Analytics for SaaS
Free analytics for SaaS: site, signup funnel and API together
Totallytics is free analytics for SaaS, no cookies, no credit card: marketing site, 2 to 6 step signup funnels with median and p90 time to convert, custom events, 12-week retention cohorts and your API's requests, errors and p95 latency per route, in one account.
The marketing site
Pageviews, visitors, top pages, referrers, countries, devices and UTM campaigns, with ChatGPT referrals shown as their own source because OpenAI tags its links with utm_source=chatgpt.com. Any range up to 400 days, hourly detail for ranges up to 4 days, and the script is about 4 KB compressed.
The signup funnel
A goal is one step: a page like /welcome or a custom event like signup. A funnel is 2 to 6 steps completed in order on the same UTC day, for example /pricing, then /signup, then the signup event, then /app. Each step shows how many visitors reached it, where they dropped off, and the median and 90th percentile time between steps. Break any goal down by referrer, entry page, country, device, browser, operating system or UTM to see which channel actually converts.
Goals are computed from data you already have, so a goal added today reports on last month, and a changed funnel re-runs over the past. 20 goals and funnels per site.
Custom events
In the browser, one call: window.tt_event("signup", { plan: "team" }). Metadata is stored up to 4,096 characters of JSON per event. From your backend, POST https://totallytics.com/events with a JSON body and no API key; a server-side event gets a server-side identity, so it counts in event totals but cannot follow a visitor through a browser funnel. Put funnel steps in the browser.
Your API, in the same account
Add the totallytics npm middleware to Hono, Express, Fastify, Next.js or Cloudflare Workers, or the Go module to a Go service. Every endpoint reports requests, status codes, p50, p95 and p99 latency, errors with samples, and consumers. Alert rules email you when the 5xx share passes a threshold, when p95 passes a millisecond limit, or when a route that had traffic yesterday goes silent, checked every minute over a 5, 15 or 60 minute window. Windows with fewer than 20 requests never fire, and alerts hold for at least 10 minutes to avoid flapping.
Retention without cookies
Weekly cohorts over 12 weeks show how many of the visitors first seen in a given week came back in each later week. The only state is a small response the visitor's browser keeps in its own HTTP cache, holding the day it was first seen and the day it was last seen; the weekly cohorts are computed from that when you look. No cookies, no local storage, no user IDs.
Limits
| Limit | Value |
|---|---|
| Websites and APIs per account | 50 |
| Goals and funnels per site | 20 |
| Funnel steps | 2 to 6, same UTC day |
| Event metadata | 4,096 characters of JSON |
| Alert rules per site | 20 |
| Recipients per alert rule | 10 |
| Alert windows | 5, 15 or 60 minutes |
| Active API keys per site | 10 |
| Stats query range | Up to 400 days |
| Price | Free, no credit card |
What it is not
Totallytics is web and API analytics, not product analytics. There are no user IDs or per-user timelines, no session replay, no heatmaps, no feature flags, no A/B tests and no revenue or MRR tracking. If you need those, PostHog's free tier covers 1 million events a month with 1 project and 1 year of retention.
Set it up
Sign in with Google, add your domain and paste the tracking script into your marketing site:
<script
async
src="https://totallytics.com/latest.js"
data-hostname="example.com"
data-verify="YOUR_SITE_VERIFY_TOKEN"
></script>
Then add your API as a second site and install the middleware from the API analytics guide.
FAQ
Can I track a user from signup to upgrade?
Only within one UTC day in the browser. Funnels follow the daily visitor hash, which resets at midnight UTC and never identifies a person. There are no user IDs.
Does the signup funnel work if signup happens on another domain?
Only if both domains are the same registered site. The hash includes the site, so a funnel cannot cross from example.com to app.example.com unless both are tracked under one hostname with data-hostname.
Can I send events from my backend?
Yes, POST /events takes a JSON body without a key, and the event appears in the events breakdown. It cannot be a funnel step tied to a browser visitor.
Where is the data stored?
In Frankfurt, Germany, collected on Cloudflare's network. IP addresses are never stored.
Updated October 7, 2026