Privacy Policy

Last updated: September 2026

M-Analytics is built around one idea: it's your data, on your Matomo server, and it should stay that way. This policy is short because there isn't much to say — we (CreativeApplications.Net, the developer of M-Analytics) do not collect, store, transmit, or have access to any of your data.

What the app does with your information

When you set up M-Analytics, you enter two things: the address of your Matomo server, and an API token you generate yourself in Matomo's admin panel. Both are stored only on your device — the server address in your device's standard app storage, and the token in the iOS/macOS Keychain, the same secure system every app uses to store passwords.

The app uses that address and token to make requests directly from your device to your Matomo server, over HTTPS (or plain HTTP if you've deliberately pointed it at a self-hosted server on your local network — see below). Those requests ask Matomo for the same reporting data you'd see logging into Matomo's own dashboard: visit counts, pageviews, visitor locations, referrers, and similar site-traffic metrics. Matomo's response is displayed in the app and, if you've enabled widgets, cached briefly on your device so your Home Screen widgets can show it without a live connection every few seconds.

None of this ever passes through a server we operate, because we don't operate one. There is no analytics SDK, crash reporter, advertising framework, or other third-party code embedded in the app that could collect or transmit anything on our behalf.

What we collect

Nothing. We have no way to see your server address, your API token, your site's traffic data, or anything else the app displays. If you contact us directly for support (see below), we'll have whatever you choose to send us in that message, and nothing more.

Network connections

By default, the app expects your Matomo server to use HTTPS. It also allows plain HTTP connections, because Matomo installs on a local network or an internal server are common and often don't have a certificate — that's a deliberate accommodation for real-world setups, not a way of routing your data anywhere insecure. Either way, the only destination for any request the app makes is the server address you typed in yourself.

Data on your device

Your server address, site selection, and display preferences are stored in standard app storage on your device. Your API token is stored in the Keychain, which iOS and macOS encrypt at rest. If you use the app on both a Mac and an iPhone, each keeps its own separate copy — nothing syncs between them, because there's no service of ours for them to sync through.

Children's privacy

M-Analytics is not directed at children and does not knowingly collect information from anyone, of any age — see above.

Changes to this policy

If this policy ever changes, the update will be posted here with a new "last updated" date. Given the app's design, we don't expect that to happen often.

Contact

Questions about this policy or the app: