Analytics disclosure
Varve measures only a few aggregate product and website questions. Unknown consent fails closed, and no autocapture, session replay, cookie, or fingerprint is used. The Plausible loader is injected only after consent, with its automatic capture features disabled.
Website events
| Event | Fields | Purpose |
|---|---|---|
| website_page_viewed | normalized route | Understand which documentation and product pages are useful. |
| website_download_started | release, platform, architecture, package type, release channel | Measure the download funnel and platform demand. |
| website_outbound_clicked | destination category | Understand whether GitHub, documentation, or community links help visitors. |
Desktop events
| Event | Fields | Purpose |
|---|---|---|
| app_launched | surface | Count opted-in product sessions. |
| document_created | blank, template, or import source | Understand activation without seeing the document. |
| feature_used | closed feature category | Prioritize features with meaningful adoption. |
| export_completed / export_failed | format and coarse duration or error category | Find export reliability and performance problems. |
| renderer_fallback / performance_sample | backend, reason, metric, duration bucket | Find platform-specific renderer and performance issues. |
Never collected
Documents, canvas pixels, screenshots, exported artwork, clipboard data, filenames, paths, project or layer names, user text, comments, URLs from designs, imported metadata, image hashes, geometry, generated code, AI prompts, raw exception strings, raw stacks, device identifiers, authentication identities, advertising identifiers, and arbitrary payload fields are prohibited by the schema and runtime privacy boundary.
Consent and transport
Website consent is separate from desktop usage analytics, diagnostics telemetry, and crash reporting. The client uses a bounded in-memory queue, never blocks editing or navigation, and discards pending events when consent is revoked or the process ends. The production deployment is configured for the aggregate Plausible site at varve.studio; local and unconfigured builds remain endpoint-free.