Back to Tools
Glyphex logo

Glyphex

Partially Compliant

Finnish cookieless analytics on a sub-1KB script, hosted on Hetzner in Germany. No DPA is published, which is a problem for hosted use.

šŸ‡«šŸ‡®FinlandšŸ‡ŖšŸ‡ŗEU HostedšŸ‡ŖšŸ‡ŗ EuropeanFreemium
Glyphex website screenshot

GDPR Compliance Data

Not independently verified
GDPR Status
Partially Compliant
HQ CountryFinland
OwnershipEuropean-owned
Foreign Disclosure ExposureNot yet verified
Data Hosting Location
European Unionā€œAll data is stored on servers in the European Union. We use: Hetzner Cloud (Germany) for database storage and application hosting. No data transfers to non-EU countries.ā€
EU Servers Available
Data Processing AgreementNot verified
Sub-processor ListNot verified
Schrems II Risk
Low Risk
SCCs in Place
NotesFinnish origin is recorded on the information of this directory's owner, not from vendor documents: Glyphex publishes no imprint, legal entity, company registration or terms of service, and its footer reads only 'Ā© 2026 glyphex'. Treat ownership as attested rather than evidenced until an imprint appears. The technical privacy design is documented at /docs/privacy and is genuinely strong: no cookies, IP addresses used for geo-lookup then discarded, visitors counted via a SHA-256 hash of IP and User-Agent with a salt that rotates every 24 hours, and 'All data is stored on servers in the European Union ... Hetzner Cloud (Germany) ... No data transfers to non-EU countries'. What does not exist is a Data Processing Agreement. Whether that is a problem depends on a contested question: Glyphex's position is that it processes no personal data at all, and if that holds then it is not a processor, GDPR does not engage and no DPA is required. Plausible Analytics takes the same position and some supervisory authorities have accepted it. The opposing reading is that a salted hash of IP and User-Agent remains pseudonymised personal data, in which case Article 28(3) requires a written contract and none is available. That page is documentation rather than a legal document: it names no controller, no retention period, no sub-processors, no security measures, no breach procedure and no data subject rights process. Practically, many procurement and DPO processes require a signed DPA regardless of the legal argument, so buyers who need one should ask before committing. Recorded as PARTIAL to reflect the unresolved position, not as a compliance failure.

About Glyphex

Glyphex is a lightweight cookieless analytics tool built as a direct Google Analytics replacement, with a tracking script under 1 KB and no consent banner required. It identifies visitors by hashing IP and User-Agent with a daily-rotating salt, so nothing persistent is stored, and it reports traffic arriving from AI assistants. Data is stored on Hetzner Cloud in Germany.

Key Features

Tracking script under 1 KB
Cookieless, no consent banner required
No IP storage, daily-rotating hashed visitor IDs
Reports visits referred by AI assistants
Hosted on Hetzner Cloud in Germany

Pros & Cons

Genuinely small script and a clear privacy design
EU hosting on Hetzner in Germany, stated in the docs
Surfaces AI-assistant referrals, which most trackers miss
Free tier
No Data Processing Agreement published, which GDPR Article 28 requires
No imprint, legal entity or terms of service on the site
Very early stage, around 113 sites tracked
Not open source, so self-hosting is not an escape route

Categories

Glyphex GDPR & data protection: common questions

Is Glyphex GDPR compliant?

Partly. Glyphex meets some of the requirements, with caveats worth reading before you commit. Glyphex is a European company headquartered in Finland, data is hosted within the European Union.

Where does Glyphex store data?

Glyphex states: "All data is stored on servers in the European Union. We use: Hetzner Cloud (Germany) for database storage and application hosting. No data transfers to non-EU countries.". Data is hosted within the European Union.

Does Glyphex offer a Data Processing Agreement (DPA)?

We could not locate a published DPA for Glyphex. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.

What a DPA has to cover →

Is Glyphex a European company?

Yes. Glyphex is headquartered in Finland and, as far as we can establish, European-owned.

Spot an error in the compliance data? Get in touch