Tools

Umami

Open-source privacy analytics. Easy self-host; cloud also available.

Log in to add an offering to your organisation’s current stack.

MIT · https://umami.is

Web analytics

Self-hosted

Hosting: Self-hosted

MIT-licensed analytics you run on an EU VPS.

Fair 5.0 Easy 3.0 Secure 4.0

Pillar Criterion Score Evidence
Easy Day-one UX Can non-technical staff use it without a project? 4 Clean modern UI. Source
Easy Operate Admin burden, updates, backups and language coverage. 2 You operate updates. Source
Easy Integrate SSO, mail/CalDAV, APIs and common NGO connectors. 3 Share/embed and APIs. Source
Fair Lock-in / exit Can you leave with your data in open formats, at known cost? 5 You own Postgres/MySQL data. Source
Fair Sovereignty EU legal entity, EU hosting, and exposure to extra-EU lawful access? 5 Host country is yours. Source
Fair Openness Open source or open standards? Are independent implementations possible? 5 MIT open source. Source
Secure IT security Authentication, encryption, patch cadence and independent audit. 4 Your hardening. Source
Secure User security 2FA, roles, phishing resistance and safe defaults. 3 Your IAM. Source
Secure Personal data GDPR fit: DPA, residency, sub-processors and Schrems II posture. 5 Data stays with you. Source

Umami cloud

Hosting: Global SaaS

Vendor cloud; prefer self-host or EU VPS for sovereignty.

Fair 3.7 Easy 4.3 Secure 3.7

Pillar Criterion Score Evidence
Easy Day-one UX Can non-technical staff use it without a project? 5 Same UI as self-host. Source
Easy Operate Admin burden, updates, backups and language coverage. 5 Fully managed. Source
Easy Integrate SSO, mail/CalDAV, APIs and common NGO connectors. 3 Same tracking API. Source
Fair Lock-in / exit Can you leave with your data in open formats, at known cost? 4 Open source makes exit easy. Source
Fair Sovereignty EU legal entity, EU hosting, and exposure to extra-EU lawful access? 2 Confirm cloud region and vendor jurisdiction. Source
Fair Openness Open source or open standards? Are independent implementations possible? 5 MIT open source. Source
Secure IT security Authentication, encryption, patch cadence and independent audit. 4 Managed SaaS baseline. Source
Secure User security 2FA, roles, phishing resistance and safe defaults. 4 Team plans. Source
Secure Personal data GDPR fit: DPA, residency, sub-processors and Schrems II posture. 3 Review DPA before storing EU visitor data. Source