Review collected fields
Document the pageviews, events, referrers, campaigns, and custom payloads your site sends. Do not place names, emails, credentials, or other unnecessary personal data in event fields or URLs.
Privacy
Amami documents its tracking, authorization, retention, and hosting controls so your team can review them. Compliance is not automatic: it depends on what you collect, how you configure the service, where you operate, and which laws apply.
Document the pageviews, events, referrers, campaigns, and custom payloads your site sends. Do not place names, emails, credentials, or other unnecessary personal data in event fields or URLs.
Cookie use is only one part of privacy review. Determine whether your tracking configuration, event data, local rules, and legal basis require consent or another disclosure.
The hosted setup flow uses browser authorization and writes the MCP API key to a local configuration file. Do not paste login details or API keys into prompts, logs, or public issue reports.
Use these questions with your privacy or legal reviewer before enabling analytics:
Security model
Next steps
List the standard fields, custom events, URL parameters, and imports your deployment will process.
Check access, MCP scopes, retention, hosting, deletion, backup, and incident-response responsibilities.
Have the appropriate privacy or legal owner approve notices, legal basis, consent behavior, and processor terms.
See how browser authorization, local credential storage, read-only defaults, and explicit write scopes work in the current MCP setup. Then use the Google Analytics alternative guide to plan a measured migration.