AnalyticsFFDocsPricing

Privacy Policy

Last updated October 1, 2026

AnalyticsFF ("we", "us") records what people do in websites and apps and shows it to the people who run them. This policy covers two groups: people who have an AnalyticsFF account, and visitors to websites and apps that use the AnalyticsFF SDK.

For the second group, the site owner decides what is recorded and why. We store and show that data on the site owner's behalf and only on their instructions.

1. Your AnalyticsFF account

When you sign up and use analyticsff.com we collect:

  • Account details: your email address, name and username, and how you signed in (Google, GitHub, or email and password). From Google and GitHub we receive only your name, verified email address and account id. Passwords are stored hashed, never in plain text.
  • Projects and settings: the projects, keys, dashboards and feature flags you create.
  • Billing details: your plan and billing history. Card payments are handled by our payment provider; we never see or store your full card number.
  • Sign-in cookies: two cookies, access_token and refresh_token, keep you signed in for up to a year. They are not used for anything else.

We do not run analytics, advertising or tracking scripts on analyticsff.com. The only email we send today is the sign-in code you ask for. If we start sending other account email, such as billing notices, it will only be about your account.

2. Data recorded on sites that use AnalyticsFF

When a site owner adds the AnalyticsFF SDK, the following can be sent to us from their visitors' browsers. The site owner can turn each part on or off.

  • Page views: the page address including its query string, page title, the previous page, screen and window size, browser language, and campaign tags (utm_source and similar).
  • Clicks on links and buttons: the element's type, id and classes, up to 100 characters of its visible text or label, and the link address.
  • Errors: the error message, stack trace, and the file and line it came from.
  • Browser: the user agent string the browser sends with each request.
  • Ids: a random device id and session id kept in the browser's local storage, and a user id plus any details the site owner chooses to attach to it, which can include an email address.
  • Session replays, only if the site owner turns them on: a recording of the page's layout and visible text, mouse movement, clicks and scrolling. Input fields are masked unless the site owner chooses to record what is typed in them. Password fields are always masked, and site owners can hide any other part of a page.
  • Custom events the site owner sends, with whatever details they attach.

What we do not collect:

  • We do not store visitors' IP addresses, and we do not look up their location.
  • The SDK sets no cookies.
  • Events never carry what is typed into form fields, and replays never record password fields.

3. How we use data

  • To run AnalyticsFF: store events, draw dashboards, play replays and answer queries.
  • To sign you in and keep your account secure.
  • To find and fix problems with the service.
  • To bill you for your plan.
  • To meet legal obligations.

We do not sell data, use it for advertising, train AI models on it, or combine one customer's data with another's. We look at a customer's recorded data only when they ask us to help, or when we need to for security or the law.

4. AI assistants

You can connect Claude or another AI assistant to your account through our MCP server. When you do, the assistant reads your project data through the tools it calls, and that data is then handled by the assistant's provider under its own terms. You choose whether to connect one, and you can disconnect it at any time.

When an assistant asks for screenshots of a session replay, we render the replay on our servers and keep the images for 30 days.

5. Services we rely on

We do not share personal data except with these providers, which run parts of AnalyticsFF for us:

  • Amazon Web Services (United States): hosting, databases, file storage for replays, and sign-in email.
  • ClickHouse Cloud (United States, on Amazon Web Services): the database that stores recorded events.
  • Google and GitHub: only if you choose to sign in with them.
  • Our payment provider: to take payment for your plan.

We may also disclose data when the law requires it, or to protect the rights and safety of our users or the service. Data is stored in the United States.

6. How long we keep data

  • Account details: while your account is open.
  • Recorded events: for as long as the project they belong to exists.
  • Session replays: deleted automatically 30 days after they are recorded.
  • Replay screenshots: deleted automatically after 30 days.

When you close your account, or ask us to delete data, we delete it within 30 days. Copies in our providers' backups are removed on their normal schedule.

7. If you put AnalyticsFF on your site

You decide what AnalyticsFF records about your visitors, so you are responsible for telling them and, where the law requires it, asking for their consent first. In the EU and UK, storing a device id in the browser can need consent in the same way a cookie does.

The SDK gives you these controls:

  • Turn off automatic page views, clicks or errors, or record replays for only a share of sessions.
  • Skip any part of the page with data-ff-ignore.
  • Hide text from replays with the ff-mask class, or a whole element with ff-block.
  • Clear a visitor's ids with reset().

If one of your visitors asks you to delete their data, send us their user id, device id or email address and we will delete their events.

8. If you visited a site that uses AnalyticsFF

The site you visited controls what was recorded about you, so contact them first. If you cannot reach them, contact us and we will help.

9. Your rights

Depending on where you live, you may have the right to see the personal data we hold about you, correct it, delete it, get a copy of it, or object to how we use it. To do any of these, email geoff@marketbyorder.com. We answer within 30 days. If you are in the EU or UK, you can also complain to your local data protection authority.

We use your account data because we need it to provide the service you signed up for, and to keep the service secure. We use data recorded on customers' sites only on those customers' instructions.

10. Security

All data travels over encrypted connections. Access to our systems is limited to what is needed to run the service, and links to replays expire after 15 minutes. No system is perfectly secure, and we cannot promise that data will never be exposed.

11. Children

AnalyticsFF accounts are for people aged 18 or older. We do not knowingly collect data from children under 13. If we learn we have, we will delete it.

12. Changes to this policy

When we change this policy we update the date at the top. If a change matters to how we handle your data, we will email account holders before it takes effect.

13. Contact

Questions or requests about privacy: geoff@marketbyorder.com.

© 2026 AnalyticsFFHomePricingDocsPrivacyTerms