Nemel · Radar

Your analytics can’t see AI. Watch us see it.

Send your AI assistant to a link made for you. Its visit lands here in seconds — the name it gave, and what we call it and why: at once for an assistant that names itself as one we know (ChatGPT, Claude, Perplexity), within minutes for everything else. Most assistants fetch a page without running its scripts, so your analytics records nothing.

Three random words. No sign-up, no cookies.

The rules

Which reasons make which class

The classifier’s own table, drawn from it when this page was built. It decides at the request and again over your key’s hour: the first line a visit’s reasons meet gives its class, and what the rules leave unknown, the model may class.

  1. declared-client beside none of browser-family honeypot impersonation

    first-party-client
  2. at least 2 of browser-family assets-loaded beacon-seen and no other reason but vendor-fetch-beside declared-client anywhere, not counting no-asset-loads beside beacon-seen — unless a rule even beside a person’s reasons holds

    human
  3. at least 2 of those and any other reason — unless a rule even beside a person’s reasons holds

    unknown
  4. declared in-range user-triggered

    user-directed-agent
  5. declared in-range

    crawler
  6. bot-auth-valid agent-signature even beside a person’s reasons

    user-directed-agent
  7. bot-auth-valid declared even beside a person’s reasons

    user-directed-agent
  8. bot-auth-valid browser-family even beside a person’s reasons

    user-directed-agent
  9. bot-auth-valid headless-family even beside a person’s reasons

    user-directed-agent
  10. bot-auth-valid tool-family even beside a person’s reasons

    user-directed-agent
  11. declared impersonation

    scraper
  12. one-signature-many-keys no-asset-loads

    automated
  13. honeypot no-asset-loads

    scraper
  14. honeypot declared

    scraper
  15. honeypot one-signature-many-keys

    scraper
  16. headless-family no-asset-loads

    automated
  17. headless-family one-signature-many-keys

    automated
  18. headless-family honeypot

    scraper
  19. bot-auth-platform honeypot

    scraper
  20. bot-auth-platform declared even beside a person’s reasons

    automated
  21. bot-auth-platform browser-family even beside a person’s reasons

    automated
  22. bot-auth-platform headless-family even beside a person’s reasons

    automated
  23. bot-auth-platform tool-family even beside a person’s reasons

    automated
  24. headless-family assets-loaded even beside a person’s reasons

    automated
  25. headless-family beacon-seen even beside a person’s reasons

    automated
  26. tool-family no-asset-loads

    automated
  27. header-mismatch datacenter-address

    automated
  28. header-mismatch no-asset-loads

    automated
  29. stack-mismatch datacenter-address

    automated
  30. stack-mismatch no-asset-loads

    automated
  31. non-permuting-hello datacenter-address

    automated
  32. non-permuting-hello no-asset-loads

    automated
  33. datacenter-address no-asset-loads

    automated
  34. anything else

    unknown

What Nemel never reads

What Nemel keeps of a visit

In the store for 30 days, in backups for up to 7 more; a machine’s visit also goes back to this site’s analytics as an $http_log event, as it would to yours.

This page also runs PostHog, as your site does, so your own visit shows what the page’s ping reported of PostHog. PostHog’s script reads what analytics scripts read — the screen and window size, the user agent, the language, the time zone; this project discards your address. The lists above are Nemel’s.

How ShaderGhost’s kind of tracking works, and why we refuse it ↗

On your site

How Nemel sees your requests

On Cloudflare
One Worker on your route and a Tail Worker beside it, deployed with one command each. The Worker adds a trace header to your pages; for Safari and iOS browsers arriving from outside your site it also writes one tag into the page’s head. Nothing else in your page changes.
On any other server
A small library in your application does the same (Python and WSGI today): the trace header on every page, and the one tag in the head when Safari or an iOS browser arrives from outside your site. A log shipper sends us your proxy’s access log (Traefik’s today).
In every case
Nothing runs in your visitors’ browsers but the analytics you already have, and a small script beside it that puts the trace on its events and sends us a ping when the page has loaded.