Post 9tXmUbqGFtpWQLhonY by irl@57n.org
(DIR) More posts by irl@57n.org
(DIR) Post #9tXJ8z9e0ARngY6naK by markosaric@fosstodon.org
2020-03-30T12:31:34Z
0 likes, 2 repeats
Are you using Google Analytics on your website?Consider replacing it with a simpler, privacy-friendly solution. I helped work on the new version of the Plausible Insights app:No cookies,No personal data collected,Open-source,Lightweight.Take a look 👇https://plausible.io/
(DIR) Post #9tXJ8zSQsJTacotns0 by brian@ap.tiuxo.com
2020-03-30T14:57:59.467289Z
0 likes, 0 repeats
@markosaric GoatCounter is a nice similar project, if you're into that. I self-host an instance and so far it's been pretty great. Super light on resources and easy to deploy (It's all packed into a single binary!). https://www.goatcounter.com
(DIR) Post #9tXmUbqGFtpWQLhonY by irl@57n.org
2020-03-30T12:58:59.006609Z
0 likes, 0 repeats
@markosaric "No personal data collected" is perhaps a goal, but looking at your dashboard I bet you can't guarantee it. A referrer or mistyped URL would be enough to uniquely identify a user.You are also tracking "visitors" which means you have some way of linking page views for the user, and this must be on some key that can uniquely identify that user.The website also talks about tracking devices and country, which again could uniquely identify a user.Other than big claims, what steps have you taken to protect privacy? I'd love to read a design document or something like that.
(DIR) Post #9tXmUcCaurh7Xc9ebo by markosaric@fosstodon.org
2020-03-30T18:49:40Z
0 likes, 0 repeats
@irl thanks! i wrote a data policy and it should hopefully answer all the questions when published in a day or so. idea is to provide a good alternative to GA. only country code is used (no more granular info than that), only brand of operating system (not even the version number). page visitors is just the total number of ip addresses. ip addresses are hashed and never stored which is considered anonymized data under gdpr
(DIR) Post #9tXmUcbPQbXmmZlTHs by irl@57n.org
2020-03-30T19:53:32.245378Z
0 likes, 0 repeats
@markosaric I'm not going to claim to be a GDPR expert, but that's irrelevant as the claim is that you've not collected personal data. I think it is reasonable to say that personal data would include personally identifying data.The main concern when storing data if you want to protect privacy should be to prevent linkability, however to count unique visitors precisely requires linkability. You may hash IP addresses but when the user returns, you'll hash the IP address again and be able to confirm that it is the same user. In this way, you've stored personally identifying data.You've not anonymised data, you've given users pseudonyms, which is not the same thing.I bet that the combination of country code and brand of operating system would be enough to uniquely identify a visitor too in a non-zero number of cases.
(DIR) Post #9tXmUd1zpkoM72ChjE by irl@57n.org
2020-03-30T19:55:20.658943Z
0 likes, 0 repeats
@markosaric Wait a second... you said no cookies! :blobnomcookie:
(DIR) Post #9tXmUdNGYfpDB09gsi by fireglow@social.firc.de
2020-03-30T20:00:41.233420Z
0 likes, 0 repeats
@irl @markosaric
(DIR) Post #9tXmUdoutrwWYl5lyq by wolf480pl@mstdn.io
2020-03-30T20:26:48Z
0 likes, 0 repeats
@fireglow @irl @markosaric why does this look like a freezer?