Trust & transparency

What we collect, who we use, and what we won’t claim

A privacy product should be able to answer these questions plainly. Here is exactly what happens on this website and inside the product, the providers involved, and the security claims we deliberately do not make.

Last reviewed 2026-07-14.

What this website collects

Nothing until you consent

Analytics and marketing scripts do not load until you allow their category. Only strictly-necessary storage (your login session and your cookie choice) is set without asking.

Cookieless on this site

Our own analytics runs here in cookieless mode: no cookie, no localStorage, no device identifier. A daily, server-derived identifier is used only to avoid double-counting within a day, and it cannot follow you across sites or days.

Campaign attribution

If you arrive from a campaign link and allow analytics, the UTM tags are kept in your browser session only to attribute a signup you actively submit. Nothing is stored and no ping fires before you consent.

Account details

If you create an account, your email and the sites you connect. Card details are entered with our payment provider at checkout, not stored by us.

What the product collects

Traffic, not people

DevDome Analytics records page events, clicks, country, and a human-or-bot verdict. Cookieless mode is the default on new installs; a site owner can opt into a returning-visitor cookie, and when they do the product warns that a cookie is set and consent may be required.

IPs are hashed

A visitor IP is used to resolve country and network reputation and is stored only as a hash, never in the clear.

No cross-site profile

The daily, server-derived identifier includes the site in its input, so the same person on two connected sites never becomes one profile.

The cookie banner categories are: strictly necessary, functional, analytics, and marketing. Only the first is on by default.

Providers we use

These are the third parties that can process data on our behalf. Each links to that provider’s own security or legal documentation.

Website hosting (Workers), edge delivery, and Turnstile bot challenge on forms.

Authentication and the account database.

Merchant of record

How billing works →

Payment processing for paid plans: card checkout, recurring charges and any applicable taxes. Card details are entered on the provider’s secure checkout and are not stored on our servers.

Transactional email (verification, password resets, account notices).

Google Analytics

Google privacy →

Optional site analytics. Loads only if you allow the analytics category in the cookie banner.

Self-hosted DevDome Analytics

How it works →

Our own analytics engine on infrastructure we operate. On this website it runs in cookieless mode and stores nothing on your device.

Your data is yours

Get a copy of your data

Request a copy of your account data at any time and we will send it to you.

Contact support →

Delete your account

You can delete your account and its data. If you have an active subscription, billing is cancelled first, so deletion never leaves a charge running.

Security →

It is your data

We do not sell personal information. We share only with the providers listed above, and only as needed to run the service.

Privacy policy →

Security we can show you

  • Everything is served over HTTPS/TLS. You can verify the certificate in your browser.
  • Sign-in and account pages enforce a strict Content-Security-Policy that blocks injected scripts; account actions require re-authentication and support app-based two-factor.
  • Payment card details are entered on our payment provider’s secure checkout and never reach our servers.
  • Passwords are checked against known-breach lists at sign-up and change.

What we do not claim

  • We do not claim SOC 2 or ISO 27001 certification.
  • We have not commissioned a third-party penetration test, and do not claim one.
  • We do not offer a contractual uptime guarantee or SLA.
  • We do not promise a specific data-residency region.
  • We describe our providers’ security by linking their own documentation rather than restating it as our own guarantee.

Reporting a security issue

Found a vulnerability in the website or a plugin? Email our team with the details and steps to reproduce. We read every report and will confirm receipt. Each plugin page also links a way to report an issue for that specific plugin.

Straight answers, on the record

Read the full privacy policy, or see how bot detection actually works.