← Back to Newsletter
SEP 1, 2026

The Analytics I Deliberately Broke

Data collection is treated as a binary choice. Either we collect nothing and fly blind, or we collect everything, build a profile, and sell the excess to data brokers. The standard response in this industry is to harvest every single interaction and exploit it for profit. I reject both options. I refuse to operate that way.

The Insight

Last week, I evaluated the telemetry on this site. I needed to know how the content performed so I could iterate and improve the mechanics of my writing. But the default model is wildly invasive. Standard email service providers automatically attach hidden tracking pixels to monitor exactly who opens an email, what device they use, and the exact second they open it. Typical web analytics tools ingest IP addresses and infer physical locations down to the neighborhood.

The data broker business model relies on this unquestioned scale. Trading audience trust for fractions of a cent per record is a catastrophic operational failure. Furthermore, collecting granular, personally identifiable information is not a strategic asset. It is a massive liability. The moment I hold that data, I am responsible for securing it against breaches and leaks. The absolute best way to secure sensitive data is to never collect it in the first place.

The Fix

I tore out the standard tracking implementations. I designed a new architecture for ethical telemetry. Here is the breakdown of what worked, what broke, and what it cost.

First, IP anonymization. I flipped the IP-discard setting in the analytics backend so the raw address is never stored, then added a second step to the ingestion pipeline — ordered to run right after the built-in location lookup — that strips everything more precise than country. City, postal code, exact coordinates: gone before the event is ever written. What worked: I still get aggregate pageviews and bounce rates, plus one number I didn’t have before, country-level readership. What broke: I can no longer see what city a reader is in, or their zip code, or their coordinates down to the meter. That is exactly the point.

Second, aggregate engagement tracking. I disabled individual open and click tracking in the email pipeline. I built a custom webhook that intercepts engagement events, strips all recipient metadata, and simply increments a global counter for the entire issue. What it cost: I permanently lost the ability to prune inactive subscribers automatically based on their personal open rates. I now have zero idea who specifically opened an email. But I know exactly how many people read the article overall.

The Hard Truth

We do not need to surveil individuals to build better systems. We can trade invasive analytics for the guarantee that an audience can read the work without being watched. Security and privacy are not promises written in a legal document. They are mechanical guarantees built directly into the code. The machine either collects the data, or it doesn’t. Mine collects the one fact that’s actually useful, and throws the rest away before it’s ever written down.

ABOUT THE PRACTICE

Every Tuesday, I send The Practice—a letter from the frontlines of AI workflows and solo ventures. You get the raw mechanics of what worked, what broke, and how to build it yourself.

Get the Newsletter →