Simple and privacy-friendly alternative to Google Analytic
github.com
github.com
I mean, let's be honest - the days are fast coming when anything that looks like remotely hosted javascript is going to be blocked, no matter how benign it is.
So could it be that the future is home grown analytics subsystems that reside in your own stack?
That way people who need deeper types of tracking can do it, while those that need shallow analytics can do it too.
It certainly seems to be heading in that direction.
One way to incentivize even more sites to move from GA et al would be to create some kind of privacy criteria and whitelist those analytics that fulfill it (open source, minimal data, no personal data, no cookies/persistent identifiers, no cross-site/device tracking, no connection to adtech etc).
Site owners want analytics. We offer self-hosted service but most sites don't want to deal with managing analytics server as it is not an easy job. So by blocking every analytics tool (good or bad) the incentive for site owners is more on trying to avoid being blocked rather than on moving to something more privacy-friendly.
(I'm the Plausible co-founder)
However, we’re still on that slippery slope as described I think.
At some point Firefox, Chrome and Safari is going to start blocking almost everything by default - or at best severely restrict them.
The question is, how can we move to some kind of embedded analytics? It’s already kind of there in most of the larger platforms.
IMO all this will do is end up with yet more lists for adblockers and not only do we already have a huge mess with those we are also seeing them being strangled by API changes like in Chromium. Personally I'd much rather visit a site that use GA (because I know I can block it) than go in and "hope for the best" like it is with ad blocklists. Whitelists would either have to be bulletproof (IE. back to the proven privacy problem) or they would be like cookie pop-ups where most have no idea which to use and trust. I most definitely do not trust someone who builds a Chromium derivative to decide what to whitelist. Whitelists belongs in the users hands where they already are, not some remote company that is bleeding money. We have seen how that works out with a certain adblocker already.
I'm a site owner for a small business with zero tracking scripts and zero external connections from the site so I know for a fact that tracking is unnecessary even in areas with lots of online competition. Sure I could do a lot of tracking to make more money for the business but that is the rub isn't? Tracking is about greed. Webservers already tell us enough otherwise.
Edit: I'll also just add that anyone who is in the tracking business and use CNAME fiddling is per definition not trustworthy.
There are a few aspects that can't be tracked from server logs, for example screen size. I think this can be fairly important for UX reasons.
There's some other tracking that can be useful as well; for example if you're considering removing a button or feature then it's useful to know how many people are using that. If this is a JS-only feature (like, say, sorting a table in JS) then you need some JS tracking on this.
In short, I feel lobbing all "tracking" in one category is a mistake. It's all about how you use it and what you do with it. This applies to most technology really.
I do agree that trust is a big concern; I don't really have a clear comprehensive solution to this.
Or, more realistically, the tracking will move to the browser, and since the dominant force in online advertising is also the dominant force in the browser market, they’ll continue to dig their most and track us all.
That's exactly what your GGP is proposing ("create some kind of privacy criteria and whitelist those analytics that fulfill it")
The way they work is not by downloading and checksumming scripts to see if they are allowed it not. They just downright refuse to download what is blocked.
So someone could use your special whitelist status to get their creepy tracking into visitor web browsers.
That does not make sense to allow for blockers.
Hence, you will continue to be blocked.
Great effort, though. I wish this were the future of analytics.
Don't get me wrong, I have no reason to doubt your claims and do trust you specifically, but basing the entire system on "I decide to trust Marko from Plausible" doesn't really scale.
I am in the same boat as you as I run GoatCounter; I know I do everything like I say I do, but I also know that there's nothing preventing me from doing any of the above and actually collecting much more from what I say I do. It's not hard to set up and no one will ever find out. Theoretically there are legal limits on this. In practice this is a very weak guarantee. This is a big reason why self-hosting was always a first-class supported use case for this.
Theoretically there are some technical things you can do to improve matters; for example a per-domain device ID generated by the browser (or JS, doesn't really matter actually). But then you run in to legal limits due to the way the GDPR is phrased, even though it's more privacy-friendly and not really in the spirit of what the GDPR is about :-/ We talked a bit about this over email last year IIRC.
The real crux is finding something that's practical, usable, and will actually be implemented/used. We can all think of some idealized system, but if it's not realistic that it'll be implemented then it's a pretty academic exercise. In practice this means that any browser solution will need buy-in from at least the Chrome and Safari teams to really be useful, and I don't rate the chances of that as very high of happening any time soon.
This isn't even because I subscribe to some "Big Evil Google and Their Nefarious Dark Plans" view, but just because they have little incentive to do any of this and it's quite a lot of work to do it well. It's easier to just block the lot and, arguably, this is perhaps better than doing nothing. If GoatCounter is impacted by this then so be it. At the end of the day site owners are not the customers of Safari and Chrome: people using those browsers are.
https://developers.google.com/web/fundamentals/performance/o...
* I work at Google but not on Chrome
Unpopular Opinion on HN.
This is hard. And sort of force everyone into the same bracket of privacy. As a contrarian, I actually want to know returning visitors ( It doesn't even need to be 100% accurate ). Right now, Tech uses privacy as a word for anonymous. In a real world analogy, the current privacy definition means I would be intruding my customer's privacy if I recognise the same customer coming into my coffee shop everyday during roughly the same time ordering the same latte with Oat milk.
I dont need to know who they are, and I shouldn't be able to buy what ever set of Data to match their profile or be able to sell my data for others to match him/her. Which is what I think is wrong with current tracking and adtech. But knowing my customers should not be it.
I'm sorry but what? Remotely hosted JS seems to always be growing in popularity, at least in the SaaS business and related area. Can I ask what industry you're in where you see more and more people blocking _all_ JS, not just analytics/tracking? (The HN bubble doesn't count as a "industry")
I have a really hard time as seeing your statement as "the truth". People today seem even more likely to accept arbitrary JS running in their browser, than how it used to be.
Individuals are not blocking. It’s the browsers that are heading in that direction.
I’m just reading the tea leaves brah.
I agree with GP, I can certainly see a future where browsers make a move to block cross-origin JavaScript files.
But as a user, I am starting to get frustrated by how often I visit "normal" sites that just don't work in certain browsers because of all this blocking. There are plenty of legitimate reasons for people to load external content on websites, and it's important not to throw the baby out with the bath water here.
I am also concerned that certain big tech companies, notably including Google though it is hardly the only one, have a tendency to shoot first and not even ask questions later in terms of collateral damage when they deem something to be the appropriate course of action. Chrome has historically had no problem with killing off major functionality that some useful sites required, and other browsers have often followed. Apple has a tendency to do the same (or to achieve the same result by refusing to support functionality in the first place) particularly on iOS. It's always done in the name of improving privacy or security or reliability or some other worthy cause, but it still effectively removes useful content from the Web based on the decision of a handful of people who work on browsers. We should be very wary of that kind of power, particularly when it is wielded by people with little accountability or oversight.
Where do you see any indication that browsers would prohibit executing cross-origin or cross-site JavaScript? (Browsers are limiting all sorts of things, but this is not one I'd expect or have heard discussion of.)
(Additionally, this is really easy for site owners to get around through CNAME or proxying)
It’s shortsighted IMO to fight with remotely hosted JavaScript. It makes things more complex, but doesn’t really help with privacy that much for longer term.
A simple one would be showing me the visitors to /blog/ and its subdirectories. And from there allow drilling down to them.
And from a UX perspective, none of them seem to support searching for a specific page to display the stats for. Yes, you can edit the URL, but that’s a horrible way to do it.
edit: To add, they are also very expensive. Above 1 million views/month (which I would say is still a pretty small commercial site) goatcounter already is in "ask us" territory and plausible wants $69/month. As the value add seems very small, we rather use our own homegrown, bare-bones analytics system for anyone who doesn’t consent to analytics.
(I'm the co-founder of Plausible)
- /docs/self-hosting 4.1k 5.7k 67%
- /docs/ 2.1k 2.7k 30%
- /docs 1.6k 2.1k 15%
- /docs/self-hosting-configuration 1.2k 1.8k 57%
You have to select "/docs/self-hosting" directly, and once you done that, you don't see the subpages of that page anymore. If you select "/docs" you only see docs, not "/docs" + subpages so you can see the most popular blogpost and only pages under "/docs"
Right now if you want to drill into /blog you have to scroll down to the bottom and scroll back up again to see the results.
I can give some context on this: determining a good pricing on these kind of things is rather tricky. In principle this is easy: "cost + markup". But "costs" is actually pretty variable and independent of number of pageviews as such: sending 1 million pageviews on a single path is cheap. Sending them spread out over 1 million paths is much more expensive.
For smaller sites this is not a big deal, but above a certain amount this can matter a lot. I don't want to overcharge "light" users, but I also don't want to undercharge "heavy" users.
Basically, figuring out a good pricing is just hard. One of the goals is to be a viable alternative for GA for at least a bunch of use cases (though not all), and being cheap is part of that. This is the entire reason there's a free plan in the first place: when I started working on this there was no real alternative: you either had to shell out money or self-host, which is too high of a barrier for many people's blogs and whatnot (especially if they're not technical and will have trouble self-hosting). It's all a bit of a balancing act.
> And from a UX perspective, none of them seem to support searching for a specific page to display the stats for. Yes, you can edit the URL, but that’s a horrible way to do it.
That is supported, unless I misunderstand what you mean?
(I'm the co-founder of Plausible)
While the sys admins use kibana/grifana to view data the sort of data analytics provides such as where and how people are going, if people are converting, bounce rate aren't important. The raw stats are what are important. I would not recommend plausible to the sysadmins.
(I'm the co-founder of Plausible)
I've stumbled upon it while implementing a self-hosted matomo solution. I like the approach, which allows for a much nicer UX of their consent process (of course I would prefer to not having to have one in the first place).
Being able to create password protected links for my colleagues is really nice though!
I don’t think it helps.
Perhaps tracking should be done be regulated bodies who must abide by the rules
(I'm the Plausible co-founder)
In fact, in that context, if you're a pro-privacy person then Google should - again in theory - be more prone to recommend privacy-respecting sites to you. True, that's counterintuitive given Google's biz model. However, that biz model breaks down even faster when people stop returning because they are unhappy w/ search results.
Put another way, it's only a matter of time before DDG and the like use the pro-privacy signal to move sites up the SERP. DDG already knows you probably prefer that, as that's why you use DDG. It certainly would be a helpful icon DDG could add to their SERPs.
Is there a way to invite clients and give them access to only their site's?
Effectively, I'd pay for it for myself and would add (mostly) pro-bono NPO client sites.
https://plausible.io/docs/shared-links
(I'm the co-founder of Plausible)
Can I still use utm_* codes? Or something similar appended to a link (in the query string) in order to add attributes to a visit? And then analyze / filter by those attributes?
URL of the visited page. Referer header. User-Agent header. Screen size. Country name based on IP address. A hash of the IP address, User-Agent, and random number
As such, it seems to be processing user data that could be linked to an individual person.
I'd be cautious about the claim that GoatCounter is totally GDPR compliant (without a consent notice). You're safe, for now, on the basis that this doesn't seem likely to be tested in law.
It claims it's probably GDPR compliant, but it's pretty transparent about various possible caveats and such on the GDPR page[1].
"There should always be an option to add GoatCounter to your site without requiring a GDPR consent notice."