Privacy policy
Plain language, and literally true — this page describes what the code actually does. The short version: your analytics data lives on your own isolated instance, we don't sell or share it, the SDK is cookieless, and leaving is one curl.
Who we are
smolanalytics (smolanalytics.com) is operated by Arjun Varma. Contact for anything on this page: karjunvarma2001@gmail.com.
This policy covers two things: your account on smolanalytics.com, and the analytics data your projects collect.
Your account data
When you sign up we store your name, email, and (if you sign in with GitHub) your GitHub username and avatar. Passwords are salted and hashed, never stored in plain text.
Billing is processed by Dodo Payments; we never see or store your card details.
We send transactional email (verification, invites, billing) and a daily analytics brief. Every brief has a one-click unsubscribe that works without logging in.
Analytics data your projects collect
Each project runs on its own isolated instance with its own storage volume — there is no shared events database across customers.
The SDK is cookieless by default. Visitors are distinguished per site without third-party cookies or cross-site tracking, and we never sell, share, or use your visitors' data for our own purposes. Your analytics data is yours.
Event data lives on your instance until you delete it, set a retention window, or delete the project. Deleting a project destroys its instance and volume.
You can export everything (CSV/JSONL) at any time — the exit is a curl, not a support ticket.
The GitHub App and your source code
If you connect a repository, we read it once to generate the instrumentation pull request. Relevant files are sent to Anthropic's API for that one-time generation and are not used to train models under Anthropic's commercial terms.
We do not store your source code. What we keep: the PR we opened (which lives on GitHub anyway), its status, and the repository name. Installation tokens are short-lived and never stored.
After that, webhook events (merged pull requests) are used only to record deploy markers on your own instance.
Subprocessors
Fly.io (instance + control-plane hosting), Neon (control-plane database), Vercel (website hosting), Anthropic (one-time instrumentation PR generation), Resend (email), Dodo Payments (billing). Each receives only what its job requires.
What we use on this site
smolanalytics.com runs smolanalytics — cookieless, no third-party trackers, no ad pixels. The same product we sell is the only analytics on this site.
Deletion and your rights
Delete a project and its data is gone with its instance. Delete your account and we remove your account records. Instance-level per-user deletion exists for your visitors' data-subject requests (delete_user_data).
Email karjunvarma2001@gmail.com for access, correction, deletion, or export requests and we'll handle it within 30 days.
Changes
If this policy changes materially we'll note it here with a date. Last updated: August 1, 2026.
Related: terms of service · security & continuity