@kalydron/pulse
v1.0.0
Published
Cookieless ~1KB pageview beacon for Kalydron Pulse. No cookies, no fingerprinting, no consent banner — referrer-based traffic classification (including AI assistants) happens server-side.
Maintainers
Readme
@kalydron/pulse
Cookieless pageview beacon for Kalydron Pulse — ~1 KB, zero dependencies, no cookies, no fingerprinting, no consent banner needed.
The beacon is deliberately dumb: it sends path + referrer + utm_source and nothing else.
All intelligence — bot filtering, traffic classification (organic / social / referral /
direct / AI assistants like ChatGPT and Perplexity), visitor counting via a
daily-rotating salted hash — happens server-side. That means pinned versions keep
benefiting from classification improvements without an update.
The entire client source is ~40 lines. Read it: src/index.js.
Install
Script tag (hosted, always current):
<script defer src="https://kalydron.com/k.js" data-site="YOUR_SITE_ID"></script>Script tag (pinned version via CDN, with integrity lock):
<script defer src="https://cdn.jsdelivr.net/npm/@kalydron/[email protected]/dist/pulse.iife.js"
integrity="sha384-…" crossorigin="anonymous"
data-site="YOUR_SITE_ID"></script>npm (SPAs / JS apps):
npm install @kalydron/pulseimport { init } from '@kalydron/pulse';
const pulse = init({ site: 'YOUR_SITE_ID' });
// SPA route changes are tracked automatically (pass spa: false to opt out).
// pulse.track() sends a pageview manually if you need one.Privacy properties
- No cookies, no localStorage, nothing written to the device.
- No personal data collected: no raw IP stored, no user-agent stored, no identifiers.
- Visitors are counted server-side with a salted hash whose salt rotates daily — re-identification across days is impossible by design.
- Payload is
text/plainviasendBeacon, so there is no CORS preflight and the script can never delay or break a host page. Every code path is wrapped so a failure is silent.
MIT © Kalydron
