Cookieless Analytics: How It Works and What It Tracks
Cookieless analytics is web analytics that measures traffic without cookies or other persistent identifiers on the visitor's device. The server groups pageviews into visits and counts unique visitors with short-lived hashes. You keep traffic, source, and conversion data. You give up long-term, cross-device identity.
This guide explains how cookieless tracking works, which methods exist, and what the law says. It also shows how Pulse, the privacy-first analytics tool from Ciphera, applies these methods in production.
Consent banners cost you data. A peer-reviewed study of more than 4 million banner interactions measured this. In GDPR countries, the share of visitors who rejected cookies rose from 3.49% to 20.56% once sites added a one-click Reject All button. The study counts only visitors who clicked. Visitors who ignore the banner never appear in cookie-based analytics either. A behavior study of 1.2 million users on B2B sites, run by the consent agency Advance Metrics, found that 68.9% closed or ignored the banner.
TLDR
- Cookieless analytics measures website traffic without storing a persistent identifier on the visitor's device.
- The server counts pageviews, sources, and visitors. It does not follow one person across sites or devices.
- EU rules cover any storage or access on a visitor's device, not only cookies. Fingerprinting falls under them too.
- GA4 sets two first-party cookies by default, and each lasts two years.
- Pulse by Ciphera sets no cookie, hosts all data in Switzerland, and ships a tracker 55 times smaller than Google's. A free plan is available.
What Is Cookieless Tracking?
Cookieless tracking is any method that measures visitor activity without storing a cookie in the browser. People also search for it as “cookie less tracking” and “tracking without cookies.”
A cookie is a small text file that a website stores in your browser. It holds an ID. The site reads that ID on your next visit and recognises you.
Cookieless tracking removes that step. The tool recognises activity through other signals, or it skips recognising individuals at all.
What Changes When Cookies Are Removed?
- Returning visitors. The tool cannot read a stored ID. Recognition depends on other methods, or it stops after a set period.
- Sessions. The server groups pageviews into visits instead of the browser.
- Consent. Tools that store nothing on the device face a different legal test. Confirm your case with counsel.
- Cross-device identity. It disappears. A person on a phone and a laptop may count twice.
- Data volume. Visitors who reject or ignore a banner still count, because the tool needs no consent step to run.
How Does Cookieless Tracking Work?
Cookieless tracking follows four steps:
- A small script on your page sends one event for each pageview.
- The server reads details from the request, such as page path, referrer, browser, and country.
- The server groups events into visits using a short-lived value that it calculates itself.
- The tool stores aggregated counts, not a profile of each person.
The browser keeps no ID. The server does the grouping. That is the core difference from cookie-based tools.
What Is Cookieless Analytics?
Cookieless analytics is the reporting layer built on this collection method. It is also called analytics without cookies or website analytics without cookies. You see pageviews, top pages, sources, devices, countries, and conversions. You do not see a named person's history.
Analytics for a cookieless web answers site-level questions. Which pages attract visitors? or Which sources bring them? Which pages lead to a signup? It does not answer who a specific visitor is.
How Does Cookieless Analytics Work?
Most cookieless analytics platforms follow the same pattern:
- The script sends an event for each pageview.
- The server reads the country from the request, then drops the raw IP address.
- The server counts visits and visitors with rotating hashes. A hash is a one-way code. The tool cannot turn it back into the original data.
- Because the hash rotates, it stops linking activity after a set period.
- The dashboard shows aggregated counts.
Cookieless Tracking vs Cookieless Analytics
The terms overlap, but the goals differ.
| Cookieless tracking | Cookieless analytics | |
|---|---|---|
| Purpose | Recognise or follow users without cookies | Measure site performance in aggregate |
| Output | User-level signals or profiles | Counts, trends, and reports |
| Typical methods | Probabilistic matching, identity graphs, fingerprinting | Server-side event counts, rotating hashes |
| Typical user | Ad tech and attribution teams | Site owners, marketers, developers |
| Privacy risk | Higher, and often still needs consent | Lower when no personal data is stored |
If you want to understand your website, you need cookieless analytics. If you want to retarget individuals, you need something else, and that something else carries legal risk.
So First Off, What Are Cookies and Why Do Websites Use Them?
A cookie is a small text file that a website stores in your browser. Websites use cookies to keep you logged in, remember your cart, save your language, measure traffic, and show ads.
Cookies Fall Into Two Main Categories
- First-party cookies. The site you visit sets them. Sites use them for login, preferences, and most analytics.
- Third-party cookies. Another domain embedded in the page sets them. Advertisers use them to target ads and follow people across sites.
Cookies also differ by lifespan. Session cookies disappear when you close the browser. Persistent cookies stay for days, months, or years.
What Are Analytics Cookies?
Analytics cookies, also called analytical cookies, are small files that a measurement tool stores in the browser. They recognise returning visitors and group pageviews into sessions. Most are first-party cookies.
Google Analytics Cookies
Google's documentation says GA4 uses first-party cookies to distinguish unique users and sessions. The two default cookies are _ga, which distinguishes users, and _ga_<container-id>, which keeps session state. Each lasts two years by default.
Browsers shorten that life. Chrome limits first-party cookie lifespan to 400 days and Safari to 7 days when a user does not return.
Why Cookies Became a Compliance Problem
Four developments turned cookies into a legal issue:
- The ePrivacy Directive. Directive 2002/58/EC, amended in 2009, requires consent before a site stores or reads information on a user's device. People call it the Cookie Law.
- The GDPR. It took effect in 2018. It raised the standard for valid consent and set heavy fines.
- Regulator enforcement. In January 2022, the French regulator CNIL fined Google a total of 150 million euros and Facebook 60 million euros over cookie rules, including how hard sites made refusal.
- Wider technical scope. The EDPB's Guidelines 2/2023 explain that the ePrivacy rule covers more than cookies. It also covers methods such as fingerprinting.
The result is the consent banner. Sites now ask every visitor for a decision before they measure anything.
Do Tracking Cookies Really Require Consent Banners?
Usually yes in the EU, for analytics and tracking cookies. Article 5(3) of the ePrivacy Directive requires consent unless an exemption applies.
Two exemptions matter. Strictly necessary cookies, such as login and shopping cart cookies, do not need consent. The CNIL also allows a narrow exemption for audience measurement when strict conditions are met. The CNIL states that most large audience measurement offerings fall outside this exemption regardless of their configuration.
So check each tool you run. A single ad pixel, chat widget, or embedded video can bring the banner back.
Disadvantages of Cookie Consent Banners
- They remove visitors from your data. In the Politecnico di Torino study, rejection in GDPR countries rose from 3.49% to 20.56% after sites added a one-click Reject All button. Across all regions, only 1% to 4% of visitors opted out when refusal took more than one click.
- Many visitors ignore them. Advance Metrics found that 68.9% of 1.2 million B2B site users closed or ignored the banner. Those visitors never appear in cookie-based reports.
- Design nudges the outcome. The same study notes that research has found banners often push users toward acceptance with dark patterns.
- Few people read the policy. Only 0.24% of interactions in the study involved opening a cookie or privacy policy.
- Your reports describe consenting visitors only. They may not reflect all visitors.
- You must keep the setup correct. Rules and regulator guidance change, and your configuration must follow.
The Hidden Overhead of Cookie-Based Analytics
Cookie-based analytics costs more than the tag itself. These costs vary by company, but most teams meet several of them:
- Script weight. On 8 September 2026, Ciphera measured Google's gtag.js at 148,504 bytes gzipped. The Pulse tracker measured 2,700 bytes.
- A consent management platform. Many teams pay for one, such as Cookiebot or OneTrust, next to the analytics tool.
- Configuration upkeep. Someone must keep banner settings, tag rules, and consent signals correct.
- Legal review. Teams run data protection impact assessments and review vendor and transfer terms.
- Separate tools. Teams often add an uptime monitor, a page speed monitor, and a Search Console dashboard.
Why Cookieless Tracking Matters Now
Browser Restrictions
Safari limits first-party cookies to 7 days for visitors who do not return, according to Google's documentation. Safari and Firefox block third-party cookies by default. Chrome is different. Google confirmed on April 22, 2025 that Chrome will keep third-party cookies available by default. Google has also retired most Privacy Sandbox technologies. Do not build your measurement plan on a Chrome cookie phase-out. It is not coming.
Regulatory Requirements
Article 5(3) of the ePrivacy Directive, the GDPR, CNIL guidance, and the EDPB's Guidelines 2/2023 all shape what you may store or read on a visitor's device. Regulators treat fingerprinting as in scope. A first-party label does not exempt a tool.
Limitations on Insights
Consent-based analytics sees only visitors who accept. Google's Consent Mode fills part of the gap with modeling. You then read estimates, not measured counts. A cookieless tool measures every visit it receives and does not model the gap.
Cookieless Tracking Methods and Technologies
Five methods appear most often. They differ in privacy risk, so choose carefully.
Server-Side Tracking
The server receives events and decides what to keep. The browser stores nothing. The server can drop the IP address after it reads the country. Server-side collection also reduces how often ad blockers and browser rules affect your data.
First-Party Data
First-party data is information you collect directly on your own site. It is more reliable than data from third parties. The label alone does not exempt a tool from consent rules. What matters is what the tool stores or reads on the device.
Probabilistic Tracking
Probabilistic methods estimate the missing data. Google's Consent Mode is an example. When a visitor denies consent, tags send cookieless pings, and Google Analytics fills the gaps with behavioral and conversion modeling. You read modeled numbers, not measured ones.
Browser Fingerprinting
Fingerprinting combines signals such as fonts, screen size, and hardware to identify a browser. Avoid it. The Article 29 Working Party's Opinion 9/2014 placed fingerprinting inside the scope of the ePrivacy rules, and the EDPB's Guidelines 2/2023 build on that opinion. Fingerprinting can provide cookie-like tracking without storing a cookie.
Privacy-Preserving Browser APIs
Google built the Privacy Sandbox to replace third-party cookies with browser APIs. Google has since retired most of those technologies. Some remain, such as CHIPS, FedCM, and Private State Tokens. They serve embedded content, sign-in, and fraud checks. They do not replace analytics.
Does GA4 Use Cookies?
Yes. GA4 sets _ga and _ga_<container-id> by default. Each lasts two years. When you link GA4 to Google Ads, the tag sets additional cookies.
Can You Use Google Analytics Without Cookies?
Partly. Google states that its tag does not require cookies to send data. Without cookies, though, GA4 cannot recognise returning users.
GA4 Cookieless Tracking and Consent Mode
Consent Mode offers a second route. When visitors deny consent, tags send cookieless pings. Google describes these pings as events with coarse dimensions that cannot directly identify an individual. Google Analytics then uses them for behavioral and conversion modeling.
Three limits apply. Google says Consent Mode does not provide a banner, so you still run one. The data from denied visitors arrives as modeled estimates. The data still goes to Google.
If you want measured data with no consent step, a tool built without cookies fits better. See Ciphera's guide to moving off Google Analytics.
Difference Between Cookieless Tracking and Consent-Based Analytics
| Consent-based analytics (for example GA4 with a banner) | Cookieless analytics (for example Pulse) | |
|---|---|---|
| Data stored on device | Cookies, such as _ga and _ga_<id> | No cookie and no persistent identifier |
| Consent step | Banner required before measurement | Designed to need none. Confirm for your site |
| Visitors counted | Visitors who accept, plus modeled estimates | Every visit the tool receives |
| Identity | Recognises returning users, up to the cookie lifespan | Short-lived. One calendar month in Pulse |
| Data type | Measured plus modeled | Measured |
| Ongoing upkeep | Keep banner and consent signals correct | Minimal. Nothing to configure |
How Ciphera Pulse Provides Cookieless Analytics
Pulse is privacy-first web analytics from Ciphera, hosted in Switzerland. It sets no cookie. It also stores nothing about an individual visitor.
What Pulse Collects
The script sends one anonymous event per pageview. The event holds the page path, referrer, device type, browser, and country. Pulse resolves the country from the IP address at the moment of the request. It never stores the IP.
How Pulse Counts Visits and Visitors
The server derives two hashes:
- A salted session hash rotates daily and ties pageviews into one visit.
- A visitor hash rotates monthly and removes duplicate visitors within the month.
Both stay on the server and follow your site's own calendar. The browser holds no identifier. The only client-side item is a five-second sessionStorage guard that prevents double counting on a refresh. Pulse never sends it, and the tab wipes it.
Pulse does not use fingerprinting. A returning visitor counts once per calendar month, and then the key rotates away.
What You Get in One Dashboard
Most privacy tools show pageviews and little else. Pulse adds more:
- Traffic reports: visitors, pageviews, pages per visit, bounce rate, engaged visit duration, referrers, channels, UTM campaigns, and scroll depth
- Funnels, journeys, custom events, and revenue attribution
- Uptime monitoring with incident history, and page speed monitoring
- Google Search Console, Bing Webmaster Tools, and Bunny CDN data
- A public read API, an open-source CLI, a WordPress plugin, and CSV export
Every feature runs on every plan, including the free one. The free plan covers one site and 5,000 pageviews a month with no credit card. Paid plans start at €7 a month for 10,000 pageviews. See Pulse pricing.
Script Size
On 8 September 2026, Ciphera measured the Pulse tracker at 2,700 bytes gzipped. Google's gtag.js measured 148,504 bytes gzipped. That makes the Pulse tracker 55 times smaller. Plausible's script (1,283 bytes) and Fathom's (2,090 bytes) are smaller than Pulse's. Pulse does not claim the smallest script.
Swiss Hosting and EU Adequacy
Pulse runs on infrastructure in Switzerland. The European Commission granted Switzerland an adequacy decision on 26 July 2000, and a review published on 15 January 2024 maintained it. For an EU customer, sending data to Switzerland is not a restricted transfer. Swiss hosting also keeps the data outside US jurisdiction.
Verify It Yourself
You can inspect Pulse without signing up. The dashboard for ciphera.net is public at the Pulse live demo, including the slow weeks. The dashboard and tracker are open source under AGPL on GitHub. A shared dashboard also never shows a breakdown row with fewer than five visitors.
Who Pulse Suits and Who It Does Not
Pulse suits SaaS founders, agencies, and small and mid-sized businesses in the EU and Switzerland that want one dashboard and no consent setup. It is a weaker fit for these cases:
- Enterprises that run GA4 with BigQuery and Looker for custom attribution
- Teams that need session recording or heatmaps
- Mobile-native apps, because Pulse has no iOS or Android SDK
- Teams that must follow one person across devices
- US-only companies with no European exposure
The Accuracy Case for Cookieless Analytics
Accuracy depends on what you measure. Cookieless analytics counts more visits and recognises fewer people.
- More visits counted. Visitors who reject or ignore a banner still appear, because the tool needs no consent step to run.
- Measured, not modeled. Consent Mode fills gaps with estimates. A cookieless tool reports what it received.
- Less identity. A returning visitor counts once per calendar month in Pulse. A person on two devices counts twice.
Expect your numbers to differ from GA4. Run both tools for two to four weeks and compare trends, not exact totals.
No Consent Banner Required? What the Law Actually Says
The honest answer is that it depends on what your tools store and read on the visitor's device. Here is what applies.
The ePrivacy Rule Covers More Than Cookies
Article 5(3) of the ePrivacy Directive regulates storing or accessing information on a user's device. The EDPB's Guidelines 2/2023 explain which technical operations fall under it. The rule covers cookies, fingerprinting, and similar methods.
CNIL Allows a Narrow Exemption
France's regulator sets conditions for audience measurement that needs no consent. The conditions include a single purpose, which is measuring your own audience, and no reuse of the data by the provider for its own purposes. The CNIL also states that most large offerings fall outside the exemption regardless of how you configure them. It points to open-source software that you configure yourself, such as Matomo, as one route.
GDPR Applies When You Process Personal Data
An IP address usually counts as personal data. A tool that discards the IP and keeps no persistent identifier processes far less. That reduces your duties around lawful basis, retention, and deletion. Read Ciphera's GDPR analytics checklist for the full list.
What Pulse Claims and What It Does Not
Pulse sets no cookie and stores no persistent identifier on the device. It writes one five-second sessionStorage guard that never leaves the browser and identifies no one.
Whether your site still needs a banner depends on your country's rules and your other tools. Ad pixels, chat widgets, and embedded video can all require consent. Confirm your setup with your data protection officer or legal counsel. Ciphera's guide on cookie banners and analytics explains the reasoning in more depth.
Benefits of Cookieless Tracking for Marketers
Accuracy
You count every visit the tool receives. Your channel reports no longer depend on who clicked Accept.
Privacy-Friendly Analytics
Privacy-friendly analytics and privacy-focused analytics collect less and keep less. You hold less personal data, so you have less to protect, export, and delete.
Privacy and GDPR Regulations
A tool that stores no identifier and drops the IP address simplifies your GDPR work. You still document your setup and review it when rules change.
User Privacy Expectations
Visitors act on their privacy preferences when refusing is easy. In the Politecnico di Torino study, rejection rose from 3.49% to 20.56% once a Reject All button appeared. Cookieless analytics respects that preference without asking.
Speed and Simplicity
A 2.7 KB script adds far less weight than a 148 KB tag. You can also replace a consent platform and several monitoring tools with one dashboard.
Limitations of Cookieless Analytics
- No cross-device tracking. A person on a phone and a laptop may count twice.
- A short identity window. Pulse deduplicates visitors within one calendar month.
- No individual journeys over time. That limit is the privacy design, not a flaw.
- No session replay or heatmaps in Pulse. Ciphera does not plan to add them.
- No mobile app SDK. Pulse is web only.
- Narrower search data. Bing data in Pulse covers daily totals only, not query-level detail.
Some teams should keep GA4. Choose it if you run Google Ads, need the GA4 event model, or want free BigQuery export.
Types of Website Analytics
Cookieless tools mainly cover digital analytics. Some other types depend on identifying individuals, so they fit cookieless tools less well.
Attribution Analytics
Attribution analytics assigns credit for conversions to marketing touchpoints. Multi-touch models need to link visits from one person across sessions, which cookieless tools avoid. You can still get channel-level attribution from referrers, UTM campaigns, and revenue by source.
Digital Analytics
Digital analytics measures traffic and behavior across digital channels in aggregate. Cookieless analytics covers the web portion well. It reports pageviews, sources, devices, and conversions.
Product Analytics
Product analytics measures how logged-in users use features inside an app. It needs user IDs, so it sits outside cookieless web analytics. Many teams run a product analytics tool next to a cookieless one.
Frontend Analytics
Frontend analytics measures what happens in the browser, such as page speed, scroll depth, and errors. Pulse offers page speed monitoring and scroll depth without storing an identifier.
Unified Marketing Analytics
Unified marketing analytics combines data from ads, email, CRM, and web into one view. Pulse brings Search Console, Bing, and Bunny CDN data into one dashboard. It does not pull in ad platform or CRM data.
Data Enrichment Analytics
Data enrichment analytics adds outside attributes to visitor records, such as company or demographic details. It relies on identifying individuals or organisations. Privacy-first cookieless tools avoid this by design.
Which Metrics Should You Track?
Start with a small set. Five well-chosen metrics beat fifty ignored ones. Tools differ in how they define each metric, so read your tool's documentation.
Regular Metrics
Unique Users
Unique users are the distinct visitors in a period. Pulse deduplicates visitors within a calendar month.
Page Views
Page views are the total pages loaded. The tool counts each event.
Bounce Rate
Bounce rate is the share of visits that leave without further interaction. Pulse reports bounce rate.
Average Session Duration
Average session duration is the time visitors spend per visit. Pulse reports engaged visit duration.
Pages Per Session
Pages per session is the average number of pages in a visit. Pulse reports pages per visit.
Traffic Sources
Traffic sources show where visitors come from. Pulse reports referrers, channels, and UTM campaigns.
New Visitors
New visitors are people who have not visited before. Without a long-lived ID, tools can separate new from returning visitors only inside a short window. Check how your tool defines it.
Returning Visitors
Returning visitors are people who come back. In Pulse, a visitor who returns within the same calendar month counts once, not twice.
Custom Event Tracking
Custom events record named actions, such as signups, downloads, and purchases. Pulse supports custom events and revenue attribution.
Advanced Metrics
Segments describe groups of visitors, not individual people. Pulse also hides any breakdown row with fewer than five visitors in shared dashboards.
Visitor Segments
Visitor segments group traffic by attributes such as country, device, and browser. Pulse breaks traffic down by all three.
Traffic Source Segments
Traffic source segments compare channels, referrers, and campaigns. Use them to see which sources bring engaged visitors.
Conversion Segments
Conversion segments show which groups complete a goal. In Pulse, you build funnels and track custom events and revenue to see this.
Cookieless Tracking Tools and Platforms: What to Look For
Questions to Ask Each Vendor
- Does the script set a cookie or write to local storage?
- Does the tool store IP addresses?
- Where does the vendor host and process the data?
- Can you inspect the code or a live demo?
- Can you export your data on every plan?
- What does the tool not measure?
Cookieless Analytics Platforms Compared
These notes reflect Ciphera's own comparison pages. Check each vendor's current documentation before you buy.
| Tool | Cookie approach | Best when |
|---|---|---|
| Ciphera Pulse | No cookie | You want traffic, uptime, page speed, and Search Console in one dashboard with Swiss hosting |
| Google Analytics 4 | _ga and _ga_<id> by default | You run Google Ads or need the GA4 event model and BigQuery export |
| Plausible | Cookieless by design | You want a long track record, a larger community, or a supported self-hosted edition |
| Fathom | Cookieless by design | You want a proven, done-for-you product with a longer history |
| Matomo | Cookieless by configuration | You must self-host or need heatmaps, session recording, or A/B testing |
| Simple Analytics | Cookieless by design | You want privacy-first traffic reporting with a similar posture to Pulse |
| Umami | Cookieless by design | Your budget is zero and you can run it yourself |
How to Respect Privacy and Get Rid of Cookie Consent Banners
- Audit your cookies. Open your browser's developer tools and list what your site stores.
- Choose a cookieless tool. Use the questions above.
- Add the script. Pulse needs one line of HTML. See the installation guide.
- Run both tools for two to four weeks. Compare trends, not exact totals. Expect your old tool to undercount visitors who rejected consent.
- Update your privacy policy. Remove the banner only after you confirm that no other tool needs consent.
Try the cookie banner loss calculator to estimate how much data your banner costs you today.
Respect User Privacy with Cookieless Analytics: Start Free with Pulse
You can see how cookieless analytics performs before you commit. Open the live Pulse demo and read ciphera.net's real traffic with no login.
Then add one line of HTML to your site. Your first pageview appears within seconds. The free plan covers one site and 5,000 pageviews a month, includes every feature, and needs no credit card.
See related guide at ciphera.net
FAQ
Frequently Asked Questions
Related Articles
Get started
Put this into practice.
Ciphera builds privacy-first infrastructure — analytics, identity, bot protection, and email that don’t surveil. The tools this article describes are the ones we run.


