Rybbit: Self-Hosted, Cookieless Web Analytics with Session Replays
Rybbit - open-source and privacy-friendly alternative to Google Analytics that is 10x more intuitive.
At a glance
- What is it?
- Rybbit is an AGPL-3.0 open-source web analytics platform that runs without cookies and stores no personal identifiers. It offers session replays, funnel analysis, error tracking, and user journey mapping, which most lightweight privacy-friendly analytics tools omit.
- Who is it for?
- Rybbit is a reasonable choice for teams that want privacy-friendly analytics with session replay and error tracking without paying for a commercial tool, and who are willing to operate their own ClickHouse and PostgreSQL stack. The AGPL-3.0 license means any modified version run as a network service must be open-sourced.
- Can I use it commercially?
- Yes, with strict conditions. AGPL-3.0 is a network copyleft licence: if people use a modified version over a network, for example as a hosted service, you must offer them its source code under the same licence.
- Is it still maintained?
- Yes. The repository last received commits 2 days ago.
- What is it written in?
- Mainly TypeScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What Rybbit Provides Beyond Basic Page Views
Rybbit is positioned as a privacy-friendly alternative to Google Analytics. The README describes it as cookieless and privacy-friendly, collecting the standard metrics (sessions, unique users, pageviews, bounce rate, session duration) alongside features that go further: session replays, custom events with JSON properties, error tracking, user profiles, funnels, user journey analysis, and retention analysis. A real-time dashboard shows current activity. The platform also supports public dashboards, meaning analytics data can be shared without requiring a login.
The comparison table in the README shows that Plausible, another privacy-focused analytics tool, does not offer session replays, user profiles, or error tracking. Google Analytics 4 offers funnels and user journeys but not session replays or error tracking. Rybbit includes all of these. The trade-off is operational complexity: Rybbit requires running ClickHouse for analytics storage and PostgreSQL for application data, compared to Plausible's simpler deployment.
Rybbit tracks three levels of location data: country, region, and city, with advanced map visualisations. Advanced filtering covers more than 15 dimensions. The platform supports organisations, which means multiple teams can share one Rybbit instance with separate access controls for each site and an unlimited number of sites per organisation.
Architecture: ClickHouse, PostgreSQL, and Caddy
The docker-compose.yml in the repository shows the required services. Event data goes into ClickHouse, using version 26.3.17.4 in the compose file. Application metadata and user accounts are stored in PostgreSQL. A Caddy reverse proxy handles TLS and routing, with the domain name set via the DOMAIN_NAME environment variable.
The .env.example file shows the configuration surface:
DOMAIN_NAME=demo.rybbit.com
BETTER_AUTH_SECRET=insecure-secret
DISABLE_SIGNUP=false
CLICKHOUSE_PASSWORD=frog
POSTGRES_PASSWORD=frogThe repository is a pnpm workspace requiring Node 22.13.0 or newer. The client and server are separate packages. The setup.sh script in the repository root handles initial deployment, and update.sh handles upgrades. Support for organisations means multiple teams can share one Rybbit instance with separate site access.
Getting Rybbit Running with Docker Compose
The primary deployment path is Docker Compose. The repository provides a docker-compose.yml and a docker-compose.cloud.yml for self-hosted and managed deployments respectively. After cloning the repository and copying the example env file:
git clone https://github.com/rybbit-io/rybbit.git
cd rybbit
cp .env.example .envEdit the .env file to set DOMAIN_NAME, BETTER_AUTH_SECRET, and the database passwords. The .env.example includes sane defaults for local testing, such as CLICKHOUSE_PASSWORD=frog. Running setup.sh starts the stack. The Caddy service handles TLS automatically for the configured domain, listening on ports 80 and 443. The hosted service at rybbit.com is available for teams that do not want to run their own infrastructure.
The package.json at the workspace root shows the dev and build scripts and declares a minimum Node.js version of 22.13.0. For local development of the client and backend separately, the CONTRIBUTE.md file documents the pnpm workspace setup with pnpm version 10.33.0.
Session Replays and Error Tracking: What the README Documents
Session replays record user interactions so developers can watch what visitors actually did. The README lists session replays as a key feature and includes a dedicated dashboard section for them. This is the capability that most directly differentiates Rybbit from lighter alternatives like Plausible, which does not offer replays in its Community Edition.
Error tracking captures front-end JavaScript errors and links them to sessions. The README lists it as a feature present in Rybbit but absent from GA4, Plausible, and Cloudflare Analytics. Having error data in the same system as session data means engineers can correlate a reported error with the exact session replay where it occurred, without switching tools. This combination is more commonly found in dedicated error tracking products.
Custom events accept JSON properties, which allows tracking arbitrary user actions with structured data. Goals, funnels, and user journeys can be built on top of custom events to measure conversion paths and drop-off points. The Retention analysis dashboard shows how users return over time, which is useful for measuring the impact of product changes.
Limitations and the AGPL License
Web Vitals are listed in the README's feature comparison with two asterisks indicating they are only available on paid cloud tiers. Self-hosted deployments do not include Web Vitals. Teams that need Core Web Vitals measurement will need to supplement Rybbit with a separate tool or use the hosted version at rybbit.com.
Session replay data generates significantly more storage volume compared to plain event data. The README does not document storage estimates or retention configuration options for replays, which is a planning gap for teams managing their own infrastructure. The react-native/ directory in the repository root suggests mobile SDK work is in progress, but the README does not document a stable mobile integration path.
The AGPL-3.0 license has an important implication for organisations that modify Rybbit and run it as a service for others. AGPL requires that the modified source code be made available to users of the service. This is stricter than MIT or Apache licenses and may affect commercial use cases. Internal self-hosting for your own organisation's analytics does not trigger this requirement.
Rybbit vs Plausible: Self-Hosted Privacy Analytics
Plausible is the most direct comparison. Both are open-source, cookieless, self-hostable analytics tools designed as alternatives to Google Analytics. Plausible is the more established project with a larger self-hosting community.
The key functional difference, as documented in Rybbit's own README comparison table, is that Plausible does not offer session replays, user profiles, or error tracking. Rybbit includes all three. Plausible's self-hosted Community Edition has limited features compared to its cloud product, a point the README also notes.
The operational difference is the data store. Plausible uses ClickHouse but with a simpler stack. Rybbit adds PostgreSQL for application data and Caddy for the web server. Engineers who want the simplest possible self-hosted analytics setup will find Plausible easier to operate. Engineers who need session replay will need Rybbit or a commercial product.
The last push to the repository was on 2026-09-26. The v2.9.0 release shipped on 2026-09-12.
Editorial conclusion
Rybbit is a reasonable choice for teams that want privacy-friendly analytics with session replay and error tracking without paying for a commercial tool, and who are willing to operate their own ClickHouse and PostgreSQL stack. The AGPL-3.0 license means any modified version run as a network service must be open-sourced. Organisations with data residency requirements will appreciate self-hosting, but should plan for the storage requirements of session replay data. Web Vitals are only available on paid cloud tiers, not in self-hosted deployments.
Frequently asked questions
What is Rybbit?
Rybbit is an open-source, cookieless web analytics platform. It tracks standard metrics like sessions and pageviews without cookies, and adds session replays, error tracking, user journeys, funnels, and retention analysis. It can be self-hosted via Docker Compose or used as a hosted service.
What is a good Rybbit alternative?
Plausible is the most similar open-source alternative: cookieless, self-hostable, and privacy-friendly. It lacks session replays and error tracking, which Rybbit includes. Google Analytics 4 offers more analytical depth but requires cookies and collects personal data.
Does Rybbit support self-hosting via Docker?
Yes. The repository includes a docker-compose.yml that runs ClickHouse, PostgreSQL, a Caddy reverse proxy, and the Rybbit frontend and backend. A setup.sh script in the repository root handles the initial deployment.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/rybbit-io-rybbit)