Cookies & GDPR
Last updated 1 August 2026
This page is maintained by the Bot Analytics team and explains how our script behaves with regard to cookies and EU data protection rules. It is a description of our practices, not legal advice or an independent certification.
Cookies set by the tracking script
None. The script does not set cookies, does not write to local storage or session storage, and does not use any other form of persistent device identifier. The session identifier it generates lives in page memory and disappears when the tab is closed.
Cookies set by the dashboard
The Bot Analytics dashboard stores a sign-in token in your browser so you stay logged in. This is strictly necessary for the service to function and applies only to customers, not to visitors of customer websites.
Why no consent banner is required for our script
- No cookies or device storage are used, so the ePrivacy consent requirement does not apply
- IP addresses are hashed and truncated before storage and cannot be reversed
- No profile of an individual visitor is built, and no data is shared with advertisers
You should still describe Bot Analytics in your own privacy notice, as you would for any analytics processor.
Roles under the GDPR
For traffic data collected from your website you are the controller and we act as processor on your instructions. For your own account data we are the controller. A data processing agreement is available on request.
Where data is stored
Traffic and account data are stored with our hosting and database provider. Page content submitted for AI audits is sent to our AI provider solely to generate the audit summary and is not used to train models.
Requests
Data protection requests: privacy@botanalytics.io. We respond within 30 days.