# HitKeep > HitKeep is privacy-first web analytics for managed cloud and self-hosted deployments. You can self-host it as a single Go binary with zero external service dependencies, or run it in HitKeep Cloud in EU or US regions. Current Linux release binaries are about 100 MB. Data lives in DuckDB and can be exported in open formats such as JSON, CSV, Parquet, NDJSON, and XLSX where the product surface supports them. Linux release binaries target a modern glibc baseline. HitKeep is for DevOps engineers, developers, and privacy-conscious site owners who want analytics ownership without running PostgreSQL, Redis, Kafka, ClickHouse, or a separate queue. The tracking snippet (`hk.js`) is cookie-less by default, respects Do Not Track when enabled, can automatically emit `outbound_click`, `file_download`, and `form_submit` events, stores derived city/provider/ASN metadata without storing raw visitor IP addresses, and keeps Web Vitals collection in an opt-in same-origin split bundle. The first-party WordPress plugin installs the same tracker and automatic-event defaults without adding a separate analytics vendor. Current stable release: HitKeep 2.9.0, published on July 4, 2026. It adds the experimental Ask AI dashboard assistant, a new multi-site overview, ECharts-based analytics charts, expanded report range presets, hosted cloud setup polish, and a round of dashboard fixes. HitKeep 2.8.1 fixed password settings validation, the breadcrumbs scrollbar, Google Search Console timezone test coverage, Portuguese translations, and missing QR code labels. This file is a compact navigation map for HitKeep MCP/docs clients. It is not required for Google Search, AI Overviews, or AI Mode; the HTML docs are the public pages readers should use first. ## Start Here - [Introduction](/guides/introduction/): Product model, single-binary philosophy, and feature summary. - [HitKeep Cloud](/cloud): Managed EU or US cloud hosting and region selection. - [Installation](/guides/installation/): Choose binary, Docker Compose, or Kubernetes and Helm deployment. - [Configuration Reference](/reference/configuration/): Flags and environment variables. - [Public Roadmap](/support/roadmap/): Recently shipped work, target buckets, and the live GitHub Projects release-bucket view. ## Install And Operate - [Binary Installation](/guides/installation/binary/): Run HitKeep on bare metal, a VM, VPS, or Raspberry Pi. - [Docker Compose](/guides/installation/docker-compose/): Compose setup with persistent storage and reverse proxy examples. - [Kubernetes and Helm](/guides/installation/kubernetes/): Official OCI Helm chart, StatefulSet manifest fallback, persistent paths, and upgrade guidance. - [Trusted Proxies](/guides/installation/trusted-proxies/): Configure real client IP resolution behind proxies. - [Backups and Restore](/guides/data/backups-and-restore/): Single-tenant and multiteam backup strategies. - [S3 Backups](/guides/data/s3-backups/): AWS S3, MinIO, Cloudflare R2, and Backblaze B2 backup configuration. - [Data Retention and Archiving](/guides/data/retention/): Raw data retention and Parquet archive behavior. - [Disaster Recovery](/guides/data/disaster-recovery/): Recovery planning and restore checks. - [Open Exports and Takeout](/guides/data/takeout/): JSON, CSV, Parquet, NDJSON, and XLSX export paths. ## Track Data - [Tracker Architecture](/guides/tracking/tracker-architecture/): How `hk.js` sends pageviews and events. - [Automatic Events](/guides/tracking/automatic-events/): Outbound click, file download, and form submission tracking. - [Custom Events](/guides/tracking/custom-events/): Browser and server-side custom event tracking. - [Server-Side Tracking](/guides/tracking/server-side-tracking/): Trusted pageviews and events with caller-provided timestamps. - [UTM Parameters](/guides/tracking/utm-parameters/): Campaign attribution and UTM builder behavior. - [QR Campaigns](/guides/tracking/qr-campaigns/): Dynamic QR campaign redirects, UTM attribution, print exports, QR-only share links, and QR-scoped analytics. - [IP Exclusions](/guides/tracking/ip-exclusions/): Filter own traffic and known bots. - [Bot and Spam Filtering](/guides/tracking/spam-filtering/): Referrer spam, abuse networks, and hostname filtering. - [AI Fetch on AWS](/guides/tracking/ai-fetch-aws/): Collect AI crawler fetches from CloudFront or AWS edge logs. - [CloudFront AI Crawler Tracking](/guides/tracking/cloudfront-ai-crawler-tracking/): Campaign guide for AI crawler log forwarding. - [Track GPTBot and ClaudeBot](/guides/tracking/track-gptbot-claudebot-perplexity/): Campaign guide for common AI crawler user agents. ## Analyze - [Period-over-Period Comparison](/guides/analytics/comparison/): Prior-period overlays and KPI deltas. - [Event Analytics](/guides/analytics/events/): Event timeseries, property breakdowns, and audience segmentation. - [Goals](/guides/analytics/goals/): Path-based and event-based conversion tracking. - [Funnels](/guides/analytics/funnels/): Multi-step conversion funnel analytics. - [Ecommerce Analytics](/guides/analytics/ecommerce/): Revenue, orders, products, source reporting, and checkout metrics. - [AI Visibility Analytics](/guides/analytics/ai-visibility/): AI crawler fetches, AI-referred visits, and correlation context. - [AI Chatbot Analytics](/guides/analytics/ai-chatbot-analytics/): Conversations, prompts, citations, handoffs, and assisted conversions. - [Ask AI Analytics Assistant](/guides/analytics/ask-ai/): Optional dashboard-session assistant for site-scoped analytics questions, streamed answers, citations, charts, and safe dashboard actions. - [Web Vitals Analytics](/guides/analytics/web-vitals/): Opt-in p75 LCP, INP, CLS, FCP, and TTFB reporting, rating distribution, path breakdowns, and browser, country, language, and device context. - [Opportunity Recommendations](/guides/analytics/opportunities/): Saved evidence-backed recommendations from deterministic detectors, with optional AI enrichment limited to cited aggregate evidence and localization-safe keys. - [AI Visibility Reporting Template](/guides/analytics/ai-seo-reporting-template/): Report structure for AI visibility work. - [Shareable Dashboards](/guides/sharing/dashboard-links/): Read-only share links for clients, stakeholders, or public dashboards. - [Email Reports](/guides/notifications/email-reports/): Weekly digest and per-site email reports. ## Migrate And Integrate - [Migrate to HitKeep](/guides/migration/): Choose the right migration path for history, live tracking, and exports. - [Import Plausible](/guides/data/import-plausible/): Import historical Plausible aggregate analytics. - [Import Simple Analytics](/guides/data/import-simple-analytics/): Import the Simple Analytics All CSV datapoints file. - [Google Search Console](/guides/integrations/google-search-console/): Import finalized Search Analytics aggregates and show authenticated drilldowns. - [WordPress Integration](/guides/integrations/wordpress/): First-party WordPress plugin for `hk.js` and automatic events. - [Official MCP Server](/guides/integrations/mcp/): Optional leader-only read-only analytics MCP route, listed in the official MCP Registry as `io.github.PascaleBeier/hitkeep`. - [Read-only MCP Server for Web Analytics](/use-cases/read-only-mcp-server-web-analytics/): Tool-surface overview for aggregate traffic, events, ecommerce, Search Console, Web Vitals, AI crawler analytics, screenshots, and the MCP permission boundary. - [HitKeep Agent Skills](/guides/integrations/hitkeep-agent-skills/): Official Agent Skills for scoped HitKeep analytics questions through MCP and dashboard localization work. - [AI Development With HitKeep](/guides/integrations/ai-development/): Choose between MCP, Agent Skills, REST API, dashboard workflows, exports, optional AI model configuration, and the public i18n skill for AI-assisted HitKeep development. ## Admin And Security - [Teams and Data Isolation](/guides/admin/teams/): Team organization and per-team DuckDB data-plane isolation. - [Roles and Permissions](/guides/admin/permissions/): Instance, team, and site-level access control. - [System Status and Settings](/guides/admin/system-administration/): Health, storage, workers, mail, spam filtering, and audit visibility. - [AI Model Configuration](/guides/admin/ai-model-configuration/): Optional AI model setup for self-hosted deployments, HitKeep route and budget env vars, goAI provider credential env vars, status fields, and audit boundaries. - [API Clients](/guides/security/api-clients/): Personal and team-owned bearer tokens for programmatic access. - [Two-Factor Authentication](/guides/security/two-factor-authentication/): TOTP and WebAuthn setup. - [Account Recovery](/guides/security/recovery/): Recovery codes, owner MFA reset, and CLI break-glass recovery. - [Verifying Artifacts](/guides/security/verify-artifacts/): Cryptographic verification for binaries and Docker images. ## Reference And API - [Architecture](/reference/architecture/): DuckDB, embedded NSQ, clustering, tenancy, and frontend stack. - [Facts and Limits](/reference/facts-and-limits/): Runtime facts, about 100 MB binary size, memory use, storage boundaries, privacy behavior, exports, MCP limits, and non-goals. - [Configuration Reference](/reference/configuration/): CLI flags and environment variables, including AI model configuration fields and local token budgets. - [Security Overview](/reference/security/): Zero third-party frontend requests, no telemetry, JWT cookies, WebAuthn, and rate limiting. - [Tech Stack](/reference/tech-stack/): Dependency list and target operator/developer audiences. - [REST API](/api/): Generated OpenAPI documentation for HitKeep endpoints. ## Compliance - [Compliance Overview](/compliance/overview/): Product capabilities and deployment caveats for privacy compliance. - [GDPR](/compliance/gdpr/): GDPR-oriented deployment guidance. - [PECR and ePrivacy](/compliance/pecr-eprivacy/): Cookie and device-storage guidance. - [CCPA and CPRA](/compliance/ccpa-cpra/): California privacy-law guidance. - [Digital Sovereignty](/compliance/sovereignty/): Data residency, EU-first design, and jurisdictional control. ## Use Cases Use these pages for adoption, positioning, and search-oriented questions after checking the task guides above. - [Use Cases](/use-cases/): Entry point for privacy-first analytics, managed cloud, self-hosting, WordPress, AI visibility, ecommerce, and conversion reporting. - [Open-Source Sovereign Web Analytics](/use-cases/open-source-sovereign-web-analytics/) - [Privacy-First Web Analytics](/use-cases/privacy-first-web-analytics/) - [Managed EU or US Cloud Analytics](/use-cases/cloud-analytics-eu-us/) - [Single-Binary Self-Hosted Analytics](/use-cases/self-hosted-analytics-single-binary/) - [Self-Hosted GA4 Alternative](/use-cases/self-hosted-ga4-alternative/) - [Google Analytics Alternative for WordPress](/use-cases/google-analytics-alternative-wordpress/) - [WordPress Privacy Analytics](/use-cases/wordpress-analytics/) - [AI Visibility Analytics](/use-cases/ai-visibility-analytics/) - [Read-only MCP Server for Web Analytics](/use-cases/read-only-mcp-server-web-analytics/) - [Ecommerce and Conversion Analytics](/use-cases/ecommerce-conversion-analytics/) - [Cookieless Event Tracking](/use-cases/cookieless-event-tracking/) ## Comparisons Use comparison pages for migration and vendor-evaluation questions. Check visible source notes and reviewed dates on each page before quoting competitor facts. - [HitKeep vs Google Analytics (GA4)](/vs/google-analytics/) - [HitKeep vs Plausible Analytics](/vs/plausible/) - [HitKeep vs Umami](/vs/umami/) - [HitKeep vs Matomo](/vs/matomo/) - [HitKeep vs Fathom Analytics](/vs/fathom/) - [HitKeep vs Simple Analytics](/vs/simple-analytics/) - [HitKeep vs Cloudflare Web Analytics](/vs/cloudflare-web-analytics/) - [HitKeep vs PostHog](/vs/posthog/) - [HitKeep vs GoatCounter](/vs/goatcounter/) - [HitKeep vs Pirsch Analytics](/vs/pirsch/) - [HitKeep vs Piwik PRO](/vs/piwik-pro/) - [HitKeep vs Adobe Analytics](/vs/adobe-analytics/) - [HitKeep vs Rybbit](/vs/rybbit/) - [HitKeep vs Offen](/vs/offen/) - [HitKeep vs Vince](/vs/vince/) - [HitKeep vs Clamp](/vs/clamp/) ## Release And Project - [Changelog](/changelog/): Release history and shipped changes. - [HitKeep 2.9.0](/blog/hitkeep-2-9-0/): Release post for experimental Ask AI, the new overview page, ECharts charts, expanded report ranges, hosted cloud setup polish, and dashboard fixes. - [HitKeep 2.8.1](/changelog/version/v2-8-1/): Patch changelog entry for password settings validation, breadcrumbs scrollbar behavior, Google Search Console timezone tests, Portuguese translations, and QR code labels. - [HitKeep 2.8.0](/blog/hitkeep-2-8-0/): Release post for QR campaigns, Portuguese dashboard localization, AI assistant enablement through MCP and Agent Skills, public AI contributor guidance, and GoAI structured-output validation coverage. - [HitKeep 2.7.0](/blog/hitkeep-2-7-0/): Release post for faster realtime analytics refreshes, Angular 22, Go 1.26.4, AI fetch ingest, and internal API semver boundaries. - [HitKeep 2.6.1](/blog/hitkeep-2-6-1/): Maintenance release post for Web Vitals metric identity, dashboard site selectors, dependency updates, refreshed IP metadata, and MCP registry metadata. - [HitKeep 2.6.0](/blog/hitkeep-2-6-0/): Release post for city/provider/ASN analytics, embedded IP metadata, tabbed metric cards, Opportunities evidence, MCP aggregates, takeout, retention, and IP2Location attribution. - [HitKeep 2.5.1](/blog/hitkeep-2-5-1/): Patch release post for the dashboard refresh, clearer API-client site grants, token rotation, shared Web Vitals reports, and stale AI provider warning cleanup. - [HitKeep 2.5.0](/blog/hitkeep-2-5-0/): Release post for opt-in Web Vitals analytics, evidence-backed Opportunity Recommendations, optional AI model configuration, and Web Vitals MCP aggregates. - [HitKeep 2.4.2](/blog/hitkeep-2-4-2/): Patch release post for the site export dropdown fix. - [HitKeep 2.4.1](/blog/hitkeep-2-4-1/): Patch release post for MCP reverse-proxy reliability and Go 1.26.3 security fixes. - [HitKeep 2.4.0](/blog/hitkeep-2-4-0/): Imports, Search Console, MCP reporting, server-side ingest, and Dutch localization. - [Public Roadmap](/support/roadmap/): Public release buckets. The live bucket board is tracked in GitHub Projects. - [Blog](/blog/): Release posts with screenshots and upgrade context. - [Getting Help](/support/help/): Bug reports, feature requests, and support options. - [Contributing](/guides/contributing/): Contribution workflow. - [Localizing the UI](/guides/localization/): Dashboard translation workflow. - [Supporting HitKeep](/support/funding/): Funding and sponsorship options. Public release buckets: https://github.com/users/PascaleBeier/projects/1 ## Security Properties - Zero third-party frontend requests from self-hosted dashboards. Assets are served from the user's instance. - No telemetry, phone-home, or external license validation. - Favicon images are proxied server-side via DuckDuckGo. Browsers do not request third-party favicon URLs directly. - Air-gap compatible when deployment choices avoid outbound services such as SMTP or managed cloud integrations. - JWT sessions use HTTP-only cookies. - WebAuthn / FIDO2 passkeys and TOTP 2FA are supported. - Recovery codes provide MFA fallback. - Sec-Fetch validation protects state-changing requests. - Token bucket rate limiting covers public and login endpoints. - Cookie-free public tracking is the default, but PECR / ePrivacy analysis still depends on deployment and jurisdiction because browser storage behavior matters. ## Technical Facts - Language: Go 1.26+ - Binary size: About 100 MB for current Linux release binaries. - Cloud memory: Recent HitKeep Cloud checks showed about 205-769 MiB of memory use. Treat this as a practical reference point, not a sizing guarantee. - Database: Embedded DuckDB v2.5, one file per tenant data plane. - Queue: Embedded NSQ v1.3, in process and loopback only. - Ingest: Batch DuckDB appender for pageviews and events. - Clustering: HashiCorp Memberlist. - Frontend: Angular 22, PrimeNG 21, Tailwind CSS 4, and ECharts for dashboard charts. - Tracking snippet: esbuild-compiled `hk.js`; the public tracker is cookie-less by default, uses `sessionStorage` for session continuity, respects DNT unless explicitly configured otherwise, and keeps Web Vitals in opt-in same-origin `hk-vitals.js` disabled by default. - Automatic events: `outbound_click`, `file_download`, and `form_submit`. Query strings, hashes, link text, form fields, and request bodies are excluded. - QR campaigns: Dynamic `/q/{token}` redirects can add UTM fields, custom query parameters, and `hk_qr` attribution, with QR opens, QR-filtered analytics, SVG/PNG artwork exports, QR-only share links, and open export formats. - Exports: JSON, CSV, Parquet, NDJSON, and XLSX where the product surface supports them. Retention archives and backup snapshots use Parquet-backed DuckDB export flows. - Optional MCP: leader-only Streamable HTTP route at `/mcp`, disabled by default, bearer API client tokens only, read-only MCP aggregate analytics, Web Vitals aggregates, and docs tools. MCP is listed in the official MCP Registry as `io.github.PascaleBeier/hitkeep`, does not accept dashboard cookies, and does not expose write workflows. - AI development surfaces: MCP for aggregate assistant reads, Agent Skills for assistant guidance and dashboard localization, REST API for normal automation, dashboard for human setup and review, open exports/takeout for portable files, and optional AI model configuration for validated product features. - Non-replacements: HitKeep does not replace Google Ads attribution, GA4 Explorations, app analytics, session replay, feature flags, experimentation, a CMP, a SIEM, a CRM, or a warehouse used as the system of record. - IP geolocation: embedded compressed IP2Location LITE-derived lookup assets. No external geolocation API or runtime metadata download. - Localization: English, German, Spanish, French, Italian, Dutch, and Portuguese. - License: MIT. - Source: https://github.com/pascalebeier/hitkeep ## Contact - Maintainer: Pascale Beier - Email: mail@pascalebeier.de - Website: https://pascalebeier.de