We bootstrapped our open source Google Analytics alternative to $500k ARR
plausible.io
plausible.io
>We have a $0 paid advertising budget and we don’t have an affiliate program either. We pretty much ignore all the best marketing practices.
This is very impressive, but I am not sure it generalizes to the average bootstrapped startup.
I guess the marketing best practices they ignore wouldn't be best practices if it did :)
Still, it's nice to see that the model can work. As a happy customer, I'm pleased to see that the model is sustainable. When a product decides to stick to word-of-mouth alone, incentives are very aligned for them to make the user experience good enough to tell other people about (as I have).
They would find forums with questions about address correction, and provide great answers that DID NOT require using their software.
Then just put their site in the profile or at the end of the post in a tactful way.
I started using them based on the expertise in these posts.
Not sure how they're missing this, but they are not ignoring best practices. Content and SEO are fundamental marketing practices. This post and their entire blog is content and SEO. I guess they think it sounds cool to say "we don't care about marketing", but they are marketing the same way most bootstrappers people would tell you to.
It doesn't have any user journey but only entry and exit, no A/B testing, no heatmap for click and scrolls.
If it doesn't provide any actionable intels, you don't call that analytics but just a counter.
Check Countly's intro video on what analytics is. Though the base is open source, most of its analytics features are behind enterprise edition.
For an open source solution, you might want to look at PostHog instead. (But paid plans exist for some features.)
- # of visitors / sessions over time
- where those people were coming from
After that, most of GA's features were wasted on me. Plausible has the two things above, so for me it's a valid alternative.
This isn't because you're bootstrapped, it's likely because you don't have a PR team pitching on your behalf. That's how stories get placed.
Congrats!
Now with Plausible I still have no cookies or third-party requests on my websites, but I get to see numbers too.
I assume you are using the self-hosted version?
* Third party requests from the browser are problematic in general for technical and privacy reasons: it's impossible for the browser to know whether the request is privacy-preserving or not. And they need to be enabled in tooling like CSP. It's much easier not to have any.
* Third-party requests from my server don't give me any more information than I had before. I could store my logs and process them, or I can engage a third-party to aggregate my data for me. Plausible have no way to know that the requests I'm sending aren't entirely fictitious, and I can sleep slightly more soundly knowing that there's one less moving part that I need to maintain myself.
(We're a Plausible and Clickhouse user at my company)
https://microfounder.com/blog/cofounder-in-marketing
They are remote co-founders, if you will.
This image blows my mind. Basically from 0 to 50,000 uniques in month?! Congrats
https://microfounder.com/storage/posts/originals/sjswkbxufvl...
https://www.starterstory.com/privacy-firendly-web-analytics-...
The answers are content marketing and spreading words in niche tech communities.
They profile companies that have 2 to 2,000 (or so?) people, but most focus on having an opinionated take (over growth for its own sake).
How can you stay competitive long-term?
you can add their script tag to the head and then use the API to get the stats for every site you track
they also give you the possibility to embed their dashboard for each site via iframe, which made integrating their product into ours frictionless and easy experience
It’s ridiculous that PR news (Tech crunch etc..) are always focused on funded-startup or fundind instead of bootstrapped startup which in mine option are way more interesting!
I'm a very happy (paying) user of the product, too.
I LOVE that the script is less then 2KB of JavaScript, and that their privacy design is aligned with my values.
I find their dashboard UI solves my needs just fine, whereas I still can't find things easily in the GA interface despite using it for over fifteen years!
I like how you stated that you're not going to change much and continue with the same growth vs forcing results with an investor (without one is plausible of course). I'm always keen on what if's to forcing things with interesting outcomes, lol. Well done and congrats on the rising success.
LOL, nice.
Is it customary to use extrapolations/projections to measure ARR in the startup/business world? Even projections based on less than a year of data?
(Different from an entity downloading your software and self-hosting which you say is allowed)
https://plausible.io/blog/open-source-licenses
From their blog post:
> If you used AGPL-licensed code in your web service in the cloud, you are required to open source it. It basically prevents corporations that never had any intention to contribute to open source from profiting from the open source work.
> It explicitly prohibits corporations from parasitically competing with an open source project. They won’t be able to take the code, make changes to it and sell it as a competing product without contributing those changes back to the original project. [emphasise mine]
The blog post above was discussed heavily on Hacker News back in Oct 2020: https://news.ycombinator.com/item?id=24763734
Many projects are moving from an AGPL-like license to a proprietary license just to prevent this though. MongoDB, ElasticSearch, and just yesterday, Apollo Federation 2.
> We have a free as in beer Plausible Analytics Self-Hosted solution. It’s exactly the same product as our Cloud solution with a less frequent release schedule (think of it as a long term support release).
> Bug fixes and new features are released to the cloud version several times per week. Features are battle-tested in the cloud which allows us to fix any bugs before the general self-hosted release. Every six months we combine all the changes into a new self-hosted release.
[1]: https://github.com/plausible/analytics#can-plausible-analyti...
In the SaaS industry MRR is the most commonly used metric.
ARR = 12 MRR
500k ARR = 41k MRR
ARR is just used in the title caused it's a bigger number and makes it look more impressive.
`hash(daily_salt + website_domain + ip_address + user_agent)`"
Isn't this just PII with extra steps? OK it's at least better then the traditional approach. Keep in mind though that anonymizing is also a use of personal data in it self and requires a legal basis. https://www.insideprivacy.com/data-privacy/german-federal-co...
But if it was, it most likely would be enough anyway if the salt isn't stored anywhere. An irreversible hash of data is enough anonymization
Where the definition of personal data is:
"(1) 'personal data' means any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;"
So if the listed information isn't PII (an IP address however is PII) then it would become PII if you can identify a unique visitor with it.
Am I wrong here? It sounds to me that this hash fits the definition of Art. 4
Privacy improvements using crypto is somewhat marketing, but here the numbers show that they have a really good product, an impressive revenue model and a good marketing message so I think that's what we should look at.
Technically, at the end of the day, they store utm_source, they store the IP address (just in an encoded form with a salt + day added to it).
-> So yeah, you can be tracked, but in theory you will appear under a pseudonymised hash of your IP+UA.
A unique identifier which let's them track a user everywhere isn't either if there is no way to match this id to a real name etc
They will likely still need to disclose this tracking (ianal), but the identifier used to track the visits isn't PII
the natural person is the link to a real name. it only becomes PII if its somehow possible to link a real name or similar to this identifier. If this is impossible, it will never be PII, even if it identifies a single individual.
I don't think I am wrong here. But I am willing to admit when I am wrong, where is my mistake?
[0]https://gdpr-info.eu/recitals/no-30/ [1]https://gdpr.eu/eu-gdpr-personal-data/?cn-reloaded=1
its not PII as long as its impossible to link it back to a unique identification from the real world such as a name, social security number or similar.
so my previous blanket statement of IP addresses not being PII is slightly exaggerated, they can be, but they rarely are.
most people access the internet either with dynamic ip addresses or from a corporations internet providers. people that have a static ip address on a private landline and without a NAT are rare, which is why generally speaking, IP addresses aren't PII.
it does become PII if the person in question has a static ip address and is the only person using this connection.
If it was, ycombinator would have to adhere to much more stringent regulation wrt them.
I can understand your point and it was nice to entertain this conversation with you. I can't see how to convince you from my view and I don't see how you could convince me of yours. But I will keep you arguments in mind and will look for some more information regarding to it. Thank you!
GDPR handles all kinds of data related to a person, so yes: a username is personal data wrt GDPR
personally identifiable information (PII) on the other hand is only a subset of data handled by the general data protection regulation (GDPR)
This might clear that up https://techgdpr.com/blog/difference-between-pii-and-persona...
They do tell you what it means in the second paragraph, though.