stats. See how bots are kept out.

What’s never collected

  • The IP address. It’s used once, in memory, to make the visitor id, then discarded.
  • The full user agent, full referrer links and query strings, other than the three UTM tags.
  • Names, emails or account identifiers for any visitor.
  • Anything that links one person’s visits on different days. The visitor id changes every UTC day.

Crustat doesn’t read Do Not Track or Global Privacy Control. Every visit is handled the same anonymous way.

The daily salt

A salt is a random value mixed into the hash: 32 random bytes, a new one for every UTC day, kept only in Crustat’s database and never sent to a browser. Each day’s salt is used only during that day and deleted about a day after it ends. After that, nobody can rebuild that day’s visitor ids from an IP address and a browser, not even us.

Who can see the data

The people in your workspace, anyone you give a read-only link, and anyone you send a downloaded CSV file. For how long each part is kept, see how long your data is kept.

Still stuck? Write to hello@crustat.com.

All articles
The mascot waiting

Almost ready

We're opening to everyone soon.

Crustat is in its final checks before we open sign-ups. Leave your email and we'll write once, the day it opens, with your 14 days free waiting.

One email when we open. No newsletter. See our privacy page.