Privacy Policy

Last updated: January 14, 2026

Our Commitment

Academalytics is built on the principle that analytics should respect user privacy. We collect only what is necessary to provide useful insights, and we never sell or share your data.

Data We Collect

For Site Owners (You)

When you create an account, we collect:

  • Email address (.ac.uk domain required)
  • Name
  • Password (encrypted with bcrypt)
  • Institution details (derived from email domain)

For Your Website Visitors

When someone visits a site using Academalytics, we collect:

  • Page URL
  • Referrer (where they came from)
  • Browser type and version
  • Operating system
  • Screen resolution
  • Country (derived from IP address, then IP is discarded)
  • Session ID (generated randomly, stored in browser sessionStorage)

Data We Don't Collect

  • No cookies - We use sessionStorage instead
  • No personal identifiers - No user IDs or fingerprinting
  • No cross-site tracking - Each site's data is completely isolated
  • No precise geolocation - Only country-level data
  • No IP addresses - IPs are used only to determine country, then discarded

Do Not Track

We respect the Do Not Track (DNT) browser setting. If a visitor has DNT enabled, our tracking script will not collect any data.

Data Retention

Analytics data is retained for 24 months by default. You can configure a shorter retention period in your account settings. After the retention period, data is automatically deleted.

Data Storage & Security

  • Data is stored on Hetzner servers in Germany
  • 100% renewable energy (hydropower)
  • All connections use HTTPS/TLS encryption
  • Database backups are encrypted
  • Access is restricted to authorized personnel only

GDPR Compliance

Academalytics is designed to be GDPR compliant by default:

  • Data minimization - We only collect what's necessary
  • Purpose limitation - Data is used only for analytics
  • Storage limitation - Automatic deletion after 24 months
  • Right to access - Export your data anytime as CSV
  • Right to erasure - Delete your account and all data anytime
  • Data portability - Export in standard CSV format

Third Parties

We do not share your data with any third parties. Period.

We use the following services to operate Academalytics:

  • Hetzner - Hosting infrastructure (Germany, GDPR compliant)
  • Postmark - Transactional emails (EU data residency)

Your Rights

You have the right to:

  • Access your data
  • Correct inaccurate data
  • Delete your data
  • Export your data
  • Withdraw consent
  • Lodge a complaint with a supervisory authority

To exercise these rights, contact us at privacy@academalytics.uk

Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any significant changes via email.

Contact Us

If you have questions about this privacy policy or how we handle your data:

Academalytics is committed to transparency and user privacy. This policy is written in plain English, not legalese, because we believe you deserve to understand exactly how your data is handled.