Built in, first-party measurement
Qoralo records public-page views and link interactions through its own same-origin endpoints. This built-in analytics path does not set an analytics cookie or load third-party analytics scripts by default. The headline is about that default measurement only, not a blanket legal answer for every site or region.
A visitor hash that rotates each day
For a page view, the Worker derives a keyed HMAC hash from the request IP address and the current UTC date. It rotates every UTC day. The raw address is not stored in the page-view row; the hash is pseudonymous, not anonymous, and people sharing one network address may share a daily identifier. It is computed server-side rather than saved in a browser cookie.
Only a referrer origin
A valid HTTP or HTTPS referrer is reduced to its origin, up to 200 characters. Its path, query and fragment are discarded. Qoralo stores a coarse user-agent category and a two-character country code when Cloudflare provides one; optional campaign tags are bounded first-party labels. Repeated page and link events from the same source are deduplicated in five-minute windows.
Known bots are left out
User agents that Qoralo classifies as bots are excluded from creator-facing page views, campaign views, link clicks and impressions. The public page can still be served to those requests. The filter is based on user-agent text, so it cannot identify every automated request.
Clear retention windows
Scheduled cleanup removes page-view and analytics rows older than 30 days on Free and 365 days on Pro. The current plan determines which limit applies. Qoralo also uses essential first-party authentication cookies for logged-in features; this page describes analytics on public creator pages.
Creator-added pixels change the picture
The Pro tracking-pixel settings accept Meta Pixel, TikTok Pixel and Google Analytics 4 IDs. When an ID is configured, the published page loads the selected provider script; Qoralo does not load those scripts by default or provide a consent banner for them. Those providers can receive visit data under the creator’s setup. Depending on your audience and configuration, you may need consent and an updated privacy notice before enabling them. Qoralo’s built-in analytics do not decide those obligations.