Skip to content

Privacy policy

What Attruly collects, why, how long it is kept, and who else touches it. Written for the people whose data passes through the product, not only for their lawyers.

Effective 1 June 2026

1.Two different relationships

Attruly sits in two different positions depending on whose data is involved, and the rules differ:

  • You, our customer. When you create an account, we are the controller of your account data — your name, email, organisation and billing details. Sections 2 to 5 cover this.
  • Visitors to your website. When Attruly records events from a site you operate, you are the controller and we are your processor. You decide what is collected and why; we process it on your instructions. Sections 6 to 10 cover this.

2.What we collect about you

Personal data Attruly holds about its own customers
DataWhyKept for
Name and emailTo create your account, sign you in and contact you about the serviceWhile the account exists, then 30 days
Password hashTo authenticate you. We never store the password itselfWhile the account exists
Organisation name and slugTo identify your workspaceWhile the account exists
Billing detailsHeld by Stripe, not by us. We store only a customer reference and the plan stateAs long as required by tax law, typically 7 years
IP address and user agent at sign-inTo secure sessions and detect unauthorised access30 days
How you found us (utm parameters at signup)To understand which of our own marketing works. We run the product we sell24 months
Audit log of account changesSo you can see who changed what, and so we can answer support questions24 months

3.Why we are allowed to hold it

  • Contract. We cannot provide an account without an email address and a password.
  • Legitimate interests. Securing the service, preventing abuse, and understanding which of our own marketing channels work. We have balanced these against your interests and consider the processing proportionate.
  • Legal obligation. Retaining invoices and tax records.
  • Consent. Product announcement emails, which you can decline at signup and unsubscribe from at any time. Transactional emails — verification, password reset, quota warnings, billing failures — are not marketing and continue regardless.

4.Your rights

You can access, correct, export, restrict or delete your account data. Most of it is editable directly in settings; deletion of the whole organisation is a button in the danger zone.

For anything not available in the product, email privacy@attruly.com. We respond within 30 days. If you are in the EU or UK and are not satisfied with our response, you may complain to your local supervisory authority.

5.Cookies on attruly.com

The signed-in application sets only the cookies the product needs to work. There is no advertising network anywhere on this domain, and we do not sell or share what we collect.

The public marketing pages — everything outside the signed-in application — also load Google Analytics, so we can see which pages bring people to a signup. It is deliberately not loaded once you are signed in: those URLs contain your organisation, project and profile identifiers, and we are not sending those to Google.

Cookies set by attruly.com
CookiePurposeLifetime
attruly.session_tokenKeeps you signed in30 days
attruly.session_dataCaches session state to avoid a database read per request5 minutes
_ga, _ga_H67M713Z60Google Analytics, on the marketing pages only. Distinguishes visitors so a page view is not counted twice2 years
attruly-themeRemembers light or dark mode. Stored in localStorage, not a cookieUntil cleared

6.What Attruly records on your customers’ sites

When a website operator installs Attruly, the following is recorded about each visit. The operator chooses what else to send through custom events and traits.

Data recorded by the Attruly tracking snippet
DataPurpose
A randomly generated visitor idTo recognise a returning browser. Stored first-party. Not derived from any device characteristic and not usable across sites
Page URL, path and titleTo report which pages are visited and which page a visit started on
ReferrerTo identify where the visit came from
UTM parameters and ad click idsTo attribute the visit to a campaign
User agent, parsed to device, OS and browserTo report the device mix and to identify automated traffic
IP addressUsed to resolve an approximate country and to apply the operator’s exclusion list. Not stored against the visit
TimestampsTo order the touch path and bucket reports by day
Custom events and traitsWhatever the operator chooses to send. Entirely under their control

What is never recorded: no cross-site tracking, no device fingerprinting, no advertising identifiers, no third-party cookies, and no data sharing between the projects of different customers. A visitor id from one Attruly customer's site is meaningless on another's.

7.IP addresses

A visitor's IP address reaches our servers because it is part of every HTTP request. We use it to resolve an approximate country and to apply the site operator's own exclusion list, and then we discard it — the IP is not written to the visit record. Country is stored; the address itself is not.

8.Data processing terms

Where we act as your processor, we commit to the following, and these terms form part of the agreement between us:

  • We process visitor data only on your documented instructions, which are the settings you configure and the events you send.
  • Everyone with access is under a duty of confidentiality.
  • We apply the security measures described in section 9.
  • We use only the sub-processors listed in section 10, and will tell you before adding another.
  • We assist you with data subject requests, with security incidents, and with impact assessments, to the extent our position makes that possible.
  • On termination we delete your data as described in section 11.
  • We make available the information needed to demonstrate compliance, and allow audits on reasonable notice.

Enterprise customers who need a signed data processing agreement on their own paper should contact legal@attruly.com.

9.Security

  • All traffic is encrypted in transit with TLS 1.3. Data at rest is encrypted at the disk level.
  • Passwords are hashed with a memory-hard function. Session tokens are random, httpOnly, sameSite and, in production, secure.
  • API keys are stored as SHA-256 digests. The plaintext is shown once at creation and is not recoverable afterwards.
  • Every query in the product is scoped to an organisation at the database level, and access is proved before a project is read rather than checked afterwards.
  • Backups are encrypted and tested by restore.
  • Access to production is limited to named individuals, requires multi-factor authentication, and is logged.
  • We will notify you without undue delay, and within 72 hours, of a breach affecting your data.

10.Sub-processors

Third parties that process data on Attruly’s behalf
ProviderWhat forData reaching them
Hetzner Online GmbH (Germany)Application and database hostingAll customer and visitor data
Stripe, Inc. (USA)Payments and subscriptionsBilling contact and payment details. No visitor data
Resend, Inc. (USA)Transactional email deliveryRecipient email address and message content. No visitor data
Vercel, Inc. (USA)AI Gateway routing for the analysis featureAggregated report figures only — never an identifier of any individual
Functional Software, Inc. dba Sentry (USA)Error monitoringStack traces and request metadata, with personal data scrubbed before transmission

Transfers outside the EEA and UK rely on the Standard Contractual Clauses, or on an adequacy decision where one applies.

11.Retention and deletion

  • Raw events and visits are kept for the retention window of the plan the organisation is on, between 30 days and 24 months. A nightly job prunes anything older.
  • Aggregated daily statistics are kept for the life of the project. They contain no identifier of any individual.
  • Deleting an organisation removes its events, profiles, projects and keys within 30 days.
  • Backups age out within 90 days, after which deleted data is unrecoverable.
  • Invoices and tax records are kept for as long as tax law requires, regardless of account deletion.

12.Changes to this policy

We will email the account owner at least 30 days before a change that materially affects how we handle personal data. Other changes take effect when published, and the effective date at the top of this page always reflects the current version. See also our terms of service.

13.Contact

Privacy questions, data subject requests and anything else covered here: privacy@attruly.com. Security reports: security@attruly.com.