Security & Data Ethics
Your data is your competitive advantage. We've built Badgerlytics with a privacy-first architecture so it stays that way.
Our core promises
You own your data
Analytics data your sites generate belongs to you. We process it on your behalf. We never sell, rent, or trade it.
Instant deletion
Delete any property's analytics data at any time from the dashboard. Deletions are irreversible and irrevocable.
Anonymous-only tracking
PII is prohibited in events. We scan for it and reject anything that looks like a name, email, phone, or government ID.
We do not sell your data. Period.
This is the most important sentence on this page. We do not sell, rent, or trade your analytics data — or your account data, or your customers' data — to third parties. Not now, not later, not at any price. We are funded by customers paying for the product, not by repackaging their data for someone else.
Anonymous analytics by design
Badgerlytics is built for anonymous analytics. PII in events is prohibited under our terms of service, and we actively scan and reject events that contain things that look like personal identifiers. Audience traits are intentionally restricted to opaque flags like plan, signed_in, or tenure_bucket — never names, emails, or phone numbers.
No-training guarantee for AI features
The AI features in Badgerlytics follow a strict policy:
- Zero training: we do not use your data to train any Badgerlytics-owned model.
- Enterprise APIs only: when we call external AI providers (OpenAI, Anthropic, etc.) we use enterprise contracts that prohibit them from using your data to train their global models.
- Data minimization: we send only the minimum data each AI call needs.
Security best practices
Encryption everywhere
TLS 1.3 in transit. AES-256 at rest. Modern ciphers only — we drop weak ones aggressively.
MFA available on all accounts
Optional multi-factor authentication on every account. We strongly recommend enabling it for owner and admin roles.
Hardened infrastructure
Hosted on reputable cloud platforms with regular security assessments, principle-of-least-privilege access, and continuous monitoring.
Questions about security?
We take this seriously and we're happy to talk specifics. with security questions, due-diligence requests, or vulnerability reports.