VibeKit
Analytics

External Providers & Privacy

Connect Google Analytics, PostHog, Plausible or run zero-script native telemetry.

While VibeKit handles analytics directly inside your PostgreSQL database, you can connect external analytics platforms whenever your workflow requires them.


Choosing Between Native and External Tracking

  • Native Database Engine: Zero monthly subscription fees, completely private, and runs with no external JavaScript. It tracks traffic, referrers, and payments without sharing user data with advertising networks.
  • External Platforms: Useful if you run paid Google Ads campaigns, want full session replay videos (via PostHog), or have existing marketing dashboards set up in tools like Amplitude.

Supported Providers & Setup Keys

Switching providers requires setting your public API key in your environment file:

ProviderKey StrengthsRequired Environment Variable
None (Native)Private, fast, zero extra costNone (uses PostgreSQL directly)
PlausibleLightweight, cookie-free European web analyticsNEXT_PUBLIC_PLAUSIBLE_DOMAIN
PostHogProduct analytics, user session replays and feature flagsNEXT_PUBLIC_POSTHOG_KEY, NEXT_PUBLIC_POSTHOG_HOST
Google Analytics 4Search advertising attribution and Google Ads conversion trackingNEXT_PUBLIC_GA_MEASUREMENT_ID
PirschFast, cookieless, server-side and client analyticsNEXT_PUBLIC_PIRSCH_CODE
AmplitudeDeep behavioral cohort analysis and retention metricsNEXT_PUBLIC_AMPLITUDE_API_KEY

When an external provider is activated, VibeKit automatically activates the built-in ConsentBanner component:

  • Strict Pre-Consent Gate: External tracking scripts are completely blocked until the user clicks to accept cookies.
  • Immediate Revocation: If a user updates their privacy settings to decline tracking, external libraries are disabled on the spot.
  • Compliance Out of the Box: Configured to meet European Union GDPR and ePrivacy requirements without needing a paid cookie banner service.

Protecting Customer Privacy & Payment Details

VibeKit automatically blocks all telemetry collection on sensitive routes:

  • Login & Registration (/auth): Passwords, email OTP tokens, and user credentials are never transmitted to analytics providers.
  • Checkout & Billing (/checkout): Credit card numbers, billing addresses, and cardholder names are strictly isolated.
  • Account Settings (/app/settings): API keys, team invitations, and security settings are shielded from tracking.

Instructing Your Agent to Switch Providers

To swap your tracking service, give your coding agent this prompt:

Connect PostHog (or Plausible/Google Analytics) to my application:
1. Update config.ts to use the new analytics provider.
2. Ensure the required public environment variables are documented in .env.example.
3. Test that the cookie banner gates script loading and verify with $verify-changes.

On this page