Analytics
External Providers & Privacy
Connect Google Analytics, PostHog, Plausible or run zero-script native telemetry.
While VibeKit handles analytics directly inside your PostgreSQL database, you can connect external analytics platforms whenever your workflow requires them.
Choosing Between Native and External Tracking
- Native Database Engine: Zero monthly subscription fees, completely private, and runs with no external JavaScript. It tracks traffic, referrers, and payments without sharing user data with advertising networks.
- External Platforms: Useful if you run paid Google Ads campaigns, want full session replay videos (via PostHog), or have existing marketing dashboards set up in tools like Amplitude.
Supported Providers & Setup Keys
Switching providers requires setting your public API key in your environment file:
| Provider | Key Strengths | Required Environment Variable |
|---|---|---|
| None (Native) | Private, fast, zero extra cost | None (uses PostgreSQL directly) |
| Plausible | Lightweight, cookie-free European web analytics | NEXT_PUBLIC_PLAUSIBLE_DOMAIN |
| PostHog | Product analytics, user session replays and feature flags | NEXT_PUBLIC_POSTHOG_KEY, NEXT_PUBLIC_POSTHOG_HOST |
| Google Analytics 4 | Search advertising attribution and Google Ads conversion tracking | NEXT_PUBLIC_GA_MEASUREMENT_ID |
| Pirsch | Fast, cookieless, server-side and client analytics | NEXT_PUBLIC_PIRSCH_CODE |
| Amplitude | Deep behavioral cohort analysis and retention metrics | NEXT_PUBLIC_AMPLITUDE_API_KEY |
Cookie Consent Banner Integration
When an external provider is activated, VibeKit automatically activates the built-in ConsentBanner component:
- Strict Pre-Consent Gate: External tracking scripts are completely blocked until the user clicks to accept cookies.
- Immediate Revocation: If a user updates their privacy settings to decline tracking, external libraries are disabled on the spot.
- Compliance Out of the Box: Configured to meet European Union GDPR and ePrivacy requirements without needing a paid cookie banner service.
Protecting Customer Privacy & Payment Details
VibeKit automatically blocks all telemetry collection on sensitive routes:
- Login & Registration (
/auth): Passwords, email OTP tokens, and user credentials are never transmitted to analytics providers. - Checkout & Billing (
/checkout): Credit card numbers, billing addresses, and cardholder names are strictly isolated. - Account Settings (
/app/settings): API keys, team invitations, and security settings are shielded from tracking.
Instructing Your Agent to Switch Providers
To swap your tracking service, give your coding agent this prompt:
Connect PostHog (or Plausible/Google Analytics) to my application:
1. Update config.ts to use the new analytics provider.
2. Ensure the required public environment variables are documented in .env.example.
3. Test that the cookie banner gates script loading and verify with $verify-changes.