Tracking, impact, and attribution
Tracking sites
A tracking site defines allowed origins, scoped write token, consent behavior and retention between 1 and 730 days. Tokens are shown only when created and should be rotated when exposed. Collection is pseudonymous by default.
Recognized events include ai_referral_visit, ai_assisted_session, page_view, engagement, lead, signup, purchase, campaign_conversion, content_interaction, crawler_visit, and publication_exposure.
The referrer classifier recognizes ChatGPT, Perplexity, Gemini, Microsoft Copilot, Claude, Meta AI and You.com. Unknown AI-like sources remain unknown_ai; they are not guessed into a named provider.
Installation options
- Browser script:
/geo.js - Next.js:
@thyris/geo-tracking/next - Server-side TypeScript client
- Google Tag Manager template
- WordPress plugin
- Events API v2
Configure HTTPS collector URL, site token, allowed origins and consent. URLs are sanitized to remove credentials, fragments and query parameters that resemble PII or secrets.
Attribution
Attribution connects publication, action and campaign touchpoints to tracked outcomes. Available models include first-touch, last-touch, linear and position-based. Attribution is directional and non-causal unless an experiment provides stronger evidence.
Confidence is bounded by tracking coverage, identity continuity, sample size and data freshness. Show unattributed outcomes rather than forcing them into a channel.
Attribution topology
| Model | Allocation | Appropriate interpretation |
|---|---|---|
| First-touch | First eligible touchpoint receives credit | Discovery-oriented directional view |
| Last-touch | Last eligible touchpoint receives credit | Conversion-adjacent directional view |
| Linear | Credit divided across eligible touchpoints | Multi-touch contribution view |
| Position-based | More weight to first and last, remainder shared | Discovery plus conversion-edge view |
None of these models establishes causality by itself.
Privacy requests
The Privacy API accepts pseudonymous access and delete requests tied to a workspace and tracking site. Request status exposes redacted subject hashes; it does not return write tokens or raw credentials.