Privacy Policy

Last Updated: September 16, 2026

TL;DR: Clics provides privacy-first analytics without cookies or cross-site tracking. We do not request identity information from website visitors by default, but a website owner may configure custom events and properties, so those owners must not send personal or sensitive data. For customers and authorized integration users, we process account, workspace, website, analytics, billing, support, and integration data needed to provide Clics. Analytics event and metrics data is stored on servers located in the European Union.

Privacy isn't just a feature for us; it's the foundation of Clics. Clics is designed to support compliance with GDPR/DSGVO, CCPA, PECR, CNIL guidance, and ePrivacy requirements, ensuring that data ownership always remains in your hands.

This policy outlines exactly what information is collected, how it is secured, and the rights you have over your data. We have never sold personal data, and we never will.

Privacy-First Analytics

Clics provides website analytics without compromising user privacy. We don't use cookies, don't track individual users, and don't request personal information from website visitors by default. Website owners remain responsible for the optional data they choose to send.

  • No User Tracking
  • No Cookies
  • Privacy Compliance: Designed to support GDPR/DSGVO, CCPA, PECR, CNIL guidance, and ePrivacy requirements.

Who This Policy Applies To

This privacy policy covers customers, authorized users, website visitors, and people who connect to Clics through an API, MCP client, or ChatGPT integration:

  • Customers: Individuals or organizations who sign up for and use Clics's analytics services for their websites.
  • Authorized users: Team members and other people authorized by a customer to access a Clics workspace, dashboard, API, or MCP integration.
  • End Users: Visitors to websites that use Clics analytics.

Our Privacy-First Principles

  • No User Identification by Default: Clics does not request names or email addresses from website visitors through the standard analytics script, and does not track visitors across websites or calendar days.
  • Customer-Controlled Events: Website owners control any optional event names and custom properties sent through their implementation and are responsible for excluding personal or sensitive data.
  • No Cross-Site Tracking: We do not use cookies or cross-site identifiers to track visitors between different websites.
  • IP Address Anonymization: We immediately transform incoming IP addresses and do not store raw IP addresses in analytics event payloads.
  • Aggregated Analytics: Clics provides aggregated reports and anonymized session analytics. Authorized customer users may also access session, event, and configuration details for their own projects.
  • No Data Sales: We never sell or share user data with third parties for advertising or marketing purposes.
  • Minimal Data Collection: We only collect what's necessary to provide meaningful analytics insights.

Information We Collect

From Our Customers (Website Owners)

When you sign up for Clics, we collect:

  • Account information: Email address, name (optional), and authentication information handled by our identity provider
  • Billing information: Payment details and contact information for subscriptions
  • Website information: Domain names and website URLs you want to track
  • Usage data: How you use our dashboard and analytics features
  • Communications: Support requests, feedback, and survey responses
  • Access and security data: API keys, crawler tokens, expiration dates, last-used metadata, authentication records, and connection metadata needed to secure the service

From APIs, MCP Clients, and ChatGPT

When a customer or authorized user uses the Clics API, local MCP server, or remote MCP integration through ChatGPT, we process the information needed to authenticate the request, authorize the selected workspace, execute the requested operation, and return the result. This may include:

  • Identity and authorization: Email address, name, user and organization identifiers, workspace membership, role, permissions, OAuth claims, and connection metadata
  • Request inputs: Project, goal, funnel, and session identifiers; domains; date ranges; time zones; metrics; dimensions; filters; sorting; pagination; goal and funnel definitions; and other parameters included in a user request
  • Returned analytics: Aggregated statistics and, where requested by an authorized user, page paths, session and event details, referrers, UTM campaign values, country, device, browser, operating system, scroll depth, event names, customer-defined event properties, and AI-crawler URLs, categories, providers, and response statuses
  • Workspace actions: The remote MCP integration can create, update, and delete projects, goals, and funnels when an authorized user requests those actions.

Clics does not need or request a full ChatGPT conversation to process an MCP request. A local MCP client uses a Clics API key for authentication; keep API keys and other authentication secrets out of event properties, tool inputs, and support messages.

From End Users (Website Visitors)

When someone visits a website using Clics analytics, we collect minimal, pseudonymous analytics data configured by the website owner:

  • Page views: Which pages were visited
  • Referrer information: Which website or search engine led to the visit
  • Technical information: Browser type, operating system, and device type
  • Geographic location: Country only (derived from anonymized IP address)
  • Session data: Time spent on site, bounce rate, and navigation patterns (anonymized)
  • Optional event data: Custom event names, scroll-depth measurements, UTM campaign values, and other customer-defined event properties sent by the website owner
Important: We receive an IP address and User-Agent at the tracking endpoint to derive country and a project-scoped daily session mapping. We immediately transform the IP address using a one-way hash function, do not store raw IP addresses in analytics event payloads, delete inactive session mappings after 24 hours, and do not use the mapping for cross-day or cross-site tracking. Website owners must not send names, email addresses, credentials, payment data, health data, government identifiers, or other sensitive information through Clics tracking or integrations.

No Cookies, No Tracking

Unlike traditional analytics services, Clics is designed to respect user privacy:

  • No Cookies: We don't use cookies or any cross-site tracking to track users.
  • Limited Session Measurement: We use a project-scoped daily session mapping for analytics continuity; it is not used for cross-site or cross-day tracking and inactive mappings are deleted after 24 hours.
  • No Cross-Site Tracking: We can't and don't track users as they move between different websites.
  • No Advertising Profiles: We don't sell analytics data or build individual advertising profiles from it.

How We Use Information

We use the information described above to:

  • Provide, operate, and improve the Clics dashboard, analytics, API, CLI, and MCP integrations
  • Authenticate users, connect the workspace they select, enforce workspace permissions, and maintain account security
  • Process subscriptions, usage limits, billing, invoices, and plan entitlements
  • Prevent abuse, enforce rate limits, investigate security incidents, and maintain service reliability
  • Respond to support requests and send service-related communications
  • Comply with legal obligations and establish, exercise, or defend legal claims

We do not sell Clics analytics data or use it for third-party advertising, behavioral advertising, or cross-site profiling.

MCP and ChatGPT Data Flow

The remote Clics MCP integration is connected through OAuth. During connection, Clics receives identity and authorization information from our authentication provider so it can identify the user, determine the selected organization or workspace, and enforce the user's role and permissions. ChatGPT then sends only the MCP tool request needed to perform the action selected by the user. Clics returns the requested result to the connected client.

OpenAI's own terms and privacy policy govern data that OpenAI processes in ChatGPT. This Clics policy governs the request, response, account, workspace, and analytics data that Clics receives and processes. You can disconnect or revoke an integration authorization through the connected integration controls when available, or contact us for assistance.

MCP can read analytics and can change workspace configuration through project, goal, and funnel tools. Read, create, update, and delete operations are limited by authentication and workspace permissions. Do not use Clics MCP, API, CLI, or tracking inputs to submit credentials, authentication secrets, payment card data, health information, government identifiers, or other sensitive data.

Service Providers and Recipients

We share information only with service providers and other recipients that help us provide Clics, protect the service, or meet legal obligations. Depending on the feature used, these categories include:

  • WorkOS/AuthKit: Authentication, OAuth, user identity, organization membership, and permissions
  • Convex: Account, workspace, project, goal, funnel, and application configuration data
  • Tinybird: Analytics events, metrics, sessions, funnels, custom event properties, and AI-crawler analytics
  • Cloudflare: Hosting, network delivery, edge security, and infrastructure protection
  • Stripe and Autumn: Payments, subscriptions, billing, usage limits, and plan entitlements
  • Resend: Transactional email and service communications
  • OpenAI/ChatGPT: When you connect Clics through ChatGPT, OpenAI routes the user-authorized MCP request to Clics; OpenAI's own privacy terms govern OpenAI's processing
  • Legal and security recipients: Authorities, advisers, auditors, or other parties when required by law or necessary to protect rights, safety, and the service

Analytics event and metrics data is stored on EU-located servers. Other service providers may process the limited information needed for their service in the jurisdictions where they operate.

Retention and Deletion

We retain information only for as long as needed for the purposes described in this policy, subject to the following product retention rules:

  • Analytics event and metrics data: Pro plans include up to 3 years of retention, Business plans include up to 5 years, and Enterprise retention is the custom period agreed for the account.
  • Session mappings: Inactive mappings are deleted after 24 hours. The daily design prevents cross-day tracking.
  • Account, workspace, project, goal, and funnel data: Retained while the account or workspace is active. When a customer deletes a project or workspace, the deletion workflow removes the related configuration and analytics data; backup copies may remain until normal backup rotation and records may be retained where required by law or needed for security, fraud prevention, disputes, or accounting.
  • OAuth connections and API keys: Retained while needed to provide the connection or authentication, and removed or made unusable when revoked, expired, or deleted, subject to security and legal retention requirements.
  • Billing, support, and security records: Retained for the period required to provide the service, resolve disputes, meet accounting or legal obligations, and protect Clics and its users.

To request access, export, correction, or deletion of customer data, contact us at the address below. Because standard website analytics does not identify individual visitors, we generally cannot locate or delete one visitor's historical events without information supplied by the website owner.

Your Controls

  • Choose which websites, projects, environments, workspaces, and integrations are connected to Clics
  • Manage workspace members and permissions through the Clics account controls
  • Create, expire, rotate, and revoke API keys and crawler tokens
  • Disconnect or revoke an MCP/ChatGPT authorization through the connected integration controls when available, or request revocation from us
  • Delete projects, workspaces, and account data through the available Clics controls or by contacting us
  • Ask us to access, correct, export, restrict, or delete personal data where applicable
  • Control optional event names and properties in your own website implementation and omit personal or sensitive data

Privacy Rights and Compliance

Your Rights (Customers)

As a customer, you have the right to:

  • Access: Request copies of your personal data
  • Rectification: Correct inaccurate information
  • Erasure: Request deletion of your account and related personal data where applicable
  • Restriction: Limit how we process your data in certain circumstances
  • Objection: Object to processing based on legitimate interests where the law allows
  • Portability: Receive your data in a structured, commonly used format where applicable

End User Rights

As an end user (website visitor), you have the right to:

  • Information: Understand what data is collected, as described in this policy
  • Objection: Use browser settings, Do Not Track where supported, or similar tools to limit analytics you do not want
  • Limitations on erasure: Because standard analytics does not identify individual visitors, we typically cannot delete data for one specific person; the retention and deletion rules are described in the Retention and Deletion section above.

Data Security

  • Encryption: Data is protected in transit and at rest using industry-standard encryption.
  • Access controls: We apply strict access limits and authentication for systems that store customer data.
  • Data minimization: We collect and retain only what is needed to provide the service.
  • Sensitive data: Do not send credentials, authentication secrets, payment card data, health information, government identifiers, or other sensitive data through Clics tracking, API, CLI, or MCP inputs.

Contact Us

If you have any questions about this Privacy Policy, want to exercise your privacy rights, or have concerns about how your data is handled, please contact us. You can also review our Data Policy, Data Processing Addendum, and Terms of Service.

Privacy contact: contact@clics.dev