Asuito

Privacy

Last updated 2 September 2026

This covers two different things, and they are kept separate below: the data Asuito holds about you as a customer, and the data you collect about your own visitors using our script.

If you are here because you saw the tracker on a site

Nothing is stored on your device. No cookie is set, no identifier is kept, and there is nothing for you to opt out of that would still leave something behind.

The site you visited records the page, the referrer, your browser, operating system and device type, and roughly where you are — the country and the nearest city your internet provider’s address block is registered to. That is the city, not you: everyone on the same provider in the same area resolves to the same point, and the coordinates stored are the centre of that city rather than anywhere you have been.

Your IP address is not stored. It is used at the moment of the visit to work out the country and city above, and to make an identifier by hashing it together with your browser string and a secret that is replaced every night. Once that secret rotates, yesterday’s identifier cannot be linked to today’s — by anyone, including us. That is what allows a visitor count without a cookie and without any way to follow you between days, and it is a property of the design rather than a promise about our conduct.

There is no session replay, no heatmap, and no cross-site tracking. Those do not exist in this product deliberately.

What we collect about you, the customer

When you sign in. We use Google or GitHub to sign you in. From them we receive your email address, display name and avatar image. We never receive or store your password for either service.

When you connect Google. Connecting Search Console or Analytics grants read-only access. We store the token so scheduled reports can run, and nothing is ever written back to your Google account. Disconnecting from the dashboard revokes it.

When you pay. Payment is handled entirely by Stripe. Card numbers never reach our servers and we cannot see them. We receive only a confirmation that a payment succeeded, and the amount.

The data you collect is yours

Analytics gathered through your sites belong to you. We do not sell them, do not share them with advertisers or data brokers, and do not use them to build any audience or profile across sites. You can export everything through the API and delete a site and all of its data from the dashboard.

A dashboard is private until you publish it. If you switch one to public, its traffic figures become readable by anyone with the link — that is the point of the feature, and it is off by default.

Who else processes data

  • Supabase — database, sign-in and file storage
  • Railway — application hosting
  • Stripe — payment processing
  • Google and GitHub — sign-in, if you choose to use them
  • Resend — the emails we send you
  • OpenAI, Anthropic, Google, Perplexity and xAI — only if you enable AI visibility, and only the questions it asks. Your visitor data is never sent to any of them.

Cookies

On this site we set one kind of cookie: the session cookie that keeps you signed in. There are no advertising or third-party tracking cookies here, and the tracker we distribute sets none at all.

Keeping and deleting data

Raw events are kept for 30 days on the free tier and 365 on a paid plan, then deleted. Daily rollups — counts with no per-visit detail — are kept indefinitely, which is what lets a chart span years without keeping a log of individual visits.

You can delete your account and everything in it from the dashboard, or ask us to at johnnyhashim@gmail.com. Where a payment record must be kept for tax purposes, we keep the minimum required and detach it from your account.

Contact

Questions, corrections and deletion requests go to johnnyhashim@gmail.com.