The Monoid Blog

Privacy, analytics, and the open web — written for developers.

RSS feed
7 min readEngineering & Performance

navigator.sendBeacon vs fetch keepalive: Reliable Analytics Delivery Without Blocking Unload

How to send analytics payloads that survive page unload without holding up navigation — and why the choice between sendBeacon and fetch keepalive matters for cookieless collection.

Read more
7 min readEngineering & Performance

The 402 Return of Payment Required: What HTTP Status Codes Tell Analytics About Bot Traffic

HTTP status codes carry more signal than most analytics tools use. Here's how server-side status parsing helps separate humans from bots without tracking anyone.

Read more
7 min readEngineering & Performance

The Visibility State Transition: Measuring Page Views Without Beacons You Can Trust

pagehide, visibilitychange, and the Beacon API each behave differently across browsers. Here's how to record a session end reliably without cookies or persistent identifiers.

Read more
6 min readEngineering & Performance

The Sec-GPC Header Is Now Everywhere: Server-Side Detection for Analytics

Global Privacy Control ships as the Sec-GPC request header on every request. Here is how to read it at the edge and honour it in a cookieless analytics pipeline.

Read more
6 min readEngineering & Performance

Timing-Allow-Origin: What Analytics Sees in the Resource Timing API

The Timing-Allow-Origin header controls how much cross-origin timing detail a page can read. Here is what it means for privacy-first performance measurement.

Read more
7 min readEngineering & Performance

Speculation Rules and Prerendering: What Analytics Gets Wrong About Prefetched Pages

Chrome's Speculation Rules API can render a page before a user ever clicks. Here's how it distorts naive analytics — and how cookieless, edge-based measurement stays honest.

Read more
4 min readEngineering & Performance

Your Analytics Script Is Probably Disabling the Back/Forward Cache

The back/forward cache makes back-button navigations near-instant, but one unload listener disables it for the whole page. Tracking scripts are the usual culprit — and CrUX now measures the damage.

Read more
4 min readLaw & Regulation

GDPR Data Transfers Are the One Compliance Risk You Can Architect Away

The EU-US Data Privacy Framework survived its first court challenge but is now on appeal to the CJEU. Analytics that never transfers EU data to the US has nothing to lose either way.

Read more
5 min readLaw & Regulation

The EDPB's 2026 Enforcement Target Is Your Privacy Notice

The EDPB's 2026 coordinated action audits transparency under GDPR Articles 12–14. The shortest path through it is collecting so little that the notice writes itself.

Read more