Hacker Newsnew | past | comments | ask | show | jobs | submit | more JackWritesCode's commentslogin

Woah this thread is packed. Most of these companies didn’t exist when we started Fathom back in 2018, so it’s great to see how the privacy-first analytics space is thriving.

I’m Jack Ellis, the cofounder of https://usefathom.com. We’re a two person, self-funded company from Canada. Our software is used in projects by companies like IBM, GitHub, Tuple, Tailwind and lots of other awesome companies.

You shouldn’t use Fathom if you flinch at $14/m for a highly available service. We’re self-funded, priced to be sustainable long term, and we don’t guess on privacy law.

Recently, we launched a feature called EU Isolation following the Schrems II ruling (where Max Schrems sued Facebook). Long story short, if you’re using analytics and are passing your EU website visitors personal data (IP & User agent) to US-controlled cloud servers (even if they’re located in the EU), you’re violating the GDPR. Well with Fathom, we use both EU infrastructure and US infrastructure, but we automatically route all your EU visitors through German-owned infrastructure, and hash all personal data there, meaning your EU website visitors personal data will NEVER touch our core US infrastructure. This approach was put together with our Canadian and EU lawyers, and hasn’t been seen before in the analytics space. Lots of companies run on “EU servers”, but they’re controlled by US cloud providers and subject to FISA. This means they’re not GDPR compliant.

We don’t guess on legal matters, and we don’t cheap out on infrastructure. The lawyers we invest in work with some of the world’s largest companies, and they’re a big budget item for us. We run our infrastructure across multiple availability zones and invest heavily in serverless infrastructure. If you compare Fathom against most privacy-first analytics providers, you’ll see our uptime is uncontested. It costs us more, yes, but keeping our customers’ analytics reliable is of crucial importance to us. We run only on managed services, as we want experts (like some of the DevOps folk on here) maintaining it for us, and we stick to our strength (building our application).

With our custom domain solution (to bypass adblockers), we handle automatic SSL for you and serve your website visitors from a CDN, keeping things really fast.

We’ve also recently launched multi-domain, which is super powerful for holding multiple domains under a single dashboard (something the OP was speaking about). Especially since you can also then utilize our API to generate custom reports.

We’re going from strength to strength, and we’re the best option for folks who need GDPR compliance. We are also based in Canada, so we have adequacy ruling under the GDPR.

Hope this post is helpful for anyone who is already wondering about Fathom :)


I’m a big fan of Fathom. I switched from GA to Plausible and then to Fathom. Fathom is the only one that has reliably been able to log page views in Firefox and bypass ad blockers. Also, they’re great people and I value their stance on privacy.


And if you’re serving those pop-ups from US-controlled servers (even if they’re in the EU), you’re violating the Schrems II ruling.


Sure :)


Never expected to see someone defending me on Hacker News. I appreciate it. To clear things up:

* I found AWS Shield Advanced organically

* It was a DDoS attack

* I am incredibly happy with the personalized service. It’s like hiring someone to handle it, except you have people on call 24x7


> It’s like hiring someone to handle it, except you have people on call 24x7

This is what confuses me out of a lot of these replies, saying you're being swindled for paying for this "absurd service" when you should just "own your infra yourself and hire people to manage this"

Do they think owning all this yourself and hiring specialized DDoS people is gonna cost less than $36k/yr? Because I don't think it will.


That sounds incredible. We’re used in a lot of universities right now and it would be great to see more


Dealing with AWS hasn’t been hassle but is expensive. However, the value proposition is well worth it for us.


Can’t talk about this publicly, sorry :(


The data was full of spam & was targeted at high profile customers. It was also run every hour for one period then ramped up to 500,000 concurrents. It was a DDoS :(


You and me both, fargle. When the attacks started, I thought someone was attacking us just so I would write a technical blog post.


Public access point. The server accepts pageviews, so they DDoS'd that.


The article mention the use of lambda/serverless. If he had a server many of these issues would not exist in the first place :)


And I does not looks like a DDoS either, this amount of connections is quite normal for mid-sized apps, and connections can be kept open in case you app is slow, making your stats higher than it actually should be.

Btw, two servers plus a bit of architecture simplification solves this and cut the costs down to ~$400 or less.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: