PureStats documentation
Measurement methodology and verification
Understand PureStats visitor definitions, tracker-size evidence, first-party proxy verification and fair comparisons with other analytics tools.
PureStats is free with unlimited sites and tracked traffic. Unlimited product access does not remove payload validation, rate limits or protection against abuse. This guide explains what our numbers mean and how to verify collection without inflating real reports.
Visitors are not people identified across the internet
Default anonymous tracking uses site-scoped, daily rotating visitor hashes. A browser can therefore appear as a new anonymous visitor on another day. Browsers that block or do not run the script may never produce a browser pageview. Server-side requests, AI crawlers and human browser visits are different signals: compare them within the same traffic mode rather than treating every HTTP request as a person.
Optional persistent identity changes retention coverage. It must be deliberately configured; raw identity values are not stored. See retention analytics for coverage and cohort definitions. Visits, unique visitors, events and conversions are different metrics, even when they come from the same activity.
Reproducible tracker-size evidence
The lightweight tracker page reads the current core version and Gzip size from the generated build manifest. It is not an estimate or an old marketing claim. The source, minified output and checksums are validated together in CI. Optional Web Vitals, experiments, search and replay are separate downloads and are not included in the core measurement.
Download the current https://purestats.io/pf.min.js and measure its Gzip size using gzip -n -9 -c pf.min.js | wc -c. The -n switch excludes the local filename and timestamp. Browser transfer size can differ because of compression settings, HTTP headers, caching and protocol overhead. A small script is useful but does not guarantee a particular Lighthouse or Core Web Vitals result.
Worked verification: the proxy-IP trap
A common first-party deployment mistake is to forward the event body but lose the browser's client address. Every visitor then appears to come from the proxy server. Adding an arbitrary X-Forwarded-For header from the browser is not a safe correction: visitors can forge that header.
- Register the proxy's egress addresses or CIDRs in the site's approved proxy settings.
- Resolve the client address at the trusted server or edge connection. Discard visitor-supplied forwarding and PureStats signature headers.
- Forward the untouched request body, trusted client context and, where configured, a server-generated HMAC signature. Keep signing material in server-side secret storage.
- Cache only successful tracker JavaScript. Do not cache event ingestion, replay uploads or authenticated APIs.
- Run an isolated tracking test, check accepted and rejected results, and verify the script, configuration and event paths independently.
- Confirm a subsequent genuine visit in the intended timezone and traffic mode. Do not inject fake conversions just to make a dashboard appear active.
The first-party proxy guide contains the actual paths, Nginx, Apache and signed Worker examples. Proxying cannot promise complete collection or bypass a visitor's consent choice. The same privacy settings remain in force.
Comparing tools and imported history
Align timezone, date boundaries, bot inclusion, consent rules and reporting identity before comparing totals. A server log records requests, a browser tracker records successful script execution, and an imported aggregate report records the provider's own reporting model. Differences are not automatically lost data.
Historical imports remain labeled aggregates; they do not become artificial sessions or visitor profiles. Overlapping import and native periods are not silently summed. The Google Analytics comparison and Plausible comparison link to provider documentation and state their review dates. Features shared by products are not presented as exclusive to PureStats.
Discovery is not the same as adoption
Search-engine impressions, a crawler fetching documentation, a human referral from an AI assistant and a successfully configured agent site are separate outcomes. llms.txt is a documentation entry point, not authentication, a ranking guarantee or proof that an assistant cited a page. Agent documentation states which APIs are live and which plugin integrations are still unavailable.
Publisher and corrections
PureStats publishes these definitions and checks product claims against the implemented behavior. For a suspected measurement error, contact support@purestats.io with the domain, timeframe, timezone and traffic mode. Do not include tokens, recovery material or unredacted visitor details. See About PureStats and the privacy controls.