· 1 min read
Analytics Without Surveillance
Most websites need to know which pages get read, not who is reading them. Umami is built around that difference.
For years, adding analytics to a website meant adding Google Analytics.
It was free, it was everywhere, and nobody questioned it much. The real cost showed up later: a cookie banner on every page, a consent dialog most visitors dismiss without reading, and visitor data flowing to a company whose business is advertising.
For most websites, that trade makes very little sense.
A personal site or a small product needs answers to a handful of questions. Which pages get read? Where do visitors come from? Did the last post reach anyone? None of them require knowing who a specific person is, or where else they go on the web.
Privacy-first analytics starts from that observation. Instead of collecting everything and deciding later what it was for, it collects only what those questions need.
Umami is the tool I settled on, and it now runs on this site.
It sets no cookies. It records page views, referrers, browser, operating system, device type, and country, and nothing that identifies a person. The tracking script is under 5 KB. It’s open source, so those claims can be checked against the code, and it can be self-hosted if the data should never leave your own infrastructure.
With no cookies and no personal data, there is in most cases nothing to ask consent for. No banner, no preference panel, no button designed to be misclicked.
There are trade-offs. You don’t get user-level funnels, cross-device identities, or advertising audiences. If the business depends on those, Umami is the wrong tool.
Most sites don’t depend on them. They need a few honest numbers and a dashboard that can be read in ten seconds.
The best way to protect visitor data isn’t a better consent banner.
It’s not collecting the data in the first place.