Privacy-first analytics
— no cookie banner needed

The headline applies to Qoralo’s built-in page analytics. See what those records contain, how long they stay, and what changes when you add outside pixels.

What Qoralo’s built-in analytics collect

Built in, first-party measurement

Qoralo records public-page views and link interactions through its own same-origin endpoints. This built-in analytics path does not set an analytics cookie or load third-party analytics scripts by default. The headline is about that default measurement only, not a blanket legal answer for every site or region.

A visitor hash that rotates each day

For a page view, the Worker derives a keyed HMAC hash from the request IP address and the current UTC date. It rotates every UTC day. The raw address is not stored in the page-view row; the hash is pseudonymous, not anonymous, and people sharing one network address may share a daily identifier. It is computed server-side rather than saved in a browser cookie.

Only a referrer origin

A valid HTTP or HTTPS referrer is reduced to its origin, up to 200 characters. Its path, query and fragment are discarded. Qoralo stores a coarse user-agent category and a two-character country code when Cloudflare provides one; optional campaign tags are bounded first-party labels. Repeated page and link events from the same source are deduplicated in five-minute windows.

Known bots are left out

User agents that Qoralo classifies as bots are excluded from creator-facing page views, campaign views, link clicks and impressions. The public page can still be served to those requests. The filter is based on user-agent text, so it cannot identify every automated request.

Clear retention windows

Scheduled cleanup removes page-view and analytics rows older than 30 days on Free and 365 days on Pro. The current plan determines which limit applies. Qoralo also uses essential first-party authentication cookies for logged-in features; this page describes analytics on public creator pages.

Creator-added pixels change the picture

The Pro tracking-pixel settings accept Meta Pixel, TikTok Pixel and Google Analytics 4 IDs. When an ID is configured, the published page loads the selected provider script; Qoralo does not load those scripts by default or provide a consent banner for them. Those providers can receive visit data under the creator’s setup. Depending on your audience and configuration, you may need consent and an updated privacy notice before enabling them. Qoralo’s built-in analytics do not decide those obligations.

Ready to put this into practice?

Create a focused Qoralo page and start with the useful essentials.

Create your page — free