Self-Hosted Analytics: Tools, Server Costs, Setup and What Breaks

Self-hosted analytics means running an open-source web analytics tool, such as Umami, Plausible Community Edition or Matomo, on a server you control, so every pageview and event lands in your own database instead of a vendor’s cloud. You get the raw data, no per-pageview bill and a say over where the data lives. In exchange you become the operator: server, updates, backups, proxy setup and bot filtering are your job.
This guide compares the tools that are worth installing in 2026, gives the server requirements from each project’s own docs, walks through setup step by step, prices the whole thing including your time, and lists the failure modes that quietly break the numbers. It ends with the part most guides skip: turning self-hosted pageviews into conversions and money per landing page.
What self-hosted analytics is, and what it is not
A self-hosted analytics setup has three parts: a small JavaScript tracker on your pages, a collection endpoint that receives each hit, and a database plus dashboard where the reports live. In a self-hosted setup the last two run on your machine. The tracker usually sends a hit when a page loads and when you fire custom events such as a form submit.
Three things often get mixed up with it:
- Self-hosted Google Analytics does not exist. GA4 is a hosted Google service with no on-premise edition. A server-side tag container you run yourself still forwards the data to Google, so you do not own the reporting database.
- Server log analyzers are a different approach. Tools like AWStats and GoAccess read your web server’s access logs. They need no JavaScript and see visitors who block scripts, but they also count bots, cached assets and crawlers, and they cannot see what happens inside the page, like a form submit handled by JavaScript.
- Self-hosted is not “self-serve.” Self-serve analytics means business users can build their own reports without a data team, usually in a BI tool such as Looker Studio, Power BI, Tableau or Metabase (Metabase can itself be self-hosted). It describes who builds reports, not where the software runs.
Why teams self-host, and what it does not fix
The reasons cluster into four:
- Data ownership. Every row sits in your database. You can query it with SQL, keep it as long as you like, delete it on request and move it when you change tools.
- Data location and privacy posture. You choose the country the server is in, and no analytics vendor sits between your visitors and your database. Most of the popular tools are cookieless by default.
- Predictable cost. Hosted privacy tools usually bill by monthly pageviews or events. A server bill grows in steps, not per hit, which matters most on high-traffic sites.
- Fewer blocked hits. A tracker served from your own subdomain is not on the same blocklists as a well-known vendor domain. In a Plausible GitHub discussion, a maintainer said their own self-hosted instance recorded more traffic than the cloud one because the cloud domain is blocked by uBlock and Brave.
What self-hosting does not do on its own:
- It does not make you compliant. You are now the party deciding what is collected and for how long, so retention, IP handling and your privacy notice are on you.
- It does not give you more features. Several vendors keep their best features in the paid cloud product (details below).
- It does not replace Google Ads conversion tracking or audience features. If your ad bidding depends on GA4 conversions, you still need GA4 or a direct ads tag.
- It does not tell you what a visit was worth. Most self-hosted tools count visits well and value them poorly. See the last section.
Self-hosted analytics tools compared
The list below covers every tool that appears in the current search results and community threads. Licenses are the projects’ own; “stack” is what you have to run and maintain.
| Tool | Stack you run | License | Best for | Watch out for |
|---|---|---|---|---|
| Umami | Node.js app + PostgreSQL | MIT | Blogs, small SaaS, agencies with many small sites | Lighter funnels and no native ecommerce reports |
| Plausible Community Edition | Elixir app + PostgreSQL + ClickHouse (Docker) | AGPLv3 (tracker MIT) | Content sites that want a one-screen dashboard | No funnels or ecommerce revenue goals in CE; ClickHouse needs real memory |
| Matomo On-Premise | PHP + MySQL or MariaDB | GPLv3 (some plugins paid) | GA-style depth: goals, ecommerce, segments, many sites and users | Heaviest of the web tools; report archiving needs a cron job |
| GoatCounter | Single Go binary + SQLite or PostgreSQL | EUPL-1.2 | Hobby sites that want the smallest footprint | Pageviews, referrers and campaigns only, by design |
| PostHog | Many services including ClickHouse, PostgreSQL and Redis | MIT core | Product analytics in an app: funnels, replay, flags | Far heavier than web analytics needs; overkill for a blog |
| OpenPanel, Swetrix, Rybbit | App + ClickHouse (and PostgreSQL for some) | Open source | Teams wanting funnels, journeys or performance data without PostHog’s weight | Younger projects: check release activity before committing |
| Ackee | Node.js + MongoDB | MIT | Static and Jamstack sites wanting a tiny Node service | Slow feature development; small ecosystem |
| Open Web Analytics, Countly | PHP + MySQL (OWA); Node + MongoDB (Countly) | Open source (Countly Lite) | OWA: click heatmaps on PHP hosting. Countly: web plus mobile apps | Check OWA’s recent release activity; Countly’s richer features sit in paid editions |
| Fathom Lite | Go binary | MIT | Nothing new: the original open-source Fathom | No new features; the company now builds only its paid cloud product |
| Paid self-hosted: DooStats, Pirsch Enterprise | PHP folder upload (DooStats); licensed server (Pirsch) | Commercial | People who want self-hosting without Docker (DooStats) | You pay a license and still run the server |
One pattern is worth knowing before you choose: the companies behind most of these tools earn their money from hosted plans, so the self-hosted edition is often deliberately smaller. Plausible is explicit about it. Its GitHub README says the Community Edition is a long-term release published twice a year, uses basic bot filtering based on the User-Agent header and referrer spam lists, and leaves out marketing funnels, ecommerce revenue goals, SSO and the sites API. It is also community supported only. Read the equivalent page for any tool before you assume the self-hosted build matches the demo.
Which tool to pick
| Your situation | Pick | Why |
|---|---|---|
| One content site, you want traffic and sources | Umami or Plausible CE | Cookieless, simple dashboard, low maintenance |
| Many small client sites, low budget | Umami | Multi-site in one install on a small server |
| You need goals, ecommerce revenue, segments and user permissions | Matomo | The most complete open-source option for GA-style reports |
| You track behavior inside a product (signup, activation, retention) | PostHog, or OpenPanel if hardware is tight | Event-based product analytics, not just page stats |
| You want the smallest possible thing and will never need funnels | GoatCounter | One binary, one small database |
| Shared PHP hosting only, no Docker, no SSH | Matomo or a PHP tool such as DooStats | Docker-based tools cannot run there |
| Nobody on the team will patch a server | A hosted plan of the same tool | An unpatched analytics server is a liability, not a saving |
If you are still weighing hosted options too, our GA4 alternative guide covers the cloud tools, product analytics and enterprise suites by category. For app-style analytics, see PostHog alternatives.
Server requirements
Sizing advice in blog posts varies a lot, so start from each project’s own numbers. Matomo publishes the most detailed table. From its on-premise requirements FAQ:
| Monthly pageviews | Matomo’s recommended setup |
|---|---|
| Up to 100,000 | 1 server: 2 CPU, 2 GB RAM, 50 GB SSD |
| Up to 1 million | 1 server: 4 CPU, 8 GB RAM, 250 GB SSD |
| Up to 10 million | App server 8 CPU / 16 GB + database server 8 CPU / 16 GB / 400 GB SSD |
| Up to 100 million | App servers 16 CPU / 16 GB+ + database server 16 CPU / 32 GB / 1 TB SSD |
| Over 100 million | 3+ app servers, 2 database servers, load balancer and CDN |
The same page lists Matomo 6 as needing PHP 8.1 or newer and MySQL 8.0+ or MariaDB 10.6+. Matomo also asks you to replace its default browser-triggered report archiving with an hourly cron job once traffic grows past a small site, or dashboards get slow.
For the other tools, the practical rules are:
- Umami is one Node.js app and a PostgreSQL database. According to the Umami environment variable docs, the database connection string is the only required setting, which is why it is the easiest to get running.
- Plausible CE bundles ClickHouse, which is memory-hungry and needs a modern CPU instruction set. Read the requirements in the community-edition repository before you buy the smallest server on offer.
- PostHog runs many services and is the heaviest by a wide margin. Treat it as a project, not a weekend install.
- Shared hosting works only for PHP tools (Matomo, Open Web Analytics, DooStats). Docker tools need a VPS or a container platform. Umami can also run on a serverless platform with a hosted PostgreSQL database, which removes the server but means your data sits with those two providers.
How to set up self-hosted analytics in 10 steps
The commands differ by tool, but the shape is the same for all of them. Follow your tool’s official install guide for the exact files; these steps are the decisions and checks around it.
Step 1: Pick the tool and a tracking hostname
Use the decision table above. Then choose a subdomain of your own site on the standard HTTPS port 443. Avoid obvious names like analytics. or stats., which blocklists match, and avoid non-standard ports: in the Plausible discussion above, moving the script off port 8000 brought the self-hosted counts back in line, and some school and office firewalls block other ports.
Step 2: Provision the server
Size it from the official requirements, not from the cheapest plan. If data location matters to you, pick a region accordingly, and remember that a CDN or proxy service in front of the endpoint is another company processing the data.
Step 3: Deploy the stack
Most tools ship a Docker Compose file. You set secrets (for example Umami’s APP_SECRET, Plausible’s SECRET_KEY_BASE), the public URL and the database connection, then start the containers. Pin a version tag instead of latest so an update never happens by accident.
Step 4: Put a reverse proxy in front and pass the real visitor IP
Caddy, nginx or Traefik terminates HTTPS and forwards requests to the app. This is the step that silently breaks most installs: unless the proxy forwards the visitor’s address in a header the app trusts, every hit arrives from the proxy’s own IP. Unique visitor counts collapse and every visitor appears to be in your server’s country. Umami documents a CLIENT_IP_HEADER variable for proxies that use non-standard headers. A minimal Caddy setup looks like this:
# Caddyfile
t.example.com {
reverse_proxy localhost:3000
# Caddy sets X-Forwarded-For by default; make sure the app reads it.
# Behind a CDN, trust only the CDN's ranges and use its client IP header.
}Step 5: Add the tracking script
Add the snippet once, in the layout every page shares, with defer, loaded from your own hostname. On a single-page app, confirm the tool records route changes. Never load two trackers that use the same global name on one page.
<script defer src="https://t.example.com/script.js" data-website-id="YOUR-ID"></script>
Step 6: Exclude yourself and check bot filtering
Exclude your own visits and staging hostnames. Check that bot filtering is on: Umami excludes bots by default, while Plausible CE’s filtering is the basic version described above, so watch for sudden spikes from data center traffic.
Step 7: Set retention and IP handling
Decide how long raw events are kept, whether IP addresses are stored, truncated or discarded, and write that into your privacy notice. These are your choices now, not a vendor’s.
Step 8: Back up and test a restore
Schedule a nightly database dump (for example pg_dump for PostgreSQL, mariadb-dump for MariaDB, and ClickHouse’s own backup for Plausible’s event data) and copy it off the server. Restore one to a spare machine once. A backup you have never restored is a guess.
Step 9: Plan updates and monitoring
Watch the project’s releases, read the upgrade notes (database migrations are where updates fail), and update on a schedule. Add an uptime check on the tracking endpoint and an alert on disk usage. An analytics server that is down loses data for good: hits sent while it is offline are not resent.
Step 10: Run it next to your current tool
Run both for two to four weeks. Expect different totals, because each tool defines visitors and sessions differently and is blocked differently. Compare trends and the ranking of pages and sources, not exact counts. Export your old tool’s history before you remove it. Matomo has a Google Analytics importer; check whether your new tool has one before you count on it.
What it really costs: a worked example
Most comparisons price only the server. The bigger cost is the time you spend on it. Here is the full calculation with illustrative numbers; swap in your own.
| Line (illustrative) | Year 1 | Year 2 |
|---|---|---|
| Server: $12/month | $144 | $144 |
| Off-site backup storage: $2/month | $24 | $24 |
| Setup: 6 hours × $60/hour | $360 | $0 |
| Maintenance: 1 hour/month × $60/hour | $720 | $720 |
| Total | $1,248 | $888 |
Compare that with a hosted plan of the same tool. At an illustrative $20 a month ($240 a year), self-hosting costs more in both years. At an illustrative $150 a month ($1,800 a year), which is the range hosted tools reach at high traffic, self-hosting wins from year one. The break-even point is:
With the numbers above that is $14 (server and backup) + $60 = $74 a month. Below that hosted price, self-host only for reasons other than money: data location, ownership or the learning. If your maintenance time is really zero, you are not maintaining it, and that risk shows up later as a breach or a lost database.
Failure modes: why self-hosted numbers go wrong
When a self-hosted install reports odd numbers, the cause is almost always in this table.
| Symptom | Likely cause | How to check and fix |
|---|---|---|
| Unique visitors roughly equal pageviews, or almost none; every visitor in one country | Proxy not passing the client IP | Log the incoming headers; configure X-Forwarded-For (or the CDN’s header) and the app’s trusted header setting |
| Counts much lower than another tool | Non-standard port, blocked hostname or script name, or a strict Content-Security-Policy | Open the page with the browser network tab; move to port 443 and a neutral hostname; allow the host in CSP’s script-src and connect-src |
| No data at all after install | Mixed content (HTTP tracker on HTTPS page), wrong site ID or domain, or CORS | Check the browser console; the collect request should return 2xx |
| Sudden spike from one city or data center | Bots or uptime monitors | Turn on or tighten bot filtering; exclude your monitor’s user agent |
| Matomo dashboards slow or reports missing recent days | Browser-triggered archiving | Set up the archiving cron and disable browser archiving |
| Gaps of hours or days | Server down, out-of-memory kills, or a full disk | Uptime and disk alerts; check container restart counts; give ClickHouse more memory |
| Pageviews doubled | Script added twice (theme plus tag manager), or SPA router firing on top of auto pageviews | Search the rendered HTML for the script; disable one source |
| Daily totals shifted by a day | Time zone set differently in the tool and your other reports | Set the site time zone to the one your business reports in |
TRACKER_SCRIPT_NAME and COLLECT_API_ENDPOINT settings whose stated purpose is avoiding some ad blockers. Whether you use them is a judgment call: they recover visits from people whose blocker targets known filenames, but a visitor who blocks trackers on purpose has made a choice. Cookieless, first-party measurement with no personal data is the defensible middle ground; disguising a tracker that collects more is not.Privacy, consent and licenses
Is self-hosting legal? Yes. The licenses of all the open-source tools above allow you to run them on your own server for any purpose. Two license details matter. Plausible’s AGPLv3 says that if you modify the code and let others use it over a network, you must publish your changes; running it unmodified for your own site triggers nothing. Matomo’s core is GPLv3 and some of its plugins, such as heatmaps and session recording, are sold separately.
Consent. Whether you need a cookie banner depends on where your visitors are and what the tool stores on their device, not on where the server sits. Cookieless tools that keep no persistent identifier are designed to avoid consent prompts in many jurisdictions, but EU rules are interpreted by each country’s regulator, so check your own. A self-hosted Matomo with cookies turned on is no more consent-free than any other cookie-based tool. Our cookieless tracking guide explains the methods and what each one stores.
Data location. A server in your chosen country removes the analytics vendor from the data flow. Your hosting company, backup storage and any CDN in front of the endpoint still process the data, so they belong in your records and privacy notice.
Where the top results disagree
- How much memory Umami needs. Estimates in current guides range from about 256 MB to 1 GB. Both can be right: the app idles small, and PostgreSQL grows with your data. Start small and watch memory for a month.
- Whether Fathom Lite is “well maintained.” One list calls it maintained for bug fixes, another calls it stale. Both agree it gets no new features and that the company builds its paid cloud product. For an internet-facing service, check the date of the last release and image yourself before deploying.
- Matomo’s minimum server. Guides quote anything from 2 GB to 8 GB for a small site. Matomo’s own table says 2 CPU and 2 GB RAM for up to 100,000 pageviews a month, so start there.
- Whether self-hosting is easy. Some guides call it a 20-minute job; developers in community threads describe failing to get Umami and Plausible running. The difference is usually the proxy, TLS and IP steps above, which quick-start guides skip.
When self-hosting is the wrong call
- Nobody on the team can SSH into a server and fix it on a bad day.
- Your small traffic puts the hosted plan well under the break-even price above, and data location is not a requirement.
- Your ad bidding depends on GA4 conversions, audiences or Google Ads imports. Keep GA4 for that and add a second tool only if you will read it.
- You need certifications such as SOC 2 or HIPAA-grade audit trails for the analytics processor. You would have to build and audit that yourself.
From self-hosted pageviews to conversions and value
Self-hosted tools are good at counting visits by page and source. The question a business asks next is which pages and channels produce leads and revenue, and how much. Getting there takes three additions on top of any tool:
- Track the actions that matter: form submits, calls, email clicks, demo bookings and purchases, as custom events or goals.
- Give each action a value, using the method in how to calculate conversion value.
- Report by landing page and channel, because search engines hide most keywords and AI assistants send visits from their own referrers.
An illustrative example shows why the third step changes decisions:
| Organic landing page (illustrative) | Visits | Demo requests | Value per lead | Pipeline value |
|---|---|---|---|---|
| /blog/how-to-choose-x | 6,000 | 6 | $300 | $1,800 |
| /pricing-guide | 1,200 | 18 | $300 | $5,400 |
The value per lead here is an illustrative $1,500 average deal times a 20% lead-to-customer rate, which is $300. A traffic report ranks the blog post first; a value report shows the smaller page is worth three times as much. Our SEO conversion tracking guide covers the full setup. If you would rather not build this on top of a self-hosted install, SEOConversion is a cookieless, first-party script that tracks forms, calls and purchases, puts a value on each conversion and reports it by landing page for organic search and AI assistants.
FAQ
Is self-hosting legal?
Yes. Running open-source software on a server you rent or own is legal, and the licenses of tools like Umami (MIT), Matomo (GPLv3) and Plausible (AGPLv3) explicitly allow it. What you must still follow are privacy laws for the data you collect, the terms of your hosting provider, and license duties such as AGPL’s rule that if you modify the code and offer it to others over a network, you share those changes.
Can you self-host Google Analytics?
No. Google Analytics 4 is a hosted Google service with no downloadable or on-premise edition. When people say “self-hosted Google Analytics” they mean an open-source alternative such as Matomo, Plausible Community Edition or Umami running on their own server. A server-side tag container still sends data to Google, so it does not give you self-hosted analytics.
What is replacing Google Analytics?
There is no single replacement. Content sites often move to privacy-first tools like Plausible, Umami or Matomo, product teams pick product analytics such as PostHog or Mixpanel, and large companies use enterprise suites or their own warehouse. Many sites keep GA4 for Google Ads and add a second tool for the reports they actually read.
What does self-serve analytics mean?
Self-serve (or self-service) analytics means business users can build their own reports and dashboards without asking a data team, usually in BI tools like Looker Studio, Power BI, Tableau or Metabase. It is about who builds reports, not where the software runs. A self-hosted tool can be self-serve, and a cloud tool can be too.
Can you self-host a search engine?
Yes. SearXNG is a popular self-hostable metasearch engine that queries other engines and strips tracking, and YaCy is a peer-to-peer search engine you can run yourself. For searching your own site or documents, engines like Meilisearch, Typesense and OpenSearch are built to be self-hosted.
What are some good self-hosting sites?
The best-known directory is the awesome-selfhosted list on GitHub, which groups open-source software by category, including an analytics section. The r/selfhosted community on Reddit is useful for setup questions, and each analytics project’s own docs and GitHub discussions are the place to check requirements and known issues before you install.
Count visits anywhere. Know which pages earn money.
SEOConversion is one cookieless, first-party script that tracks forms, calls and purchases, puts a value on each conversion and reports it by landing page for organic search and AI assistants.
Start free