Everything it does
Every feature, in words. Nothing is paid, limited or held back.
What it tracks
The browser script only sends raw signals. The server works out everything else, so the script stays tiny.
| Area | What trckable records or does |
|---|---|
| Sources | referrer site and URL, channel (Direct, Search, Social, AI assistants, Email, Paid, Referral), ref links |
| Campaigns | all UTM parameters; ad click IDs (Google, Meta, Microsoft, TikTok…) mark a visit as Paid |
| Pages | pageviews incl. SPA routes, entry/exit, time on page, scroll depth, outbound links, downloads |
| Visitors | unique visitors, new vs returning, sessions, bounce, session time, online now |
| Location & tech | country (city optional) · browser incl. in-app browsers, OS, device, screen, language |
| Goals | click goals with properties, scroll goals, JS API, funnels |
| Revenue | Stripe, Lemon Squeezy, Polar, Paddle, Dodo: payments, refunds, renewals, disputes, test mode, currencies; which visit brought each paying customer |
| Behaviour | funnels, hour-by-weekday rhythm, one visitor's whole journey, a world map |
| Robots | AI assistants answering a question, search indexers, training crawlers — reported by your own server, because robots never run JavaScript |
Nothing here is paid, limited or held back. Each of these is either on by default or one switch away in Settings → Modules, which prices every module in bytes before you turn it on.
Reports
- Core — visitors, pageviews, bounce, session time, online now, and top sources, pages, locations, devices and goals on one screen. Full (press
F) opens every card into sortable, searchable tables with revenue and conversion on each row. - Animated charts drawn by an in-house SVG kit — no chart library at all — with a compare-period ghost line, drag-to-zoom, crosshair and annotations.
- A time-lapse scrubber: drag across the chart and every number, card and map re-animates to that moment.
- GA-style date picker: 16 presets, a two-month calendar, typed dates, previous period / last year / custom comparison,
←→to shift. - Click any row to filter. Saved views. Every view is a URL, so a report can be pasted into a message.
- A Filter menu with every dimension grouped (Acquisition, Content, Location, Device, Behaviour) and a search inside each, plus saved views you can reopen from the menu or the strip under the header.
- Replay the period: press play (in Core too) and the lists race, counting every day so far, with rows sliding past each other until the period's totals.
- Live pulse: each visit drops onto the chart as it arrives, a goal in its own colour, a sale as a coin with its amount.
- Notes on any day: pick the day from the period's traffic, or press + on the chart's crosshair; a day's notes show in full in its tooltip.
- Export the view you are looking at as CSV, filters and all, or read the same numbers over the HTTP API.
- Live feed of visits as they happen (SSE), and a money trail: hover a source to see where those visitors went and what they paid.
- Content groups — read a site by section ("Blog", "Docs", "Pricing") instead of four hundred URLs.
- Retention cohorts, funnels, an hour × weekday rhythm, one visitor's whole journey, and a world map.
- Core Web Vitals at the 75th percentile, measured by the browsers that actually visited, riding along with an event trckable already sends.
- AI crawlers & bots: which assistants read your pages to answer questions, which robots index you, and which are collecting training data.
- Core and Full, dark and light, built to WCAG 2.1 AA: axe-core checks the main screens in both themes and three browsers on every change.
Revenue
- Stripe, Lemon Squeezy, Polar, Paddle and Dodo. Paste one restricted API key and trckable creates the webhook endpoint itself; manual setup stays available.
- Payments, refunds (per refund, never double-counted), disputes, renewals, trials, proration, test mode kept apart, and every currency converted at the payment date.
- Attribution at query time, so a refund arriving before its payment still resolves. Last non-direct touch or first touch, switchable; renewals follow the visit that won the customer.
- Revenue, conversion and revenue-per-visitor beside your traffic, and on every breakdown row.
- Reconciliation against each provider's API every six hours, so a webhook that never arrived is not a hole in your numbers.
Privacy, and the paperwork around it
- IP addresses are never stored — not in a log, not in the database. One lookup in memory, then gone.
- Nothing is loaded from another company: no fonts, no CDN, no pixels, no telemetry.
- Cookieless mode: nothing stored in the browser, no city, DNT and GPC honoured, for every visitor wherever they live — enforced by the server, so a cached script cannot opt back in.
- Cookie consent — keep the cookie and ask first, two ways. trckable's own bar for sites with no consent manager: one cookie, one question, refusing as easy as agreeing, your wording, your colours, your CSS, in a shadow root so your stylesheet and ours never meet. Or keep the manager you already run and trckable reads it: Google Consent Mode v2 and IAB TCF v2.2. Withdraw consent and the cookie is deleted, not just ignored.
- A privacy paragraph written from your actual settings — turn a module off and the text changes with it — plus a plain list of what it cannot know for you.
- Data requests: find, export or erase everything held about one visitor or email, with payments unlinked rather than destroyed.
- Per-site retention with a daily prune, excluded paths, stricter bot filtering, and a delete-site path that clears the analytics rows too.
Running it
- One binary, one container, no external database. Boots to accepting events in under a second.
- Encrypted daily backups, kept seven deep, with
trckabled backupandtrckabled restore(round-trip tested; a wrong key is refused). - Alerts — tracking stopped, a busy day, someone paid, disk filling — to any webhook, checked against internal addresses before it is stored.
- Health panel: version, disk and days left, writer lag, last backup, reconciliation status and the last webhook.
- Import from Plausible, Umami and Google Analytics 4 (
trckabled import, NDJSON or CSV; it reads their column names as well as ours, and GA4's BigQuery export as it comes). - Two-step sign-in (hand-written RFC 6238, the QR drawn in your browser — no image service), recovery codes, a viewer role, and per-instance people management.
- Public share links with an optional password and end date, revenue hidden on the server rather than in the page, and embeddable in an iframe on the sites you name.
- Read-only API keys and an MCP server (
npx trckable mcp) so your own AI can ask about your traffic.