Consent & Privacy
Attri gives you three tracking modes. You pick the tradeoff between measurement precision and the identifiers you set on a visitor’s browser. The mode you choose changes what the script stores, whether it sets cookies, and how visitors are counted.
The three modes
Section titled “The three modes”The default. Attri creates a persistent visitor identity and stores it in first-party cookies, so it can connect a person’s visits across days and sessions in the same browser. This is the mode that powers exact cross-day unique counts and end-to-end attribution from a click to a conversion that happens a week later.
Full mode sets three first-party cookies:
| Cookie | Lifetime | Purpose |
|---|---|---|
_attri_vid | 1 year | Visitor ID. De-duplicates the same person across visits. |
_attri_sid | 30 minutes | Session ID. Groups a single browsing session. Refreshes on activity. |
_attri_cid | 1 year | Click ID. Ties an on-site conversion back to the shortlink that drove it. |
Because Full mode sets persistent identifiers, most privacy regulations treat it as requiring visitor consent. If your site shows a cookie banner, gate Full mode behind it (see Signaling consent below).
Anonymous
Section titled “Anonymous”The cookie-free mode. Attri sets no cookies and stores no persistent identifier. Instead, the edge derives a temporary visitor ID by hashing the visitor’s coarse signals (user agent, IP, and site hostname) against a secret salt that rotates every 24 hours. The raw inputs are never stored, and the salt from previous days is discarded, so yesterday’s ID cannot be reconstructed or linked to today’s.
Anonymous mode is designed to run without a cookie banner. It collects no cookies and keeps no cross-day identifier, which is what most privacy-first analytics tools (Plausible, Fathom, Simple Analytics) do. It is not legal advice: confirm your obligations with your own privacy counsel, since the answer depends on your jurisdiction and what else your site collects.
What you give up in Anonymous mode is honest and worth stating plainly:
- Within-day numbers are exact. Daily pageviews, daily unique visitors, sources, devices, geography, top pages, bounce rate, and time on page have no drift.
- There is no cross-day de-duplication, by design. A person who visits on five different days counts as roughly five unique visitors over a multi-day range. This is inherent to any daily-rotating identifier, and it is the same way every cookie-free analytics tool behaves.
- A small seam exists at midnight (UTC). A session that is live at the moment the salt rotates splits into two. The number of sessions active at that hour is tiny, and everyday factors like bot filtering and ad-blocker loss move your totals far more than this does.
If you need exact cross-day counts, that is what Full mode is for. Anonymous mode is not a fuzzy version of Full mode. It is a deliberate tradeoff: slightly less cross-period precision in exchange for not setting anything on the visitor’s browser.
No analytics at all. Attri sends no pageview, conversion, or custom event beacons and sets no cookies. The script still cleans up UTM parameters and strips the click ID from your URLs, and forms with spam protection still work. Use this when you want the shortlink and form features without any visitor analytics.
Where visits don’t connect
Section titled “Where visits don’t connect”Attri connects a click, the visit it leads to, and any conversion by matching the visitor’s identity. Some journeys break that match, and the conversion then counts on its own instead of being credited to where the visitor came from. These are the current limits, per mode.
| Journey | Full | Anonymous |
|---|---|---|
| Same site, same day | Connected | Connected |
| Same site, across days | Connected | Not connected, by design |
Across subdomains (example.com to app.example.com) | Not connected | Not connected |
Across different domains (example.com to exampleapp.io) | Not connected | Not connected |
| Across devices (phone to laptop) | Not connected | Not connected |
| Visitor changes network mid-visit (Wi-Fi to mobile data) | Connected | Splits into two visitors |
| From an Attri shortlink to its destination | Connected | Connected on the same day |
Subdomains are the one most sites hit. If your marketing site is on example.com and signup happens on app.example.com, the signup is not credited to the blog post, search query, or campaign that brought the visitor to your marketing site. Full mode’s cookies are scoped to the exact hostname, and Anonymous mode’s temporary ID includes the hostname, so each subdomain sees a new visitor.
Until that changes, route the links that cross over through a shortlink with data-attri-link. The conversion is then credited to that link, so you can see which button or page placement produced a signup, even though the earlier part of the journey is not attached.
Anonymous mode can also merge visitors. The temporary ID is built from the user agent and IP address, so two people on the same office network using the same browser version on the same day can count as one visitor. At typical traffic levels this is rare.
Signaling consent
Section titled “Signaling consent”Set window.attriConsent in a script that runs before your Attri snippet, to choose the mode for that visit:
<script> window.attriConsent = "anonymous"; // "full", "anonymous", or "off"</script><!-- Your Attri snippet (copied from Settings > Tracking) goes below this -->The value can be a string ("full", "anonymous", "off") or a boolean for convenience (true means Full, false means Off).
The mode is resolved once when the script initializes. It does not switch partway through a session, so set it before the script loads.
Gating Full mode behind a banner
Section titled “Gating Full mode behind a banner”The common pattern is to default to Anonymous and upgrade to Full only after the visitor accepts cookies. Set the default in your workspace (below), then have your consent banner set window.attriConsent = "full" and reload, or set it before the script on pages loaded after consent is stored.
<script> // Read your banner's stored choice however you already do it. window.attriConsent = hasAcceptedCookies() ? "full" : "anonymous";</script><!-- Your Attri snippet (copied from Settings > Tracking) goes below this -->Workspace default
Section titled “Workspace default”If a page never sets window.attriConsent, Attri uses your workspace default. Set it in the app under Settings > Tracking, where you can choose Full, Anonymous, or Off for the whole workspace.
This lets a privacy-first site default every visitor to Anonymous without touching any code. A page can still override the default per visit with window.attriConsent.
Verifying the mode
Section titled “Verifying the mode”Open your browser’s developer tools after loading a page:
- Anonymous or Off: the Application tab shows no
_attri_cookies. - Full: the Application tab shows
_attri_vidand_attri_sid, plus_attri_cidif the visitor arrived through an Attri shortlink.
In every mode you can watch the Network tab for the beacon to attri.io. In Off mode there is no analytics beacon.
Next steps
Section titled “Next steps”- Installation — Add the tracking script to your site
- Pageview Tracking — What pageview data is captured
- Conversion Tracking — Track form submissions, purchases, and other conversions