no black boxes · the honest version

Security & continuity

We can't show you a compliance badge or a decade of history. What we can show you is an architecture where one tenant's breach is never everyone's, the complete list of who touches your data, and an exit you can run with one curl.

how it's built

One isolated instance per project
Every project runs as its own instance: its own process, its own storage volume, its own keys. There is no shared events database. A breach of one tenant is a breach of one tenant, not of all of them.
TLS everywhere
Every hop is encrypted in transit: your browser to this site, the SDK to your instance, the control plane to your instance.
Passwords hashed
Passwords are salted and hashed (scrypt), never stored or logged in plain text. Reset links expire after an hour.
API keys scoped per project
A write key belongs to one project and can only talk to that project's instance. A leaked key exposes one project, never your account or anyone else's data.

who touches your data

This is the complete list. Six companies, and exactly what each one sees.

subprocessorrunssees
Vercelthe control plane (this site + dashboard)account emails, project names, billing state. Never analytics events.
Neonthe control-plane Postgresthe same: accounts, orgs, plans. Never analytics events.
Fly.iotenant instances + their volumesyour analytics events live here, in one isolated app per project.
Anthropicthe one-time instrumentation pull requestthe files it needs to write that PR, once, when you ask for one. Not used to train models under Anthropic's commercial terms. We do not store your source.
Resendtransactional email and the weekly briefyour email address and what the message says. No analytics events.
Dodo Paymentsbilling and invoicespayment details. Card numbers never touch our servers.

no analytics-event data ever touches the control plane. events live only in your project's instance.

Your exit is built in

# your entire dataset, one curl (CSV or JSONL)
curl -H "Authorization: Bearer $KEY" \
  "https://YOUR-INSTANCE/v1/export?format=jsonl" > events.jsonl

The JSONL is a documented, re-importable format: load it into a warehouse, a script, or another tool. Leaving is a 10-minute operation, not a data hostage negotiation.

continuity, in plain words

smolanalytics is built and run by one person today. You should price that in, so here is the commitment, in writing:

  • · If the cloud ever shuts down, you get 90 days notice.
  • · Exports stay up the whole 90 days.
  • · Your export is one file in a documented format, usable anywhere that reads CSV or JSON lines, never a proprietary dump.
  • · Trial instances without a plan are stopped 7 days after the trial ends (data kept), and removed about a month later, never without an emailed export notice at least 7 days before. Paid instances are never touched.

The API and export formats are frozen, additive-only surfaces: what your integration and your exports rely on today keeps working tomorrow.

no lock-in, by construction

If we vanish, your data walks out in one file. That is architecture, not a promise.

Your data exports in one file, any time
One curl gives you everything as CSV or JSONL. No export tier, no ticket, no waiting. The exit exists before you ever need it.
No phone-home
Your instance sends nothing anywhere you did not point it: no third-party calls from the data path, no telemetry. Events go in, reports come out, and that is the whole loop.
A documented, stable format
Events live in an append-only log that seals into columnar segments, and the API and export formats are frozen, additive-only surfaces. What you export today stays readable tomorrow.
An exit you can rehearse on day one
The JSONL export round-trips: re-import it into a fresh project and the history is intact, or load it anywhere that reads JSON lines. Run the curl on day one and you know exactly what leaving looks like.

don't take our word for it: run the export curl on day one

report a vulnerability

Found something? Please report it privately by email, not in a public post, and we will respond fast. For anything this page didn't answer, check the live status or email karjunvarma2001@gmail.com.