惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
腾讯CDC
Recent Announcements
Recent Announcements
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Hugging Face - Blog
Hugging Face - Blog
H
Help Net Security
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Last Week in AI
Last Week in AI
博客园_首页
D
DataBreaches.Net
P
Proofpoint News Feed
云风的 BLOG
云风的 BLOG
V
Visual Studio Blog
月光博客
月光博客
Jina AI
Jina AI
Stack Overflow Blog
Stack Overflow Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
Vercel News
Vercel News
WordPress大学
WordPress大学
J
Java Code Geeks
博客园 - 聂微东
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
U
Unit 42

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
I Built a 2.8KB Cookieless Analytics Tool After Google An...
Azaan Ali Raza · 2026-06-24 · via DEV Community
Cover image for I Built a 2.8KB Cookieless Analytics Tool After Google Analytics Hid 35% of My Traffic

Azaan Ali Raza

Last month my Next.js SaaS showed 1,200 visitors in Google Analytics.

AmazeMatrix showed 1,847.

That's 35% of my traffic GA simply missed because of ad blockers and cookie consent rejections. I am 20, building from Meerut, and I was making product decisions on broken data.

So I deleted GA and built my own.

The problem
I launched AmazeMatrix in early 2026 with GA4 installed. Three things broke immediately:

The cookie banner killed UX. 60% of Indian users clicked "Reject". My bounce rate jumped.
Ad blockers ate my data. Over 40% of internet users run blockers that kill analytics cookies by default.
Speed. GA's script was 45KB. My LCP went from 1.9s to 3.1s on mobile.
I tried the privacy tools everyone recommends:

Plausible — $9/mo, super clean, but no heatmaps, no Core Web Vitals
Fathom — $15/mo, managed, but no AI insights, no India pricing
OpenPanel — $2.50/mo, great product analytics, but I still needed timeline annotations for deploys
I didn't want 4 tools. I wanted one lightweight snippet that gave me traffic, speed, and why things changed.

Investigation: how cookieless actually works
I spent a week reading how the good ones do it. Three patterns:

  1. No persistent cookies. Instead of storing an ID for months, you generate a daily rotating hash from IP + user agent + salt that changes every 24h. You can count uniques today, but you can't track someone forever.

  2. Server-side or edge capture. If the browser never sets a cookie, ad blockers have nothing to block.

  3. Relative coordinates for heatmaps. Instead of sending screenshots (heavy), you send x/y as percentages of the element. That's under 0.2KB per click.

That was the blueprint.

Solution: I built AmazeMatrix
Tech stack I chose because I live in Next.js 16:

Frontend: Next.js App Router, Tailwind, Framer Motion
Edge: Cloudflare Workers / Vercel Edge
DB: Neon Postgres + Drizzle ORM
Auth: Better Auth
AI: Gemini SDK
Billing: Razorpay (because Stripe doesn't work for most Indian founders)
The entire snippet is 2.8KB gzipped:

3 lessons I learned building privacy analytics

  1. Don't fingerprint, rotate.
    I first tried a persistent hash. It felt creepy and broke privacy laws. Daily rotating hash gives me accurate daily uniques without storing PII. Privacy-first is not a marketing line, it's an architecture choice.

  2. Heatmaps don't need images.
    Everyone sends full-page screenshots. I send {x: 0.42, y: 0.18, el: '#pricing'}. That's 18 bytes. Multiply by 10k clicks and you save megabytes.

  3. Founders don't want another dashboard, they want answers.
    The most used feature is not the graph. It's the AI chat. "How is page speed affecting sales?" gets more clicks than any chart.

How you can try it
I kept it stupid simple:

Sign up, get siteId
Paste 2 lines
See data in 10 seconds
Free for first 7 days

I'm building in public on X and Threads as [@razavi_azaan]. If you want the self-host Docker compose, comment "self-host" and I'll DM it.