How Sealmetrics Works
Sealmetrics measures your website traffic without cookies or anything stored on the visitor's device — and, by our self-assessment, without a consent banner for its own analytics — on a simple principle: measure the visit, identify no one. You add one script tag; each visit the tracker sees is recorded as a set of non-identifying signals; your reports show aggregate patterns.
What gets recorded
A small set of non-identifying fields per hit:
- Timestamp — when the visit happened
- User Agent — used for device classification (browser, OS, device type). The raw string is never written to storage; only the derived categories persist in aggregates
- Current URL — which page was viewed
- Referral URL — where the visitor came from
- Browser timezone — used to assign the visit's country
- Session identifier — tells a second pageview from a new entrance (see below)
No IP addresses stored, no cookies, no localStorage, no persistent identifiers. Hits within one visit are grouped by a session identifier: the tracker computes, in the browser, a hash of standard device characteristics (a device fingerprint) that is never written to the device. On the server it is re-keyed with a salt that rotates and is destroyed every day, so the stored identifier changes daily and cannot recognise a returning visitor on another day. A session ends after roughly two hours of inactivity.
Because nothing is stored on the visitor's device, no data that identifies anyone is stored, and the session identifier rotates daily and cannot be reconstructed afterwards, Sealmetrics self-assesses that it fits the ePrivacy audience-measurement exemption and asks for no consent for its own analytics (in Germany an open question: the DSK does not extend §25(2) TDDDG to audience measurement, and reading device properties via JavaScript may count as "access" under §25(1) — see Germany) — which is also why cookie-based tools lose the visitors who reject or ignore the cookie banner — depending on sector, brand strength and traffic mix — while Sealmetrics does not. The tracker does read standard browser properties to compute the session identifier; Analytics Cookies: Consent Exemption Requirements covers how the audience-measurement exemption criteria apply to that read. The full reasoning is in What is Consentless Analytics?, and the exact field list with retention is in What We Track.
What you get in reports
Traffic and entrances, traffic sources and campaigns, conversions and revenue with last-click attribution at channel level, aggregate engagement (bounce rate, engagement rate, pages per session), country from browser timezone, and device/browser breakdowns. Hits appear within seconds — the Last hit timestamp on the Overview report lets you verify your install immediately.
What you do not get is anything that needs a persistent identifier: unique visitors, session duration, cross-session journeys or cohorts. See the Metrics Reference for how each metric is calculated.
How the data flows
- The tracker (1.1 KB gzipped, asynchronous) detects page views and the events you instrument.
- Hits are sent to Sealmetrics infrastructure in Dublin, Ireland. We don't store IPs. To filter bots we check the IP in flight against a public list of automated-traffic IPs, and don't keep it.
- Each hit is processed on its own and aggregated. Event-level rows are purged after 1 day; daily aggregates and conversions are kept 24 months.
- Known bots, crawlers, scrapers and monitoring tools are filtered out so reports show real visitors — see Bot Detection.
The same path, from the browser to your reports:
Getting started
Add one script tag to your <head>, then instrument conversions with sealmetrics.conv(). It works with any stack — WordPress, React, Vue, plain HTML — natively or through Google Tag Manager. A REST API and CSV export are available for pulling the data into your own systems.
Related documentation
- First Steps with Sealmetrics — go from signup to live data
- Installation — add the script tag
- What is Consentless Analytics? — the model and why, in our assessment, no banner is needed
- What We Track vs What We Don't — every field, with retention
- Overview Report — the aggregate insights this architecture produces