visz.ai
Cookieless analytics

Cookieless analytics, honestly explained.

Cookieless analytics at visz.ai means, concretely: the snippet sets no cookies, neither first-party nor third-party. GDPR-first, EU-hosted, free. And honestly: you still need your visitors' consent.

“Cookieless” is often sold as a promise to skip the consent banner. For behavior analytics that is not true, and visz.ai does not promise it to you.

What is true: the visz.ai snippet works entirely without cookies. What it does instead, where the limits are, and what that actually buys you: that's this page.

Start for free

The snippet sets no cookies.

There is no cookie access anywhere in the visz.ai tracker. The snippet stores neither first-party nor third-party cookies.

To recognise returning visitors, it stores an anonymous, random ID in the browser's localStorage after consent, per site (first-party), with no cross-site tracking and no fingerprinting. If storage access is denied, the tracker falls back to an in-memory ID that ends with the tab.

Cookieless does not mean consent-free.

§ 25 TDDDG covers any storing or reading of information on the device, localStorage included and not just cookies. And session recording requires consent under Art. 6 GDPR anyway.

That is why consent-first stays mandatory at visz.ai. Before consent there are zero events, recordings, or fingerprints, and even the anonymous ID is only created after consent. A set “Do Not Track” signal stops tracking entirely.

What cookieless actually buys you.

No cookie lifetimes, no third-party cookies, no cross-site tracking. Recognition stays limited to your site and is a random ID instead of a profile.

In your cookie documentation you don't need to list any cookies for visz.ai. What remains to disclose is the localStorage entry as device access. That is the honest extent of the benefit.

Data minimisation beyond cookies.

Cookieless is only one building block. PII is masked client-side before anything leaves the browser, only utm_ parameters are kept in page URLs, and identify() never sends raw PII, only a non-reversible hash.

Server-side, the visitor IP is stored anonymised, the full address never. Hosting is exclusively in the EU, with Hetzner.

GDPR facts about cookieless analytics.

No cookies in the snippet

The tracker never touches cookies. Recognition uses an anonymous first-party ID in localStorage, created only after consent.

No cross-site tracking, no fingerprinting

The anonymous ID is per site. Visitors are not followed across other sites, and no browser fingerprints are built.

Consent-first stays mandatory

Before consent there are zero events, recordings, or fingerprints. “Do Not Track” overrides everything.

EU hosting with Hetzner

The data lives with Hetzner in the EU, with no transfer to the US.

To be honest: cookieless does not save you a consent banner. § 25 TDDDG also covers localStorage, and session recording requires your visitors' consent anyway (Art. 6 GDPR).

More on the Trust & GDPR page

Your visitors leave. They know why, but do you? See what they see.

Analytics without cookie baggage.

Install the snippet, wire up your consent banner, get going. visz.ai is free, with no tiers and no credit card.

Start for free