numaiprivate beta

Analytics your coding agent installs, and proves it works.

Analytics for builders who develop with AI coding agents — cookieless by default. You do not copy a snippet or hunt for a measurement ID — your agent instruments the app over MCP and verifies the first event arrived. One dashboard to read. One flat price.

No cookies. No personal data stored by design. No signup to start — the project your agent creates is anonymous, and you can claim it later.

Install: register the server, then say one sentence

The MCP server runs on your machine and carries only a project API key — never database or analytics credentials.

  1. Register the MCP server

    Claude Code — once, for every project:

    claude mcp add numai -s user -- npx -y https://numai.aimgonna.com/numai-mcp.tgz

    Cursor — the same server in .cursor/mcp.json:

    {
      "mcpServers": {
        "numai": {
          "command": "npx",
          "args": ["-y", "https://numai.aimgonna.com/numai-mcp.tgz"]
        }
      }
    }

    The server runs on your machine and holds nothing but a project API key. It acts on the directory your agent was started in.

  2. Tell your agent: "add analytics to this app"

    That sentence is the whole setup. What the agent does with it:

    • create_project — an anonymous project, no account, no card. The id, API key and claim URL land in .numai.json, which is added to .gitignore for you.
    • install_snippet — called first without apply, so it returns a diff and a plan_token. You read the diff; the agent calls again with apply: true and that token, which binds the write to what you approved. It adds the tracker to your root layout and a first-party /api/nm route — the tracker is served from your own origin and events are forwarded from it, so ad blockers never see a third-party analytics host.
    • verify_ingestion — polls for up to 60 seconds and echoes the events that actually landed. "It works" is backed by rows, and if the first hit came from a headless browser you are told it was classified as bot traffic instead of being shown an empty screen.
  3. Ask for numbers where you already are

    "How did yesterday look?" or "did that deploy move signups?" runs against query in the terminal. The dashboard reads the same three queries when you want to look rather than ask.

ToolWhat it does
create_projectCreates a project with no account and no signup, returns an API key plus a claim URL. Idempotent per directory.
install_snippetNext.js App Router. Previews a diff with a plan_token, then applies exactly what you approved.
rollback_installRestores the files the install touched. Files edited since then are left alone.
track_eventReturns the exact call and placement rules for a custom event you asked for.
verify_ingestionPolls up to 60s and echoes the events that actually landed, bot flag included.
queryoverview, same-day funnel, and before/after a deploy. Bots excluded.

Why not PostHog?

PostHog is a platform of thirteen products. numai is one product your agent attaches in five minutes. The difference is not the free event limit — it is that there is one dashboard to read, the price is flat, and the agent finishes both instrumentation and verification. If GA4 was too much, PostHog is another GA4.
  • A write MCP loop, not a read-only one. Other lightweight tools expose analytics to an agent so it can ask questions. Here the agent changes the code, gets your approval on the diff, and then confirms the data arrived.
  • Cookieless and first-party by default — not an option you have to find, and not a CNAME record you set up yourself.
  • Flat pricing. One number per month, whatever the traffic does.

Pricing

You are not paying for an event ceiling. You are paying for the agent automation around it — instrumentation that stays correct, and reports after each deploy.

Free

$0 / month

  • 3 projects
  • 100,000 events per month
  • No card required
  • Full MCP toolset

Flat

$9 / month

  • Unlimited projects
  • 1,000,000 events per month
  • Soft cap: over the limit we sample and tell you, rather than bill you
  • Deploy comparison reports

Bot-flagged events are never billed. Every project also has a hard cap, so no single site can run up a surprise.

Privacy

No cookies. No personal data stored by design.

  • Visitors are counted with a hash of a daily-rotating salt, the project id, the IP and the user agent. The salt changes every day, so yesterday cannot be linked to today.
  • Raw IP and user agent are never stored. Country and region, and coarse browser / OS / device buckets, are derived at the edge and the originals are discarded.
  • The query string is dropped, not stored. A URL's parameters are your data — a date of birth, a coordinate, a reset token, whatever someone typed into a search box — and you never asked for them to be collected. Only utm_*, ref and source are kept, so campaign attribution survives and the rest does not arrive at all: the tracker drops it before sending, and the collector drops it again on receipt.
  • gclid and fbclid are dropped too — most tools keep them. They identify one ad click, and the platform that issued them can join that back to a person, which is the kind of identifier this is supposed not to hold. Campaign-level attribution works without them.
  • No cookies, no localStorage, no cross-site identifier. Nothing follows a visitor to another site. One thing is kept in the browser and it is not a person: sessionStorage remembers which campaign or referrer this visit arrived from, so a signup ten pages later is still credited to it. It holds a channel, not an id, and the tab closing ends it.
  • Collection runs through a route on your own domain, so a visitor's browser never makes a request to a third-party analytics host.

What we do not claim. We will not tell you that this removes your consent-banner decision — that is not ours to make. EDPB Guidelines 2/2023 treat a hashed IP and user agent as potentially in scope of ePrivacy 5(3), and some regulators do not accept cookieless as consent-free by default. What we hand you instead is the documentation to decide with your own counsel: exactly what is collected, what is discarded, and when.

What cookieless costs you

These limits follow from not identifying people. We print them here rather than letting you discover them in a number that looked wrong. They are the price of the default, not a wall: a project that needs retention or a funnel across days can turn on identified mode and pay a different price — the item on returning visitors below says what that price is. It is decided per project rather than for you.

  • Uniques are exact per day, not across days. The visitor hash rotates at midnight, so "visitors this week" is not a sum anyone can trust, and the dashboard does not print one.
  • Funnels are same-day only. A funnel spanning midnight would silently undercount, so the query is pinned to a single day instead.
  • Paths are stored in full — the query rule does not extend to them. A path is the one field analytics cannot do without, so if you put an identifier in one — /orders/a1b2c3 — that identifier is stored. Nothing here can tell a product slug from a share token. If your URLs carry something you would not keep, that is worth knowing before you install rather than after.
  • Acquisition counts person-days, not people. Compare sources against each other with it; do not read it as how many people found you. That number does not exist here, because getting it means following someone across days.
  • Returning visitors and multi-day retention need an id you supply. That is identified mode, and it ships: a project turns it on for itself, and from then on events may carry one field — your own user id for someone who already has an account. It is hashed on arrival with a per-project salt and the plaintext is never stored, but that hash does not rotate, which is the whole of what it buys and the whole of what it costs. It is also not retroactive. Turning it on makes you the one who tells your users what you collect.
  • Bots are stored, then excluded. Analytics leaves flagged rows out; the recent-events view shows them, so a first hit from curl reads as flagged rather than missing.
  • Delivery is best-effort in v0. One retry, then the batch is dropped. An explicit tradeoff, not an accident.