Last updated 6 September 2026
Privacy
Inqetra measures websites without identifying the people who visit them. This page says exactly what that means: what is collected, what never is, how long it is kept, and who else can see it.
If you visited a site that uses Inqetra
Nothing that identifies you is stored, and no cookie is set on your device. There is nothing to opt out of because there is nothing that follows you.
When you load a page, our collector receives your IP address and browser user-agent the way every web server does. Neither is written down. They are combined with the site's id and a secret that changes every day, hashed, and only the hash is kept:
SHA-256(dailySalt, siteId, ipAddress + userAgent)
Because the salt rotates at midnight UTC, the same person browsing tomorrow produces a different hash. It is enough to count you once today. It is not enough to recognise you tomorrow, to link you across two sites, or to work backwards to your address.
What is stored, per event
- Page path
- /pricing — the path only, never the query string
- Referrer domain
- The site you came from, not the full URL
- Channel
- Search, social, referral or direct
- Country
- From Cloudflare's edge. Country only — no city, no region
- Browser, OS, device
- Chrome, macOS, desktop — a short list, not a fingerprint
- Time on page
- Capped at thirty minutes
- Visitor and session
- The daily hashes above
- Custom events
- A name, and any properties the site's owner chose to send
What is never stored
Your IP address. Your full user-agent. Any cookie, localStorage entry or device identifier. Your name, email or anything you typed into the site. Mouse movement, scroll depth, keystrokes or session recordings — Inqetra has no such feature.
Custom event properties are the one exception worth naming: those are chosen by the site's owner, not by us, and a site could choose to send something personal. That is their decision and their responsibility under their own policy.
If you have an Inqetra account
Here you are a customer rather than a measured visitor, and more is held — because an account has to be signed into, billed and secured.
- Name, email, avatar
- What you entered, or what GitHub or Google returned
- Password
- Hashed. Never stored or recoverable in plain text
- Sessions
- Your IP address and browser, so you can see and end your own sessions in Account → Devices
- Two-factor secret
- Only if you turn it on
- Your sites and API keys
- Domains you added; keys are stored hashed
- Billing
- A Stripe customer id and a mirror of your subscription's plan and status. Card details are held by Stripe and never reach us
Unlike visitor data, this is deliberately identifying: it is your account. You can change it in the dashboard, and deleting your account removes it.
How long it is kept
- Recent analytics
- 90 days in Cloudflare Analytics Engine, the window the dashboard reads by default
- Historical analytics
- Kept beyond 90 days in object storage, as hashed events with no identifier that outlives its day
- Account data
- Until you delete the account
- Invoices
- Held by Stripe for as long as their records require
Who else can see it
Inqetra sells nothing to anyone and runs no advertising. Data is processed by three companies, each doing one job:
- Cloudflare
- Runs the whole product — collection, storage, database and the dashboard itself
- Stripe
- Payments. Holds card details, which never reach us
- Resend
- Sends verification and password-reset emails
Your rights
For account data: view and change it in the dashboard, or ask us to export or delete it.
For visitor data there is nothing to request, and that is the point. Without a stored identifier there is no record that is yours to retrieve — a lookup would mean building the very thing this design avoids.
Changes and contact
Material changes will be reflected in the date at the top of this page. Questions about any of it: hello@inqetra.com.
Analytics that needs no banner
Nothing above is a setting you have to find. It is how the product is built.
Start free