Sereno Analytics
Privacy
This is the whole policy. It is short because the product collects almost nothing — and what little it does collect is described here in full rather than summarised.
Last updated 26 August 2026
The two kinds of data, and which one is which
Almost every privacy policy in this category is confusing because it mixes two different things together. There are the people who visit our customers' websites, and there are our customers — the people who pay us and sign in. The rules are different for each.
For visitors to a customer's website, we act on that customer's instructions: in data protection language they are the controller and we are the processor. For our own customers we are the controller.
Visitors to a website using Sereno
We do not collect personal data about them. No cookies are set, nothing is written to their browser, and nothing we store identifies anybody.
Each time a page is viewed, the script sends us:
- the path of the page —
/pricing, not the full address with its query string - the hostname of the site they came from, if any —
google.com, never the full referring URL - the country, worked out at our edge from the connection and then discarded
- a bucket for screen width — small, medium, large — not the exact size
- the browser, operating system and device type, read from the user-agent
- campaign tags (
utm_source,utm_medium,utm_campaign) if the link had them - the name of an action, if the site's owner has asked us to count one
What is never collected: IP addresses, cookies, local storage, device fingerprints, mouse movement, scroll depth, form contents, session recordings, or anything that follows a person from one site to another. We could not build a profile of somebody if we wanted to, because nothing we keep can be joined up.
To count returning visits within a single day without identifying anyone, we make a one-way hash of the visitor's IP address, their browser's user-agent and the site — with a secret that changes every night. The IP address is never written down, the hash cannot be reversed, and because the secret rotates, the same person on the same device is a different hash tomorrow. That is why our figures for a week are a sum of daily counts rather than a count of people, and it is also why the tool needs no cookie banner.
We keep the raw events for up to three months, and the summed daily totals for as long as the account exists.
Our customers
To have an account you give us an email address. That is the only personal detail we ask for — there is no name field, no company field, no phone number.
Alongside it we hold the domains you have added, the counts your sites have generated, whether you have asked for the weekly summary email, and, if you subscribe, the identifiers Stripe gives us for your customer and subscription. We never see or store your card details.
- Why we hold it: to give you the service you asked for, to bill you, and to send the emails you have chosen.
- The legal basis: performance of our contract with you, and our legitimate interest in running and securing the service.
- How long: while your account exists. Delete it and we delete this within 30 days, apart from records we are required to keep for tax — invoices, for six years.
Who else touches it
As few companies as we can manage. Each of these does one job:
- Cloudflare — hosting, the network our service runs on, and the storage the numbers live in.
- Stripe — payments. Card details go directly to Stripe and never reach us.
- Resend — the sign-in links and the emails you have asked for.
Some of these are based outside the UK. Where data reaches them it is covered by the standard contractual terms the law provides for such transfers. We do not sell data, we do not share it for advertising, and no advertising network has any access to any part of this.
Cookies on our own site
One, and only when you sign in: a cookie that keeps you signed in. It is strictly necessary for the service to work, which is why there is no banner asking you about it. Your choice of light or dark theme is remembered in your own browser and never sent to us.
Your rights
You can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, object to how we use it, or ask for it in a portable form. Email privacy@serenoanalytics.com and we will answer within a month.
If you are unhappy with how we have handled it you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first.
If you are one of our customers and someone asks you to remove their data from your analytics, there is nothing to remove — we hold nothing that can be traced back to an individual. You are welcome to send them this page.
Changes
If this policy changes in a way that matters, we will email account holders before it takes effect. The date at the top always says when it last changed.
Sereno Analytics is a business run by Tiago Daubigne as a sole trader in the United Kingdom. [Business address, United Kingdom]. Questions: hello@serenoanalytics.com.