Data as of Sep 19, 2026 · Based on 32 AI responses from ChatGPT Search and Google AI Mode · See how Parse measures this
Brands AI recommends here
Named in 100% of answers
Named in 100% of answers
Named in 97% of answers
Named in 72% of answers
If you mean **privacy-focused analytics that can satisfy a procurement/security checklist covering both hosted and self-hosted deployment, retention, deletion, exports, and contractual privacy terms**, the strongest matches I found are: Tool | Managed/cloud | Self-hosted | Retention controls | Deletion workflow | Data…
If you mean privacy-focused analytics that can satisfy a procurement/security checklist covering both hosted and self-hosted deployment, retention, deletion, exports, and contractual privacy terms, the strongest matches I found are:
| Tool | Managed/cloud | Self-hosted | Retention controls | Deletion workflow | Data export | Contractual privacy terms |
|---|---|---|---|---|---|---|
| Matomo | Yes | Yes | Yes — granular raw/report retention | Yes | Yes | Yes — Cloud DPA |
| Plausible | Yes | Yes | More limited/simple | Yes | Yes — CSV/API | Yes — DPA |
| Umami | Yes | Yes | Yes, particularly with self-hosting | Yes, with infrastructure under your control | Yes/API | Hosted contractual terms need closer review |
| PostHog | Yes | Yes | Yes | Yes | Yes | Yes, but its product-analytics architecture and privacy model are more complex |
Matomo is probably the most complete fit if these requirements are explicit procurement criteria. Its Cloud service and On-Premise deployment give you both managed and self-managed options. Its retention system distinguishes raw visitor data from aggregated reports and lets administrators automatically purge old data.
For Cloud customers, Matomo's DPA explicitly covers deletion and data return/export: after termination, customer personal data is deleted within 30 days, with a limited backup-retention period, and customers can export data before deletion.
Best fit when: you need a conventional, feature-rich analytics platform plus demonstrable governance controls.
Plausible has both a managed Cloud service and an officially supported self-hosted version. Its self-hosting documentation describes running the platform on your own infrastructure, while its Cloud offering provides managed infrastructure and maintenance.
It has particularly clear privacy/legal documentation: its DPA says customers retain ownership/control of their data and provides an explicit account/site deletion process.
Exports are available as CSV, through the Stats API, and for some customers through scheduled raw-event exports; self-hosted exports can remain on your own filesystem until you delete them.
Best fit when: you want relatively minimal data collection and straightforward privacy governance rather than a GA4-scale product-analytics suite.
Umami is another strong option if self-hosting is important. It is open-source and can be operated on infrastructure you control; its hosted version is available as well.
The important distinction for procurement is that self-hosting puts much more of the contractual/privacy responsibility on your organization and infrastructure provider. In other words, you gain deployment and data-location control, but shouldn't treat that automatically as equivalent to having a vendor DPA.
Best fit when: infrastructure ownership/control matters more than having extensive vendor-managed compliance documentation.
PostHog is worth including if by "analytics" you mean product analytics—events, funnels, user behavior, session replay, feature flags, etc.—rather than primarily website traffic analytics. It has both managed and self-hosting options.
It can therefore satisfy the deployment/export/governance requirements, but its larger product-analytics feature set means there are more categories of potentially sensitive telemetry to govern.
Best fit when: you need product analytics rather than a lightweight privacy-first website counter.
For the specific requirements you listed, I'd structure the evaluation like this:
One important procurement nuance: "self-hosted" and "contractual privacy terms" are different requirements. With self-hosting, the vendor may provide software and documentation but your organization becomes responsible for much of the processor/controller, infrastructure, backup, retention, and deletion architecture. With managed Cloud, you should specifically review the DPA, subprocessors, data-location commitments, termination/deletion terms, backup retention, and export mechanism rather than relying on a generic "GDPR compliant" statement.
If you give me your required checklist (e.g. SOC 2, GDPR DPA, EU/US data residency, configurable retention ≤90 days, API export, DSAR deletion, SSO, audit logs), I can turn this into a procurement-style feature matrix.
Best fit when: you need a conventional, feature-rich analytics platform plus demonstrable governance controls.
Plausible has both a managed Cloud service and an officially supported self-hosted version. Its self-hosting documentation describes running the platform on your own infrastructure, while its Cloud offering provides managed infrastructure and maintenance.
It has particularly clear privacy/legal documentation: its DPA says customers retain ownership/control of their data and provides an explicit account/site deletion process.
Exports are available as CSV, through the Stats API, and for some customers through scheduled raw-event exports; self-hosted exports can remain on your own filesystem until you delete them.
Best fit when: you want relatively minimal data collection and straightforward privacy governance rather than a GA4-scale product-analytics suite.
Umami is another strong option if self-hosting is important. It is open-source and can be operated on infrastructure you control; its hosted version is available as well.
The important distinction for procurement is that self-hosting puts much more of the contractual/privacy responsibility on your organization and infrastructure provider. In other words, you gain deployment and data-location control, but shouldn't treat that automatically as equivalent to having a vendor DPA.
Best fit when: infrastructure ownership/control matters more than having extensive vendor-managed compliance documentation.
PostHog is worth including if by "analytics" you mean product analytics—events, funnels, user behavior, session replay, feature flags, etc.—rather than primarily website traffic analytics. It has both managed and self-hosting options.
It can therefore satisfy the deployment/export/governance requirements, but its larger product-analytics feature set means there are more categories of potentially sensitive telemetry to govern.
Best fit when: you need product analytics rather than a lightweight privacy-first website counter.
For the specific requirements you listed, I'd structure the evaluation like this:
When looking for privacy-focused web analytics that cover all bases—**managed (cloud) and self-hosted deployment options, built-in retention controls, deletion workflows, data exports, and formal contractual privacy terms (like a Data Processing Agreement or DPA)** —only a few mature platforms check every single box.…
When looking for privacy-focused web analytics that cover all bases—managed (cloud) and self-hosted deployment options, built-in retention controls, deletion workflows, data exports, and formal contractual privacy terms (like a Data Processing Agreement or DPA) —only a few mature platforms check every single box.
Below are the top privacy-first analytics tools that fit these criteria, along with how they handle each requirement.
Matomo is the most feature-complete, enterprise-grade open-source alternative to Google Analytics. It is explicitly built to comply with strict regulations like the GDPR and CCPA.
Plausible is a lightweight, open-source web analytics tool designed to be privacy-friendly, cookie-banner-free, and simple.
PostHog is an all-in-one product analytics suite (including session replays, feature flags, and web analytics) that heavily emphasizes transparent, privacy-first controls.
| Feature / Requirement | Matomo | Plausible | PostHog |
|---|---|---|---|
| Self-Hosted Option | Yes (Free On-Premise) | Yes (Community Edition) | Yes (Open-Source/Docker) |
| Managed Cloud Option | Yes (Matomo Cloud) | Yes (Plausible Cloud) | Yes (PostHog Cloud) |
| Retention / Purge Controls | Automated raw log purging | Manual/Account-level wipe | Advanced person/data deletion |
| Data Exports | CSV, API, Data Warehouse | CSV, Stats API | API, Data Warehouse sync |
| Contractual DPA Available | Yes (Cloud) | Yes (Cloud) | Yes (Cloud) |
If you want to narrow this down, let me know:
If by “privacy-focused analytics” you mean **a tool that can satisfy a procurement/compliance checklist across managed cloud and self-hosting, configurable retention, deletion workflows, exports, and contractual privacy terms**, the strongest options are **Matomo and Plausible**, with **Umami** worth considering if…
If by “privacy-focused analytics” you mean a tool that can satisfy a procurement/compliance checklist across managed cloud and self-hosting, configurable retention, deletion workflows, exports, and contractual privacy terms, the strongest options are Matomo and Plausible, with Umami worth considering if you want a simpler/open-source stack.
| Tool | Managed cloud | Self-hosted | Retention controls | Deletion workflows | Data exports | Contractual privacy terms |
|---|---|---|---|---|---|---|
| Matomo | ✅ | ✅ | Strong | Strong | ✅ | Strong for Cloud |
| Plausible | ✅ | ✅ | Good | Strong | Strong | Strong |
| Umami | ✅ | ✅ | ◐ | ✅ | Strong | ◐ |
| PostHog | ✅ | ✅/open-source components | Strong | Strong | Strong | Strong |
Matomo is probably the most complete match if you need explicit administrative controls.
Best fit: organizations that need granular retention/purge controls and a mature compliance story.
Plausible has an unusually clean combination of hosted and self-hosted deployment.
Caveat: Plausible is deliberately minimalist. If you need extensive raw-event/user-level analytics and sophisticated deletion/retention administration, Matomo is generally the stronger choice.
Umami offers both a managed Cloud service and self-hosting, with the same open-source platform in either deployment model. Its self-hosted model keeps the data on your own infrastructure.
It also explicitly supports full data exports, rather than limiting you to summarized dashboard metrics.
I'd put it behind Matomo/Plausible for a stringent vendor-contract checklist, though, because the publicly documented contractual/DPA story isn't as extensive.
PostHog is a different category: it's much more oriented toward product/event analytics, funnels, feature flags, session replay, etc. rather than lightweight privacy-preserving website analytics. The self-hosted analytics landscape generally categorizes it as product analytics.
It's therefore attractive when your requirement is closer to “privacy-conscious alternative to Mixpanel/Amplitude,” rather than “privacy-conscious Google Analytics replacement.”
If I were turning your requirements into a vendor evaluation:
One important procurement distinction: “self-hosted” and “has a DPA” aren't necessarily complementary requirements. With self-hosting, the analytics vendor generally isn't processing your production visitor data as a processor; your own organization and infrastructure providers take on that responsibility. Matomo explicitly makes this distinction.
If you give me your exact checklist (e.g. GDPR/CCPA, SOC 2/ISO 27001, configurable retention ≤90 days, DSAR deletion, API export, EU residency, signed DPA, SSO), I can turn this into a requirements-by-requirements comparison matrix and identify which vendors actually meet each one.
PostHog is a different category: it's much more oriented toward product/event analytics, funnels, feature flags, session replay, etc. rather than lightweight privacy-preserving website analytics. The self-hosted analytics landscape generally categorizes it as product analytics.
It's therefore attractive when your requirement is closer to “privacy-conscious alternative to Mixpanel/Amplitude,” rather than “privacy-conscious Google Analytics replacement.”
A select group of privacy-focused analytics platforms bridge the gap between compliance, data autonomy, and enterprise-grade controls. These tools offer both **managed (cloud)** and **self-hosted (on-premise / private cloud)** deployments while supporting granular data retention, explicit deletion workflows, data…
A select group of privacy-focused analytics platforms bridge the gap between compliance, data autonomy, and enterprise-grade controls. These tools offer both managed (cloud) and self-hosted (on-premise / private cloud) deployments while supporting granular data retention, explicit deletion workflows, data portability, and formal legal terms.
Would you like to narrow these options down by evaluating their infrastructure requirements (like RAM or database engines like ClickHouse vs. PostgreSQL) or comparing their pricing models for managed tiers?
Finding a privacy-focused analytics platform that cleanly bridges the gap between **managed (cloud)** and **self-hosted** deployments—while fully supporting **retention controls, deletion workflows, data exports, and enterprise contractual privacy terms (DPAs)** —narrows the field to a few mature, open-core or…
Finding a privacy-focused analytics platform that cleanly bridges the gap between managed (cloud) and self-hosted deployments—while fully supporting retention controls, deletion workflows, data exports, and enterprise contractual privacy terms (DPAs) —narrows the field to a few mature, open-core or dual-licensed leaders.
When you self-host, contractual data processing agreements (DPAs) with a vendor dissolve because you act as your own data controller. However, these top tools provide the dual capability: formal contractual terms (like GDPR-compliant DPAs) for their managed cloud tiers, alongside identical codebases or robust administrative tools for self-hosting.
Matomo is arguably the most comprehensive enterprise-grade alternative to Google Analytics that natively satisfies every single requirement on your list for both deployment types.
Originally built for product analytics, PostHog has evolved into an all-in-one suite (analytics, feature flags, session replays) with an aggressive commitment to data transparency.
Plausible is lightweight, cookieless, and privacy-first by design. It draws a hard line against personal data collection.
| Feature / Requirement | Matomo | PostHog | Plausible |
|---|---|---|---|
| Self-Hosted Option | Yes (Open source / On-Premise) | Yes (Docker / Kubernetes) | Yes (AGPL Community Edition) |
| Managed Cloud Option | Yes (Matomo Cloud) | Yes (PostHog Cloud) | Yes (Plausible Cloud) |
| Retention & Purge Controls | Extremely granular (scheduled log/report deletion) | Event/Person deletion and batch retention | Minimal footprint (aggregate-focused) |
| Data Export Capabilities | API, scheduled raw data logs, CSV/JSON | Data warehouse sync, API, CSV | Direct CSV dashboard download |
| Contractual Terms (DPA) | Formal Cloud DPA available | Enterprise DPA available | EU-based DPA available |
Would you like to narrow these down based on your expected monthly traffic volume , or do you need a deep dive into the infrastructure resource requirements (RAM/CPU) for self-hosting one of them?
If you mean **analytics platforms that can satisfy all of these procurement/privacy requirements**—managed hosting *and* self-hosting, configurable retention, deletion workflows, data export, and contractual privacy terms—the strongest candidates are **Matomo** and **Plausible**. **Umami** is worth considering for a…
If you mean analytics platforms that can satisfy all of these procurement/privacy requirements—managed hosting and self-hosting, configurable retention, deletion workflows, data export, and contractual privacy terms—the strongest candidates are Matomo and Plausible. Umami is worth considering for a lighter/open-source stack, but its contractual/compliance documentation is less mature.
| Tool | Managed + self-hosted | Retention controls | Deletion workflows | Data exports | Contractual privacy terms | Overall |
|---|---|---|---|---|---|---|
| Matomo | ✅ Cloud + On-Premise | ✅ Extensive | ✅ Individual/user + scheduled deletion | ✅ API/export | ✅ Cloud DPA + ToS | Best enterprise fit |
| Plausible | ✅ Cloud + Community Edition | ✅ Cloud retention tiers; self-host gives infrastructure control | ✅ Site/account deletion | ✅ Stats API; raw exports on Enterprise | ✅ DPA + ToS | Best simple/privacy-first fit |
| Umami | ✅ Cloud + self-hosted | ✅ | ✅, especially with self-hosting/database control | ✅ API/database | ⚠️ Less extensive vendor-contract framework | Best lightweight OSS option |
| PostHog | ✅ Cloud + self-hosting, but self-hosting has important support limitations | ✅ Strong product-data controls | ✅ Strong | ✅ API/data pipelines | ✅ Enterprise privacy agreements | Best for product analytics, not pure privacy analytics |
Matomo is the clearest match if this is an enterprise/vendor-risk checklist.
Verdict: If your checklist is for legal, security, or procurement review, Matomo is probably the safest first choice.
Plausible Analytics is particularly attractive if you don't need Matomo's extensive visitor-level functionality.
Caveat: Plausible intentionally collects less than Matomo, so if your deletion requirement means “find and erase every event associated with a particular identifiable user”, verify that its aggregate-oriented model meets your exact requirement.
Umami Analytics offers both Cloud and self-hosting and is MIT-licensed. It is a strong option when data sovereignty and operational simplicity matter more than enterprise compliance paperwork.
The main issue isn't the technology: self-hosting gives you substantial control over retention, deletion, backups and exports. The question is whether Umami's current Cloud contractual documentation satisfies your organization's DPA, subprocessors, breach-notification, transfer and deletion requirements.
I'd therefore put it behind Matomo/Plausible for a regulated procurement process.
PostHog supports strong retention, deletion and export capabilities and is much more capable for identified product analytics, funnels, session replay, feature flags and experimentation.
However, its self-hosting story is materially different from Matomo: current comparisons note that PostHog's self-hosted deployment is officially unsupported/unversioned, so it shouldn't automatically be treated as equivalent to a supported on-premise enterprise deployment.
So I'd select PostHog if your requirement is product analytics, rather than simply “privacy-preserving website analytics.”
For the requirements you gave, I'd rank them:
The important distinction is that “self-hosted” does not itself satisfy contractual privacy requirements. For Cloud deployments, you should specifically verify the DPA, subprocessors, international-transfer mechanism, breach obligations, deletion/return clause, retention commitments, and whether backups are covered.
If you want, I can also turn this into a procurement-style 20–30 criterion comparison covering GDPR/CCPA, DPA/SCCs, EU/US hosting, SSO, audit logs, RBAC, user-level deletion, API exports, backup deletion, retention granularity, and self-hosting support.
PostHog supports strong retention, deletion and export capabilities and is much more capable for identified product analytics, funnels, session replay, feature flags and experimentation.
However, its self-hosting story is materially different from Matomo: current comparisons note that PostHog's self-hosted deployment is officially unsupported/unversioned, so it shouldn't automatically be treated as equivalent to a supported on-premise enterprise deployment.
So I'd select PostHog if your requirement is product analytics, rather than simply “privacy-preserving website analytics.”
For the requirements you gave, I'd rank them:
Yes. If your checklist is specifically **managed + self-hosted deployment, configurable retention, deletion workflows, data export, and contractual privacy terms (DPA/terms)**, the strongest options are **Plausible** and **Matomo**. [Plausible…
Yes. If your checklist is specifically managed + self-hosted deployment, configurable retention, deletion workflows, data export, and contractual privacy terms (DPA/terms), the strongest options are Plausible and Matomo.
| Tool | Managed | Self-hosted | Retention controls | Deletion | Exports | Contractual privacy terms |
|---|---|---|---|---|---|---|
| Plausible Analytics | ✅ Cloud | ✅ Community Edition | ✅ Configurable/enterprise options | ✅ Account/site deletion | ✅ CSV, API; raw-event exports on Enterprise | ✅ DPA automatically applies |
| Matomo | ✅ Cloud | ✅ On-Premise | ✅ Detailed raw/report retention | ✅ Automated raw-data deletion + deletion tools | ✅ Extensive export/API options | ✅ Cloud DPA; self-hosted means you control the processing relationship |
| PostHog | ✅ Cloud | ⚠️ Self-host available, but governance/operational model differs | ✅ Strong retention controls | ✅ User/event deletion capabilities | ✅ APIs/data warehouse integrations | ✅ Commercial privacy/DPA documentation |
1. Plausible — best for straightforward privacy-first web analytics. Plausible offers the same core software as managed Cloud and self-hosted Community Edition. Cloud data is hosted on EU-owned infrastructure, while self-hosting gives you control over location and infrastructure.
It supports CSV/API exports, including full historical exports, and Enterprise customers can arrange scheduled raw-event exports to S3-compatible storage. Plausible Analytics You can permanently delete an account or individual site data. Plausible Analytics Its current compliance documentation says a DPA applies automatically to customers and covers processor responsibilities, data location, breach notification, and subprocessors.
2. Matomo — best when governance and retention granularity matter most. Matomo has both Cloud and On-Premise deployments and supports migration between them. Analytics Platform - Matomo Its retention system can distinguish different categories of data and automatically delete old raw data, while report data can have different retention requirements.
For Cloud, Matomo provides a formal DPA. For On-Premise, Matomo explicitly says there isn't a Matomo DPA because you're running the processing infrastructure yourself; your relevant subprocessors can provide their own DPAs.
If "contractual privacy terms" means you need a vendor to sign a DPA as your processor, managed Matomo Cloud and managed Plausible are the cleanest fits.
If instead you need maximum data sovereignty, self-hosted Matomo or Plausible is stronger: you control the database, retention jobs, backups, deletion process, and hosting jurisdiction. But you also take on responsibility for those controls.
My shortlist:
If you tell me whether this is for GDPR/UK GDPR, HIPAA, SOC 2 procurement, or a general enterprise privacy review, I can turn this into a vendor due-diligence matrix with specific evidence for each requirement.
1. Plausible — best for straightforward privacy-first web analytics. Plausible offers the same core software as managed Cloud and self-hosted Community Edition. Cloud data is hosted on EU-owned infrastructure, while self-hosting gives you control over location and infrastructure.
It supports CSV/API exports, including full historical exports, and Enterprise customers can arrange scheduled raw-event exports to S3-compatible storage. Plausible Analytics You can permanently delete an account or individual site data. Plausible Analytics Its current compliance documentation says a DPA applies automatically to customers and covers processor responsibilities, data location, breach notification, and subprocessors.
2. Matomo — best when governance and retention granularity matter most. Matomo has both Cloud and On-Premise deployments and supports migration between them. Analytics Platform - Matomo Its retention system can distinguish different categories of data and automatically delete old raw data, while report data can have different retention requirements.
For Cloud, Matomo provides a formal DPA. For On-Premise, Matomo explicitly says there isn't a Matomo DPA because you're running the processing infrastructure yourself; your relevant subprocessors can provide their own DPAs.
If "contractual privacy terms" means you need a vendor to sign a DPA as your processor, managed Matomo Cloud and managed Plausible are the cleanest fits.
Evaluating privacy-focused analytics options requires examining how they balance compliance and data ownership across both cloud-managed and self-hosted deployments. Several prominent privacy-first analytics tools meet these specific criteria (managed/self-hosted deployment, retention controls, deletion workflows,…
Evaluating privacy-focused analytics options requires examining how they balance compliance and data ownership across both cloud-managed and self-hosted deployments.
Several prominent privacy-first analytics tools meet these specific criteria (managed/self-hosted deployment, retention controls, deletion workflows, data exports, and contractual privacy terms like a DPA):
If you're narrowing down your choice, let me know:
I can help you select the best fit for your tech stack.
If your requirement is specifically **managed + self-hosted deployment, configurable retention, deletion workflows, data export, and contractual privacy terms (DPA/processor terms)**, the shortlist narrows considerably. Tool | Managed cloud | Self-hosted | Retention controls | Deletion workflow | Data export |…
If your requirement is specifically managed + self-hosted deployment, configurable retention, deletion workflows, data export, and contractual privacy terms (DPA/processor terms), the shortlist narrows considerably.
| Tool | Managed cloud | Self-hosted | Retention controls | Deletion workflow | Data export | Contractual privacy terms | Overall fit |
|---|---|---|---|---|---|---|---|
| Matomo | ✅ | ✅ Full-featured | ✅ Strong/configurable | ✅ | ✅ | ✅ Cloud DPA | Excellent |
| Plausible Analytics | ✅ | ✅ Community Edition | ✅ | ✅ | ✅ | ✅ DPA | Excellent for web analytics |
| Umami | ✅ | ✅ Same open-source platform | ⚠️ More operator-controlled self-hosted | ✅ via platform/admin controls | ✅ Full export/API | ⚠️ Cloud contractual terms need procurement review | Very good |
| PostHog | ✅ | ⚠️ Available, but substantially more operationally complex | ✅ | ✅ | ✅ | ✅ Cloud contractual terms | Good for product analytics |
Matomo is probably the best match if governance requirements are the priority.
Its Cloud offering has a formal DPA, configurable retention, export/return provisions, and deletion commitments. The current DPA says customer personal data is deleted within 30 days after termination, with encrypted backups potentially retained for up to 60 days for backup-integrity purposes. It also explicitly says retention periods can be configured by the customer.
Self-hosting gives you substantially more control because the analytics database and infrastructure are yours. Importantly, Matomo distinguishes this from its Cloud contractual relationship: there is no Matomo DPA for self-hosted Matomo itself, because Matomo isn't processing the data for you.
Best when: you need enterprise web analytics, auditability, granular privacy controls, and a credible self-hosted deployment.
Plausible Analytics is particularly attractive if you don't need individual-level product analytics.
Its DPA applies automatically to customers and covers processor responsibilities, subprocessors, breach notification and deletion instructions. Customers can delete sites/accounts, and Plausible states that data is permanently deleted without undue delay after deletion.
It also provides exports: after cancellation, customers can still export collected data before the eventual deletion.
The Community Edition can be self-hosted, although it doesn't have feature parity with Cloud.
Best when: privacy-by-default, minimal collection, EU hosting, and straightforward data governance matter more than sophisticated behavioral analytics.
Umami has an unusually clean deployment model: the same open-source platform can be run as managed Cloud or on your own infrastructure. Umami explicitly says that with self-hosting, your data never leaves your infrastructure. It also offers full data export and a REST API.
It supports events, funnels, journeys, retention analysis, and sessions while maintaining a privacy-first model.
The caveat is contractual/privacy documentation: compared with Matomo and Plausible, I'd want procurement/legal to examine Umami Cloud's current DPA, subprocessors, deletion commitments and backup-retention language before treating it as an enterprise-grade contractual match.
Best when: you want one lightweight OSS product that can move between Cloud and infrastructure you control.
PostHog is the outlier. It is much more capable for product analytics—events, funnels, retention, session replay, feature flags, etc.—but that also means considerably more data and operational complexity.
It has a Cloud offering and a self-hosting path, but PostHog itself has acknowledged that self-hosting has become difficult because of the breadth of the platform; its current strategy emphasizes Cloud, with self-hosting retained primarily for users who want it.
So I'd choose PostHog when product behavior and experimentation are the core requirement, rather than when the main goal is simple privacy-preserving website measurement.
One important distinction: self-hosting isn't itself a privacy contract. It moves the controller/operator responsibilities to you. For a vendor assessment, I'd separately verify the exact DPA, subprocessors, data residency, backup deletion period, retention configuration, DSAR/deletion mechanism, export format/API, and termination data-return clause for the version/plan you're buying.
If you're building a vendor-selection matrix for procurement/security review, I can also turn this into a detailed 15–20 criterion comparison (DPA, SCCs, HIPAA/BAA, SOC 2/ISO 27001, EU residency, encryption, RBAC, audit logs, retention, deletion, backups, exports, API, self-hosting, and support).
Self-hosting gives you substantially more control because the analytics database and infrastructure are yours. Importantly, Matomo distinguishes this from its Cloud contractual relationship: there is no Matomo DPA for self-hosted Matomo itself, because Matomo isn't processing the data for you.
Best when: you need enterprise web analytics, auditability, granular privacy controls, and a credible self-hosted deployment.
Plausible Analytics is particularly attractive if you don't need individual-level product analytics.
Its DPA applies automatically to customers and covers processor responsibilities, subprocessors, breach notification and deletion instructions. Customers can delete sites/accounts, and Plausible states that data is permanently deleted without undue delay after deletion.
It also provides exports: after cancellation, customers can still export collected data before the eventual deletion.
The Community Edition can be self-hosted, although it doesn't have feature parity with Cloud.
Best when: privacy-by-default, minimal collection, EU hosting, and straightforward data governance matter more than sophisticated behavioral analytics.
Umami has an unusually clean deployment model: the same open-source platform can be run as managed Cloud or on your own infrastructure. Umami explicitly says that with self-hosting, your data never leaves your infrastructure. It also offers full data export and a REST API.
It supports events, funnels, journeys, retention analysis, and sessions while maintaining a privacy-first model.
The caveat is contractual/privacy documentation: compared with Matomo and Plausible, I'd want procurement/legal to examine Umami Cloud's current DPA, subprocessors, deletion commitments and backup-retention language before treating it as an enterprise-grade contractual match.
Best when: you want one lightweight OSS product that can move between Cloud and infrastructure you control.
PostHog is the outlier. It is much more capable for product analytics—events, funnels, retention, session replay, feature flags, etc.—but that also means considerably more data and operational complexity.
Several prominent privacy-focused analytics platforms successfully meet all of these requirements—providing both **managed (cloud)** and **self-hosted (on-premise/private cloud)** deployment options, configurable data retention controls, deletion workflows, data export features, and formal contractual privacy terms…
Several prominent privacy-focused analytics platforms successfully meet all of these requirements—providing both managed (cloud) and self-hosted (on-premise/private cloud) deployment options, configurable data retention controls, deletion workflows, data export features, and formal contractual privacy terms (like a Data Processing Agreement / DPA) for their managed tiers.
The top industry solutions that check every box include:
Comparison Matrix at a Glance
| Feature / Requirement | Matomo | PostHog | Plausible |
|---|---|---|---|
| Managed & Self-Hosted | Yes | Yes | Yes |
| Retention Controls | Advanced (Log vs. Aggregated) | Advanced (Event/Person level) | Minimal/Cookieless by default |
| Deletion Workflows | Automated cron/database purges | API & Project-level deletion | Manual/Instance level |
| Data Exports | CSV, API, BigQuery | Batch/Warehouse exports, API | CSV, JSON API |
| Contractual DPA | Yes (Cloud tier) | Yes (Cloud tier) | Yes (Cloud tier) |
If you have a preference regarding the infrastructure stack (e.g., Elixir vs. PHP/MySQL vs. Kubernetes/ClickHouse) or need specific compliance frameworks like HIPAA or CCPA , let me know and I can narrow down the best fit.