Privacy policy
For UniFi Stats, the program serving this page. Last updated 2026-09-10.
Where the data is
UniFi Stats runs on a computer that the library, library system or state agency using it owns or operates, and keeps everything it records in one database on that computer. Active DataComm, which develops the program, does not operate that computer, has no access to the database and receives nothing from it. The organization running the program is responsible for the data it holds; this policy describes what the program does with it.
What is collected from the network
From the UniFi consoles its API keys reach, the program reads the list of devices connected to each network at every poll, the console's own log of past connections when a site is first polled, the names and models of the consoles, sites, networks and UniFi devices, and the gateway's traffic rates. From the connected devices it makes sessions: when a device connected and disconnected, on which network and through which access point or switch, and whether it used the guest portal. No content of anyone's traffic is read or stored.
Privacy protection is on unless an administrator turns it off. With it on, a device's hardware (MAC) address is replaced by an anonymous ID as the session is recorded, made with a secret created once for the installation, and the device's name and IP address are not recorded at all. The ID lets the program count a returning device as the same device; it cannot be turned back into the address without the secret, which stays in the database. With protection turned off for a console, the addresses, names and IP addresses are recorded as the console reports them.
What is kept, and for how long
Session records are kept for the retention period set on the Settings page, two years unless changed, and then deleted. The daily and hourly statistics made from them, counts of sessions, devices and peaks per site, network and access point, hold no device identifiers and are kept indefinitely. Reports and exports made from the data are in the hands of whoever makes them.
Accounts and sign-ins
An account is a username and a password, stored as a salted hash, and, when two-factor authentication is on, the authenticator's secret, the hashes of the backup codes and the public keys of any passkeys. The audit log records each account's sign-ins, sign-outs, failed sign-ins and failed second steps with the address of the browser, its exports, and every change it makes to the configuration, so that an administrator can see who did what. The interface uses two cookies, one for the session and one against cross-site request forgery, both necessary for it to work, and keeps the theme choice in the browser's own storage. No advertising, analytics or tracking of any kind is used.
What leaves the computer
The program connects to the UniFi consoles it is given keys for: through Ubiquiti's cloud at api.ui.com, which sees the requests and the API key and is covered by Ubiquiti's own privacy policy, or directly to a console on the network. When an SMTP server is configured, the scheduled reports go to the recipients configured for each library system, and the mail log records the addresses and subjects. Once a day, unless the check is turned off on the Settings page, the program fetches the changelog of the latest release from GitHub to say when a newer version is out; that request carries the program's version number and, like any web request, the computer's address, and nothing else. Nothing else is sent anywhere.
Access to the data
Only accounts of the interface see the data: administrators all of it, viewers the figures, and a viewer limited to one library system that system's alone. The database file is created readable by its owner only, and the installers limit its folder to the service account and the computer's administrators. Anyone with administrative access to the computer can read the database, the API keys and SMTP password it holds included.
Changes and questions
This policy describes the program as released; it changes when the program does, and the version in the footer says which one is running. Questions about the program go to Active DataComm at callactive.com; questions about a particular installation and its data go to the organization running it.