Last updated · 2026-08-31
04 · In practice
juuna keeps each customer’s analytics on a dedicated instance provisioned in the EU, with its own server and its own Postgres, no third parties in the tracking path, and erasure and export built into the dashboard. It is a tool for your GDPR posture, not a compliance badge.
I
The premise
Every paid plan is one machine rented for you alone, provisioned in the EU, running its own Postgres. There is no shared warehouse and no pooled cluster: your visitors’ events land on your instance and mix with nobody else’s. When you cancel, we hand you a full export, then destroy the instance and its backups.
The tracking path contains no third parties. The script loads from your instance, events post to your instance, and enrichment happens on the box: even the IP-to-geo lookup is a local GeoLite2 database on the instance, not a call to a geolocation service. The parties involved are you, us operating the instance for you, and the data centre the machine stands in. That is the whole list.
II
The posture
Compliance is a property of your processing, not of any product, so juuna does not claim it for you. What it supplies is the machinery a defensible posture leans on: collection kept minimal, retention that actually expires, and subject rights reduced to a dashboard action.
Concretely: raw events are kept about 90 days by default and then dropped, while long-range dashboards read aggregate rollups that carry no identifiers. Session recordings are masked by default, never store IPs, and expire after about 30 days. An erasure request removes a person’s events, traits and recordings in one transaction. Export to CSV is a dashboard view, not a support ticket.
Consent, lawful basis and your records of processing remain decisions you make with counsel. What juuna changes is the length of the appendix: one instance, one region, and no subprocessor chain inside the tracking path to enumerate.
III
The architecture
With multi-tenant analytics, your visitors’ data lives inside a vendor’s shared infrastructure, and your data map inherits that vendor’s subprocessor list. Single-tenant collapses the picture: the blast radius, the access model and the answer to “where exactly is it” are all one machine you can point at.
It shows up in the boring places. Backups are dumps of your database alone, taken daily with the last seven kept, and on request hourly dumps can be written to an S3-compatible bucket that you own. Leaving is not a deletion request in someone’s queue; it is your machine being destroyed.
IV
The ledger
§
Asked and answered
Keep reading
Cookieless analytics · Session replay · juuna vs Matomo · juuna vs Google Analytics · juuna vs Plausible · The integration docs · Pricing
Flat plans, everything included; every paid plan is a dedicated instance of your own.