Privacy
Two different questions get asked on this page: what this website knows about you, and what the software it sells knows about the people who visit sites running it.
This website
twillingate.dev is a static site. It runs the twillingate tag in its default anonymous mode, which is the same configuration described below: no cookies, no local storage, no identifiers. We see counts of page views, the country a request came from, the kind of device, and which site referred you — never who you are.
Fonts are served by Google Fonts, which means your browser makes a request to
fonts.gstatic.com and Google sees your IP address as a result. Nothing
else on the page calls a third party.
What the collector stores
When you run twillingate on your own site, this is what it keeps — and a test scans the database file and the log output on every release to confirm it.
- IP addresses and full User-Agent strings are never stored or logged.
- A visitor who sends no identifier is recorded as a hash of the connection under a key that rotates every 24 hours. The previous key is overwritten, so the same person on two different days cannot be linked.
- Query strings are stripped down to a UTM allowlist. Referrers are reduced to a source name. Known bots are dropped at ingestion.
- Paths are stored exactly as sent. If your URLs contain personal data, strip it before it reaches the tracker.
- A tag configured for identified tracking sends a user id, user name and install id, and those are stored as given. Group ids and names are always stored raw, because a group is an organisation rather than a person.
What the SDK keeps on the device
Nothing, unless you ask for it. With consent declared on the tag, it persists its
failed-batch retry queue and — on an identified tag — the visitor, user and group in
localStorage. That is terminal-equipment storage under ePrivacy, in the
same legal category as a cookie, which is why it is off until a consent signal says
otherwise.
Access and erasure
Enabling the console exposes every stored identifier to every valid token holder,
over MCP and the REST routes alike. Complete erasure for a project is
twillingate project delete, which is deliberately available only from
the command line.
Reading further
The full privacy and GDPR notes live with the source, and the consent and storage behaviour is specified in the documentation. Questions go to hello@twillingate.dev.