Privacy first, by default.

You can delete your cookie banner tonight.
Not after a legal review. Not next quarter. Tonight.
If that sounds like a stretch, it's because you've quietly accepted something you were never supposed to accept in the first place.
The banner isn't the safeguard
Nobody has ever clicked "Accept All" because they wanted to. They click it the way you slap an alarm clock. Half awake, annoyed, wanting the thing to stop. We built a whole compliance industry around a button that no human being on earth actually reads.
The banner isn't consent. It's a toll booth on your own website that you pay for and your visitors resent.
Here's my admission, and it isn't flattering. I've spent years around API management and identity systems. The paranoid end of software, where people argue about token lifetimes and tenant isolation for a living. And for most of that time I couldn't have told you what my own analytics tool was storing about the people visiting my sites. I had a banner. I assumed the banner meant I was covered.
The banner is the confession that you're doing something that needs one.
Read this one properly. The useful part is near the end and you'll want it the next time someone asks you a question about your data that you can't answer.
Collection debt
Every row you store about a stranger is debt. Not metaphor debt. Real debt with real interest. Storage you pay for every month. A breach surface that grows while you sleep. A data subject request you'll answer by hand on a Friday afternoon. A processing agreement you have to keep current forever. A regulator's question that takes you three weeks to answer badly.
Bruce Schneier called it years ago when he said data is a toxic asset. He was right and almost nobody acted on it.
The interest on collection debt compounds quietly. You only find out the balance on the worst day of your quarter.
Most teams think they're building a data advantage. They're building a liability with a dashboard on top of it.
The Discard Test
The question isn't "are we compliant." Compliance asks whether you have permission to hold something. That's the wrong question and it's why the banner exists at all.
The better question is what you can throw away and still answer the thing you actually wanted to know. We call it the Discard Test, and it's five questions long.
Can you use it and then drop it?
We need a visitor's IP address to tell you which country your traffic comes from. There's no way around that. So we use it for a moment and then it's gone. The raw IP goes through HMAC-SHA256 with a secret that never leaves our infrastructure. At the same time it goes to a geo provider on an EU only endpoint to resolve an approximate city. Then it's dropped.
There's no column for a raw IP anywhere in our database. Not redacted. Not encrypted. Absent. We don't keep access logs that would contain it either, because that's the usual back door where IPs survive after everyone swore they deleted them.
Can you measure without identifying?
Clerion can tell you a form was interacted with and which fields someone touched. It never reads what they typed. Not because we promise not to. Because the code that watches forms doesn't look at values at all.
So "email address" shows up in your funnel. The email itself never leaves the page.
Can you resist the clever trick?
This is the one the industry fails. When cookies go away, the instinct is to rebuild identity some other way. Canvas fingerprinting. Font enumeration. All the quiet techniques that reassemble a person after you've told everyone you stopped tracking them.
We don't do any of it. Session identity is a random token that lives in the tab and dies when the tab closes. It isn't readable by other tabs. It expires after thirty minutes of inactivity. A persistent visitor ID exists only if someone has actually consented, and it's gated in the code rather than in the policy. No consent, the function returns nothing and no ID is created.
Can you let it expire?
Data you keep forever turns into a liability eventually. So a purge job runs every day and deletes events past your plan's retention window. Thirty days at the bottom. Around two years at the top. The code that does it cites the storage limitation rule in GDPR, which says you don't keep personal data longer than the purpose needs.
Inside the product this shows up as one small piece of honesty. On the activity view there's a horizon line marking the days that have been purged, with a note that reads "This day has been let go."
I like that line more than I should. It's the whole philosophy in five words.
Can you obey a signal you were never forced to obey?
If a browser announces Global Privacy Control or Do Not Track, Clerion stops before anything else runs. No events queued. Nothing sent to our servers. It's the first check in the script, ahead of the consent logic, ahead of everything.
GPC is legally required under CCPA and Colorado's privacy law. We honour it everywhere, for every visitor, regardless of where they live, because writing a geographic exception into that check would tell you exactly what kind of company we are.
That's the test. Use it and discard it. Measure without identifying. Refuse the clever trick. Let it expire. Obey the signal.
The tradeoffs, unrounded
If you're somewhere between "I installed GA4 in 2019 and never opened the settings" and "I have a compliance folder I've genuinely never read," this section is for you specifically.
Every privacy page on the internet rounds its edges. Here are ours.
Cookieless means we lose returning visitors
We cannot tell a returning visitor from a new one across separate visits. That's a real loss and I'm not going to pretend otherwise. If you need cross visit identity you turn on consent mode, and only then, only after the visitor opts in, does anything persistent get written to their device.
Unique visitors are an estimate
We count distinct hashed IPs. Two people in the same office share an address, so they count as one. The hash doesn't rotate, so the same address maps to the same value for the life of the deployment. It's a directional number, not an exact one. We think that's the right trade for a metric meant to guide decisions rather than bill anyone, but it's a trade and you should know which side of it we picked.
We store the text of clicked elements
Capped at a hundred characters. Combined with a path and a referrer, that's more identifying than the word anonymous suggests. Which is exactly why our docs tell site owners not to put personal data into button labels.
What the AI layer actually sees
Clerion's briefings run on Claude, and Claude never sees an individual event row. It gets pre aggregated numbers built by our own queries. Counts, percentages, ranked lists, time series. No IP hashes. No session IDs. No visitor IDs. Geography gets cut down to country level before it leaves, so city and network operator stay in the EU database and go nowhere near a model.
Anyone who won't tell you their tradeoffs doesn't have fewer of them. They have the same ones, unlabelled.
I write about this sort of thing most weeks over at getclerion.com/writing, if that's your kind of reading.
The ten minute audit
Tonight, open your analytics vendor's documentation. Not the marketing page. The docs. Then answer seven questions. This is an engineering audit rather than legal advice, and it'll still tell you more than your last compliance review did.
Where is the raw IP stored and for how long?
The good answer is nowhere, discarded after use.
What identifier gets written to the visitor's device by default?
The good answer is none.
If you switch the banner off tomorrow, what breaks?
The good answer is cross visit identity and nothing else.
Does the script check GPC and DNT before it does anything at all?
The good answer is yes, first, no geographic exceptions.
What happens to data older than your retention window?
The good answer is that something deletes it on a schedule you can name out loud.
Which fields could possibly contain something a person typed?
The good answer is none. Field names yes, values never.
If a regulator asks for everything you hold about one person, can you find it?
The good answer is that you architecturally can't link rows to a person, and you can explain why in one paragraph without a lawyer in the room.
Seven questions. Ten minutes. If your vendor needs a sales call to answer yes or no seven times, they've already answered them.
The houseguest
Stop thinking about analytics as a telescope. Think about it as a houseguest.
A bad houseguest photographs your rooms while you're out. Keeps a copy of your mail. Mentions your habits to people you've never met. Stays long after you stopped needing them there.
A good one notices you're low on coffee, tells you on the way out, and leaves nothing behind.
You don't need a consent form for a good houseguest. You need one for the other kind.
What privacy first actually means
None of this makes the analytics worse, which is the part people don't believe until they try it. You still see your traffic, your sources, your popular pages, where people leave. What you don't get is a pile of personal data you never wanted to be responsible for. What your visitors don't get is a banner asking permission for something that isn't happening.
Not a badge on a marketing page. A set of decisions in the code, with the tradeoffs left where you can see them.
Delete the banner. Pay off the debt. Let the days go.