Privacy

Last updated 17 August 2026

Peeko is web analytics built so that it does not need to know who anybody is. We set no cookies on the sites that use us, we never store an IP address, and we do not sell, share or enrich anything we collect. This page explains exactly what that means, in the order that actually matters.

Who we are

Peeko is a product of Cloco, operated by Mahdi Farra, an individual based in California, USA. For anything on this page, including a request to delete your data, write to [email protected].

There are two kinds of people in this document: visitors, who browse a website that has installed Peeko, and customers, who have a Peeko account. Almost all of the privacy question is about visitors, so that comes first.

What Peeko records about a visitor

When someone loads a page on a site running Peeko, the snippet sends us one small message. It contains:

  • the path of the page, without the query string
  • the referring site, and the utm_source, utm_medium and utm_campaign values if the link carried them
  • the country, taken from a header our network adds, never from a lookup we perform on a stored address
  • the device type, browser and operating system with their major versions, screen and window size, and whether the visitor prefers a light or dark theme
  • the time of the visit
  • a visitor hash, described in the next section

If the site owner has turned on click tracking, we also record which tagged element was clicked. That is the entire list. There is no cookie, no local storage, no device identifier, no advertising identifier and no canvas or font fingerprinting.

How a visitor is counted

The visitor hash is how Peeko can count people without knowing them. We take the IP address and the browser user agent, run them through a one way keyed hash with a secret only we hold, and keep the first part of the result. The IP address itself is never written to a database or a log file.

There are two of these hashes, and it is worth being precise about the difference:

  • The main one mixes in the current date, so it changes for everybody every day. It is what counts unique visitors.
  • A second one leaves the date out. It is what lets the dashboard say that a visitor is returning rather than new, and it links a person's pageviews into a journey across days.

Neither hash can be turned back into an IP address or a name, and neither is combined with anything else to identify anyone. Peeko stores no profile record: a visitor exists only as their rows, so deleting the rows deletes the visitor. Analytics are always queried within a single site, and we never combine or compare data across different customers' sites.

The secret salt can be rotated, which resets every identity at once and makes it impossible for any journey to bridge that moment.

AI crawlers

Peeko separately records visits from AI crawlers and other bots, because showing you which models read your pages is the point of the product. For those requests we store the path, the time and the raw user agent string the crawler sent. No IP address, and no visitor hash, is involved on that path at all. A crawler is a piece of software, not a person.

Your account, if you are a customer

To run your account we store your email address, your name if you give us one, your organisation and its members, your sites and their settings, the API keys you create, and a customer reference plus subscription status from Stripe. We never see or hold your card details.

We send transactional email only: sign in links, invitations to join an organisation, and a warning when your usage approaches your plan limit. There is no marketing email unless you asked to be told when Peeko launched.

Who else touches the data

Peeko runs on a small number of services, each doing one job. We do not send data to anyone else, and none of these are advertising companies.

  • Hetzner, which hosts the servers and the database, in Germany
  • Cloudflare, which sits in front of the service and tells us the country a request came from
  • Stripe, which handles payment and holds all card details
  • Resend, which delivers our email
  • Google, only if you choose to sign in with a Google account

How long we keep things

Analytics data is kept for the retention window on your plan and is then deleted automatically. A site owner can shorten that window per site in the site settings, and deleting a site deletes everything recorded for it immediately. Account data is kept for as long as you have an account.

Deleting your account and your data

Self service deletion is not built yet, so we do it by hand and we do it properly. Email [email protected] from the address on your account and ask us to delete it. We will confirm, and your account, your sites and all analytics recorded for them will be gone within 30 days. Backups roll over on their own schedule and any copy in them ages out within a further 30 days.

You can also delete any single site yourself from the dashboard at any time, which removes its data immediately and does not need us.

Your rights

If you are in the UK, the EU or another place with similar law, you can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, or object to how we use it. Write to the address above and we will answer within 30 days.

For visitors to a site running Peeko, there is a practical limit worth stating honestly: because we hold no identifier that can be traced back to a person, we usually cannot find one visitor's rows on request. That is a consequence of collecting so little, not a way of avoiding the question.

Cookies

Peeko sets no cookies on the sites it measures. The only cookie we set anywhere is the session cookie on this domain, after a customer signs in to their own dashboard, and it exists solely to keep them signed in.

Changes to this page

If we change how any of this works we will update this page and change the date at the top. If a change is significant and you are a customer, we will email you about it rather than hope you check.