Respectlytics Respect lytics
Menu
Replace Matomo Mobile No PII collected

Replace Matomo Mobile to stop collecting personal data in analytics

Migrate from Matomo Mobile to Respectlytics. 5-field event schema enforces no PII at the API boundary. Helps developers avoid collecting personal data.

Example Matomo Mobile call (the "before")

swift Respectlytics
import MatomoTracker

let tracker = MatomoTracker(siteId: "1", baseURL: URL(string: "https://your-matomo.example.com/matomo.php")!)
tracker.userId = userId

let event = Event(
    tracker: tracker,
    action: ["purchase"],
    eventCategory: "ecommerce",
    eventAction: "purchase",
    eventName: "paywall",
    eventValue: NSNumber(value: price).floatValue
)
tracker.track(event)

Most analytics SDKs accept arbitrary event parameters — the path of least resistance for an engineer adds user_id, email, phone, address to events over time. Respectlytics's 5-field event schema (event_name, session_id, timestamp, platform, country) rejects extra fields at the API with a 400 — making PII drift architecturally impossible.

Remove Matomo Mobile cleanly

  1. 1

    Remove the Matomo SDK from your build (MatomoTracker / org.matomo.sdk:tracker / matomo_tracker)

  2. 2

    Remove Tracker.builder().build() initialisation and track(...) call sites

  3. 3

    Decide whether your Matomo server stays online (for web traffic) or gets decommissioned

  4. 4

    If you used Matomo's visitor segments alongside web data, plan how you'll bridge web ⇄ mobile analytics under Respectlytics (web isn't Respectlytics's primary surface)

Matomo Mobile vs Respectlytics — no pii collected

Matomo MobileRespectlytics
Accepts arbitrary event parametersYes (per-event params or properties)No (5-field schema, extras rejected with 400)
Persistent user identifier— see tool note aboveNo (session_id rotates every 2h, RAM-only)
IP address stored— see tool note aboveUsed transiently to derive country, then discarded
Per-user historical record— see tool note aboveOut of scope (use your account system)

Frequently asked questions

How do we attribute revenue to a specific user without `user_id`?

You don't — at least not in your analytics. Your billing system (Stripe, RevenueCat, App Store Connect) is the authoritative source of per-user revenue, with refund-aware totals and the appropriate access controls. Respectlytics tells you the product signal (conversion rate, funnel completion) at the session level; per-user revenue lives where it belongs.

What if our analytics team needs to slice by user segment (paid vs free)?

Encode the segment into the event name. Instead of track('paywall_view', { tier: 'paid' }), fire track('paywall_view_paid_user') and track('paywall_view_free_user'). The aggregation buckets them automatically; no per-user identity is stored.

Doesn't the country field count as personal data?

Country-only resolution is generally considered the most minimised form of geographic data and is widely accepted in privacy reviews — but consult your legal team to determine your specific situation. Respectlytics derives country from the request IP server-side, then discards the IP before storing the event.

What happens if a teammate accidentally adds an extra field to a `track` call?

The API returns a 400 with the offending field name in the response body. Your integration test fails on the first run that includes the new field, so the regression is caught at PR review — not after months of unnoticed silent PII collection.

Related migration guides

Track what matters. Collect nothing you don't.

Five-field event schema, RAM-only event queue, no IDFA, no AAID, no persistent user IDs. Helps developers avoid collecting personal data in the first place.