What we never collect.
Rialto is analytics for sites that respect their visitors. This page says exactly what is recorded and what is impossible by construction.
Everything counts, nobody is remembered
The full product works without any cookie. A click, a scroll depth and a reading time all happen inside one visit and are sent as they happen. One visit holds together through a value in tab memory that dies with the tab. Counting different people uses a hash regenerated every day, so it cannot recognise anyone tomorrow and cannot be reversed into a person.
One cookie, one purpose
With consent, Rialto sets a single first-party cookie so the same browser is recognisable across days. That is what makes returning-visitor counts and multi-day attribution possible. The cookie holds a random value with nothing personal in it, salted and hashed before storage, so the database never contains the value in your browser. Consent comes from the site's own consent tool where one exists - Rialto detects it and obeys - or from Rialto's own small banner.
- Pageviews, with the page title
- Clicks, with the element's visible label
- Scroll depth marks, active seconds against idle
- The referring website's hostname only
- Country and city at Cloudflare's coarse level
- Custom events a site defines itself
- IP addresses stored
- Fingerprinting of any kind
- Tracking across other websites
- Form contents, keystrokes, session replay
- Advertising use of any kind
- Referrer paths - stripped to the hostname before storage
Where it runs
Rialto runs on Cloudflare Workers with data held in Cloudflare D1. Raw events are pruned after 400 days. Site owners can export their data as CSV at any time.
The result
The anonymous layer requires no consent under GDPR, CCPA or PECR, so the numbers are complete even where banners are law. The identity cookie is set only with consent, obtained through the site's consent tool or ours. That split is deliberate: measurement that respects the no, and memory only after the yes.