Analytics & privacy
Exactly what a shared demo measures, what it never stores, and every way to turn analytics off — for the whole embed or for a single viewer. Cookieless and anonymous by default, so no consent banner is required.
When someone watches a demo you shared or embedded, DemoMate records a small, anonymous stream of usage events so you can see how far viewers got. This page states exactly what is collected, what is never collected, and every way to switch it off.
What is collected
For each viewing session the player sends a handful of events:
- The event type —
demo_view,step_view,completion,cta_click,form_submit. - The step index — which step number an event refers to (a number, not its contents).
- An anonymous session id — a random UUID generated fresh in the browser for that single page load. It is not stored anywhere, not a cookie, and cannot be linked to a person or to any other session.
- When the event happened — the time each event fired, as reported by the viewer's own browser clock. Events are sent in small batches, so without it every event in a batch would look simultaneous and "time spent on a step" could not be measured. It is a clock reading only — no timezone, no locale, nothing device-identifying — and the server bounds it to a plausible window around the moment the batch arrives.
That is the whole payload. The player uses navigator.sendBeacon to send it and buffers events so a session sends at most a few small requests.
What is never collected
- No cookies. The analytics beacon sets and reads no cookies. (Some access gates — password or email-domain links — set a cookie so a viewer isn't re-challenged on every step; that is a separate, opt-in feature covered under Share-link gates, not analytics.)
- No IP address and no user-agent are stored. The events table has no column for either — they are not persisted.
- No personalization values. Any
?v_*URL parameters are stripped before an event or referrer is ever sent.
Analytics is anonymous by default. A viewer's identity is attached to events only when you explicitly ask for it — through an email gate, an overlay form the viewer fills in, or a ?u.email= link parameter you send. Even then the address is never verified: it is "the email someone typed," not an authenticated identity. Treat it as a claim, not proof.
Do Not Track and Global Privacy Control are honored
If the viewer's browser sends a Do Not Track signal or Global Privacy Control (Sec-GPC, the modern successor to DNT — sent by privacy browsers and extensions), the passive analytics beacon does not fire. This is enforced in two places:
- Client side — the player checks
navigator.globalPrivacyControland the DNT flags before wiring any beacon. - Server side — the events endpoint also drops any request carrying
Sec-GPC: 1orDNT: 1, so the signal is honored even if a request somehow reaches it.
Turning analytics off
You have three switches, from broadest to most specific:
- Per embed, in the snippet — when you copy an embed snippet you can choose to disable analytics; the generated snippet carries
?analytics=0(inline iframe) ordata-disable-analytics(declarative embed). The player then wires no beacon at all. - Per viewer, in the URL — append
?analytics=0to any share link (/d/your-demo?analytics=0). That single view sends no analytics. - Automatically, by the viewer's browser — DNT / GPC, as above. No action needed by you or the viewer beyond having the signal on.
Forms still work when analytics is off
Turning analytics off silences passive measurement only. If your demo has an overlay form, it still submits when a viewer fills it in — because that is an explicit action the viewer chose to take, not passive tracking. When analytics is off the submission is simply not joined to an anonymous session id. This distinction is deliberate: consent scope here is passive analytics, not the data a viewer knowingly hands you.
Why there is no consent banner
A cookie/consent banner exists to disclose cookies and cross-site tracking. DemoMate's analytics is cookieless and anonymous, honors DNT and GPC, and stores no IP or user-agent — so there is nothing a banner is required to disclose. Adding one would be theater, not consent.
A note on fonts
The player renders with the system font stack and self-hosted fonts served from the same origin as the demo. It does not pull fonts from a third-party font CDN, so there is no cross-origin font request to disclose or make "GDPR-safe." What the browser needs to render a demo comes from the demo's own origin.