Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
YouTube Security VideosTechLinked: MacOS 27 launch ain't looking so good(23.09.2026 um 21:00 Uhr)
•
YouTube Security VideosNeil Patel: Don't Just Be Right. Be Repeatable. #shorts(23.09.2026 um 20:04 Uhr)
••
YouTube Security VideosMicrosoft Mechanics: How to Share a Copilot Agent With Your Team(23.09.2026 um 20:30 Uhr)
••••
Sicherheitslücken (CVE)USN-8806-1: NetworkManager vulnerability(23.09.2026 um 15:24 Uhr)
•
Sicherheitslücken (CVE)USN-8807-1: Open-iSNS vulnerability(23.09.2026 um 19:07 Uhr)
•
Unix & Linux ServerUSN-8808-1: SQL parse vulnerabilities(23.09.2026 um 20:19 Uhr)
•
YouTube Security VideosTechLinked: MacOS 27 launch ain't looking so good(23.09.2026 um 21:00 Uhr)
•
YouTube Security VideosNeil Patel: Don't Just Be Right. Be Repeatable. #shorts(23.09.2026 um 20:04 Uhr)
••
YouTube Security VideosMicrosoft Mechanics: How to Share a Copilot Agent With Your Team(23.09.2026 um 20:30 Uhr)
••••
Sicherheitslücken (CVE)USN-8806-1: NetworkManager vulnerability(23.09.2026 um 15:24 Uhr)
•
Sicherheitslücken (CVE)USN-8807-1: Open-iSNS vulnerability(23.09.2026 um 19:07 Uhr)
•
Unix & Linux ServerUSN-8808-1: SQL parse vulnerabilities(23.09.2026 um 20:19 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

I Launched My Analytics Tool 3 Months Ago. It Got 1 Upvote. Here's What I Rebuilt.

The Original Problem (Still Valid) Google Analytics sends every user interaction to Google's servers. Every click, every session, every IP address — all of it leaves your infrastructure. For developers who care about user trust, that's a…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!




The Original Problem (Still Valid)



Google Analytics sends every user interaction to Google's servers. Every click, every session, every IP address — all of it leaves your infrastructure.



For developers who care about user trust, that's a problem.



The alternatives were either expensive (Mixpanel at $28/month), limited (Plausible gives you pageviews but no custom events or error tracking), or painful to self-host (Matomo).



So I built my own. The idea was solid. The execution needed work.









What Was Wrong With v1






Problem 1: API response time was 3-4 seconds



Every analytics event was being written to MongoDB synchronously, inside the request handler. Under any real load, this meant:




  • The /log endpoint was slow

  • Events were being dropped

  • The tracked application felt the impact



This was unacceptable for an analytics tool. Analytics should be invisible.






Problem 2: Wrong database schema for time-series data



I was storing analytics events as regular MongoDB documents. That works, but it's not optimized for what analytics actually is: time-ordered data queried by date range.



Queries like "show me the last 7 days" were doing full collection scans.






Problem 3: No separation of concerns



User data, analytics events, settings, API keys — all mixed together in MongoDB. No relational integrity, no proper foreign keys, no ACID transactions where they were needed.









What I Rebuilt






Fix 1: MongoDB Time-Series Collections



MongoDB has a purpose-built collection type for time-ordered data. I migrated all analytics events to Time-Series collections.



The result:





  • Automatic data bucketing by time — range queries are now index-native


  • Columnar compression — storage costs dropped significantly


  • Built-in TTL — data automatically expires after 6 months, no manual cleanup

  • API response: 3-4 seconds → 400ms



That's not a typo. The same query that took 3-4 seconds now runs in under 400ms.






Fix 2: Async Processing With BullMQ + Redis



The /log endpoint no longer writes to MongoDB directly. Every incoming event goes into a BullMQ job queue backed by Redis. A background worker processes the queue and writes to MongoDB asynchronously.




Client SDK
│
▼
Express API ──→ BullMQ Queue (Redis)
│
▼
Worker Process
│
▼
MongoDB Time-Series






The API endpoint now just validates the request and pushes to the queue — it responds in milliseconds. Events are processed in the background. Your application is never affected.






Fix 3: Polyglot Persistence



Analytics events belong in MongoDB Time-Series. But user accounts, project settings, API keys, and billing records are relational data — they have foreign key relationships and need ACID transactions.



I added PostgreSQL via Supabase for all relational data. Supabase also handles Row Level Security.



Now the data layer is:
























Data Type Database
Analytics events MongoDB Time-Series
Users, projects, settings PostgreSQL (Supabase)
Queue, caching, presence Redis


Each database does what it's best at. This is called polyglot persistence — and it's the right pattern for this kind of workload.






Fix 4: Real Infrastructure



v1 was running on a basic setup. v2 runs on:





  • Microsoft Azure VPS — backend server


  • Cloudflare CDN — global edge delivery, DDoS protection


  • PM2 — process management, zero-downtime restarts


  • Nginx — reverse proxy









New Features in v2



Beyond performance, I added features that were missing:





  • Scroll depth tracking — how far users actually scroll (Pro)


  • Core Web Vitals — LCP, FID, CLS from real users (Pro)


  • Domain ownership verification — DNS TXT record or meta tag, so you can only track sites you own


  • On-demand data deletion — delete individual events, date ranges, or everything from the dashboard


  • Free forever plan — no credit card, no expiry









The Current Stack
















































Layer Technology
SDK TypeScript, Beacon API, ~7.4KB gzipped
Frontend Dashboard Next.js, React, TypeScript, Tailwind CSS, Shadcn UI
Backend Node.js, Express, TypeScript
Analytics DB MongoDB Time-Series
Relational DB PostgreSQL via Supabase
Queue BullMQ + Redis
Auth Supabase Auth (OTP)
Infrastructure Microsoft Azure + Cloudflare
SDK Distribution npm + jsDelivr CDN








What the Dashboard Looks Like Now



The dashboard gives you:




  • Page views, sessions, bounce rate

  • Custom events with properties

  • JavaScript errors with stack traces

  • Referrers, UTM params, device/browser breakdown

  • User location (country/city only — IP is discarded immediately after geolocation)

  • Scroll depth heatmap (Pro)

  • Core Web Vitals from real users (Pro)



All without a single cookie. No consent banner required.









The Privacy Architecture (Unchanged, Still Core)



This didn't change between v1 and v2 because it was right from the start:





  • No IP storage — IPs are used for geolocation then immediately discarded


  • No cookies — session identity uses a daily-rotated hash, no persistent tracking


  • No cross-site tracking — your data stays in your project


  • No data selling — ever


  • GDPR, CCPA compliant — no consent banner needed because no tracking cookies









What I Learned From 1 Upvote



The product wasn't the problem. The launch was.



I posted on Product Hunt with a brand new account, no audience, no prior community engagement. The algorithm doesn't surface products from cold accounts. That's not a conspiracy — it's just how it works.



The lesson: build an audience before you need it.



I'm doing that now. Writing here, sharing on Twitter, building in public. If you're reading this, you're part of that process.









Try It






npm install ucoder-insight









import { initUcoderInsight } from 'ucoder-insight';

initUcoderInsight("YOUR_PROJECT_ID");






That's the entire setup. It auto-tracks page views, SPA navigation, JavaScript errors, and Core Web Vitals from that single line.








If you're building something and tired of sending your users' data to Google — give it a try.



And if you have feedback, I genuinely want to hear it. Drop a comment.






Built by Soumyadip Maity — Full Stack Developer, final year CS student, West Bengal, India.

Previously: I Was Tired of Sending My Users' Data to Google — So I Built My Own Analytics

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten I Launched My Analytics Tool 3 Months Ago. It Got 1 Upvote. Here's What I Rebuilt.

Thematisch verwandte Begriffe: Launched, Analytics, Tool, Months · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-90904 | Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) i…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel • Rechts: nächster Artikel • unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger • Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick