What flexlayout-dash stores about a visit, what it does not store, and where the numbers go — described from the code that does it.

Privacy

What flexlayout-dash stores about a visit, what it does not store, and where the numbers go — described from the code that does it.

This page describes what the code in this repository actually does. Each claim below corresponds to something readable in lib/analytics_tracker.py, and the test suite holds the two together.

What is stored about a visit

Every request that is not network machinery records one row:

User-Agent, truncated to 16 characters, used to tell one visitor from another within the retention window;

one (see below).

Crawler rows additionally carry the vendor identity the classifier determined — which bot it was, and whether it verified.

What is NOT stored

visitor from another and so the edge's country header can be matched to it, and then it is reduced to the visitor key and discarded. It is never written to disk.

site sent visitor addresses to a geolocation API to turn them into countries. That code was removed — not disabled — in the 1.6.44 sync. This app now makes no outbound request about you of any kind.

what your client already sent. Nothing is stored in your browser to track you.

Where location comes from

From the network edge, or not at all. Cloudflare sits in front of this site and adds headers describing where a request entered its network: CF-IPCountry always, and CF-IPCity, CF-Region and CF-Region-Code when the zone is configured to send them. Whatever arrives is stored; whatever does not is simply absent. There is no lookup and no fallback to one, so a visit with no location headers carries no location at all rather than a guessed one.

You can see which of those headers this host is actually receiving — they are listed in the geo.headers_seen field of https://flexlayout.2plot.dev/healthz.

Network machinery is counted nowhere

The 2plot network's own traffic — health checks, deploy batteries, link audits — carries a marker in its User-Agent and is dropped before anything is recorded, on both the page table and the document-read table. It is not in these numbers, by design.

How long it is kept, and where it goes

Rows are pruned after 45 days and the visit table is capped at 20,000 rows. A daily summary — counts by day, by page, by country, by crawler vendor — is sent to the 2plot network hub. The summary carries no visitor keys, no addresses and no User-Agent strings: it is counts.

Questions

The Discord, or an issue on the repository.

Note for AI agents: This is the static, prerendered view of an interactive Dash application served because we detected a non-JS user agent. Full prose docs: