What Millimetry stores, and what it never does
Millimetry is built so that it cannot tell you who anyone is. This page lists what that means in practice, so you can describe it accurately to your users and your lawyer.
Never stored, anywhere
Section titled “Never stored, anywhere”- IP addresses. The server uses the connection’s address in memory to work out the country and region and the daily visitor ID, then discards it. It is not in the database, the logs or error reports.
- User-agent strings. Reduced to browser and OS families with major versions, then discarded.
- Cookies and browser storage. The tracker reads and writes none: no cookies,
localStorage,sessionStorageor IndexedDB. - Device identifiers. The SDK uses no advertising identifier (IDFA), vendor identifier (IDFV), install ID, Keychain or
UserDefaultsvalue. - Fingerprints. No canvas, audio, font or plugin probing.
- Full referrer URLs and query strings. Only the referring site’s name and the
utm_source,utm_mediumandutm_campaigntags are kept.
The daily visitor ID
Section titled “The daily visitor ID”To count visitors without identifying them, the server computes a hash of the connection’s address, the device or browser description, and a random secret that changes every UTC day. The same person gets an unrelated ID the next day. The secrets are deleted after about 9 days and are never backed up. After that, no one, including us, can recompute or link that day’s IDs.
On apps, a session keeps the ID it started with, so a phone moving from Wi-Fi to cellular does not become two visitors.
The trade-off is deliberate: Millimetry shows daily visitors, sessions, funnels and paths, but not retention or “returning users”, because nothing persists from one day to the next.
On the device
Section titled “On the device”The SDK keeps one thing on disk: the queue of events waiting to be sent, in the app’s own container under Application Support/Millimetry/queue/. The folder is excluded from backups, and its files are protected until the device is first unlocked. Events leave the queue when they are delivered, after 7 days, or when it passes 1,000 events. The session is kept in memory only.
On the server
Section titled “On the server”| Data | Kept |
|---|---|
| Events (name, time, your properties, OS, app version, device model, locale, country, region; for websites the path, referrer site, UTM tags, browser, screen class) | 25 months |
| Debug events | 30 days |
| Daily visitor-ID secrets | About 9 days, never backed up |
| Backups | 14 days (weekly full backups 21 days) |
Deleting an app purges its data after a 7-day window in which you can undo it. Deleting your organization purges everything within minutes.
Your properties
Section titled “Your properties”You choose the properties you send, so you control most of what is stored. Millimetry drops properties named like personal data (email, phone, user_id, name, address, ip, idfa, device_id, token and a few more) and string values that look like an email address, a phone number or a UUID. Treat that as a safety net: don’t send personal data in the first place. See naming events.
Consent
Section titled “Consent”Whether you need your users’ consent depends on your jurisdiction and on what else your app or site does. This page gives you the facts to decide. Millimetry does not give legal advice.
Requests from your users
Section titled “Requests from your users”Because IDs rotate daily and are not tied to anything a person holds, neither you nor Millimetry can find one person’s events. If someone asks what you hold about them, you can explain that your analytics cannot single them out. Our privacy policy and DPA describe this in detail.