Cookieless analytics, honestly explained.
Cookieless analytics at visz.ai means, concretely: the snippet sets no cookies, neither first-party nor third-party. GDPR-first, EU-hosted, free. And honestly: you still need your visitors' consent.
“Cookieless” is often sold as a promise to skip the consent banner. For behavior analytics that is not true, and visz.ai does not promise it to you.
What is true: the visz.ai snippet works entirely without cookies. What it does instead, where the limits are, and what that actually buys you: that's this page.
The snippet sets no cookies.
There is no cookie access anywhere in the visz.ai tracker. The snippet stores neither first-party nor third-party cookies.
To recognise returning visitors, it stores an anonymous, random ID in the browser's localStorage after consent, per site (first-party), with no cross-site tracking and no fingerprinting. If storage access is denied, the tracker falls back to an in-memory ID that ends with the tab.
Cookieless does not mean consent-free.
§ 25 TDDDG covers any storing or reading of information on the device, localStorage included and not just cookies. And session recording requires consent under Art. 6 GDPR anyway.
That is why consent-first stays mandatory at visz.ai. Before consent there are zero events, recordings, or fingerprints, and even the anonymous ID is only created after consent. A set “Do Not Track” signal stops tracking entirely.
What cookieless actually buys you.
No cookie lifetimes, no third-party cookies, no cross-site tracking. Recognition stays limited to your site and is a random ID instead of a profile.
In your cookie documentation you don't need to list any cookies for visz.ai. What remains to disclose is the localStorage entry as device access. That is the honest extent of the benefit.
Data minimisation beyond cookies.
Cookieless is only one building block. PII is masked client-side before anything leaves the browser, only utm_ parameters are kept in page URLs, and identify() never sends raw PII, only a non-reversible hash.
Server-side, the visitor IP is stored anonymised, the full address never. Hosting is exclusively in the EU, with Hetzner.
GDPR facts about cookieless analytics.
No cookies in the snippet
The tracker never touches cookies. Recognition uses an anonymous first-party ID in localStorage, created only after consent.
No cross-site tracking, no fingerprinting
The anonymous ID is per site. Visitors are not followed across other sites, and no browser fingerprints are built.
Consent-first stays mandatory
Before consent there are zero events, recordings, or fingerprints. “Do Not Track” overrides everything.
EU hosting with Hetzner
The data lives with Hetzner in the EU, with no transfer to the US.
To be honest: cookieless does not save you a consent banner. § 25 TDDDG also covers localStorage, and session recording requires your visitors' consent anyway (Art. 6 GDPR).
Goes well with.
Cookieless is the foundation, the analysis building blocks sit on top:
- Session replayWatch real visitor sessions as a replay. Consent-gated, PII masked in the browser, EU-hosted in Germany, and free with visz.ai.
- HeatmapsClick, scroll and move heatmaps, aggregated across sessions: see where visitors click and how far they scroll. GDPR-first, EU-hosted, free.
- visz.ai vs US toolsAn honest comparison of visz.ai and typical US behaviour-analytics tools: EU hosting, GDPR, data minimisation and control vs US cloud and CLOUD Act.
- Pricingvisz.ai pricing is simple: everything is free. No tiers, no credit card, just fair volume limits as cost control. Session replay, heatmaps, funnels.
Your visitors leave. They know why, but do you? See what they see.
Analytics without cookie baggage.
Install the snippet, wire up your consent banner, get going. visz.ai is free, with no tiers and no credit card.
Start for free