Analytics for builders who develop with AI coding agents — cookieless by default. You do not copy a snippet or hunt for a measurement ID — your agent instruments the app over MCP and verifies the first event arrived. One dashboard to read. One flat price.
No cookies. No personal data stored by design. No signup to start — the project your agent creates is anonymous, and you can claim it later.
The MCP server runs on your machine and carries only a project API key — never database or analytics credentials.
Register the MCP server
Claude Code — once, for every project:
claude mcp add numai -s user -- npx -y https://numai.aimgonna.com/numai-mcp.tgz
Cursor — the same server in .cursor/mcp.json:
{
"mcpServers": {
"numai": {
"command": "npx",
"args": ["-y", "https://numai.aimgonna.com/numai-mcp.tgz"]
}
}
}The server runs on your machine and holds nothing but a project API key. It acts on the directory your agent was started in.
Tell your agent: "add analytics to this app"
That sentence is the whole setup. What the agent does with it:
create_project — an anonymous project, no account, no card. The id, API key and claim URL land in .numai.json, which is added to .gitignore for you.install_snippet — called first without apply, so it returns a diff and a plan_token. You read the diff; the agent calls again with apply: true and that token, which binds the write to what you approved. It adds the tracker to your root layout and a first-party /api/nm route — the tracker is served from your own origin and events are forwarded from it, so ad blockers never see a third-party analytics host.verify_ingestion — polls for up to 60 seconds and echoes the events that actually landed. "It works" is backed by rows, and if the first hit came from a headless browser you are told it was classified as bot traffic instead of being shown an empty screen.Ask for numbers where you already are
"How did yesterday look?" or "did that deploy move signups?" runs against query in the terminal. The dashboard reads the same three queries when you want to look rather than ask.
| Tool | What it does |
|---|---|
| create_project | Creates a project with no account and no signup, returns an API key plus a claim URL. Idempotent per directory. |
| install_snippet | Next.js App Router. Previews a diff with a plan_token, then applies exactly what you approved. |
| rollback_install | Restores the files the install touched. Files edited since then are left alone. |
| track_event | Returns the exact call and placement rules for a custom event you asked for. |
| verify_ingestion | Polls up to 60s and echoes the events that actually landed, bot flag included. |
| query | overview, same-day funnel, and before/after a deploy. Bots excluded. |
PostHog is a platform of thirteen products. numai is one product your agent attaches in five minutes. The difference is not the free event limit — it is that there is one dashboard to read, the price is flat, and the agent finishes both instrumentation and verification. If GA4 was too much, PostHog is another GA4.
You are not paying for an event ceiling. You are paying for the agent automation around it — instrumentation that stays correct, and reports after each deploy.
Free
$0 / month
Flat
$9 / month
Bot-flagged events are never billed. Every project also has a hard cap, so no single site can run up a surprise.
No cookies. No personal data stored by design.
utm_*, ref and source are kept, so campaign attribution survives and the rest does not arrive at all: the tracker drops it before sending, and the collector drops it again on receipt.gclid and fbclid are dropped too — most tools keep them. They identify one ad click, and the platform that issued them can join that back to a person, which is the kind of identifier this is supposed not to hold. Campaign-level attribution works without them.sessionStorage remembers which campaign or referrer this visit arrived from, so a signup ten pages later is still credited to it. It holds a channel, not an id, and the tab closing ends it.What we do not claim. We will not tell you that this removes your consent-banner decision — that is not ours to make. EDPB Guidelines 2/2023 treat a hashed IP and user agent as potentially in scope of ePrivacy 5(3), and some regulators do not accept cookieless as consent-free by default. What we hand you instead is the documentation to decide with your own counsel: exactly what is collected, what is discarded, and when.
These limits follow from not identifying people. We print them here rather than letting you discover them in a number that looked wrong. They are the price of the default, not a wall: a project that needs retention or a funnel across days can turn on identified mode and pay a different price — the item on returning visitors below says what that price is. It is decided per project rather than for you.
/orders/a1b2c3 — that identifier is stored. Nothing here can tell a product slug from a share token. If your URLs carry something you would not keep, that is worth knowing before you install rather than after.