AGGREGATE Analytics by Subschema

Count what happens on your websites, not who did it.

Count events, not people

By default, each event keeps only a sanitized page path, a coarse referrer channel, device and screen-size buckets, and the UTC hour it happened in. No visitor or session ID, IP address, browser string or exact timestamp is stored.

See what is stored

Your BI tool is the dashboard

Power BI, Tableau, Looker or any SQL-capable tool connects to stable, versioned reporting views in your own database. There is no separate analytics product to learn, license or put through vendor review.

Connect a BI tool

Ask an AI assistant, with guardrails

Give an assistant the same read-only account as your BI tool. It sees documented views and a built-in data dictionary: released counts, never raw rows, identifiers or numbers below your disclosure threshold.

Connect an assistant

Yours to run

Self-hosted from a release ZIP on ordinary PHP hosting, with MySQL, MariaDB, PostgreSQL, SQL Server or SQLite. Open source: AGPL-3.0 for the server, BSD-3-Clause for the tracker.

View on GitHub

Governance before tooling

Most web analytics begins by identifying the visitor, with a cookie, a device fingerprint or a daily hash of an IP address. Unique visitors, sessions and funnels are all built on that identity.

For organizations that answer to a privacy office, the identity is the hard part. It has to be justified, disclosed and often consented to, and it is usually more than the question requires. Leadership wants to know which pages are read, which campaigns bring people in and whether sign-ups are rising. None of that requires following a person.

Aggregate starts from the other end. It counts what happened, enforces privacy rules on the server where the data arrives, and publishes the results into the reporting tools your organization already governs.

How it works

  1. Collect. Add the lightweight tracker or your tag manager, or send events from your own backend with no script on the page. The server removes query strings, emails, UUIDs and numeric record IDs from page paths before anything is stored.
  2. Protect. Events are grouped into completed time periods. The reporting views withhold the current period and hide any count below your minimum, five by default. That threshold lives in the database, so every report, extract and query receives the same protection.
  3. Publish. Documented, versioned SQL views, plus glossary views that label every code, give your BI tool or AI assistant what it needs to answer questions correctly. View names and column meanings stay stable across releases.

Two modes, one honest consent model

Anonymous mode (default) Enhanced mode
Applies when Consent is unknown or declined The visitor makes an affirmative choice
What is stored Sanitized path, referrer channel, device and viewport buckets, UTC hour. Optionally, allowlisted goals and country- or continent-level geography. Everything in anonymous mode, plus visitor and session IDs, custom properties and exact dimensions
How it stops Administrators can pause collection globally or exclude sensitive paths Immediately, when the visitor withdraws consent

Consent in Aggregate changes what the server records, not just what the banner says. Connect it to your consent manager and the behavior matches what your notice promises. Withdrawal is prospective: it stops future enhanced detail but does not erase what was already stored, and coarse anonymous counting continues.

What you give up

Our own documentation puts this before the feature list, and it belongs here too.

  • No unique visitors, sessions or bounce rate in anonymous mode. Computing them requires exactly the identifier Aggregate refuses to create.
  • Small numbers disappear. Counts below your threshold are withheld, and widening the date range will not bring them back. Low-traffic sites will see gaps.
  • No real-time view. Events are released after each UTC hour ends; goals and geography after each UTC day.
  • No built-in charts or assistant. Aggregate makes the data safe to query. The BI tool, the model and the connector are yours to choose and to govern.
  • "Anonymous" is the name of a mode, not a legal conclusion. Rare paths, small populations and outside information can still make data personal in context. Installing Aggregate does not by itself make a website compliant with GDPR, CCPA or any other law.

Is it the right fit?

Likely yes if you answer to a privacy office or data protection officer; run a public-sector, health, education or legal website; already own a BI stack and want measurement to feed it rather than compete with it; want to ask an AI assistant about your traffic without handing it visitor-level data; or want to explain your entire analytics data model on one page.

Likely no if you need unique-visitor counts, funnels, session replay, heatmaps or marketing attribution. Established tools such as Matomo and Plausible will serve you better, and Aggregate is not trying to win that comparison.

Where Subschema helps

Aggregate is open source and designed to be installed and operated by your own team. When the measurement decision carries regulatory or reputational weight, our advisory practice can help.

  • Measurement governance. Decide what to collect, which goals and campaign properties to allow without consent, and which disclosure thresholds suit low-traffic or sensitive sites.
  • Reporting and AI access review. Define read-only grants, approved views and assistant guardrails, so every consumer of the data receives the same protection.
  • Implementation assurance. Verify the deployment, consent-manager wiring and reporting contracts before live traffic, and document them for your privacy office.

Request a consultation

Status and next steps

Aggregate is in public beta. Start with a disposable installation and synthetic events, and review the known limitations before using it with live traffic. No independent security or privacy audit is claimed.