Updated 28 August 2026
This is a translation provided for convenience. Only the French version is legally binding.
Privacy policy
Version applicable during the private beta.
Controller: Alexandre Ribes, sole trader operating under the business name La Boîte à Code, SIRET 840 048 680 00051 (see legal notice). Data protection contact: Protected contact detail: enable JavaScript to reveal it. No data protection officer has been appointed as at the date of this policy; this address receives requests relating to personal data.
Quiet Metrics wears two distinct hats, dealt with separately below: processor for the analytics carried out on behalf of its customers, and controller for the data of its own customers and visitors.
1. Visitors to sites measured by Quiet Metrics
Quiet Metrics is an analytics tool without any identification or tracking cookie: its measurement tools place on the visitor's device no identifier, no analytics cookie and no persistent fingerprint, and no directly identifying data is kept in the statistics. Only two things may be written on the device of a visitor to a measured site, and they do not follow the same regime: the opt-out marker qm_ignore, set at the person's own request in order to stop the measurement and never transmitted to Quiet Metrics, and the visit continuity cookie qm_visit, set by the measurement for ten sliding minutes so that a network change during a visit does not cause the same person to be counted twice. Neither of them contains an identifier, their value being the same for everyone, and the second is never set on the device of a person who has opted out. The public pages of Quiet Metrics further store two non-identifying local preferences after an action by the user (chosen theme and dismissal of the information notice). All of this is detailed in the cookie policy.
Concretely: the IP address and the browser signature pass through an encrypted queue of bounded duration (15 minutes target, under 2 hours for a permanently failed job), then serve for a few milliseconds in memory to compute an ephemeral pseudonymous fingerprint. They are not written to the measurement tables. That fingerprint is not computed on the full address but on the subscriber network: the whole address in IPv4, and in IPv6 the /64 prefix alone, the remaining 64 bits identifying the machine's interface. What is observed is therefore coarser than the address received. Without the daily salt, destroyed after its grace period, it is impossible to link a fingerprint to a person or to the following days: no tracking over time, no profile. The full method is described in how we count.
The controller for the analytics of a site is that site's operator; Quiet Metrics acts as a processor (art. 28 GDPR) under the data processing agreement. To exercise your rights regarding the measurement of a site you visited, contact that site's operator. Given the design of the service (no identifying data retained), Quiet Metrics is generally unable to re-identify a visitor (art. 11 GDPR).
2. Quiet Metrics account holders
To provide the service, we process:
| Data | Purpose | Legal basis | Duration |
|---|---|---|---|
| Account (name, email, hashed password, language) | Providing the service | Performance of the contract | Life of the account + 30-day reversibility period |
| Contract profile (consumer or business status; legal name, company number and VAT number for businesses) | Formation of the contract, billing and determining the applicable rules | Pre-contractual steps and performance of the contract | Life of the account, then applicable accounting and evidential periods |
| Contractual evidence (versions and dates of acceptance, start of contract, trial and any withdrawal) | Formation, performance and proof of the contract | Performance of the contract, then legitimate interest in defending rights | Term of the contract, then evidential archiving for up to 5 years |
| Billing (details, history, invoices) | Billing, accounting | Legal obligation | 10 years (accounting records) |
| Service emails (per-site reports, quota alerts, end of trial) | Providing the service | Performance of the contract | Life of the account |
| Support exchanges | Assistance | Performance of the contract | 3 years |
| Authentication, administration and security logs (account identifier, date, action, IP address where necessary) | Securing the Service, detecting abuse and evidencing incidents | Legitimate interest in securing the Service | 6 to 12 months, save for a documented need linked to an incident or dispute |
| Person invited to an account (name, email address) | To let them accept the invitation and then access the account that invited them | Legitimate interest of the account holder in opening their account to their team | Life of the seat: deleted on removal by the holder, on the member leaving, or on closure of the account |
Card payment is handled by Stripe: card data never passes through our servers. Stripe collects billing details, the company's legal name and, where applicable, its tax identifier. No marketing outreach is carried out without your agreement; service emails are limited to the operation of the account, and periodic reports can be switched off site by site.
3. Visitors to quietmetrics.dev
We do not measure the audience of the site's public pages, not even with our own product: no analytics script is loaded there, and no measurement cookie or visitor fingerprint is created.
The contact page collects the name, email address, subject and message entered voluntarily. This data is not written to the application database: it is sent by email to the Publisher, to a mailbox hosted by Proton (§ 4), in order to answer the request, on the basis of pre-contractual steps, performance of the contract or the legitimate interest in handling enquiries, depending on their nature. Exchanges are kept in the mailbox for 3 years.
This page, and the registration form, load Cloudflare Turnstile to prevent automated submissions and account creation. To that end Cloudflare processes technical signals such as the IP address, the User-Agent header, the TLS fingerprint, the widget key and its origin. These signals serve to tell humans from bots, not for advertising or analytics. The resulting token is verified server-side before each submission; it expires quickly and can be used only once. See the Turnstile privacy addendum.
4. Hosting, recipients and processors
The service's data is hosted in France and is neither sold, rented nor shared for commercial purposes.
| Processor | Role | Acts for | Location |
|---|---|---|---|
| OVH SAS | Hosting of the platform and the data | § 1, § 2 and § 3 | France (EU) |
| Stripe Payments Europe / Stripe Inc. | Payment and billing | § 2 | EU / United States; transfers framed by standard contractual clauses and the compliance framework in force |
| Proton AG | Email: delivery of service emails and order confirmations, and receipt of messages sent to the contact and support addresses | § 2 and § 3 | Switzerland, a country recognised as adequate by the European Commission |
| Cloudflare, Inc. | Anti-bot protection of the contact and registration forms (Turnstile) | § 3 | United States; processing framed by Cloudflare's DPA and transfer safeguards |
This table brings together two distinct capacities, depending on the hat concerned. Only OVH takes part in the analytics carried out on behalf of customers (§ 1): it is therefore the only sub-processor within the meaning of article 28 GDPR, and the only one listed in § 6 of the data processing agreement. The other providers act only on the processing for which Quiet Metrics is controller (§ 2 and § 3); they receive no personal data of visitors to measured sites.
Before any AI assistance feature or MCP server involving an external provider is enabled, the provider chosen, its purpose, the location of processing, the retention period and the transfer safeguards are added to the table above and brought to the account holder's attention. No visitor data may be sent to it without the Customer's documented instruction and a prior update of the DPA. If the Customer configures their own AI provider and API key, that processing falls under their agreement with that provider.
5. Security
TLS encryption of all traffic, encrypted and promptly purged collection payloads, secret keys encrypted at rest, hashed passwords, restricted and logged access, pseudonymisation by ephemeral fingerprint for measurement (see DPA: technical measures annex). Commercial opening is conditional on encrypted off-server backups and a tested restore.
6. What we do not do
No profiling, no solely automated decision producing legal effects, no cross-referencing between customer sites, no advertising, no resale of data.
7. Your rights
Depending on the processing and its legal basis, you have rights of access, rectification, erasure, restriction, portability and objection. Write to Protected contact detail: enable JavaScript to reveal it: an answer within the legal time limit, in principle one month. Proof of identity is requested only where there is reasonable doubt as to the requester's identity. Account holders can export their statistics at any time in CSV. API access is reserved for the Pro and Agency plans. You may lodge a complaint with the French data protection authority, the CNIL (cnil.fr).
8. Updates
This policy may change; the update date appears at the top. Substantial changes are notified to account holders.