mandera's analytics are privacy-first, your data stays in Germany, and none of it is ever used to train AI. Everything your legal team needs is on this one page.
Part one: how the analytics measure without ever identifying a person. Part two: the infrastructure behind them, from hosting and sub-processors to security, your rights, and setup.
mandera measures your traffic without anything that can identify a person. Many privacy-focused analytics tools still derive a short-lived identifier from each visitor, typically by hashing the IP address together with the user agent. That can be done thoughtfully, but it leaves your data protection team with something to assess: an identifier derived from a person.
mandera removes the question entirely. A visitor's IP address is dropped the instant a request arrives, before it is stored, logged, or processed in any way, so there is never an identifier to assess. Nothing is hashed, and no record can be traced to a person. A visit is recognized from the referrer, not from anything derived from the visitor. Every signal we touch is listed in our how we track documentation.
| How mandera analytics track | |
| Cookies | none |
| Personal data | never collected |
| IP addresses | never stored, logged, or processed; dropped the instant a request arrives |
| Consent banner | not required (§25 TTDSG) |
| Fingerprints & cross-site tracking | never |
| URL query strings | stripped, full URLs never stored |
| Page views, sources, devices | yes, aggregated |
| Country | from the browser timezone |
| Engagement (time, clicks, scroll, mouse movement) | yes, aggregated |
| Campaign tracking (UTM) | supported |
mandera is designed, developed, and operated in Germany by mandera Software GmbH. Your analytics data is stored and processed on servers in Germany, stays in the EU, and is never transferred outside it. One company, one stack, one jurisdiction, under European privacy law.
A few necessary providers sit around that core, each one in the EU and named in full in the table below: hosting, the AI model, and the SEO data source. Each receives only the minimum it needs, your visitors' data is never shared with any of them, and the AI is never trained on your data.
| mandera | |
| Legal entity | mandera Software GmbH, Germany |
| Data location | EU servers in Germany |
| Transfers outside the EU | none |
| Sub-processors, the necessary minimum, all in the EU | |
| Hosting | Hetzner, in Germany |
| AI | Mistral Large 3, the flagship model of the French company Mistral, hosted in the EU, with zero data retention and never trained on your data |
| SEO data | DataForSEO, on servers in Germany, receives only domains and keywords |
| Personal or visitor data shared | never, it does not leave mandera |
| Changes to sub-processors | 14 days notice, with a right to object |
| Full list | mandera.ai/subprocessors |
| Security | |
| Encryption in transit | HTTPS/TLS |
| Access control | role-based and least-privilege, with MFA for admin accounts |
| Backups | regular, with rolling deletion |
| Your rights | |
| Data ownership | yours |
| Sold or shared | never |
| Data export and deletion | any time |
| Deletion after cancellation | within 90 days, backups included |
| Data Processing Agreement | public at mandera.ai/dpa |
| GDPR | analytics compliant by design with no personal data (Art. 25); stored content covered by the public DPA |
| Setup | |
| Installation | one line of code in your website head |
| Time to live | about two minutes |
| Ongoing maintenance | none, it runs automatically |
Start your free trial, or talk to us if your legal team needs a DPA or a closer look.
Start free trial